Posts

DATA PROCESSORS; THE RULES OF ENGAGEMENT UNDER NIGERIAN LAW

By Aderonke Alex-Adedipe and Eustace Aroh

DOWNLOAD PUBLICATION

The requirement to leverage on third party service providers for the dissemination of products and services has remained in constant demand for businesses. With the continuously increasing number of data-driven businesses around the world,  engaging third party data processors to process the personal data of customers has also become relevant. Given the emerging rules surrounding the protection of personal data, it is also crucial for a business (“Controller”) to understand certain steps which should be taken before engaging the services of a data processor (“Processor”).  Today’s newsletter highlights a few of these steps to ensure compliance with the Nigerian Data Protection Regulations 2019 (“NDPR“).

  1. Researching Applicable Law.

It is important for the company to, first and foremost, conduct research into the applicable laws. This is relevant as there are certain restrictions on the processing of personal data. For instance, the following restrictions apply to the processing of personal data;

  • Sensitive personal data cannot be processed except with the consent of the data subjects[i]
  • Bank Verification Number of individuals can only be processed for banking purposes and cannot be stored or processed outside Nigeria.[ii]
  • Personal data cannot be transferred to countries which are not on the whitelist without the specific consent of the data subject[iii]

2. Conducting a DPIA

It is also important to conduct a Data Protection Impact Assessment (DPIA). A DPIA is an assessment conducted to identify, evaluate and minimize the possible risks associated with a data processing activity. Prior to engaging the services of a Processor, it is prudent for the Controller to assess the potential risks attributable to the processing activity. This can be carried out by a Data Protection Officer or a licensed Data Protection Compliance Organisation (DPCO). This is particularly more important where it is a new business process or activity which would involve the use of sensitive information or heavy use of personal information of individuals. Generally, the DPIA will enable the Controller identify the risks and mitigate such risks.

3. Audit of the Service Provider

Under the Nigeria Data Protection Regulation (NDPR), the Controller is responsible for ensuring that the Processor has complied with the provisions of the NDPR. Consequently, before a Processor is engaged, the Controller is required to conduct an audit/ of the practices of the Processor to ensure that the Processor generally complies with the NDPR and any other applicable data protection laws in relation to collection, storage and other processing activities. This is also imperative because the Controller and Processor will be jointly liable for the acts or omissions of the Processor.

The audit may be conducted by sharing a questionnaire requesting responses and evidence on relevant data privacy matters as well as conducting an on-site inspection by a representative of the Controller.

4. Entering into a Data Processing Agreement

A company engaging a Processor is expected to enter into a contract with the Processor, containing provisions which ensure that the Processor:

  • only processes personal data as instructed by the Controller;
  • adopts adequate security measures to prevent a data breach;
  • together with its employees, are under confidentiality obligations;
  • do not engage a sub processor without the consent of the Controller and subject to compliance with the law;
  • assists the company to comply with the Data Subject rights;
  • assists the company in the event of a breach (notification of the National Data Protection Bureau and the data subject) or conducting a DPIA;
  • deletes the data upon conclusion of the engagement;
  • provides evidence of compliance with the NDPR including allowing and contributing to audits and inspections.

Conclusion

The President of Nigeria recently approved the establishment of the Nigeria Data Protection Bureau (NDPB), a government agency precisely dedicated to promoting and implementing the NDPR and other data privacy issues, previously within the scope of the National Information Technology Development Agency.[iv]

With the growing awareness of data protection in Nigeria, companies are expected to adopt proper steps before engaging Processors to ensure their compliance with the data privacy laws.

[i] Article 5.3.1 NDPR Implementation Framework

[ii] Article 1.9 Central Bank of Nigeria Regulatory Framework for Bank Verification Number (BVN) Operations and Watch-list for the Nigerian Banking Industry

[iii] Article 2.12 of the NDPR and 7.2 of the NDPR Implementation Framework

[iv] The website of the NDPB is https://www.ndpb.gov.ng/

THE REGULATION OF TECHNOLOGY COMPANIES IN NIGERIA – THE PROPOSED NITDA ACT 2021

DOWNLOAD PUBLICATION

By Seun Timi-Koleolu and Eustace Aroh

The National Information Technology Development Agency (NITDA) was created under the NITDA Act 2007 (the “Act”) to implement the Nigerian Information Technology Policy and coordinate general Information Technology development in Nigeria. NITDA, however, recently shared a proposed law with stakeholders titled the National Information Technology Development Agency Act 2021 (the “Bill”) which if enacted would repeal and replace the Act.

In addition to repealing the Act, the bill seeks to establish a framework for mandatory licenses to be obtained by Technology companies from NITDA; expand the regulatory oversight of NITDA; and generally, foster the development of the Nigerian information technology sector and the digital economy. In this article, we have analysed the provisions of the Bill.

  1. Companies to be Regulated

The Bill grants power to NITDA to regulate and license companies involved in digital services, products and platforms. This includes companies that use any digitally enabled system in the provision of service or products; and companies that carry out a business within the information technology space in Nigeria.

  1. Licensing and Registration Requirement

One of the major changes proposed under the Bill is the introduction of mandatory licenses to be obtained by companies regulated by it.  More specifically, it states that operators within the information technology and digital economy sector are to apply and obtain licences and authorisation from NITDA to operate. Furthermore, it provides that companies that fail to obtain the requisite license may be guilty of an offence and subject to a fine of N30,000,000 or imprisonment of its principal officers.

The Bill seeks to create three categories of licenses namely: (i) Product Licence, (ii) Service Provider Licence; and (iii) Platform Provider Licence. The Bill, however, does not clearly state the factors that would be considered by NITDA in determining which of the licenses a company is to obtain.

In addition to issuing licences,  the Bill empowers NITDA to maintain a register of operators within the information technology and digital economy sector and publish the register for the general public’s information.

  1. Tech Companies to be Levied

Similar to the Act, the Bill establishes the National Information Technology Development Fund (NITDF) to be used for advancing the nation’s digital economy objectives and related purposes. The NITDF will be funded by a levy of 1% of the profit before tax of regulated companies, amongst other funding sources set out in the Bill.

It is pertinent to note, that the existing Act already requires certain companies to pay a similar levy to NITDA which was however limited. The Bill now seeks to extend the list of the companies required to pay levies as follows:

i.mobile and fixed telecommunications companies;

ii.information technology, e-commerce companies; (new)

iii.digital platform operators and providers; (new)

iv.foreign digital platforms targeting the Nigerian market; (new)

v.pensions managers and pension-related companies;

vi.banks, financial institutions and companies providing financial services using information technology tools;

vii.insurance companies; and

viii.such other companies and enterprises as determined by regulations from time to time by the Agency. (new)

  1. Other Notable Changes

The Bill seeks to empower the NITDA, with support from the Standard Organisation of Nigeria, to develop standard requirements for operators within the information technology space. The Bill also confers a duty on NITDA to regulate amongst other things, the use of digital signature and digital contracts; and the use of data for business analytics and intelligence.

Conclusion

An Act that seeks to uniformly and fairly regulate the technology sector and startup space in Nigeria would be a welcome development. The Bill appears to be an attempt at achieving this uniformity. This, however, cannot be achieved by NITDA in silos. The effect of a standalone regulation like the Bill is that companies in the tech space in Nigeria would be over-regulated and weighed down with excessive levies and licensing requirements.

To successfully regulate the Tech space, NITDA must work with other regulators such as the Central Bank of Nigeria, the Securities and Exchange Commission, the Nigerian Communications Commission, and the National Insurance Commission to streamline licences, levies and develop regulations that adequately govern the activities of Tech companies without stifling their growth.

In addition to the foregoing, there are certain ambiguous terms in the Bill that should be clarified which includes terms like “operators within the information technology and digital economy”, “foreign digital platforms targeting the Nigerian market” and “digital economy”. Furthermore, the licensing categories to be established by the Bill should be clarified to ensure companies are clear on the licence they are to obtain.

DATA PROTECTION IN NIGERIA: DISTINGUISHING BETWEEN A DATA CONTROLLER AND A DATA PROCESSOR

By Seun Timi-Koleolu and Praise Adetunmibi

 

DOWNLOAD PUBLICATION

Introduction

In this digital age, data has become a vital asset for both individuals and corporate bodies. It has in fact been regarded as the world’s most valuable resource[1]. The question then is, what is data?

Data can simply be defined as information that has been translated into a form that is efficient for movement or processing[2]. It can be collected, used, shared, measured, analysed, stored and destroyed (data processing). The most common type of data is personal data, which refers to any information related to an identified or identifiable natural person. In Nigeria, the National Information Technology Development Agency (NITDA) through the Nigeria Data Protection Regulation (NDPR)[3], regulates the processing of personal data of Nigerian citizens. Persons who engage in data processing activities can either be Data Controllers or Data Processors.

Under the NDPR, startups, businesses and companies that engage in the processing of personal data of over 1000 Nigerians, are mandated to conduct a detailed annual audit of their data processing activities. This audit is to be conducted by a licensed Data Protection Compliance Organisation (DPCO). Failure to comply with the provisions of the NDPR will result in the payment of a fine of 10 million Naira or 2% of the annual turnover (whichever is greater).

In view of the foregoing, it is useful to understand when you will be considered as a data processor and when you will be considered to be a data controller; for the purpose of complying with the provisions of the NDPR. In this article, we have provided a guide on how to identify each category.

Who is a data controller?

A data controller simply means any person or company that determines “why” data is to be processed and “how” data is to be processed. Most businesses/companies collect the personal data of clients/customers in the course of providing services to them (e.g. by requiring the customers to complete an online or physical, registration form for the service or for the purpose of payment); in all such instances that company/business is a data controller.

Furthermore, where companies/businesses share personal details of their customers, such as names, email addresses, phone numbers to third-party service providers, for various business purposes such as to market their products  (e.g. sharing with a Digital Marketing Agency); or to enhance their service delivery (e.g. sharing with an Information Technology Partner), that company/business remains the data controller in those instances and primarily responsible for the use and protection of the data.

In addition, companies and business owners are data controllers of data they collect in respect of their employees and remain primarily responsible for the use of such data.

Who is a data processor?

Companies/businesses are regarded as data processors when they are involved in the processing of data, on the instruction and on behalf of another person (data controller). Effectively, a data processor cannot act on its own or undertake any data processing activity without the permission of the data controller.

In the scenarios given above, the Digital Marketing Agency and Information Technology Partner are data processors. Also, where a company outsources payroll payment to a third party or other human resource related services, that third party would be seen as the data processor.

Can a data processor be a data controller?

Yes. What distinguishes a data controller from a data processor is control. Where you have control over which data is to be collected and the purpose for which the data is to be collected, you are the data controller. Where all you have is the possession of the data and must act in accordance with the instructions of another person, then you are the data processor.

Where you, however, have both control and possession of data (i.e. the data was given to you by a third party), in such an instance, you act as both a data controller and a data processor.

Conclusion

Under Nigerian law, data controllers and data processors are required to undergo Data Protection Compliance audits and generally adhere to the provisions of the NDPR. Each business should be clear on whether they are handling data in the capacity of a data controller or a data processor as the obligations of a data controller vary from the obligations of a data processor.

If you require clarity as to whether your business would be categorised as a data controller or a data processor, please do not hesitate to contact the team at Pavestones Legal.

[1] The Economist, ‘The World’s Most Valuable Resource is no Longer Oil, but Data’   Economist (6 May 2017) <https://www.economist.com/leaders/2017/05/06/the-worlds-most-valuable-resource-is-no-longer-oil-but-data>

[2] https://searchdatamanagement.techtarget.com/definition/data

[3] To understand more about the NDPR, follow the link to our article https://pavestoneslegal.com/nigeria-data-protection-regulation-2019/

Data Protection In Nigeria; Impact On Open Banking Regulation

By Aderonke Alex-Adedipe and Eustace Aroh

Introduction

The rapid growth of finance and technology (fintech) companies in the last decade have been necessitated by consumers’ needs for faster and more convenient financial services. These needs continue to evolve over time and traditional financial institutions struggle to keep up. Open banking offers financial institutions who have access to information of customers (“Providers”) the opportunity to share such information with other financial institutions (“Consumers”) to keep them aware of those needs and enable them offer optimum services.

In our previous article, we highlighted the provisions of the recent Central Bank of Nigeria’s (CBN) Regulatory Framework for Open Banking in Nigeria (“Framework”). In today’s article, we consider specifically, the implication of data sharing under the Framework in light of the Nigeria Data Protection Regulation 2019 (NDPR).

NDPR
The NDPR was issued by the National Information Technology Development Agency (NITDA) in 2019 to regulate the collection, processing and storage of personal data. Personal data is information relating to an individual who can be identified, directly or indirectly, in particular by reference to an identifier. It includes a name, address, a photo, an email address, bank details, medical information, IP address, IMEI number, IMSI number, SIM, and others.

Due to the fact that the damage an individual may suffer in the course of breach of some personal data may be higher, data such as ethnic and racial information, religious beliefs, biometric and health information are categorized as sensitive data. These data must, therefore, be subject to a higher level of protection. Although the NDPR does not classify financial data as sensitive data, financial institutions have access to a number of sensitive data such as ethnicity and biometrics.

Applicable Personal Data
Under the Framework, four types of data qualify for the open exchange of data. These are Product Information and Service Touchpoints (PIST), Market Insight Transactions (MIT), Personal Information and Financial Transaction (PIFT), Profile, Analytics and Scoring Transaction (PAST). Only the PIFT and PAST, however, involve the sharing of personal data of consumers amongst participants.

The PIFT deals with the sharing of customer’s information provided during the Know Your Customer (KYC) process and information of the customer’s transactions such as account balance, payments, loans, recurring transactions etc. The PAST involves the sharing of information on the customer which analyses, provides scores and gives an opinion on customer behaviour (profiling).

Safeguards of the Framework
The Framework stipulates a number of security standards and protocols with respect to sharing of personal information over the Application Programming Interface (API) as it relates to authentication, authorisation, encryption, and secure hosting of data. The Framework also provides for a risk management system for each participant to, among others, track the risk of data sharing with other participants, comply with data privacy laws such as the NDPR, and report such associated risks to the CBN.

Consent
Irrespective of the data protection requirements under the Framework, the Framework specifically requires participants to comply with all extant laws on data privacy such as the NDPR and the NDPR Implementation Framework. Under the NDPR, before personal data of a customer can be used for a purpose different from that which it was initially given, the data controller, (in this case, the financial institution) is required to inform the customer of:

  1. the purpose for which the data was originally collected;
  2. if there is any connection between the original purpose and the proposed purpose;
  3. the possible impact of the new processing on the data subject; and
  4. the existence of security safeguards to protect the data.

The Framework further requires participants to list the specific rights which customers may grant to the participants and obtain the consent of the customer for each right separately.

Providers are also expected to ensure that customers revalidate their consent annually or after 180 days in cases where the services of the provider have not been used.

Conclusion
While the Framework seeks to support innovation in the Nigerian financial sector, participants of the open exchange of data are expected to reassess their data privacy practices to ensure they meet data compliance requirements of the NDPR and the Framework.

Data Protection Update: Insights on the Data Protection Bill 2020

By Seun Timi-Koleolu and Olawale Atanda

The National Information and Technology Development Agency (“NITDA”) recently published the Draft Data Protection Bill 2020 (the “Bill”) for the input of stakeholders. The Bill, if enacted, will be an addition to the laws that govern the use and protection of the data in Nigeria.

The Bill seeks to establish a framework for the protection of personal data particularly to protect data subjects’ data vis-à-vis the use of such data by organisations and security agencies; establish a regulatory authority that will coordinate data protection and privacy issues and have oversight on data controllers and data processors; and ensure that personal data is processed in accordance with NITDA’s data protection principles.

The protections offered in the Bill are similar to those stated in the Nigeria Data Protection Regulation, 2019 (“NDPR”) issued by NITDA which regulate the collection and processing of data. However, the bill includes novel additions and expands on existing data protection rules which we have highlighted below.

 

Key Changes and Improvements in the Bill

  1. Scope of the Bill – The Bill builds on the scope of the NDPR by expressly listing the persons and bodies that will be subject to its provisions. These are: persons resident in Nigeria and Nigerian nationals irrespective of residence; public and private companies in Nigeria; unincorporated joint ventures or associations operating in Nigeria; any institution or body which maintains an office, branch or agency through which business activities are carried out in Nigeria; and foreign entities targeting persons resident in Nigeria.

 

  1. Categories of Data – The categories of data to be protected are expanded and include personal information such as religious affiliation, sexual orientation, and even trade union memberships. The Bill goes further to protect other personal information such as banking records, academic transcripts, health records, and personal subscription data. It should be noted that what constitutes personal data is not exhaustive under the Bill as it makes a provision for definitions to be included in guidelines to be made by the Data Protection Commission.

 

  1. Establishment of Data Protection Commission – The Bill seeks to establish a Data Protection Commission (the “Commission”) to enforce its provisions by regulating the processing of personal information; having oversight over data processors and controllers, amongst others. The powers of the Commission are similar to that of NITDA. It is important that there is a clear delineation of powers between the Commission and NITDA before the Bill is passed into law.

 

  1. Rights of a Data Subject – The Bill provides for persons to be notified within 48 hours after a data breach affecting them has been reported by the individual or body in possession of their data (“data controller”) to the Commission. The Bill, however, does not state when or how the data controller is to report to the Commission upon being aware of the breach of the data it controls.

 

  1. Penalties for Breach of Data Bill – The Bill strictly penalizes breaches of data by individuals/bodies, data controllers/processors, and staff of the Commission. The Bill provides for fines of up to ₦10,000,000.00 (Ten Million Naira) and imprisonment terms of up to 5 (five) years for persons or bodies convicted under the Bill. The Bill also provides for the forfeiture of assets by convicted persons under the Bill and allows for the compensation of victims of data breaches.

 

Conclusion.

The Bill, on its face, seems to repeat provisions already in the NDPR. It sheds light, however, on protections provided in the NDPR. There are also novel inclusions such as the Data Protection Commission and the significant expansion of penalties for data breaches. The Bill is in draft form and it is expected that NITDA would provide clarity on the questions that arise from the review of the Bill before it is passed into law.