Data Privacy & Protection Policy
How we collect, use, store, and protect your personal information.
The City Law Firm and Consultants (“TCLFC” or “the Firm”) is committed to maintaining the trust and confidence of its Data Subjects. For the purposes of this policy, Data Subjects are defined as individuals whose personal information (such as names, telephone numbers, and addresses) makes them easily identifiable. This includes current, past, and prospective employees, clients, merchants, suppliers, vendors, customers of merchants, and other individuals with whom the Firm communicates.
1. Introduction and Scope
TCLFC adheres strictly to the Nigeria Data Protection Act (NDPA) 2023 and the General Application and Implementation Directive (GAID) 2025. Compliance with these regulations and this Policy is mandatory. Any failure to comply constitutes a material violation of TCLFC’s policies and will lead to disciplinary action, which may include suspension or termination of employment or business relationships.
Scope
This Policy applies to all systems, operations, and processes within the Firm’s environment involving the collection, storage, use, transmission, and disposal of Personal Data. The scope includes:
- All TCLFC employees.
- External business partners (merchants, suppliers, contractors, and vendors).
- Third-party Data Processors who process data on behalf of the Firm.
2. General Principles for Personal Data Processing
TCLFC adheres to the following core principles to ensure a positive privacy culture:
- Lawfulness, Fairness and Transparency: Personal Data must be processed in a transparent manner and only for specific, legitimate, and lawful purposes consented to by the Data Subject, or as otherwise allowed by the legal grounds recognized in the NDPA.
- Data Accuracy: The Firm ensures that Personal Data is accurate, kept up-to-date, and not misleading. Inaccuracies discovered will be corrected or erased in a timely manner.
- Purpose Limitation:Personal Data is collected only for identified purposes for which consent was obtained. Data cannot be reused for incompatible purposes without new consent. Specific Legal and Operational Purposes include providing legal advice, managing client relationships, conducting legal research, complying with legal obligations, administering billing, preventing fraud, and improving the Firm's services.
- Data Minimization: Collection and usage are limited to data that is relevant, adequate, and absolutely necessary for the intended purpose. Anonymized data is used whenever the purpose allows.
- Integrity and Confidentiality: The Firm maintains controls to protect data from unauthorized access or accidental compromise. Employees may only access Personal Data necessary for their specific tasks and are prohibited from using it for private or commercial purposes.
- Personal Data Retention: Data is retained only as long as necessary for its intended purpose, or as required by contract or statute. Data is periodically reviewed and deleted when no longer required, unless needed for public interest archiving, scientific research, or historical purposes.
- Accountability: TCLFC continuously monitors and improves its privacy practices. Individuals who breach this Policy may face internal disciplinary action, as well as civil or criminal liability.
3. Data Privacy Notice Requirements
TCLFC provides Data Subjects with a Privacy Notice on any medium used for data collection. This notice must include the following:
- A description of the collectible Personal Data.
- The specific purposes for which data is collected, used, and disclosed.
- A clear definition of what constitutes Data Subject Consent.
- The technical methods utilized for data collection and storage.
- Available remedies in the event of a policy violation and the timeframe for any such remedies.
- Adequate information to initiate the exercise of privacy rights (access, rectification, and deletion).
4. Legal Grounds and Lawfulness of Processing
Personal Data processing at TCLFC is lawful only if at least one of the following bases applies:
- Consent: The Data Subject has given clear consent for a specific purpose.
- Contractual Necessity: Processing is required to perform a contract with the Data Subject or take pre-contractual steps.
- Legal Obligation: Processing is necessary for compliance with a legal obligation to which the Firm is subject.
- Vital Interests: Processing is necessary to protect the life of the Data Subject or another person.
- Public Interest: Processing is necessary for a task carried out in the public interest or under an official mandate.
- Legitimate Interest: Processing data to protect the Firm's legal and operational interests, prevent fraud, and improve the quality and security of services.
Sensitive Personal Data:Processing of Sensitive Personal Data (e.g., health, religion, political views) requires explicit consent. A simple "tick of the box" is insufficient to meet this legal standard.
Collection Methods
- Instructing or engaging the Firm for professional services.
- Client onboarding, KYC, and engagement forms.
- Consultations, interviews, meetings, and correspondence.
- Submission of legal documents, evidence, or contracts.
- Use of the Firm’s website, online forms, and client portals.
- Attendance at Firm-organized seminars or training programs.
- Communication through social media or other electronic channels.
5. Consent Management
- For consent to be valid, it must be given voluntarily by an informed Data Subject through a clear, affirmative action.
- Silence, pre-ticked boxes, or inactivity do not constitute consent.
- Consent must be requested in plain language and be distinct from other matters.
- Data Subjects must be informed that they can update, manage, or withdraw consent at any time.
- Consent of Minors: In instances involving minors, TCLFC ensures that consent is protected and obtained through the minor's legal representatives in accordance with regulatory requirements.
6. Data Subject Rights and Opt-Out Procedures
6.1 Individual Rights
Data Subjects are entitled to the following rights:
- Access: Request access to their collected data and receive it in a common electronic format.
- Information: Receive information on how their data is collected and stored.
- Objection/Restriction: Object to or request restriction of specific processing activities.
- Automated Decision-Making: Object to decisions made solely by automated systems.
- Rectification: Request the correction or modification of inaccurate data.
- Deletion: Request the erasure of data (subject to legal/statutory exceptions).
- Portability: Request the transfer of data to a third party.
- Complaints: Lodge a complaint with the Nigeria Data Protection Commission (NDPC).
- Withdrawal: Withdraw consent at any time.
6.2 Marketing Opt-Out
Data Subjects may opt out of marketing communications by:
- Contacting the TCLFC customer service team.
- Clicking the "unsubscribe" link in any Firm email.
- Disabling push notifications or marketing settings within Firm applications.
7. Data Transfer Protocols
7.1 Third-Party Processors (Nigeria)
The engagement of third parties to process Personal Data within Nigeria must be governed by a written contract. This contract must ensure the processor implements security measures that comply with the NDPA and this Policy.
7.2 Cross-Border Transfers
TCLFC only transfers Personal Data outside of Nigeria under strict conditions, such as:
- The recipient country has an Adequacy decision from the NDPC.
- The transfer is governed by Binding Corporate Rules or Standard Contractual Clauses.
- The transfer is necessary for contractual performance or public interest.
Mandatory Proviso: In all cross-border transfers, Data Subjects must be manifestly made to understand through clear warnings of the specific data protection principles that are likely to be violated in the destination country, unless the Data Subject is answerable in a duly established legal action in that country.
8. Data Breach Management and Impact Assessment
Reporting Incidents: Employees must immediately report any suspected breaches to their line manager or the DPO. Reportable incidents include loss or theft of data, accidental sharing with unauthorized parties, hacking attacks, and improper cross-border transmissions.
Investigation and Management: The Firm will validate the breach, investigate using impartial methods, identify remediation requirements, report findings to management, and coordinate with authorities and notify impacted Data Subjects as necessary.
Data Protection Impact Assessment (DPIA): TCLFC shall conduct a DPIA for any new project or IT system involving Personal Data processing that is likely to result in high risk to the rights and freedoms of Data Subjects.
9. Technical Security and Governance
9.1 Technical Controls
The Firm implements the following measures to secure Personal Data:
- Industry-accepted hardening standards for workstations, servers, and databases.
- Full disk software encryption for all corporate laptops storing Personal Data.
- Encryption at rest for key databases and enabled security audit logging.
- Restrictions on the use of removable media and physical access controls.
- Anonymization techniques for testing environments.
9.2 Data Protection Officer (DPO)
The DPO is responsible for overseeing the Firm's data strategy, including monitoring compliance, advising management, acting as the primary contact point, and ensuring DPIAs are conducted.
9.3 Compliance
TCLFC provides annual data privacy training to all staff and undergoes an annual data protection audit conducted by a licensed Data Protection Compliance Organization (DPCO).
10. Glossary
- Consent: Any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes by which they signify agreement to the processing of their Personal Data.
- Data Processor: A person or organization that processes Personal Data on behalf and on instructions of The City Law Firm and Consultants (TCLFC).
- DPCO: An organization registered by the NDPC to provide data protection audit, compliance, and training services.
- Data Subject: An identifiable natural person who can be identified by reference to an identification number or factors specific to their identity.
- NDPA: The Nigeria Data Protection Act, 2023.
- Personal Data: Any information relating to an identified or identifiable natural person, such as name, address, photo, email, or online identifiers.
- Sensitive Personal Data: Data relating to religious beliefs, sexual orientation, health, race, ethnicity, political views, trade union membership, or criminal records.
Ready to work with The City Law Firm and Consultants?
Schedule a consultation with our experienced legal team to discuss your matter in confidence.
