BALOGUNHAROLD

Case 04Data protection in Nigeria

Compliance audits and defensive litigation for a data controller.

We act for controllers and processors, never for claimants against them. Here, a client needed both a compliance programme it could rely on and a defence when users took it to court.

Client
Data controller (confidential)
Sector
Consumer technology
Practice
Privacy & Data Protection
Jurisdiction
Nigeria

The brief

Our client processes personal data at scale. It engaged us to audit its compliance under the Nigeria Data Protection Act 2023 and, when users brought proceedings against it, to defend it.

We are fundamentally counsel to controllers and processors. The two strands reinforced each other: the audit gave the defence its evidence, and the litigation showed where the compliance programme needed to go further.

Our advice

  1. 01

    Compliance audits

    Auditing the client’s processing activities, lawful bases, notices, retention and cross-border transfers against the NDPA.

  2. 02

    Remediation

    Prioritising and implementing the fixes the audits identified.

  3. 03

    Defensive litigation

    Defending the client in proceedings brought by users alleging breaches of their data protection rights.

  4. 04

    Regulator engagement

    Preparing the client for engagement with the Nigeria Data Protection Commission.

Outcome

The client came out with a stronger compliance programme and a defence that rested on documented evidence, not just on argument.