Technology experts in Nigeria are calling on organisations to strengthen their data protection practices as the use of digital platforms for various transactions continues to grow. With the increasing collection and processing of personal information, experts stress that organisations must move beyond policy declarations and implement practical measures to ensure the safe handling of customer and employee data. This move is crucial in preventing risks such as fraud, identity theft, and unsolicited communications.

The Nigeria Data Protection Act (NDPA) requires organisations that collect personal data to put measures in place to protect that information and uphold the rights of data subjects. However, some organisations may struggle to translate privacy policies into practical systems that demonstrate compliance. According to Lagos-based technology entrepreneur Abraham Esandayinze Tanta, data protection should be treated as an everyday business responsibility rather than an issue addressed only during audits or after a data breach.

Weak data management practices can expose individuals to various risks, including fraud, identity theft, and unsolicited communications. Nigerians routinely provide organisations with personal information, including names, telephone numbers, identification documents, and financial records, through various digital platforms. Tanta noted that weak data management practices could have severe consequences for individuals, emphasising the need for organisations to take practical steps to protect personal information.

To address the challenges of implementing data protection practices, Tanta Innovative, a Lagos-based technology company, has developed Asiri, a data protection platform designed to help organisations manage privacy records, document incidents, and maintain evidence of compliance activities. The platform also enables organisations to work with licensed Data Protection Compliance Organisations (DPCOs) and Data Protection Officers (DPOs).

Industry stakeholders have noted that the growing digital economy has increased the need for organisations to account for how personal information is collected, stored, and used. Beyond regulatory compliance, customers are increasingly demanding transparency over who has access to their data and how organisations respond when incidents occur. This shift in Nigeria’s data protection environment requires organisations to adopt verifiable processes and records to demonstrate their implementation of privacy policies.

Experts have emphasised that data protection has to become operational, with businesses needing systems that help them know what they have, what they have done, and what evidence exists to support their claims. Tanta said that his company does not file regulatory submissions on behalf of organisations, noting that licensed professionals remain responsible. This approach ensures that organisations take ownership of their data protection practices and comply with regulatory requirements.

The trend reflects a broader shift in Nigeria’s data protection environment, where organisations are expected not only to adopt privacy policies but also to demonstrate their implementation through verifiable processes and records. As the digital economy continues to grow, organisations that prioritise data protection will be better positioned to build trust with their customers and stakeholders. By adopting practical measures for data protection, organisations can mitigate risks and ensure the safe handling of personal information.

Key points

  • Organisations must adopt practical measures to ensure the safe handling of customer and employee data.
  • The Nigeria Data Protection Act requires organisations to put measures in place to protect personal information and uphold the rights of data subjects.
  • Customers are increasingly demanding transparency over who has access to their data and how organisations respond when incidents occur.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.