Legal framework
Our programme is designed around the Nigeria Data Protection Act 2023, the Nigeria Data Protection Commission’s General Application and Implementation Directive 2025, the constitutional right to privacy, the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 as amended in 2024, the Federal Competition and Consumer Protection Act 2018, and other sector-specific obligations that apply to schools, employment, records and payments.
Governance and accountability
- We identify controller and processor roles and use written data-processing terms with relevant service providers.
- We maintain records and privacy notices proportionate to processing risk, review lawful bases, and apply privacy by design and by default.
- We assess high-risk processing before deployment, particularly where children, sensitive data, monitoring, biometrics or significant automated decisions may be involved.
- Where thresholds in law or NDPC directives apply, the responsible controller will register, appoint the required data-protection contact or officer, and complete compliance audits or filings.
Security controls
Reasonable technical and organisational measures include least-privilege access, role separation, secure authentication and sessions, encryption in transit where deployed, audit trails, backups, vulnerability and patch management, staff confidentiality, provider due diligence, recovery planning and periodic control review. Access to student, finance and staff data is limited according to assigned responsibilities.
Data incidents
Suspected loss, unauthorised access, disclosure, alteration or destruction should be reported promptly to privacy@acudemy.school. We will contain and investigate the event, document decisions, notify the responsible controller, and notify the NDPC and affected data subjects when the NDP Act requires it, including within applicable statutory timelines.
Individual requests
Requests are logged, identity and authority are checked, relevant systems and processors are searched, exemptions are assessed narrowly, and the response is issued within the legally required period. Parents or guardians may act for a child where legally authorised, while the child’s age, capacity, rights and best interests remain relevant.
Retention, disposal and transfers
Record owners apply documented retention needs and legal holds. When no lawful need remains, data is deleted, anonymised or securely destroyed. International transfers are assessed and documented, with appropriate safeguards and processor obligations applied before transfer.
Training, monitoring and review
Personnel with data access should receive role-appropriate privacy and security guidance. Controls, incidents, processor performance and material system changes are periodically reviewed. Findings are tracked to completion, and this statement is updated when law, guidance or processing materially changes.
Regulatory sources
Authoritative materials are available from the Nigeria Data Protection Commission and the Federal Competition and Consumer Protection Commission. This public summary is not a substitute for organisation-specific legal advice or required regulatory filings.
