Site icon Nairametrics

Data protection: NDPC to sanction executives of MDAs for data breaches

NDPC, Dr. Vincent Olatunji

National Commissioner NDPC, Dr. Vincent Olatunji

The Nigeria Data Protection Commission (NDPC) has said that it will now hold chief executives of government Ministries, Agencies, and Departments (MDAs) responsible for any data breach that occurs under their watch.

Speaking in a chat with Nairametrics on the implementation of the Nigeria Data Protection Act, the National Commissioner of the NDPC, Dr. Vincent Olatunji, said the individuals heading the MDAs will be sanctioned because the government cannot be made to pay fine into its coffers. This is even as he disclosed that the level of compliance with data protection law by MDAs has just increased to 9% from 4% last year.

While the Commission has been sanctioning private companies under the Nigeria Data Protection Regulation (NDPR), no government agency has been fined even while there are concerns that they are the most culpable when it comes to data breaches.

However, Olatunji said that era is now over with the signing of the Data Protection Bill into law.

49% compliance by the private sector

Apparently, due to the enforcement of sanctions, Olatunji said the level of compliance by private sector organizations now stands at 49%, far ahead of the 9% by the public sector.

To improve compliance by both public and private organizations, the data protection boss said the is embarking on capacity building across the country to train more data protection officers.

Government agencies such as the National Identity Management Commission (NIMC), Nigeria Immigration Service (NIS), and Federal Road Safety Corp (FRSC) are some of the largest processors of Nigerians’ data currently and are required to also comply with the data protection law, which was recently signed into law by President Bola Tinubu.

Possible sanctions

According to Olatunji, in the case of a Data Controller dealing with more than 10,000 Data Subjects, the NDPR stipulates the payment of a fine of 2% of the organization’s annual gross revenue of the preceding year or the payment of the sum of N10 million, whichever is greater.

In the case of a Data Controller dealing with less than 10,000 Data Subjects, the sanction involves the payment of a fine representing 1% of the organization’s annual gross revenue of the preceding year or payment of the sum of N2,000,000.00 (two million Naira) (approx. EUR 2,000), whichever is greater.

Exit mobile version