Mr. Abimbola Adeseyoju, the Managing Director of DataPro Limited, speaks on Nigeria’s effort to drive the Data Protection compliance regime as well as the fundamentals of Data Protection and Privacy in line with the NDPR as part of activities to mark the Data Privacy Day
Nigeria’s biggest Regulatory Compliance Solutions Company and one of the licensed Data Protection Compliance Organizations (DPCOs) joined the rest of the world on 28th of January, 2021 to celebrate Data Privacy Day.
The day is set aside every year to raise consciousness about individual’s right to privacy of personal data and the regulatory obligations of those who collect and process personal data.
The issuance of the Nigeria Data Protection Regulation (NDPR) in 2019 showcased Nigeria’s commitment to Data Protection and Privacy of its citizens.
To commemorate the 2021 celebration, Mr. Abimbola Adeseyoju, the Managing Director of DataPro Limited, speaks on Nigeria’s effort to drive the Data Protection compliance regime as well as the fundamentals of Data Protection and Privacy in line with the NDPR. Excerpts below:
The NDPR was issued on 25th January 2019 to drive Data Protection & Privacy Compliance. Two years later, what achievements has the regime recorded?
The issuance of the NDPR 2019 saw Nigeria record a significant growth in Data Protection & Privacy compliance. Between 2019 and 2020, National Information Technology Development Agency (NITDA), the regulatory agency charged with driving Data Protection compliance in Nigeria, received audit fillings from 635 entities warehoused on its NDPR portal, a verifiable database. Based on the audit report filings received, the financial services sector recorded the highest level of compliance with audit report filing.
Managing Director, DataPro Limited
Notably, the Data Protection Compliance market recorded revenue upwards of N2.2b between 2019 and 2020. NITDA also licensed 70 Data Protection Compliance Organisations (DPCOs), of which DataPro Limited is one, to provide Data Protection compliance services, audit and training for Data Controllers and Processors among other functions, thereby creating 2686 jobs.
In the performance of its oversight function, NITDA issued 230 compliance and enforcement notices. The regulator also conducted 15 investigations on alleged data breaches.
With the achievements recorded so far, DataPro predicts a higher level of compliance with the regulation, as corporate entities become increasingly aware of their obligations in regard to Data Protection and Privacy.
What is the impact of the NDPR 2019 on organisations in Nigeria?
Similarly, Data Controllers and Processors who process the personal data of more than 2000 data subjects in a period of 12 months are required to conduct an annual Data Protection Audit and file the report with NITDA. This is to showcase their level of compliance with the provisions of the NDPR.
Furthermore, with the advent of the NDPR, it has become expedient for organisations to only collect relevant data necessary for the purpose of their business relationship with data subjects and maintain transparency in the processing of data.
How has the COVID – 19 pandemic affected Data Protection?
Data subject have a right to access their personal data
The COVID-19 pandemic has disrupted the traditional way of doing business. Many organisations have resorted to working remotely, which has posed significant data privacy risks as a lot of personal information is being obtained and processed over less secured networks.
As a result, organisations have become more susceptible to data breaches. To mitigate the risk of data breaches, organisations have been challenged to beef up security measures in order to ensure that their digital platforms are highly secured against cyber threats.
With the heightening of cyber-security issues, organisations are required to be forward looking and employ creative security measures.
The prevailing situation which has forced organisations to adopt stringent cyber security measures will subsequently help improve data security standards.
What are the rights of Nigerians under the NDPR?
The NDPR dictates several rights for Data subjects. The rights include:
The right of access – Data subjects have the right to access their personal data being processed by a Data Controller or Processor.
The right to rectification – Data subjects have the right to request for the correction of inaccurate personal data and to have incomplete personal data updated without delay.
The right to erasure – Data subjects have the right to request the erasure of their personal data from a Data Controller and Processor system.
The right to restrict processing – Data subjects have the right to request Data Controllers and Processors restrict the processing of their personal data under certain circumstances.
The right to data portability – Data subjects have the right to request a transfer of their personal data from one Data Controller or Processor to another.
The right to object to processing – Data subjects have the right to object to the processing of their personal data under certain circumstances.
The rights in relation to automated decision making and profiling – Data subjects have the right to object to a decision solely based on automated profiling or decision making, which significantly affects them.
It is important that Nigerians are aware that to exercise any of these rights, they must contact the Data Controller or Processor managing their personal data.
What notable steps have been taken by the regulator to drive the NDPR compliance regime?
One of the notable steps taken by NITDA in the quest to drive data protection compliance is the fining of a public institution the sum of N1,000,000.00 naira for personal data breach offence, making it the first sanctioned entity since the issuance of the NDPR. This move reinforced the government’s commitment to safeguarding the data of Nigerian citizens. It has also propelled compliance with Data Protection and Privacy among corporate organisations.
Additionally, the regulator served 51 enforcement notices on Data Controllers perceived to have breached the provisions of the NDPR 2019. It also served 180 compliance notices on Ministries, Departments and Agencies of the Nigerian Government.
Likewise, NITDA inaugurated a Data Breach Investigation team in conjunction with the Office of the Inspector General of Police to conduct effective investigation of data breach and misuse. The NDPR portal was also launched to enable reporting of data breaches.
The steps taken so far to enforce Data Protection compliance in Nigeria is commendable and showcases NITDA’s commitment to ensuring that Nigeria continues to improve on its current standing as relating to Data Protection and Privacy.
For further information and details on Data Protection and your Data Privacy rights please visit the following sites: