By Kelechi Orji
Introduction
Data in the 21st century is a most sought-after asset, as its uses vary according to the aims and objectives of the various organisations and individuals who make use of it. Data can be used by organisations for numerous purposes, for instance, hospitals use data to enable them give precise medications by analyzing past records of patients and how well they reacted to certain previous medications, Logistics companies use data to track and report orders from customers, while banks and financial institutions to use it predict and prevent cyber-crime. Advertisers track consumer behaviour and transactions in order to run targeted campaigns about their products and services. The entertainment and media industry use data to identify and focus on the right content providers at the appropriate time. This foregoing represent just a little of the enormous uses of data.
The importance of data cannot be over-emphasized, as the biggest earning and most valuable companies in the world, such as Facebook, Google, Amazon, and others (https://www.visualcapitalist.com/ranked-the-most-valuale-brands-in-the-world/) deal with large volumes of data in the format now referred to as, “Big Data”. As a result of the indispensable nature of data, and the possible misuse or violation of rights of data subjects, nations, societies and institutions across the world, have enacted various laws and regulations, which aim at protecting individual and streams of data, from misuse. Examples of these measures include, The Genera Data Protection Regulation (G.D.P.R.) which has jurisdiction mainly within the European Union, The New York Stop Hacks and Improve Electronic Data Security (S.H.I.E.L.D) Act and The Personal Information Protection and Electronic Documents Act (P.I.P.E.D.A.) of Canada.
Nigeria did not have a comprehensive law set out solely to protect individual data until the coming of the Nigeria Data Protection Regulation (N.D.P.R./The Regulation) of 2019, issued by the National Information Technology Development Agency (N.I.T.D.A/The Agency) statutorily mandated by the N.I.T.D.A. Act 2007, to regulate and monitor the use of electronic data interchange and other forms of electronic communications in all fields where electronic communication may improve the exchange of data and information.
Key Terminologies Simplified
Data/Big Data
Simply put, Data refers to information, facts, figures, records: financial records, health records, academic records, etc, of natural or unnatural persons, which is identified, collected, collated and eventually stored in an electronic format in any device.
On the other hand big data refers to large volumes of data: semi-structured, unstructured data, that can be mined or analyzed for information, which will help big corporations make better decisions and planning for future prospective profitable ventures.
Data Subject
An individual whose identity can be identified directly or indirectly from the amount of information, facts or records freely consented to, and made available to another organisation or entity for processing.
Data Controller
An individual, singular or jointly or a statutory body, which determines how personal data is, or will be, processed.
Data Controllers include telecommunication companies, hospitals. Betting organisations, schools, etc
Processing
This means any action carried out on personal data such as recording, storage, alteration etc.
Data Protection Compliance Organisations (D.C.P.O.)/ Data Protection Officer (D.P.O.)
A Professional Service Consultancy Firm or I.T. Service Provider or Audit Firm or Law Firm, licensed and subject to the Regulations and Directives of N.I.T.D.A, to ensure compliance of the provisions of the Regulation by Data Controllers. In ensuring compliance, can also train, guide, draft data protection policies and audit policies for respective Data Controllers. (Article 1(3) of The Regulation)
Provisions of the Regulation
This Regulation applies to Nigerians and Non-Nigerians resident in Nigeria, as well as Nigerians resident outside Nigeria. Data controllers are obligated to first seek consent (in which case consent could be freely withdrawn) from data subjects before processing, and after consent is freely given must ensure security of data and further ensure that such data is not transferred to a third party or subject to theft, breach or anything that could compromise such data. In order words a Data controller must observe reasonable care when handling data of individuals. However the Regulation makes provisions for where consent will not be needed:
- Legal obligation,
- Contractual obligation,
- Protection of the interest of data subject or another natural person, and
- Public Interest. ( Article 2.2 of the Regulation)
Privacy policy is an integral part of data protection and every data controller must have a simple and noticeable privacy policy to the understanding of the target Data Subjects. (Article 2.5 of the Regulation)
Financial Sanctions
A defaulting organisation, whether public or private, shall face monetary sanctions from N.I.T.D.A, which varies according to the amount of data the organisation processes from data subjects:
- Organisations which process data of more than 10,000 (Ten Thousand) Data subjects, fine of N10, 000,000 (Ten Million Naira) or 2% of the annual gross revenue of the preceding year whichever is greater.
- Organisations which process data of less than 10,000 (Ten Thousand) Data Subjects, fine of N2, 000, 000 (Two Million Naira) or 1% of the annual gross revenue of the preceding year, whichever is greater.
(Article 2.10 of the Regulation)
Powers of The Attorney General of The Federation
The Attorney General of the Federation (A.G.F.) has a wide range of supervisory powers where data is to be transferred before or after processing from Nigeria to a foreign country or an international organisation. The A.G.F. is to determine countries or international organisations with adequate data protection laws, and shall take into consideration the legal system, independent supervisory bodies and international affiliations of the Foreign country or organisation with the aim of ascertaining that any data being transferred will be adequately protected. (Article 2.11 of The Regulation)
These powers are to be co-ordinated with N.I.T.D.A and both N.I.T.D.A. and A.G.F should be notified before such transfer is done.
However where the A.G.F has not decided, the Data Controller can only transfer data to third party countries or organisations only where the following are involved:
- Consent is given by Data Subject upon adequate information on possible risks involved.
- Performance of a contract between both parties.
- Performance of a contract in the interest of the Data subject.
- Public interest
- Defence of Legal Claim
- Protection of vital interests of Data subject or another person
(Article 2.12 of The Regulation)
Rights of Data Subjects
The Regulation affords Data Subjects certain rights when their data is being processed. The right to freely give and withdraw consent is a fundamental right of a Data Subject except in circumstances mentioned above. Data subjects also have the right to receive such data presented to the Data Controller in a portable format and can subsequently transfer such data to another Data Controller unhindered.
Data Subjects reserve the right have access to their personal data, right to rectification of the information given, right to request the deletion of such personal data freely given and also obtain from the Data Controller restriction of processing of such information upon certain grounds.
(Article 2.13.9 & 10 of The Regulation)
Obligations of Data Controllers
The appointment of Data Protection Officers by outsourcing to a competent Firm or person by Data Controllers, is mandatory to ensure adherence to the Regulation, relevant data privacy instruments and data protection directives of the Data Controller. (Article 312 of The Regulation)
Data Controllers are mandated to have a simple, conspicuous and readable data protection policy or privacy policy, on any medium through which data is collected and stored. Information on the identity or contact details of the Data Controller and Data Protection Officer, the purpose for which data is processed as well as legal basis for processing, the recipients of the data and the rights of Data Subjects must be made available to the Data Subject, through the medium of collection.
Training programmes should be regularly organised for staff on the Data Protection laws and privacy policy procedures to have functional and well-structured means of compliance and the appointment of a Data Protection Officer, to ensure compliance with the Regulation.
The Regulation mandates all Data Controllers to carry out an audit on its data protection policies and practices, and Data controllers who process personal data of more than 1,000 within a period of 6 months or more than 2,000 within a 12-month period, should not only audit but also submit a summary of such audit to N.I.T.D.A.
(Article316, 317 of The Regulation)
LIMITATIONS OF THE REGULATION
Collection of data is not specific to adults alone, in a digital age, the personal data of minors are also collected, stored and process. However, the Regulation did not make provision for minors, putting into consideration that a minor lacks capacity to enter into a contract or give consent.
- The Regulation puts more obligations on the Data Controller and little or no corresponding obligations on the Data Subject. For instance, where a Data Subject, knowingly provides false information to the Data Controller which results in loss occasioned by the false information, remedies or punitive measures, should be provided for to serve as a deterrent.
- Anonymisation and Psuedonymisation
Anonymisation simply put is the total removal of personal identifiable information of the Data Subject whereby anyone who comes across such data cannot link it to the Data Subject. On the other hand psuedonymisation is the partial removal of personal identifiable information, whereby the Data Subject can only be identified through indirect or additional information.
These concepts are important in protecting the privacy of Data Subjects where their personal information albeit with consent given is used for research or as a means of ascertaining market trends for better business decision making. The N.D.P.R. does not provide for these indispensable concepts.
POSSIBLE RECOMMENDATIONS
Data Protection itself is a wide area of law and involves a wide area of research, structure, training and enforcement. A commission or Agency should be set up to handle solely Data Protection matters.
HOW FIRMS CAN TAKE ADVANTAGE AND REGISTER AS LICENSED DATA PROTECTION COMPLIANCE ORGANISATIONS (D.P.C.O.s)
The Regulation allows for any of either of the following firms: Professional Service Consultancy Firms, I.T. Providers, Audit Firms or Law Firms, to register as D.P.C.Os, to ensure compliance and enforcement of the Regulation. Every filing by Data Controllers pursuant to this Regulation, must be accompanied by a verification statement issued by a D.P.C.O. The requirements for registration include:
- Corporate Affairs Commission Registration (C.A.C.) Certificate
- Evidence of Tax Clearance
- Relevant professional or academic qualification of at least 2 listed staff
- Valid means of identification of two directors
- Website registration on .ng domain.
- Evidence of payment of prescribed licensing fees by N.I.T.D.A.
(https://nitda.gov.ng/data-protection/)
Conclusion
The N.D.P.R. (2019) has come to stay, and will be the genesis of many more Regulations, or even Statutes that provide for data protection in Nigeria. Only organisations which begin in earnest to, not only comply with this Regulation but also, educate itself and staff on the provisions of this Regulation and importance of compliance, will be ahead in comparison with their contemporaries who are yet to be aware of this Regulation. The benefits of complying with this Regulation cannot be over-emphasized as it will prevent financial sanctions from N.I.T.D.A. as well as possible litigation instigated by aggrieved Data Subjects whose data have been misused or manipulated. Data is the “oil” of the 21st century, while organisations as well as corporations digitalize their structure of business, the knowledge of data protection laws becomes paramount and critical for remaining competitive and relevant in the emerging new scenario.
COPYRIGHT: All rights reserved. No part of this publication may reproduced or stored in a retrieval system or transmitted in any form or by any means without the prior permission of the writer.
DISCLAIMER: This publication is not intended to provide legal advice, but to provide information on the matter covered in the publication. No reader should act on the matters covered in this publication without first seeking legal advice.
Orji Kelechi Clement (Esq) is a Barrister and Solicitor of Supreme Court of Nigeria(LLB, BL) with expertise in criminal, corporate, property and Data Protection Law. He has acquired certifications from Young African Leaders Initiative on Human Rights, Personal Growth and Development Strategies, and is also a Disabilities Rights Advocate. He is a Member U.S. Embassy American Center, Abuja, Nigeria and also a United Council For Youth Empowerment Volunteer. Orji can be reached on: [email protected], +2348134284673.