Technology
Data Protection and People’s Rights Under Nigeria’s Data Protection Regulations (NDPR): Know Your Rights
Data Protection and People’s Rights Under Nigeria’s Data Protection Regulations (NDPR): Know Your Rights
In a time where private information is more and more important and at risk of being exploited, safeguarding people’s privacy is now a significant priority. The implementation of the Nigeria Data Protection Regulation (NDPR) in 2019 in Nigeria is a major move in protecting citizens’ personal information and ensuring organizations follow legal and ethical guidelines when handling data. As the number of Nigerians participating in digital activities like online banking, e-commerce, and social media increases, the NDPR is fundamental in influencing the collection, processing, and protection of data. This article examines the main provisions of the NDPR, the privileges it provides to people, and its influence on companies and the digital environment in Nigeria.
What Is NDPR?
The National Information Technology Development Agency (NITDA) introduced the Nigeria Data Protection Regulation (NDPR) in January 2019. The NDPR was created to tackle the increasing concerns about personal data misuse in both private and public sectors. It is in line with worldwide data protection trends, like the European Union’s General Data Protection Regulation (GDPR), while also meeting the unique requirements of Nigeria’s digital environment.
The goal of the regulation is to safeguard Nigerian citizens’ data from unauthorized access, exposure, or exploitation. It includes a range of industries like finance, telecom, education, health, and online shopping, which commonly involve gathering and handling personal data.
Key Provisions of the NDPR
The NDPR outlines specific guidelines on how organizations should handle personal data. Some of the provision as outlines in NDPR guidelines are:
Data Collection and Consent: Organizations must obtain explicit consent from individuals before collecting their personal data. This ensures that data subjects are fully aware of what information is being collected, the purpose of its collection, and how it will be used.
Data Processing: The regulation mandates that personal data should only be processed for legitimate and specified purposes. Organizations must ensure that the data is accurate and kept up to date. Processing personal data for purposes other than those originally specified is not permitted without further consent from the individual.
Data Security: One of the core elements of the NDPR is the requirement for organizations to implement adequate security measures to protect personal data. This includes safeguarding data from unauthorized access, data breaches, or any form of manipulation.
Third-Party Sharing: If personal data is to be shared with third parties, the organization must inform the data subject and obtain their consent. The third party must also adhere to the same level of data protection as stipulated by the NDPR.
Data Breach Notifications: In the event of a data breach, organizations are required to notify the affected individuals and NITDA within a specified period. This provision ensures that individuals can take action to mitigate the effects of a breach.
People’s Rights Under The NDPR
The acknowledgement of people’s rights regarding their personal data is a key aspect of the NDPR. The rule gives Nigerians various rights to manage how their data is treated. Some of the right are:
- Right to be Informed: Individuals have the right to be informed about the collection and use of their personal data. Organizations are required to provide transparent information on the types of data collected, the purpose of the collection, and how long the data will be retained.
- Right to Access: Data subjects have the right to request access to their personal data held by an organization. This means they can inquire about the specific data collected, the reasons for its collection, and whether it has been shared with third parties.
- Right to Rectification: If an individual’s personal data is inaccurate or incomplete, they have the right to request that the organization correct or update the information.
- Right to Erasure (Right to be Forgotten): Under certain circumstances, individuals can request that their personal data be deleted. This is particularly relevant if the data is no longer necessary for the purpose it was originally collected or if the individual withdraws their consent for its processing.
- Right to Data Portability: This allows individuals to obtain and reuse their personal data across different services. They have the right to request that their data be transferred from one service provider to another in a commonly used, machine-readable format.
- Right to Object: Individuals have the right to object to the processing of their personal data in cases where the processing is based on legitimate interests or public tasks, direct marketing, or scientific/historical research.
Rights Of Individuals In Cases Of Data Misuse, Breaches, Or Use Without Consent
The NDPR grants the data subject particular rights and solutions if their data is mismanaged, disclosed, or utilized without authorization. These rights give individuals the ability to find a solution and shield themselves from additional damage. Some important rights in such situations include:
- Right to lodge a complaint:
According to Section 3.1.1(e) of the NDPR, individuals have the option to file a complaint with NITDA or other authorized regulatory entities if they suspect their data has been mishandled, processed illegally, or exposed. This privilege allows people to seek legal recourse in cases of mishandling of their information by a company.
- Right to Compensation
The NDPR acknowledges the entitlement to receive compensation for harm caused by data breaches or unauthorized data handling. Individuals can request compensation from the data controller under section 2.10 of the NDPR if they can prove that their data rights violation resulted in harm. This clause guarantees that individuals affected by data breaches can receive compensation for any financial losses, emotional distress, or harm to their reputation.
- Right to withdraw consent
Individuals can revoke their consent for the processing of their personal data whenever they choose. As per Section 2.8 of the NDPR, organizations must respect these requests and stop processing the individual’s data unless there are strong legitimate reasons for the processing. This right is important when data is utilized without permission, enabling individuals to take back control of their personal information.
- Right to Data Erasure
If personal data is breached or used without authorization, individuals have the right to request erasure. According to Section 3.1.2(f) of the NDPR, individuals have the right to ask for the deletion of their personal data if it has been used without permission or if the reason for collecting the data is no longer valid. This right, sometimes referred to as the “right to be forgotten,” guarantees that unauthorized data use is stopped and eliminated from any future handling.
- Right to Restriction of Processing
If someone believes their data has been mishandled or misused, they can ask for processing restrictions under Section 2.10.2. This right enables people to halt additional data processing during ongoing investigations. It serves as a protection, making sure no additional damage occurs during the resolution of the problem.
Benefits To Individuals
When individuals’ rights are breached under the NDPR, they are eligible for certain benefits.
- Reclaiming Privacy: Through exercising the right to be forgotten or limiting additional data processing, individuals can take back authority over their personal information and reduce the consequences of its unauthorized exploitation.
- Financial Compensation: If individuals experience financial loss or emotional distress due to a data breach or misuse, they have the right to request financial compensation from the organization at fault. This serves as a deterrent for careless data handlers and compensates for the damages they cause.
- Legal Remedy: By utilizing the NDPR’s complaint procedures and regulatory supervision, people have the opportunity to take legal measures or regulatory actions to hold those responsible for data misuse or breaches accountable.
- Public Trust: The NDPR’s protections promote trust in the digital world, inspiring people to engage in online activities knowing their data rights are secure.
Compliance Requirements For Organizations
In order to comply with the NDPR, organizations must meet various obligations related to compliance. Some of these items are:
- Appointment of Data Protection Officers (DPOs): Organizations that process a large volume of personal data must appoint a DPO to oversee compliance with the NDPR and ensure the organization’s data practices are in line with the regulation.
- Annual Data Protection Audit: Organizations are required to conduct annual data protection audits and submit the reports to NITDA. This process helps organizations identify potential risks and ensure that they are taking the necessary steps to protect personal data.
- Fines for Non-Compliance: Failure to comply with the NDPR can result in significant penalties, including fines of up to 10 million Naira or 2% of an organization’s annual revenue, depending on the nature and severity of the breach.
Challenges and Gaps in NDPR Implementation
Even though the NDPR has created a strong foundation for safeguarding data in Nigeria, there are still obstacles in its execution. An important obstacle is the lack of public awareness and law enforcement. A large number of Nigerian citizens are still not completely informed about their data rights or the responsibilities that organizations have under the NDPR. Raising public education and awareness is essential in order to give citizens the power to safeguard their privacy.
Another difficulty that must be addressed is ensuring compliance. While NITDA has made progress in encouraging adherence, there are doubts about the agency’s ability to ensure proper enforcement of regulations, especially with major international companies, government agencies and smaller domestic enterprises.
Conclusions
The NDPR in Nigeria sets up rules for data protection and gives individuals rights to safeguard their personal information. The regulation offers various solutions, such as compensation and erasure rights, in situations where there is data misuse, breaches, or unauthorized processing. These safeguards are essential for establishing confidence in Nigeria’s fast-developing digital economy and guaranteeing the preservation of privacy in the era of digital technology. As the public becomes more aware of their data rights and enforcement becomes more rigorous, the NDPR will remain vital in influencing Nigeria’s digital future.
Written By Ibrahim Abuh Sani, Co-Founder, Eybrids.
Technology
The Price of Neglect: The Economic Impact of Cyberattacks on Maritime Operations
The Price of Neglect: The Economic Impact of Cyberattacks on Maritime Operations
By Abuh Ibrahim Sani
Ports are critical infrastructure to countries economic growth and sustainability. Over 90% of nations around the world depends on importation and exportation of goods. The maritime sector has become an integral part of global trade, connecting markets and facilitating the movement of goods across regions and continents. However, as with other sectors, the growing dependence on digital systems has exposed maritime operations to the growing threat of cyberattack. These attacks have dire economic consequences, as seen in countries like USA, Nigeria, Japan, China, Netherlandwhere maritime industry contribute immensely to their economy.
Understanding Cyberattacks in Maritime Operations
Maritime functions within a complex ecosystem of ports, shipping companies, logistics providers, and regulatory authorities. Over the past two decades, ports have progressively depended on automated information and operational technologies. This digital reliance creates vulnerabilities that, in the case of a hack or incident, might incapacitate economic activities. In July 2024, a software upgrade implemented by cybersecurity firm Crowdstrikeshutdown Windows services globally, resulting in turmoil at airports and interrupting essential infrastructure, including port facilities.Incidents of this nature prompt critical inquiries regarding maritime cybersecurity measures and the potential economic and physical repercussions that may come from a cyber incident. The most common attack include ransomware, phishing, and hacking of critical systems like Automation Identification System(AIS) or terminal operating systems.
The Maritime Sector’s Economic Impact: Insights from Nigeria, USA, Netherlands, and Japan
Maritime is one of Nigeria most critical sector, with its port accounting for over 70% of the region’s trade volume in West Africa. The industry has significantly contributes to Nigeria’s Gross Domestic Product(GDP), facilitating oil exports, which makes up over 90% of the country’s foreign exchange earnings. Surprisingly, the country’s maritime industry is vulnerable to cyber threats due to limited cybersecurity professionals, measures and the usage of legacy systems still in existence. More than 95% of cargo entering the United States is transported via ship and port activities, contributing approximately $5 trillion to the annual economy.The marine industry in Japan is vital to its economy, particularly due to the country’s dependence on maritime transport for over 99% of its international trade and the transportation of products and passengers among its many islands.
The marine sector is fundamental to the Dutch economy, embodying the Netherlands’ extensive nautical legacy and critical role as a European trading center. In 2022, the maritime cluster, which includes shipping, shipbuilding, ports, and maritime services, generated a revenue of €95.2 billion. This activity produced a direct added value of roughly €25.9 billion, with an indirect contribution of €5.2 billion, resulting in a total of €31.1 billion.
Notable Incident of Cyber attacks
The International Maritime Organization (IMO) in 2020, fell victims of cyber attack that has ripple the effect of global maritime operation. In 2023, a major ports in Japan suspend operation due to ransomware attack which believes have emanated from Russia. The Port of Nagoya, responsible for approximately 10% of Japan‘s overall trade volume and managing some automobile exports for corporations such as Toyota, suspended its cargo operations on Tuesday, including the loading and unloading of containers onto trailers, following the incident.These incidents revealed weaknesses and highlighted the economic implications associated with cybersecurity in the maritime sector.
Impact of Cyber-attacks on Nations Economy
Cyberattacks often lead to operational downtime in ports resulting in delays of cargo handling and shipping schedules. In Nigeria, where ports like Apapa and Tin Can Island are already struggle with congestion, cyberattack disruptions could exacerbate inefficiencies, causing financial losses for shipping companies and businesses relying of time delivery of their goods.
Frequently cyber incidents lead to higher insurance premiums for maritime operators, insurers factors in cyber risk when underwriting policies, making costlier for shipping companies to secure comprehensive coverage.In every cyber-attack, its comes with consequences which include reputation damage. Cyber incidents destroy the company image and loss of consumer trust. The affected ports or shipping companies would look less attractive to international shipping lines and customers. This reputational destruction can have long-term economic effects, reducing countries competitiveness on maritime environments.
For example, takes Nigeria as the primary exporter of crude oil whose revenue relies heavily on its maritime sector. Cyber attack that disrupt port operations can lead to massive revenue losses. Delay in oil shipment due to compromised systems directly impact foreign exchange earnings and the broader economy.Recovering from a cyberattack involves substantial financial outlays for systems restoration, data recovery, and implementation of upgraded security measures. For a developing economy like Nigeria, these costs can strain already limited resources.
Why Cybersecurity in Maritime Operations Is Essential
The maritime sector is essential infrastructure; thus, preserving its cybersecurity is vital for safeguarding national interests, including energy exports, trade, and employment. A robust cybersecurity framework and measures enhanced the confidence of international stakeholders and customers in marine operations, hence generating increased commerce and investment. Investing in cybersecurity infrastructure and people development is more economical than the financial repercussions of a successful cyberattack. They mitigate risks, facilitating more efficient operations and financial stability.
Steps Toward Strengthening Cybersecurity Maritime Sector
The government of each country, through its marine administration and safety agency, must adopt effective cybersecurity policies specifically designed for the maritime sector. These rules must conform to international standards, including the International Maritime Organization’s principles on maritime cybersecurity. Training for port operators, shipping industry personnel, and other stakeholders on cybersecurity best practices is essential for capacity building. Competent individuals can recognize and alleviate threats prior to their escalation. Upgrading outdated technology systems, implementing modern cybersecurity solutions, and employing AI systems for threat detection will improve resistance against cyberattacks.
The world is a global village due to technology’s profound interconnectedness of our actions. Collaboration among government, business sector, and international partners is key in mitigating cyberattacks. Exchanging knowledge on cyber threats and implementing a cohesive strategy can enhance defenses across continents and regions.Formulating rapid response teams and contingency plans to ensure operations can swiftly recover following a cyber-attack will reducing economic losses and operational decline.
Conclusion
The economic impact of cyberattacks on maritime operations is a stark reminder of the price of neglecting cybersecurity. As the nation’s aspires to be a viable economy powerhouse of their regions, protecting its maritime sectors and national security from cyber threats must be a top priority. Develop a proactive measure, strong polices and strategic investments in technology will not only safeguard the industry but also bolster nations position in the global maritime landscape. The failure of government to act decisively risks costly disruptions, revenue losses, and reduce competitiveness. A price no economy can afford to pay.
Technology
Cybersecurity as a Business Priority: Experts to Lead Discussion at EyBrids Global Conference
EyBrids, an emerging tech startup recognized for its innovative solutions, has revealed the remarkable lineup of the distinguished speakers and panelists for its upcoming Global Cybersecurity Conference, themed “Secure or Crumble: Building a Cyber Resilient Future”.
As the highly anticipated Global Cybersecurity Conference, organized by EyBrids, draws closer, attention turns to one of the panel sessions, “The Business Case for Robust Cybersecurity.” This session will be led by Rianat Abbas, a seasoned product security analyst, and Victoria Ogunsanya, a professional cybersecurity analyst, who will guide the discussion on how cybersecurity is no longer just a technical consideration but a vital business priority.
In a statement released by the event organizers, Abuh Ibrahim Sani underscored the importance of the session and its leaders. “Cybersecurity has evolved from being a purely technical issue to a key driver of business resilience and growth. With Rianat and Victoria leading this discussion, participants will gain actionable insights on how strategic cybersecurity investments can safeguard operations, protect customer trust, and drive long-term success,” he said.
Rianat Abbas, known for embedding robust security measures throughout the product lifecycle, will bring her expertise to discussions on aligning cybersecurity with product innovation and development. Victoria Ogunsanya, with her focus on proactive threat detection and mitigation, governance and risk management will share strategies for helping businesses stay ahead of emerging risks while maintaining operational stability. Together, they will emphasize the critical role of cross-functional collaboration in transforming cybersecurity from a cost center into a strategic enabler of success.
This session, led by two of the conference’s most dynamic thought leaders, is set to provide attendees with practical strategies and forward-thinking approaches to address the evolving cybersecurity landscape while meeting broader business objectives.
The conference, scheduled for December 7, 2024, at 5 PM GMT via Zoom, will feature an outstanding lineup of speakers and panelists, including Ahmed Olabisi, a renowned cybersecurity expert; Olabode Folasade, a skilled Data Analyst; Dr. Olajumoke Eluwa, a distinguished Cybersecurity Professional; Jeremiah Kolawole, a leading Cybersecurity Professional; Heather Noggle, Executive Director of the Missouri Cybersecurity Center of Excellence; and Blessing Ebare, a seasoned Information Security Professional.
The panelists for the event include Olamide Olajide (Chief Panelist), a seasoned Elasticsearch Data Engineer; Rianat Abbas (Chief Panelist), a Product Security Analyst driving innovation; Destiny Young, a forward-thinking Cybersecurity Engineer; Jeremiah Folorunso, a creative Product (UI/UX) Designer; Sopuluchukwu Ani, a Senior Business Applications Administrator; Jeremiah Ogunniyi, an experienced Backend Developer; Victoria Ogunsanya, a seasoned Cybersecurity Analyst; and Bashir Aminu Yusufu, a Senior System Analyst.
The panelists, alongside other renowned speakers, will lead discussions on topics such as secure system design, cross-functional cybersecurity collaboration, and innovative approaches to mitigating threats. The conference will also feature interactive sessions, enabling participants to connect directly with experts and peers.
“This conference isn’t just about identifying challenges; it’s about equipping attendees with practical tools and knowledge to tackle them head-on,” Abuh stated. “From business leaders to IT professionals and cybersecurity enthusiasts, there’s something here for everyone.”
Technology
EyBrids Unveils Star-Studded Lineup for Global Cybersecurity Conference
EyBrids, an emerging tech startup recognized for its innovative solutions, has revealed the remarkable lineup of the distinguished speakers and panelists for its upcoming Global Cybersecurity Conference, themed “Secure or Crumble: Building a Cyber Resilient Future”.
In a statement issued by Abuh Ibrahim Sani, one of the event’s organizers, on Wednesday, November 27, 2024, the speakers were described as leading voices in the tech industry, committed to addressing some of the most urgent cybersecurity issues of today.
The conference scheduled for December 7, 2024, at 5 PM GMT via Zoom, promises to foster critical conversations about safeguarding businesses from evolving threats while emphasizing the importance of cross-functional collaboration.
According to Abuh, “Our speakers and panelists represent a wealth of experience across various cybersecurity and tech disciplines, making this conference an unmissable opportunity to learn from some of the best minds in the field.”
He added, “Their collective insights will help attendees understand why organizations must prioritize cybersecurity as a cornerstone for business resilience. Collaboration, innovative strategies, and shared responsibility are key to navigating today’s digital landscape.”
Speakers and Panelists Lineups
The event’s thought-leader panelists will focus on Panel Session 1: “𝘼 𝘾𝙧𝙤𝙨𝙨-𝘿𝙤𝙢𝙖𝙞𝙣 𝙋𝙚𝙧𝙨𝙥𝙚𝙘𝙩𝙞𝙫𝙚 𝙤𝙣 𝘾𝙮𝙗𝙚𝙧𝙨𝙚𝙘𝙪𝙧𝙞𝙩𝙮” and Panel Session 2: “The Business Case for Robust Cybersecurity,” bringing together expertise from diverse fields, including cybersecurity, data engineering, UI/UX design, product analytics, and system architecture. The sessions aim to highlight the importance of cross-domain collaboration in addressing modern cyber threats and aligning security strategies with organizational goals. Speakers at the conference include Ahmed Olabisi Olajide, a renowned cybersecurity expert; Olabode Folasade, a skilled Data Analyst; Dr. Olajumoke Eluwa, a distinguished Cybersecurity Professional; Jeremiah Kolawole, a leading Cybersecurity Professional; Heather Noggle, Executive Director of the Missouri Cybersecurity Center of Excellence; and Blessing Ebare, a seasoned Information Security Professional.
They will be joined by thought-leader panelists such as Olamide Olajide (Chief Panelist), a seasoned Elasticsearch Data Engineer; Rianat Abbas (Chief Panelist), a Product Security Analyst dedicated to embedding security into product life cycles; Destiny Young, a forward-thinking Cybersecurity Engineer specializing in secure network infrastructures; Jeremiah Folorunso, a creative Product (UI/UX) Designer focused on building secure, user-centric interfaces; Sopuluchukwu Ani, a Senior Business Applications Administrator with expertise in safeguarding enterprise systems; Jeremiah Ogunniyi, an experienced Backend Developer skilled in creating resilient system architectures; Victoria Ogunsanya, a proactive Cybersecurity Analyst dedicated to threat detection and mitigation; and Bashir Aminu Yusufu, a Senior System Analyst with expertise in optimizing organizational security. Together, these speakers and panelists will ensure attendees gain practical knowledge, actionable strategies, and fresh perspectives on building cyber resilience and aligning security efforts with business success.
The panelists, alongside other renowned speakers, will lead discussions on topics such as secure system design, cross-functional cybersecurity collaboration, and innovative approaches to mitigating threats. The conference will also feature interactive sessions, enabling participants to connect directly with experts and peers.
“This conference isn’t just about identifying challenges; it’s about equipping attendees with practical tools and knowledge to tackle them head-on,” Abuh stated. “From business leaders to IT professionals and cybersecurity enthusiasts, there’s something here for everyone.”
-
Business3 years ago
Facebook, Instagram Temporarily Allow Posts on Ukraine War Calling for Violence Against Invading Russians or Putin’s Death
-
Headlines3 years ago
Nigeria, Other West African Countries Facing Worst Food Crisis in 10 Years, Aid Groups Say
-
Foreign3 years ago
New York Consulate installs machines for 10-year passport
-
Technology3 months ago
Zero Trust Architecture in a Remote World: Securing the New Normal
-
Entertainment2 years ago
Phyna emerges winner of Big Brother Naija Season 7
-
Business7 months ago
Nigeria Customs modernisation project to check extortion of traders
-
Business9 months ago
We generated N30.2 bn revenue in three months – Kano NCS Comptroller
-
Headlines6 months ago
Philippines’ Vice President Sara Duterte resigns from Cabinet