Posts

DATA PROCESSORS; THE RULES OF ENGAGEMENT UNDER NIGERIAN LAW

By Aderonke Alex-Adedipe and Eustace Aroh

DOWNLOAD PUBLICATION

The requirement to leverage on third party service providers for the dissemination of products and services has remained in constant demand for businesses. With the continuously increasing number of data-driven businesses around the world,  engaging third party data processors to process the personal data of customers has also become relevant. Given the emerging rules surrounding the protection of personal data, it is also crucial for a business (“Controller”) to understand certain steps which should be taken before engaging the services of a data processor (“Processor”).  Today’s newsletter highlights a few of these steps to ensure compliance with the Nigerian Data Protection Regulations 2019 (“NDPR“).

  1. Researching Applicable Law.

It is important for the company to, first and foremost, conduct research into the applicable laws. This is relevant as there are certain restrictions on the processing of personal data. For instance, the following restrictions apply to the processing of personal data;

  • Sensitive personal data cannot be processed except with the consent of the data subjects[i]
  • Bank Verification Number of individuals can only be processed for banking purposes and cannot be stored or processed outside Nigeria.[ii]
  • Personal data cannot be transferred to countries which are not on the whitelist without the specific consent of the data subject[iii]

2. Conducting a DPIA

It is also important to conduct a Data Protection Impact Assessment (DPIA). A DPIA is an assessment conducted to identify, evaluate and minimize the possible risks associated with a data processing activity. Prior to engaging the services of a Processor, it is prudent for the Controller to assess the potential risks attributable to the processing activity. This can be carried out by a Data Protection Officer or a licensed Data Protection Compliance Organisation (DPCO). This is particularly more important where it is a new business process or activity which would involve the use of sensitive information or heavy use of personal information of individuals. Generally, the DPIA will enable the Controller identify the risks and mitigate such risks.

3. Audit of the Service Provider

Under the Nigeria Data Protection Regulation (NDPR), the Controller is responsible for ensuring that the Processor has complied with the provisions of the NDPR. Consequently, before a Processor is engaged, the Controller is required to conduct an audit/ of the practices of the Processor to ensure that the Processor generally complies with the NDPR and any other applicable data protection laws in relation to collection, storage and other processing activities. This is also imperative because the Controller and Processor will be jointly liable for the acts or omissions of the Processor.

The audit may be conducted by sharing a questionnaire requesting responses and evidence on relevant data privacy matters as well as conducting an on-site inspection by a representative of the Controller.

4. Entering into a Data Processing Agreement

A company engaging a Processor is expected to enter into a contract with the Processor, containing provisions which ensure that the Processor:

  • only processes personal data as instructed by the Controller;
  • adopts adequate security measures to prevent a data breach;
  • together with its employees, are under confidentiality obligations;
  • do not engage a sub processor without the consent of the Controller and subject to compliance with the law;
  • assists the company to comply with the Data Subject rights;
  • assists the company in the event of a breach (notification of the National Data Protection Bureau and the data subject) or conducting a DPIA;
  • deletes the data upon conclusion of the engagement;
  • provides evidence of compliance with the NDPR including allowing and contributing to audits and inspections.

Conclusion

The President of Nigeria recently approved the establishment of the Nigeria Data Protection Bureau (NDPB), a government agency precisely dedicated to promoting and implementing the NDPR and other data privacy issues, previously within the scope of the National Information Technology Development Agency.[iv]

With the growing awareness of data protection in Nigeria, companies are expected to adopt proper steps before engaging Processors to ensure their compliance with the data privacy laws.

[i] Article 5.3.1 NDPR Implementation Framework

[ii] Article 1.9 Central Bank of Nigeria Regulatory Framework for Bank Verification Number (BVN) Operations and Watch-list for the Nigerian Banking Industry

[iii] Article 2.12 of the NDPR and 7.2 of the NDPR Implementation Framework

[iv] The website of the NDPB is https://www.ndpb.gov.ng/

THE REGULATION OF DATA IN NIGERIA: CROSS-BORDER TRANSFER OF DATA

By Seun Timi-Koleolu and Eustace Aroh

 

INTRODUCTION

In today’s world, the commonly used phrase “the world is your oyster” can now be taken literally by businesses. With the use of technology and data analytics, companies can now reach customers across borders with products/ services tailored to meet the peculiar needs of customers in various countries.

As data analytics has become a pivotal part of most businesses, understanding the regulatory framework for proper data usage is imperative. More specifically for local and multinational companies playing in the Nigerian market, understanding the requirements of Nigerian data protection laws for cross border transactions is key.

In this article we have set out in a simplified manner the requirements of the Nigerian data protection laws for cross border transactions.

 

1. WHAT ARE THE APPLICABLE REGULATIONS?

The primary regulations are the Nigeria Data Protection Regulation (NDPR) and the NDPR Implementation Framework.

 

2. WHAT TYPE OF DATA IS SUBJECT TO REGULATIONS ON CROSS-BORDER TRANSFER?

Any personal information that can be used to identify a Nigerian citizen (Personal Data) is regulated under the NDPR and subject to the restrictions on cross-border transfer. Please note that anonymised data is excluded from the restrictions on data transfer in Nigeria.

 

3. WHEN IS A CROSS-BORDER TRANSFER CONSIDERED TO HAVE OCCURRED?

A company will be considered to have transferred data outside Nigeria where the company:

i.   hosts or transfers data to a database maintained by a company located outside Nigeria (Foreign Company);

ii.  grants staff and/or other third parties of a Foreign Company access to Personal Data; or

iii. relies on a Foreign Company for technical support and in the process grants that company access to the personal data of Nigerians.

 

4. ARE THERE COUNTRIES DEEMED AS HAVING ADEQUATE DATA PROTECTION LAWS UNDER NIGERIAN LAW?

Yes,  countries deemed to have adequate data protection laws are included on a white list contained in the NDPR framework. These include, all African countries who are signatories to the Malabo Convention 2014; all EU and European Economic Area Countries; United States of America; Japan and many more.

 

5. ARE COMPANIES IN NIGERIA FREE TO TRANSFER DATA TO COUNTRIES ON THE WHITE LIST?

Yes, but prior to such a transfer, the companies are expected to enter into data transfer agreements with the Foreign Company detailing the terms of the transfer and the measures to be adopted by the Foreign Company to protect the Personal Data received.

 

6. CAN A COMPANY IN NIGERIA TRANSFER TO COUNTRIES NOT LISTED ON THE WHITE LIST?

Yes, they will however be required to: (i) notify the individual whose data is being transferred of the risk involved in transferring data to a country without adequate level of protection; (ii) obtain the individual’s consent; and (iii) enter into a data transfer agreement with the Foreign Company prior to any such transfer.

 

7. DOES THE REQUIREMENT FOR CROSS-BORDER TRANSFER OF DATA DIFFER WHEN THE TRANSFER IS BETWEEN COMPANIES WITHIN THE SAME GROUP/SUBSIDIARIES?

Yes, to share personal data with companies within the same group, the transferring company is required to execute a Binding Corporate Rule (BCR) or  include Standard Contracting Clauses (SCC) in data transfer agreements. These documents can be provided by licensed Data Protection Compliance Organisations in Nigeria.

 

CONCLUSION

A company that complies with the foregoing requirements of Nigerian law when transferring data out of Nigeria would avoid incurring substantial financial penalties from the National Information Technology Development Agency (NITDA).

It is pertinent to note that companies (both local and foreign) handling data of over 1000 Nigerian citizens are required to engage the services of a licensed Data Protection Compliance Organisation to review their activities and make recommendations geared towards ensuring compliance.

For clarity on the foregoing article,  you may contact Pavestones Legal via info@pavestoneslegal.com. Pavestones Legal is one of the few licensed Data Protection Compliance Organisations in Nigeria and is also a full-service law practice providing support to both local and foreign clients.

THE REGULATION OF TECHNOLOGY COMPANIES IN NIGERIA – THE PROPOSED NITDA ACT 2021

DOWNLOAD PUBLICATION

By Seun Timi-Koleolu and Eustace Aroh

The National Information Technology Development Agency (NITDA) was created under the NITDA Act 2007 (the “Act”) to implement the Nigerian Information Technology Policy and coordinate general Information Technology development in Nigeria. NITDA, however, recently shared a proposed law with stakeholders titled the National Information Technology Development Agency Act 2021 (the “Bill”) which if enacted would repeal and replace the Act.

In addition to repealing the Act, the bill seeks to establish a framework for mandatory licenses to be obtained by Technology companies from NITDA; expand the regulatory oversight of NITDA; and generally, foster the development of the Nigerian information technology sector and the digital economy. In this article, we have analysed the provisions of the Bill.

  1. Companies to be Regulated

The Bill grants power to NITDA to regulate and license companies involved in digital services, products and platforms. This includes companies that use any digitally enabled system in the provision of service or products; and companies that carry out a business within the information technology space in Nigeria.

  1. Licensing and Registration Requirement

One of the major changes proposed under the Bill is the introduction of mandatory licenses to be obtained by companies regulated by it.  More specifically, it states that operators within the information technology and digital economy sector are to apply and obtain licences and authorisation from NITDA to operate. Furthermore, it provides that companies that fail to obtain the requisite license may be guilty of an offence and subject to a fine of N30,000,000 or imprisonment of its principal officers.

The Bill seeks to create three categories of licenses namely: (i) Product Licence, (ii) Service Provider Licence; and (iii) Platform Provider Licence. The Bill, however, does not clearly state the factors that would be considered by NITDA in determining which of the licenses a company is to obtain.

In addition to issuing licences,  the Bill empowers NITDA to maintain a register of operators within the information technology and digital economy sector and publish the register for the general public’s information.

  1. Tech Companies to be Levied

Similar to the Act, the Bill establishes the National Information Technology Development Fund (NITDF) to be used for advancing the nation’s digital economy objectives and related purposes. The NITDF will be funded by a levy of 1% of the profit before tax of regulated companies, amongst other funding sources set out in the Bill.

It is pertinent to note, that the existing Act already requires certain companies to pay a similar levy to NITDA which was however limited. The Bill now seeks to extend the list of the companies required to pay levies as follows:

i.mobile and fixed telecommunications companies;

ii.information technology, e-commerce companies; (new)

iii.digital platform operators and providers; (new)

iv.foreign digital platforms targeting the Nigerian market; (new)

v.pensions managers and pension-related companies;

vi.banks, financial institutions and companies providing financial services using information technology tools;

vii.insurance companies; and

viii.such other companies and enterprises as determined by regulations from time to time by the Agency. (new)

  1. Other Notable Changes

The Bill seeks to empower the NITDA, with support from the Standard Organisation of Nigeria, to develop standard requirements for operators within the information technology space. The Bill also confers a duty on NITDA to regulate amongst other things, the use of digital signature and digital contracts; and the use of data for business analytics and intelligence.

Conclusion

An Act that seeks to uniformly and fairly regulate the technology sector and startup space in Nigeria would be a welcome development. The Bill appears to be an attempt at achieving this uniformity. This, however, cannot be achieved by NITDA in silos. The effect of a standalone regulation like the Bill is that companies in the tech space in Nigeria would be over-regulated and weighed down with excessive levies and licensing requirements.

To successfully regulate the Tech space, NITDA must work with other regulators such as the Central Bank of Nigeria, the Securities and Exchange Commission, the Nigerian Communications Commission, and the National Insurance Commission to streamline licences, levies and develop regulations that adequately govern the activities of Tech companies without stifling their growth.

In addition to the foregoing, there are certain ambiguous terms in the Bill that should be clarified which includes terms like “operators within the information technology and digital economy”, “foreign digital platforms targeting the Nigerian market” and “digital economy”. Furthermore, the licensing categories to be established by the Bill should be clarified to ensure companies are clear on the licence they are to obtain.

5 THINGS TO DO TO MONITOR YOUR COMPANY’S DATA PROTECTION PRACTICES IN NIGERIA

DOWNLOAD PUBLICATION

By Seun Timi-Koleolu and Eustace Aroh 

Introduction

As data usage in Nigeria is fast becoming an inevitable part of business practices, the regulatory oversight of the National Information Technology Development Agency (NITDA) in protecting personal information now cuts across most sectors of the economy. More than ever before, it is important that all companies assess their practices in view of the Nigeria Data Protection Regulation (NDPR) to avoid penalties which could be as much as 1-2% of the annual revenue of the company.

In assessing the level of compliance by companies with the NDPR, NITDA requires companies to engage a licensed Data Protection Compliance Organisation (DPCO) to conduct a data protection audit and file the report with NITDA. Although the deadline for data protection audits for the audit year of 2020 to 2021 lapsed on June 30, 2021, companies who are yet to carry out the audit are encouraged to engage a DPCO who is empowered to apply and obtain specific extension for each company.

Companies who have been audited and therefore in good standing, are expected to continuously monitor their data protection practices, ensuring they remain compliant. In this article, we have itemised five things companies should do to properly monitor their data protection practices.

1. Appoint a Data Protection Officer

Any company or organisation that meets the following criteria is expected to appoint a Data Protection Officer (DPO) within 6 months of commencing operation. The company:

  1. processes personal information of over 10,000 Nigerians;
  2. processes sensitive personal information in the regular course of its business;
  3. processes critical national information; or
  4. is a government agency or ministry.

The DPO is to be knowledgeable in data protection; and will be responsible for monitoring compliance with the NDPR, advising the management, employees and third-party privy to personal information, and acting as the primary contact person for NITDA.

2. Conduct Data Protection Impact Assessment

A data protection impact assessment (DPIA) is a process carried out by the DPO to assess and minimise the possible risk to a data processing activity. For a company launching a new business process or activity which would involve the use of sensitive information or heavy use of personal information of individuals, the DPO of the company is to carry out a DPIA to identify, evaluate and minimise possible data protection risks. This will help companies address the risks in the processes and ensure continuous compliance with the NDPR.

3. Carry Out Regular Internal Audit

A company may monitor its compliance level by carrying out a periodic internal audit of its data protection practices to map, identify systems and improve these practices.

4. Conduct Periodic Due Diligence on Third Party

Under the NDPR, a company that qualifies as a data controller will be responsible for the actions of its data processors (data administrators) i.e. third parties using personal information to provide services to the business. Consequently, companies are expected to conduct due diligence on the third party to ensure their data processing practices are in line with the NDPR.

5. Submit to an Audit by a Licensed Data Protection Compliance Organisation

All companies that collect or process the personal information of over 1,000 individuals are required to submit to a data protection audit by a DPCO. The DPCO shall review the data protection documentation of the company, assess the systems and practices of the company and assess the knowledge of the staff before providing recommendations.

Conclusion

It is advisable for companies with the personal information of Nigerians (including foreign companies) to ensure such information is processed in compliance with the NDPR to avoid regulatory sanctions. These companies are further advised to implement these five steps to ensure their continued compliance with the NDPR.

Pavestones is a full-service law practice and a licensed DPCO supporting Nigerian and foreign clients. For more articles on data protection or clarity on our article above, contact Pavestones at info@pavestoneslegal.com

Data Protection In Nigeria; Impact On Open Banking Regulation

By Aderonke Alex-Adedipe and Eustace Aroh

Introduction

The rapid growth of finance and technology (fintech) companies in the last decade have been necessitated by consumers’ needs for faster and more convenient financial services. These needs continue to evolve over time and traditional financial institutions struggle to keep up. Open banking offers financial institutions who have access to information of customers (“Providers”) the opportunity to share such information with other financial institutions (“Consumers”) to keep them aware of those needs and enable them offer optimum services.

In our previous article, we highlighted the provisions of the recent Central Bank of Nigeria’s (CBN) Regulatory Framework for Open Banking in Nigeria (“Framework”). In today’s article, we consider specifically, the implication of data sharing under the Framework in light of the Nigeria Data Protection Regulation 2019 (NDPR).

NDPR
The NDPR was issued by the National Information Technology Development Agency (NITDA) in 2019 to regulate the collection, processing and storage of personal data. Personal data is information relating to an individual who can be identified, directly or indirectly, in particular by reference to an identifier. It includes a name, address, a photo, an email address, bank details, medical information, IP address, IMEI number, IMSI number, SIM, and others.

Due to the fact that the damage an individual may suffer in the course of breach of some personal data may be higher, data such as ethnic and racial information, religious beliefs, biometric and health information are categorized as sensitive data. These data must, therefore, be subject to a higher level of protection. Although the NDPR does not classify financial data as sensitive data, financial institutions have access to a number of sensitive data such as ethnicity and biometrics.

Applicable Personal Data
Under the Framework, four types of data qualify for the open exchange of data. These are Product Information and Service Touchpoints (PIST), Market Insight Transactions (MIT), Personal Information and Financial Transaction (PIFT), Profile, Analytics and Scoring Transaction (PAST). Only the PIFT and PAST, however, involve the sharing of personal data of consumers amongst participants.

The PIFT deals with the sharing of customer’s information provided during the Know Your Customer (KYC) process and information of the customer’s transactions such as account balance, payments, loans, recurring transactions etc. The PAST involves the sharing of information on the customer which analyses, provides scores and gives an opinion on customer behaviour (profiling).

Safeguards of the Framework
The Framework stipulates a number of security standards and protocols with respect to sharing of personal information over the Application Programming Interface (API) as it relates to authentication, authorisation, encryption, and secure hosting of data. The Framework also provides for a risk management system for each participant to, among others, track the risk of data sharing with other participants, comply with data privacy laws such as the NDPR, and report such associated risks to the CBN.

Consent
Irrespective of the data protection requirements under the Framework, the Framework specifically requires participants to comply with all extant laws on data privacy such as the NDPR and the NDPR Implementation Framework. Under the NDPR, before personal data of a customer can be used for a purpose different from that which it was initially given, the data controller, (in this case, the financial institution) is required to inform the customer of:

  1. the purpose for which the data was originally collected;
  2. if there is any connection between the original purpose and the proposed purpose;
  3. the possible impact of the new processing on the data subject; and
  4. the existence of security safeguards to protect the data.

The Framework further requires participants to list the specific rights which customers may grant to the participants and obtain the consent of the customer for each right separately.

Providers are also expected to ensure that customers revalidate their consent annually or after 180 days in cases where the services of the provider have not been used.

Conclusion
While the Framework seeks to support innovation in the Nigerian financial sector, participants of the open exchange of data are expected to reassess their data privacy practices to ensure they meet data compliance requirements of the NDPR and the Framework.

Data Protection Update: Insights on the Data Protection Bill 2020

By Seun Timi-Koleolu and Olawale Atanda

The National Information and Technology Development Agency (“NITDA”) recently published the Draft Data Protection Bill 2020 (the “Bill”) for the input of stakeholders. The Bill, if enacted, will be an addition to the laws that govern the use and protection of the data in Nigeria.

The Bill seeks to establish a framework for the protection of personal data particularly to protect data subjects’ data vis-à-vis the use of such data by organisations and security agencies; establish a regulatory authority that will coordinate data protection and privacy issues and have oversight on data controllers and data processors; and ensure that personal data is processed in accordance with NITDA’s data protection principles.

The protections offered in the Bill are similar to those stated in the Nigeria Data Protection Regulation, 2019 (“NDPR”) issued by NITDA which regulate the collection and processing of data. However, the bill includes novel additions and expands on existing data protection rules which we have highlighted below.

 

Key Changes and Improvements in the Bill

  1. Scope of the Bill – The Bill builds on the scope of the NDPR by expressly listing the persons and bodies that will be subject to its provisions. These are: persons resident in Nigeria and Nigerian nationals irrespective of residence; public and private companies in Nigeria; unincorporated joint ventures or associations operating in Nigeria; any institution or body which maintains an office, branch or agency through which business activities are carried out in Nigeria; and foreign entities targeting persons resident in Nigeria.

 

  1. Categories of Data – The categories of data to be protected are expanded and include personal information such as religious affiliation, sexual orientation, and even trade union memberships. The Bill goes further to protect other personal information such as banking records, academic transcripts, health records, and personal subscription data. It should be noted that what constitutes personal data is not exhaustive under the Bill as it makes a provision for definitions to be included in guidelines to be made by the Data Protection Commission.

 

  1. Establishment of Data Protection Commission – The Bill seeks to establish a Data Protection Commission (the “Commission”) to enforce its provisions by regulating the processing of personal information; having oversight over data processors and controllers, amongst others. The powers of the Commission are similar to that of NITDA. It is important that there is a clear delineation of powers between the Commission and NITDA before the Bill is passed into law.

 

  1. Rights of a Data Subject – The Bill provides for persons to be notified within 48 hours after a data breach affecting them has been reported by the individual or body in possession of their data (“data controller”) to the Commission. The Bill, however, does not state when or how the data controller is to report to the Commission upon being aware of the breach of the data it controls.

 

  1. Penalties for Breach of Data Bill – The Bill strictly penalizes breaches of data by individuals/bodies, data controllers/processors, and staff of the Commission. The Bill provides for fines of up to ₦10,000,000.00 (Ten Million Naira) and imprisonment terms of up to 5 (five) years for persons or bodies convicted under the Bill. The Bill also provides for the forfeiture of assets by convicted persons under the Bill and allows for the compensation of victims of data breaches.

 

Conclusion.

The Bill, on its face, seems to repeat provisions already in the NDPR. It sheds light, however, on protections provided in the NDPR. There are also novel inclusions such as the Data Protection Commission and the significant expansion of penalties for data breaches. The Bill is in draft form and it is expected that NITDA would provide clarity on the questions that arise from the review of the Bill before it is passed into law.