Privacy Policy of Website or Application - Form Pro · NG-law
✓ Valid in Nigeria · drafted to comply with local law
Create your Privacy Policy of Website or Application - Form for use in Nigeria. Answer a few plain-English questions and the document fills in automatically as you go — then download it in Word and PDF, ready to sign or share. This version has been professionally rewritten to comply with local law.
- Answer 14 simple questions — the document fills in as you go
- Live preview: watch your document update in real time
- Download as Word (.docx) and PDF
- Edit your answers and re-download anytime
Fill in the details
0/14Type below — the document on the right updates as you go.
PRIVACY POLICY FOR WEBSITE
Effective date: ________
Applicable to: ________ (the "Website")
This Privacy Policy is issued in compliance with the Nigeria Data Protection Act, 2023 (the "NDPA"), the Nigeria Data Protection Regulation, 2019 (the "NDPR") and any other applicable data protection laws, regulations and directives issued by the Nigeria Data Protection Commission (the "Commission") from time to time.
§1. DEFINITIONS
In this Privacy Policy, unless the context otherwise requires:
(a) "Commission" means the Nigeria Data Protection Commission established under the NDPA;
(b) "Content" means any content, writing, images, audiovisual content or other information published on this Website;
(c) "Data Controller" means the party who, whether alone or jointly with others, determines the purposes and means of the processing of Personal Data;
(d) "Data Processor" means any party who processes Personal Data on behalf of, or at the direction of, the Data Controller;
(e) "Data Protection Officer" or "DPO" means the person appointed by the Data Controller and responsible for overseeing data protection strategy and implementation to ensure compliance with the NDPA and the NDPR;
(f) "Data Subject" means an identifiable individual to whom Personal Data relates;
(g) "Operator" means the owner, publisher and administrator of the Website and a party responsible, together with the Data Controller, for the collection of Personal Data;
(h) "Parties" means both You (the user of the Service) and the Data Controller: ________;
(j) "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organisation, storage, use, disclosure, transfer or erasure;
(k) "Products" means the goods and products, both tangible and intangible, offered on the Website;
(l) "Service" means the Website known as ________, including all pages, sub-pages, blogs, forums and other connected internet content whatsoever;
(m) "You" or "Your" means the user of this Website as a Data Subject.
§2. INTRODUCTION
2.1 This Privacy Policy is designed to inform You about the Personal Data we collect, how we collect it, the purposes for which it is used, the lawful basis for its processing, and Your rights in relation to that Personal Data when You use this Service or purchase the Products offered on the Website.
2.2 We are committed to protecting Your Personal Data and to processing it lawfully, fairly and transparently in accordance with the NDPA and the NDPR.
2.3 By continuing to use our Website, You acknowledge that You have reviewed this Privacy Policy and, where consent is the applicable lawful basis, You consent to the processing of Your Personal Data in the manner described herein. You may withdraw such consent at any time as provided in this Policy.
§3. CONTACT DETAILS OF THE DATA CONTROLLER, OPERATOR AND DPO
3.1 The Data Controller responsible for the processing of Your Personal Data is ________, a company duly registered in Nigeria with registration number ________, and may be contacted as follows:
________
3.2 The Operator of the Website is ________ and may be contacted as follows:
________
3.3 The Data Protection Officer is ________ and may be contacted as follows:
________
§4. THE PERSONAL DATA WE COLLECT FROM YOU
4.1 We collect various categories of information to enable us provide good Service to all our users. Depending on how the Service is used, the types of Personal Data we collect are as follows:
(a) For registered users: during the process of Your registration we may collect the following information:
________
We may also require other information in relation to:
(i) Your interaction with our representatives;
(ii) the purchases You make.
(b) For unregistered users: we collect passive information from all users, including cookies, IP address information, location information and certain browser information.
(c) Sales and billing information: we may collect Your debit and/or credit card information, billing address, contact address and other information required to complete Your purchases. Sensitive payment information is processed through secure payment channels. The billing information will be retained for the following period: ________ to assist You in making future purchases.
4.2 Where we process sensitive personal data as defined under the NDPA, we shall only do so on a lawful basis recognised by the NDPA, including Your explicit consent where required.
§5. THE PERSONAL DATA WE COLLECT AS YOU USE OUR SERVICE
5.1 We use the following means to collect Personal Data from You:
Cookies: We use data collected by cookies to offer You the best experience on our Website. Cookies are information stored on Your browser when You visit our Website or use a social network with Your PC, smartphone or tablet, containing data such as the name of the server from which they originate and a numeric identifier. The types of cookies we use are as follows:
(i) Technical cookies: these are essential for the correct functioning of our Website and are required to provide the Service requested by our users;
(ii) Profiling cookies: these are used to create user profiles based on personal choices and preferences in order to deliver advertising messages to Your device, and are only deployed with Your prior consent;
(iii) Third party cookies: while using our Service, You may receive cookies from websites managed by other organisations. Third party analytical cookies may also be installed to detect information on user behaviour on our Website in order to monitor performance and improve usability;
(iv) Support in configuring Your browser: You may manage these cookies through the settings of Your browser on Your device. Deleting cookies may, however, remove the preferences You have set for this Website.
Log Data: We also use log files which store information automatically collected when users visit this Website, which may include:
(i) the domain and host from which You access the Website;
(ii) the name of the Internet Service Provider (ISP);
(iii) the date and time of visit;
(iv) Your computer operating system and browser software;
(v) the web pages visited and the duration and frequency of visits;
(vi) Your Internet Protocol (IP) address.
§6. LAWFUL BASIS FOR PROCESSING
6.1 We process Your Personal Data only where a lawful basis exists under section 25 of the NDPA, namely where:
(a) You have given consent to the processing for one or more specific purposes;
(b) processing is necessary for the performance of a contract to which You are a party or to take steps at Your request prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to which we are subject;
(d) processing is necessary to protect Your vital interests or those of another natural person; or
(e) processing is necessary for the purposes of our legitimate interests, except where such interests are overridden by Your fundamental rights and freedoms.
§7. PURPOSE OF PROCESSING PERSONAL DATA
We collect and use Your Personal Data for the following purposes:
(i) to provide, maintain and improve the Service we offer to You;
(ii) to develop new Products on the Website;
(iii) to provide personalised Service to You, including recommendations and personalised content;
(iv) to provide analytics to understand how our Service is used;
(v) to comply with applicable legal and regulatory obligations.
§8. THIRD PARTIES AND DATA PROCESSORS
8.1 Where we engage a Data Processor to process Personal Data on our behalf, we shall ensure that such engagement is governed by a written contract that imposes obligations on the Data Processor consistent with the NDPA, including obligations of confidentiality and security.
8.2 We may share Your Personal Data with third parties in order to protect our rights, property and safety, and the safety of users of this Website, in accordance with this Policy and applicable law.
§9. CROSS-BORDER TRANSFER OF PERSONAL DATA
9.1 Where it becomes necessary to transfer Your Personal Data outside Nigeria, such transfer shall only be carried out in compliance with sections 41 to 43 of the NDPA, including where the recipient country, organisation or sector is subject to an adequate level of protection, or on the basis of one or more of the conditions and safeguards permitted under the NDPA.
§10. STORAGE AND RETENTION OF PERSONAL DATA
10.1 We take the security of the Personal Data we collect seriously and adopt reasonable technical and organisational measures to reduce the risk of accidental destruction, loss, alteration or unauthorised access. However, no system involving the transmission of information via electronic storage systems or the internet is completely secure.
10.2 Your Personal Data shall be retained only for as long as is necessary to fulfil the purposes for which it was collected, or until You terminate Your account with us or withdraw Your consent, after which it shall be deleted or anonymised, subject to any retention required by applicable law.
10.3 You may withdraw Your consent to the processing of Your Personal Data at any time. Following such withdrawal, all Personal Data and information we hold about You shall be deleted, save where we are required or entitled to retain it under applicable law.
§11. PROTECTION OF PERSONAL DATA
11.1 Our Service incorporates security features designed to continuously protect Your Personal Data and to detect and block security threats. Where we detect a security risk, we may inform You and guide You through steps to remain protected.
11.2 In the event of a personal data breach likely to result in a risk to Your rights and freedoms, we shall notify the Commission within seventy-two (72) hours of becoming aware of the breach and, where required, notify You without undue delay, in accordance with section 40 of the NDPA.
§12. DISCLOSURE OF PERSONAL DATA
We do not disclose Your Personal Data except for any of the following reasons:
(i) where You have granted permission: we will disclose Your Personal Data where we have received Your unequivocal consent, which may be withdrawn at any time;
(ii) where required by law: we will disclose Your Personal Data where we are required to do so under any applicable law, regulation, court order or other legal process;
(iii) to comply with legal obligations: we will disclose Your Personal Data where necessary to comply with any legal or regulatory obligation to which we are subject;
(iv) to protect our rights and property: we will disclose Your Personal Data where necessary to protect and defend our rights, property and safety, and those of users of this Website or third parties;
(v) to enforce our policies: we will disclose Your Personal Data where necessary to enforce the terms and conditions of this Website, this Privacy Policy or any other agreement;
(vi) in the event of a business transfer: we may disclose or transfer Your Personal Data in connection with any merger, acquisition, reorganisation, sale of assets or other business transaction involving the Operator; and
(vii) for any other purpose reasonably necessary for the lawful operation of our Website.
§13. LINKS TO THIRD PARTY SITES/SERVICES
The Website may contain links to other websites which we believe may offer useful information. These linked websites are not under our control and this Privacy Policy does not apply to them. We encourage You to contact those websites directly for information on their privacy policy, security, and data collection and distribution practices.
§14. ACCESSING, MODIFYING AND DELETING YOUR PERSONAL DATA
If You wish to access, review or modify any information we hold about You, You may do so by contacting us at the following email address: ________. You may also request that we delete any Personal Data belonging to You that we have stored, subject to any contrary requirement of law.
§15. YOUR RIGHTS AS A DATA SUBJECT
In accordance with the NDPA and the NDPR, Your rights in relation to Your Personal Data are as follows:
(i) the right of access to Your Personal Data;
(ii) the right to be informed about the processing of Your Personal Data;
(iii) the right to rectify any inaccurate or incomplete Personal Data;
(iv) the right to erasure of Your Personal Data in the circumstances permitted by law;
(v) the right to restrict the processing of Your Personal Data;
(vi) the right to object to the processing of Your Personal Data;
(vii) the right to withdraw consent at any time where processing is based on consent;
(viii) the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects;
(ix) the right to data portability; and
(x) the right to lodge a complaint with the Nigeria Data Protection Commission.
§16. CONTACT INFORMATION AND COMPLAINTS
16.1 If You have any questions regarding this Privacy Policy or the Personal Data we collect, or if You wish to make any comments or complaints, please contact us at the following email address: ________.
16.2 Without prejudice to Your right to contact us, You also have the right to lodge a complaint directly with the Nigeria Data Protection Commission.
§17. GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of the Federal Republic of Nigeria, and any dispute arising hereunder shall be subject to the exclusive jurisdiction of the courts of ________.
§18. AMENDMENTS TO THIS PRIVACY POLICY
Fields you complete are inserted into the document live. This template is general guidance only — not legal advice.