Data Protection in Nigeria

Breach notification in Nigeria

Commission Notification

Within 72 (seventy-two) hours of becoming aware of a breach, if the breach is likely to result in a risk to the rights and freedoms of individuals, the data controller must notify the Commission. The data controller must immediately communicate the breach in plain and clear language, including advice about measures the data subject could take to mitigate the effect of the breach, the categories and approximate numbers of data subjects, and personal data records concerned.

Data Subject Notification

Where a personal data breach is likely to result in a high risk to the rights and freedoms of a data subject, the data controller shall immediately communicate the personal data breach to the data subject in plain and clear language, including advice about measures the data subject could take to mitigate the possible adverse effects of the data breach. If a direct communication to the data subject would involve disproportionate effort or expense, or is otherwise not feasible, the data controller may instead make a public communication in one or more widely used media sources such that the data subject is likely to be informed. 

The notifications referenced above should communicate the name and contact details of a point of contact of the data controller, describe the likely consequences of the personal breach and measures taken or proposed to be taken to address the personal breach.

Data Processor Notification

In a processing activity involving a data processor and controller or a processor and sub processor, there is an obligation on a data processor (or sub processor), on becoming aware of a breach, to notify the data controller or processor that engaged it, describing the nature of the personal data breach including where possible, the categories and approximate number of data subject and records concerned; and respond to all information requests from the data controller or processor that engaged it. 

The notifications referenced above should communicate the name and contact details of a point of contact of the data controller, describe the likely consequences of the personal breach and measures taken or proposed to be taken to address the personal breach.

Continue reading

  • no results

Previous topic
Back to top