Case 04Data protection in Nigeria
Compliance audits and defensive litigation for a data controller.
We act for controllers and processors, never for claimants against them. Here, a client needed both a compliance programme it could rely on and a defence when users took it to court.
- Client
- Data controller (confidential)
- Sector
- Consumer technology
- Practice
- Privacy & Data Protection
- Jurisdiction
- Nigeria
The brief
Our client processes personal data at scale. It engaged us to audit its compliance under the Nigeria Data Protection Act 2023 and, when users brought proceedings against it, to defend it.
We are fundamentally counsel to controllers and processors. The two strands reinforced each other: the audit gave the defence its evidence, and the litigation showed where the compliance programme needed to go further.
Our advice
- 01
Compliance audits
Auditing the client’s processing activities, lawful bases, notices, retention and cross-border transfers against the NDPA.
- 02
Remediation
Prioritising and implementing the fixes the audits identified.
- 03
Defensive litigation
Defending the client in proceedings brought by users alleging breaches of their data protection rights.
- 04
Regulator engagement
Preparing the client for engagement with the Nigeria Data Protection Commission.
Outcome
The client came out with a stronger compliance programme and a defence that rested on documented evidence, not just on argument.