Data Privacy & Protection Policy

Since the official handover of the power plant in February 2021, Transafam Power has embarked on an extraordinary journey, positively impacting Nigeria's power sector.

1. Introduction

As part of our operations, Afam Power Plc (“APP” or “the Company”) collects and processes certain types of information of individuals that makes them easily identifiable. These individuals include current, past, and prospective employees, vendors, customers/clients and their representatives, next-of-kin and other individuals whom Afam Power communicates or deals with, jointly and/or severally (“Data Subjects”). Maintaining the Data Subject’s trust and confidence requires that Data Subjects do not suffer negative consequences/effects as a result of providing Afam Power with their Personal Data. To this end, the Company is firmly committed to complying with applicable data protection laws, regulations, rules, and principles to ensure security of Personal Data handled by the Company.

2. Purpose

This Data Privacy & Protection Policy (“the Policy”) describes the minimum standards that must be strictly adhered to regarding the collection, storage, use, retention, transfer, and disclosure of Personal Data and indicates that the Company is dedicated to processing the Personal Data it receives or processes with absolute confidentiality and security.

3. Scope

3.1 This Policy applies to all forms of systems, operations, and processes within the Afam Power environment that involve the collection, storage, use, retention, transmission, and disposal of Personal Data.

3.2 This Policy applies to all employees of Afam Power, as well as to any external business partners (such as suppliers, contractors, vendors, and other service providers) who receive, send, collect, access, or process Personal Data in any way on behalf of the Company, including processing wholly or partly by automated means. This Policy also applies to Third Party Data Processors who process Personal Data received from Afam Power.

3.3 This Data Privacy & Protection Policy shall be applicable in conjunction with the Personal Data Breach Management Policy, the Data Protection Impact Assessment Policy, Data Governance Policy, Information Technology Policy & Procedures, the ERM Framework and the Document Management Policy.

3.4 Violations may result in disciplinary action, which may include but is not limited to suspension, restriction of access, or more severe penalties up to and including termination of employment or business relationships.

4. Responsibility

The Data Protection Officer (DPO) has the ultimate responsibility for the adherence to, and enforcement of this Policy. The DPO is also responsible for overseeing the Company’s data protection strategy and its implementation to ensure compliance with the NDPA and NDPR requirements. In carrying out these responsibilities, the DPO relies on the full cooperation and coordination of the Business Units within the Company and shall work within the Data Protection organisational structure set out in Appendix 1.

5. Definitions

“Consent” means any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which he or she, through a statement or a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her.

“Data” means all characters, symbols, documents, records, media, either electronic or manual which pertains to an individual’s information or the Company’s information.

“Database” means a collection of data organised in a manner that allows access, retrieval, deletion, and processing of that data; it includes but is not limited to structured, unstructured, cached, and file system type Databases.

“Data Administrator” means a person or organisation that processes data.

“Data Controller” means a person who either alone, jointly with other persons or in common with other persons or as a statutory body determines the purposes for and the manner in which personal data is processed or is to be processed.

“Data Processor” means a person or organisation that processes Personal Data on behalf and on instructions of the Company.

“Data Subject” means any person, who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural, or social identity.

“DPIA” means Data Protection Impact Assessment.

“DPCO” means an organisation registered by the NDPC to provide data protection audit, compliance, and training services to public and private organisations who process Personal Data in Nigeria.

“DPO” means the Company’s Data Protection Officer.

“GDPR” means the European Union (EU) General Data Protection Regulation 2018.

“HAGF” means the Honourable Attorney-General of the Federation.

“NITDA” means the National Information Technology Development Agency.

“NDPA” means the Nigerian Data Protection Act, 2023.

“NDPR” means the Nigeria Data Protection Regulation, 2019.

“NDPC” means the Nigeria Data Protection Commission. This is the main supervisory and regulatory authority for data protection and oversees the implementation of the NDPA and matters relating to data protection in Nigeria.

“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

“Personal Data” means any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. It can be anything from a name, address, a photo, an email address, bank details, posts on social networking websites, medical information, and other unique identifiers such as but not limited to MAC address, IP address, IMEI number, IMSI number, SIM, Personal Identifiable Information (PII) and others.

“Policy” means this Data Privacy and Protection Policy.

“Sensitive Personal Data” means Personal Data relating to religious or other beliefs, sexual orientation, health, race, ethnicity, political views, trades union membership, criminal records, or any other sensitive personal information.

“Third Party” means any natural or legal person, public authority, establishment, or any other body other than the Data Subject, the Data Controller, the Data Administrator, and the persons who are engaged by the Data Controller or the Data Administrator to process personal data.

6. General Principles for Processing of Personal Data

Afam Power is committed to maintaining the principles in the NDPA and NDPR regarding the processing of Personal Data.

To demonstrate this commitment as well as our aim of creating a positive privacy culture within Afam Power, the Company adheres to the following basic principles relating to the processing of Personal Data:

6.1 Lawfulness, Fairness and Transparency

Personal Data must be processed lawfully, fairly, and in a transparent manner at all times. This implies that Personal Data collected and processed by or on behalf of Afam Power must be in accordance with the specific, legitimate, and lawful purpose consented to by the Data Subject, save where the processing is otherwise allowed by law or within other legal grounds recognised in the NDPA and NDPR.

6.2 Data Accuracy

Personal Data kept by the Company must be accurate and kept up to date. In this regard, Afam Power:

  1. shall ensure that any Data it collects and/or processes is accurate and not misleading in a way that could be harmful to the Data Subject;
  2. will make efforts to keep Personal Data updated where reasonable and applicable; and
  3. will make timely efforts to correct or erase Personal Data when inaccuracies are discovered.

6.3 Purpose Limitation

Afam Power collects Personal Data only for the purposes identified in the appropriate privacy notice or any other relevant document or based on any other non-written communication (where applicable), provided to the Data Subject and for which Consent has been obtained. Such Personal Data cannot be reused for another purpose that is incompatible with the original purpose, except a new Consent is obtained.

6.4 Data Minimisation

6.4.1 Afam Power limits Personal Data collection and usage to Data that is relevant, adequate, and absolutely necessary for carrying out the purpose for which the Data is processed.

6.4.2 The Company will evaluate whether and to what extent the processing of personal data is necessary and where the purpose allows, anonymised data must be used.

6.5 Integrity, Security and Confidentiality

6.5.1 The Company shall establish adequate controls in order to protect the integrity, security, and confidentiality of Personal Data, both in digital and physical format and to prevent Personal Data from being accidentally or deliberately compromised.

6.5.2 Personal Data of Data Subjects must be protected from unauthorised viewing or access and from unauthorised changes to ensure that it is reliable and correct.

6.5.3 Any Personal Data processing undertaken by an employee who has not been authorised to carry such out as part of their legitimate duties is unauthorised.

6.5.4 Employees may have access to Personal Data only as is appropriate for the type and scope of the task in question and are forbidden to use Personal Data for their own private or commercial purposes or to disclose them to unauthorised persons, or to make them available in any other way.

6.5.5 The Human Resources Department as part of the induction process must inform employees at the start of the employment relationship about the obligation to maintain Personal Data privacy. This obligation shall remain in force even after employment has ended.

6.6 Personal Data Retention

All personal information shall be retained, stored, and destroyed by Afam Power in line with legislative and regulatory guidelines. For all Personal Data and records obtained, used, and stored within the Company, the Company shall perform periodical reviews of the data retained to confirm the accuracy, purpose, validity, and requirement to retain.

6.6.1 Retention Principles

The following are some of the principles to be followed by the Company with respect to retention or storage of records/data:

6.6.1.1 The Company shall store, retain, archive, and destroy Personal Data in accordance with the provisions of the Company’s Document Management Policy and the retention policy set out therein.

6.6.1.2 Certain Personal Data will be retained permanently, for business reasons including but not limited to the protection of the Company’s interest, preservation of evidence, and conformation to good business practices. All such retained records shall be archived once they are no longer in use and shall not be further processed save where permissible or required.

6.6.1.3 To the extent permitted by applicable laws and without prejudice to the Company’s retention policy, the length of storage of Personal Data shall, amongst other things, be determined by:

  1. the contract terms agreed between Afam Power and the Data Subject or as long as it is needed for the purpose for which it was obtained; or
  2. whether the transaction or relationship has statutory implication or a statutorily required retention period; or
  3. an express request for deletion by the Data Subject; except where such Data Subject is under an investigation or under a subsisting contract which may require further processing or where the Data relates to criminal records; or
  4. whether the records or Data form the subject matter of an ongoing or anticipated litigation or government proceeding or investigation. In such instance, the Company shall not alter, destroy, or conceal any records or data with the intent to impede or obstruct or influence any litigation or government proceedings or in relation to the completion of any such litigation or government proceeding or investigation; or
  5. whether the Company has another lawful basis for retaining the information beyond the period for which it is necessary to serve the original purpose.

Notwithstanding the foregoing and pursuant to the NDPA and the NDPR, the Company shall be entitled to retain and process Personal Data for archiving, scientific research, historical research, or statistical purposes for public interest.

6.6.2 Retention of Encrypted Data

Should any information retained under this Policy be stored in an encrypted format, consideration must be taken for secure storage of the encryption keys. Encryption keys must be retained as long as the data that the keys decrypt is retained.

6.7 Accountability

Afam Power demonstrates accountability in line with the NDPA and NDPR obligations by monitoring and continuously improving data privacy practices within the organisation.

7. Data Privacy Notice

7.1 The Company will ensure that the Data Subjects are provided with adequate information regarding the use of their Personal Data as well as acquire their respective Consent, where necessary.

7.2 The Company shall display a simple and conspicuous notice (Privacy Notice) on any medium through which Personal Data is being collected or processed. The following information must be considered for inclusion in the Privacy Notice, as appropriate in distinct circumstances, in order to ensure fair and transparent processing:

  1. Description of collectible Personal Data
  2. Purposes for which Personal Data is collected, used, and disclosed
  3. What constitutes Data Subject’s Consent
  4. The technical methods used to collect and store the information
  5. Available remedies in the event of violation of the Policy and the timeframe for remedy
  6. Adequate information in order to initiate the process of exercising their privacy rights, such as access to, rectification, and deletion of Personal Data

Afam Power’s Privacy Notice is available on the Company’s website via: www.transcorppower.com/privacy-policy/

8. Lawful Basis

In accordance with the NDPA, data processing shall be lawful where:

  1. The data subject has given and not withdrawn consent for the specific purpose.
  2. The processing is necessary –
    1. for the performance of a contract to which the data subject is a party;
    2. for compliance with a legal obligation to which the data controller or data processor is subject;
    3. to protect the vital interest of the data subject or another person;
    4. for the performance of a task carried out in the public interest;
    5. in the exercise of official authority vested in the data controller or data Processor; or
    6. for the purposes of the legitimate interests pursued by the data controller or data processor, or by a third party to whom the data is disclosed.

9. Consent

Where processing of Personal Data is based on Consent, the Company shall obtain the requisite consent of Data Subjects at the time of collection of Personal Data. In this regard, the Company will ensure that:

  1. the specific purpose of collection is made known to the Data Subject and the Consent is requested in a clear and plain language;
  2. the Consent is freely given by the Data Subject and obtained without fraud, coercion, or undue influence;
  3. the Consent is sufficiently distinct from other matters to which the Data Subject has agreed;
  4. the Consent is explicitly provided in an affirmative manner;
  5. Consent is obtained for each purpose of Personal Data collection and processing; and
  6. it is clearly communicated to and understood by Data Subjects that they can update, manage, or withdraw their Consent at any time.

9.1 Valid Consent

9.1.1 For Consent to be valid, it must be given voluntarily by an appropriately informed Data Subject. In line with regulatory requirements, Consent cannot be implied. Silence, pre-ticked boxes, or inactivity does not constitute Consent under the NDPA and shall not be a practice of the Company.

9.1.2 Consent in respect of Sensitive Personal Data must be explicit. A tick of the box would not suffice. In accordance with the NDPA, a data controller or data processor shall not process, or permit a data processor to process on its behalf, sensitive personal data, unless the –

  1. data subject has given and not withdrawn consent to the processing for the specific purpose or purposes for which it will be processed;
  2. processing is necessary for the purposes of performing the obligations of the data controller or exercising rights of the data subject under employment or social security laws or any other similar laws;
  3. processing is necessary to protect the vital interests of the data subject or of another person, where the data subject is physically or legally incapable of giving consent;
  4. processing is carried out in the course of its legitimate activities, with appropriate safeguards, by a foundation, association, or such other non-profit organisation with charitable, educational, literary, artistic, philosophical, religious, or trade union purposes, and the –
    1. processing relates solely to the members or former members of the entity, or to persons who have regular contact with it in connection with its purposes;
    2. sensitive personal data is not disclosed outside of the entity without the explicit consent of the data subject;
  5. processing is necessary for the establishment, exercise, or defence of a legal claim, obtaining legal advice, or conduct of a legal proceeding;
  6. processing is necessary for reasons of substantial public interest, on the basis of a law, which shall be proportionate to the aim pursued, and provides for suitable and specific measures to safeguard the fundamental rights, freedoms, and interests of the data subject;
  7. processing is carried out for purposes of medical care or community welfare and undertaken by or under the responsibility of a professional or similar service provider owing a duty of confidentiality;
  8. processing is necessary for reasons of public health and provides for suitable and specific measures to safeguard the fundamental rights, freedoms, and interests of the data subject; or
  9. processing is necessary for archiving purposes in the public interest, or historical, statistical, or scientific research, in each case on the basis of a law, which shall be proportionate to the aim pursued, and provides for suitable and specific measures to safeguard the fundamental rights and freedoms and the interests of the data subject.

9.2 Consent of Minors

Where a data subject is a child or a person lacking the legal capacity to consent, Afam Power shall obtain the consent of the parent or legal guardian, as applicable, to rely on consent under the NDPA.

The above requirement shall however not be applicable, where the processing is:

  1. necessary to protect the vital interests of the child or person lacking the legal capacity to consent;
  2. carried out for purposes of education, medical, or social care, and undertaken by or under the responsibility of a professional or similar service provider owing a duty of confidentiality; or
  3. necessary for proceedings before a court relating to the individual.

The Consents of minors (under the age of 18) will always be protected and obtained from minor’s representatives in accordance with all applicable regulatory requirements.

10. Data Subject Rights

10.1 All individuals who are the subject of Personal Data held by Afam Power are entitled to the following rights:

10.1.1 Right to request for and access their Personal Data collected and stored. Where Data is held electronically in a structured form, such as in a Database, the Data Subject has a right to receive that data in a common electronic format.

10.1.2 Right to information on their Personal Data collected and stored.

10.1.3 Right to objection or request for restriction.

10.1.4 Right to object to automated decision making.

10.1.5 Right to request rectification and modification of their Data which the Company keeps.

10.1.6 Right to request for deletion of their data, except as restricted by law or the Company’s statutory obligations.

10.1.7 Right to request the movement of data from the Company to a Third Party; this is the right to the portability of data.

10.1.8 Right to opt out of marketing and unsolicited messages.

10.1.9 Right to object to, and to request that the Company restricts the processing of their information except as required by law or the Company’s statutory obligations.

10.2 The Company shall publish a Data Subject Access Request Procedure on its website, in the form set out in Appendix 2, which sets out the Company’s well-defined procedure regarding how to handle and answer Data Subjects’ requests.

10.3 Data Subjects can exercise any of their rights by completing the Afam Power’s Subject Access Request (SAR) Form and submitting to the Company via privacy_Afam@transcorppower.com.

11. Transfer of Personal Data

11.1 Regulatory Procedures for Transfer of Personal Data Outside Nigeria

11.1.1 Where Personal Data is to be transferred to a country outside Nigeria, the Company shall put adequate measures in place to ensure the security of such Personal Data. In particular, the Company shall, among other things, conduct a detailed assessment and seek to ascertain adequacy of data protection laws.

11.1.2 The transfer of Personal Data out of Nigeria would be in accordance with the provisions of the NDPA. Afam Power will therefore only transfer Personal Data out of Nigeria on one of the following conditions:

  1. The recipient of the personal data is subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism that affords an adequate level of protection with respect to the personal data in accordance with the NDPA.
  2. The consent of the Data Subject has been obtained.
  3. The transfer is necessary for the performance of a contract between Afam Power and the Data Subject or, implementation of pre-contractual measures taken at the Data Subject’s request.
  4. The transfer is necessary to conclude a contract between Afam Power and a third party in the interest of the Data Subject.
  5. The transfer is necessary for reason of public interest.
  6. The transfer is for the establishment, exercise, or defence of legal claims; and
  7. The transfer is necessary in order to protect the vital interests of the Data Subjects or other persons, where the Data Subject is physically or legally incapable of giving consent.

Provided in all circumstances, that the Data Subject has been manifestly made to understand through clear warnings, of the specific principle(s) of data protection that are likely to be violated in the event of transfer to a third country. This provision shall however not apply to any instance where the Data Subject is answerable in duly established legal action for any civil or criminal claim in a third country.

11.1.3 For transfer of data outside Nigeria, the Company will engage with the NDPC for guidance and approval with respect to such transfer. Afam Power will provide the NDPC with the following information:

  1. A list of countries where the Personal Data of Nigerian citizens are transferred in the regular course of business.
  2. The Data Protection Laws and contact of National Data Protection Office/Administration of such countries where Personal Data is transferred to.
  3. The Privacy Policy of Afam Power which is compliant with the provisions of the NDPA.
  4. An overview of encryption methods and data security standards; and
  5. Any other detail that assures the privacy of Personal Data is adequately protected in the target country.

11.1.4 Where Personal Data is transferred out of Nigeria pursuant to Section 11.1.3 above, Afam Power will work with NDPC to coordinate transfer requests.

11.2 Transfer of Personal Data from Nigeria to other Entities within the Afam Power Group

In addition to the procedure stated in Section 11.1 of this document, where the Company transfers Personal Data to any other entity within the Afam Power Group, Afam Power will execute an Intra Group Transfer Agreement or a Third-Party Processing Agreement with such company.

12. Data Breach Management

The Company shall establish and maintain a data breach management procedure in order to deal with incidents concerning Personal Data or privacy practices leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed. All personal data breach management shall be done in line with the procedures laid down in the Company’s Personal Data Breach Management Policy.

13. Data Protection Impact Assessment

The Company shall carry out a Data Protection Impact Assessment (DPIA) in respect of any new project or IT system involving the processing of Personal Data to determine whenever a type of processing is likely to result in any risk to the rights and freedoms of Data Subjects.

Afam Power shall carry out the DPIA in line with the procedures laid down in the Company’s Data Protection Impact Assessment Policy.

14. Data Security

14.1 All Personal Data must be kept securely and should not be stored any longer than necessary. Afam Power will ensure that appropriate measures are employed against unauthorised access, accidental loss, damage, and destruction to Data. This includes the use of password-encrypted databases for digital storage and locked cabinets for those using paper form.

14.2 To ensure security of Personal Data, Afam Power will, among other things, implement any of the following appropriate technical controls:

  1. Industry-accepted hardening standards, for workstations, servers, and databases.
  2. Full disk software encryption on all corporate workstation/laptops operating systems drives storing Personal and Personal/Sensitive Data.
  3. Encryption at rest including key management of key databases.
  4. Enable Security Audit Logging across all systems managing Personal Data.
  5. Restrict the use of removable media such as USB flash, disk drives.
  6. Anonymisation techniques on testing environments; and
  7. Physical access control where Personal Data are stored in hardcopy.

14.3 In cases where data protection breaches such as illegal activities or theft of Company property, either physical or intellectual, is suspected, the Company may report such activities to the Nigeria Data Protection Commission (NDPC).

15. Training

Afam Power shall ensure that its employees who collect, access, and process Personal Data receive adequate data privacy and protection training in order to develop the necessary knowledge, skills, and competence required to effectively manage the compliance framework under this Policy and the NDPA with regard to the protection of Personal Data. On an annual basis, the DPO shall develop a capacity building plan for employees on data privacy and protection in line with the NDPA.

16. Data Protection Audit

In line with the NDPA, where the Company processes Personal Data of more than 2000 Data Subjects annually, the Company shall within the first 3 months of the following year, conduct a data protection audit through a licensed Data Protection Compliance Organisation (DPCO) to verify the Company’s compliance with the provisions of the NDPA and other applicable data protection laws. The audit report will be certified and filed by the DPCO to the NDPC as required under the NDPA.

17. Consequences of Non-Compliance

Non-compliance with the provisions of this Framework by a staff in any business unit or functional area shall be handled in line with the Company’s Disciplinary Process and Sanctions Grid Policy.

18. Delegation

Any delegation of authority conferred by this Policy shall be in accordance with the approved procedure for the delegation of authority as set out in the Delegation of Authority & Empowerment Policy.

19. Waivers

The Board shall approve all requests for any waiver to this Policy. All such waiver approvals shall be obtained in writing and kept as a record by the policy owner.

20. Review and Amendment

This Policy shall be reviewed every three years by the policy owner, and may be amended, subject to approval, if deemed necessary. The Company however reserves the right to change any of the provisions of this policy as it deems fit or required from time to time and such change shall apply to all Staff of the Company from the date of change as it relates to the subject-matter.

Appendix 1: Data Protection Organisational Structure

The Data Protection Officer (DPO) would report directly to the Management and should be in constant and direct communication with the Data Champions within the various Business Units for the implementation of the data privacy framework within the Company.

1. Data Privacy Roles and Responsibilities

1.1 Data Protection Officer (DPO)

The Data Protection Officer has the responsibility of acting as a central authority for the implementation of Afam Power’s privacy program and is responsible for the protection of the personal data within the organisation.

The main responsibilities of the DPO include, but are not limited to:

  1. Monitoring compliance with the NDPA and other data protection laws and the Company’s data protection policies and procedures.
  2. Organise, implement, monitor, and update the implementation of the data protection policies and practices of the Company and ensure compliance amongst all employees.
  3. Oversee, supervise, and guide the actions of Data Champions in each business unit.
  4. Liaise with the appointed Data Protection Compliance Organisation (DPCO) with respect to any issue regarding personal data privacy and protection.
  5. Liaise with the Data Champions to ensure compliance with the data privacy framework within the Company.
  6. Report to Management about the Data Protection compliance level of each business unit, as well as highlight any perceived or potential risks in order to mitigate such risks.
  7. Monitor and coordinate the actions of each Data Privacy Champion during the personal data breach procedure in case of a related incident.
  8. Suggest strategic actions to strengthen the level of the protection of personal data of the Company and to reduce any identified risks.
  9. Carry out data protection and privacy awareness-raising, training, and audits.
  10. Advise the business, management, employees, and third parties who carry on processing activities of their obligations under the NDPA; with the support of the DPCO, liaise with the relevant government agencies and supervisory authorities during data privacy audits.
  11. Act as a contact point for Afam Power privacy related matters.
  12. With the support of the DPCO and the Legal team, monitor the laws and regulations that apply to the Company concerning the protection of personal data.
  13. Ensure that a data privacy impact assessment is conducted in accordance with the provisions of the NDPA and monitor the action plans to mitigate any identified risks, as well as notify the Management of any high risks that have been identified by the data privacy impact assessment.
  14. Monitor and update the implementation of the data protection policies and practices of Afam Power and ensure compliance amongst all employees of the Company.
  15. Handle and maintain register of processing activities (ROPA), register of grievances and Data Subjects requests related to data subject’s personal data.

1.2 Data Champion

Each Data Champion is responsible for the protection of the personal data within their respective business units.

The main responsibilities of the Data Champions include but are not limited to:

  1. Implement the data privacy framework in their respective Units/Departments.
  2. Contribute to the design and implementation of individual policies, procedures, and guidelines, if necessary, customised for the respective Business Units/Departments.
  3. Report to the Data Protection Officer on all issues pertaining to data privacy and personal data protection.
  4. Communicate with the DPO on behalf of the Business Unit/Departments for clarifications and queries on data protection.
  5. Ensure that data collected is appropriate, relevant, and limited to what is necessary for the purpose for which it is processed and manage consents which are initially received or revoked by data subjects for processing and retaining relevant evidence.
  6. Perform data privacy impact assessment where necessary and send the results of such assessments to the DPO for further evaluation.
  7. Notify the DPO of incidents of personal data breaches within the Business Unit/Department based on relevant procedures and instruction.

1.3 Management

The Management is responsible for defining the general principles, vetting the strategy for the protection of personal data, and making the ultimate decisions on matters concerning the compliance of the Company’s personal data protection framework, subject to Board approval.

The main responsibilities of the Management include, but are not limited to:

  1. Scrutinise and present the personal data protection framework to the Board for approval and provide the needed administrative mechanisms for its implementation within the Company.
  2. Define the framework within which all processing activities relating to the protection of Personal Data are carried out.
  3. Track the overall level of Personal Data protection, ascertain the maximum acceptable level of risk, and take the final decision on necessary and appropriate administrative and/or technological protection mechanisms.
  4. Facilitate initiatives and efforts pertaining to the protection of Personal Data within the Company.
  5. Ensure that the DPO fulfils his/her duties in an independent manner.
  6. Ensure the DPO has free and unhindered access to enable the DPO carry out his or her responsibilities as stated herein.

Appendix 2: Data Subject Access Procedure

1. Data Subject Rights

1.1 Afam Power collects and processes Personal Data of Data Subjects in furtherance of its business operations.

1.2 In line with the provisions of the NDPA, Data Subjects are entitled to the rights below:

  1. Right to request for and access Personal Data collected and stored by Afam Power.
  2. Right to object to processing of Personal Data.
  3. Right to be informed of and provide consent prior to the processing of data for purposes other than that for which the Personal Data were collected.
  4. Right to object to automated decision making and profiling.
  5. Right to withdraw consent at any time.
  6. Right to request rectification and modification of your data kept by Afam Power.
  7. Right to request for deletion of your data collected and stored by Afam Power; and
  8. Right to request the movement of data from Afam Power to a Third Party i.e. the right to the portability of data.

2. Subject Access Request Response Procedure

2.1 Where a Data Subject wishes to exercise any of the rights guaranteed under the NDPR, they shall make a formal request by completing the Subject Access Request Form (SAR Form) and sending the completed form via email to the Data Protection Officer (DPO) at privacy_Afam@transcorppower.com.

2.2 Afam Power shall contact the Data Subject within 5 working days of the receipt of the SAR Form to confirm receipt of the subject access request and may request additional information to verify and confirm the identity of the individual making the request.

2.3 The DPO, on receiving any request from a Data Subject, shall record the request and carry out verification of the identity of the individual making the request using the details provided in the SAR Form and a valid means of identification such as international passport, driver’s license, national identification card or any other acceptable means of identification.

2.4 Where the request is from a third party (such as a relative or representative of the Data Subject), the DPO will verify their authority to act for the Data Subject and may contact the Data Subject to confirm their identity and request the Data Subject’s consent to disclose the information.

2.5 When the identity of the individual making the request is verified, the DPO shall coordinate the gathering of all information collected with respect to the individual in a concise, transparent, intelligible, and easily accessible form, using clear and plain language with a view to responding to the specific request. The information may be provided in writing, or by other means, including, where appropriate, by electronic means or orally provided that the identity of the Data Subject is proven by other means.

2.6 Where the information requested relates directly or indirectly to another person, the DPO will seek the consent of that person before processing the request. However, where disclosure would adversely affect the rights and freedoms of others and the DPO is unable to disclose the information, the DPO will inform the requestor promptly, with reasons for that decision.

3. Fees and Timeframe

3.1 Afam Power shall ensure that it provides the information required by a Data Subject or respond to the request by the Data Subject within a period of one month from the receipt of the request. However, where Afam Power is unable to act on the request of the Data Subject, it shall inform the Data Subject promptly at least within one month of receipt of the request of the reasons for not taking action and notify them of the option of lodging a complaint with the Nigeria Data Protection Commission (NDPC), in line with the NDPA.

Any information provided to the Data Subject by Afam Power shall be provided free of charge. However, where requests from a Data Subject are manifestly unfounded or excessive in particular because of their repetitive or cumbersome nature, Afam Power may:

  1. charge a reasonable fee taking into account the administrative costs of providing the information or communication, taking the action required or making a decision to refuse to act on the request; or
  2. write a letter to the Data Subject stating refusal to act on the request and copying the Nigeria Data Protection Commission (NDPC).

4. Exceptions to Data Subjects Access Rights

To the extent permitted by applicable laws, Afam Power may refuse to act on a Data Subject’s request, if at least one of the following applies:

  1. in compliance with a legal obligation to which Afam Power is subject;
  2. protecting the vital interests of the Data Subject or of another natural person; and
  3. for public interest or in exercise of official public mandate vested in Afam Power.

5. Changes to the Policy

Afam Power reserves the right to change, amend, or alter this Policy at any point in time. If we amend this Policy, an updated version will be issued.

6. Contact for any Queries

Afam Power has appointed a DPO responsible for overseeing the Company’s data protection strategy and its implementation to ensure compliance with NDPA requirements.

The DPO should be contacted via email at privacy_Afam@transcorppower.com if you have any queries or clarifications regarding the operation of this Policy.