The Nigeria Data Protection Act 2023 put data protection on a statutory footing and established the Nigeria Data Protection Commission (NDPC) as the regulator. It applies to public institutions as well as private companies. For government systems, which often hold the most complete records citizens have, the Act turns good practice into obligation.

Much of the Act is written for lawyers and data protection officers. Much of what it requires, though, can only be delivered by the people who design and run systems.

Lawful basis is a design decision

#

Personal data may only be processed on a lawful basis, such as consent, a contract, a legal obligation, vital interests, a task carried out in the public interest or under official authority, or legitimate interests. Public bodies typically rely on legal obligation or public task. Whichever applies, it should be recorded for each purpose, and the system should collect only what that purpose needs.

  • Make every field on a form justify itself against a stated purpose.
  • Separate data collected for different purposes, so access and retention can differ.
  • Record the lawful basis alongside the data model, not only in a policy document.

Impact assessments belong at the start

#

Where processing is likely to result in a high risk to people's rights and freedoms, a data protection impact assessment is required before processing begins. Large-scale processing of sensitive data, systematic monitoring and new technologies are typical triggers. Done early, an impact assessment changes the design. Done after go-live, it only documents risks that are now expensive to remove.

Breach notification depends on detection

#

The Act requires controllers to notify the Commission of a personal data breach likely to pose a risk to individuals within 72 hours of becoming aware of it, and in some cases to inform the people affected. Seventy-two hours is only achievable if the system can tell you that something has happened, and what data was involved.

  • Log access to personal data in a way that can be searched, and protect the logs.
  • Alert on unusual access patterns, not only on outages.
  • Know which datasets each system holds, so the scope of a breach can be assessed quickly.
  • Rehearse the response, including who decides whether a breach is notifiable.

Rights, retention and processors

#

People can ask to access, correct or, in some circumstances, erase their data, and can object to certain processing. Systems should be able to find all records about one person and act on them without manual database work. Retention periods should be enforced by the system, and contractors that process data on your behalf need contracts that bind them to the same standards.

Accountability means evidence

#

The Act expects controllers to be able to demonstrate compliance, not only to assert it. For a public institution that means knowing what personal data each system holds, why, on what basis, who can access it and how long it is kept, and being able to show the regulator or an affected citizen.

Most of that evidence can be produced by the systems themselves if they are designed to: data inventories generated from schemas, access reports from identity systems, retention enforced and logged by scheduled jobs. Evidence assembled by hand before an inspection is expensive and rarely complete.

Questions for your next system

#
  1. What is the purpose and lawful basis for each category of personal data it collects?
  2. Does this processing need an impact assessment, and has it been done before design is fixed?
  3. Who can see what, and how is that reviewed?
  4. How would we know within hours, not weeks, if data were accessed without authorisation?
  5. How do we find, export, correct or delete one person's records?
  6. When is data deleted, and what enforces it?