As part of our operations, Afam Power Plc (“APP” or “the Company”) collects and processes certain types of information of individuals that makes them easily identifiable. These individuals include current, past, and prospective employees, vendors, customers/clients and their representatives, next-of-kin and other individuals whom Afam Power communicates or deals with, jointly and/or severally (“Data Subjects”). Maintaining the Data Subject’s trust and confidence requires that Data Subjects do not suffer negative consequences/effects as a result of providing Afam Power with their Personal Data. To this end, the Company is firmly committed to complying with applicable data protection laws, regulations, rules, and principles to ensure security of Personal Data handled by the Company.
This Data Privacy & Protection Policy (“the Policy”) describes the minimum standards that must be strictly adhered to regarding the collection, storage, use, retention, transfer, and disclosure of Personal Data and indicates that the Company is dedicated to processing the Personal Data it receives or processes with absolute confidentiality and security.
3.1 This Policy applies to all forms of systems, operations, and processes within the Afam Power environment that involve the collection, storage, use, retention, transmission, and disposal of Personal Data.
3.2 This Policy applies to all employees of Afam Power, as well as to any external business partners (such as suppliers, contractors, vendors, and other service providers) who receive, send, collect, access, or process Personal Data in any way on behalf of the Company, including processing wholly or partly by automated means. This Policy also applies to Third Party Data Processors who process Personal Data received from Afam Power.
3.3 This Data Privacy & Protection Policy shall be applicable in conjunction with the Personal Data Breach Management Policy, the Data Protection Impact Assessment Policy, Data Governance Policy, Information Technology Policy & Procedures, the ERM Framework and the Document Management Policy.
3.4 Violations may result in disciplinary action, which may include but is not limited to suspension, restriction of access, or more severe penalties up to and including termination of employment or business relationships.
The Data Protection Officer (DPO) has the ultimate responsibility for the adherence to, and enforcement of this Policy. The DPO is also responsible for overseeing the Company’s data protection strategy and its implementation to ensure compliance with the NDPA and NDPR requirements. In carrying out these responsibilities, the DPO relies on the full cooperation and coordination of the Business Units within the Company and shall work within the Data Protection organisational structure set out in Appendix 1.
“Consent” means any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which he or she, through a statement or a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her.
“Data” means all characters, symbols, documents, records, media, either electronic or manual which pertains to an individual’s information or the Company’s information.
“Database” means a collection of data organised in a manner that allows access, retrieval, deletion, and processing of that data; it includes but is not limited to structured, unstructured, cached, and file system type Databases.
“Data Administrator” means a person or organisation that processes data.
“Data Controller” means a person who either alone, jointly with other persons or in common with other persons or as a statutory body determines the purposes for and the manner in which personal data is processed or is to be processed.
“Data Processor” means a person or organisation that processes Personal Data on behalf and on instructions of the Company.
“Data Subject” means any person, who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural, or social identity.
“DPIA” means Data Protection Impact Assessment.
“DPCO” means an organisation registered by the NDPC to provide data protection audit, compliance, and training services to public and private organisations who process Personal Data in Nigeria.
“DPO” means the Company’s Data Protection Officer.
“GDPR” means the European Union (EU) General Data Protection Regulation 2018.
“HAGF” means the Honourable Attorney-General of the Federation.
“NITDA” means the National Information Technology Development Agency.
“NDPA” means the Nigerian Data Protection Act, 2023.
“NDPR” means the Nigeria Data Protection Regulation, 2019.
“NDPC” means the Nigeria Data Protection Commission. This is the main supervisory and regulatory authority for data protection and oversees the implementation of the NDPA and matters relating to data protection in Nigeria.
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Personal Data” means any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. It can be anything from a name, address, a photo, an email address, bank details, posts on social networking websites, medical information, and other unique identifiers such as but not limited to MAC address, IP address, IMEI number, IMSI number, SIM, Personal Identifiable Information (PII) and others.
“Policy” means this Data Privacy and Protection Policy.
“Sensitive Personal Data” means Personal Data relating to religious or other beliefs, sexual orientation, health, race, ethnicity, political views, trades union membership, criminal records, or any other sensitive personal information.
“Third Party” means any natural or legal person, public authority, establishment, or any other body other than the Data Subject, the Data Controller, the Data Administrator, and the persons who are engaged by the Data Controller or the Data Administrator to process personal data.
Afam Power is committed to maintaining the principles in the NDPA and NDPR regarding the processing of Personal Data.
To demonstrate this commitment as well as our aim of creating a positive privacy culture within Afam Power, the Company adheres to the following basic principles relating to the processing of Personal Data:
Personal Data must be processed lawfully, fairly, and in a transparent manner at all times. This implies that Personal Data collected and processed by or on behalf of Afam Power must be in accordance with the specific, legitimate, and lawful purpose consented to by the Data Subject, save where the processing is otherwise allowed by law or within other legal grounds recognised in the NDPA and NDPR.
Personal Data kept by the Company must be accurate and kept up to date. In this regard, Afam Power:
Afam Power collects Personal Data only for the purposes identified in the appropriate privacy notice or any other relevant document or based on any other non-written communication (where applicable), provided to the Data Subject and for which Consent has been obtained. Such Personal Data cannot be reused for another purpose that is incompatible with the original purpose, except a new Consent is obtained.
6.4.1 Afam Power limits Personal Data collection and usage to Data that is relevant, adequate, and absolutely necessary for carrying out the purpose for which the Data is processed.
6.4.2 The Company will evaluate whether and to what extent the processing of personal data is necessary and where the purpose allows, anonymised data must be used.
6.5.1 The Company shall establish adequate controls in order to protect the integrity, security, and confidentiality of Personal Data, both in digital and physical format and to prevent Personal Data from being accidentally or deliberately compromised.
6.5.2 Personal Data of Data Subjects must be protected from unauthorised viewing or access and from unauthorised changes to ensure that it is reliable and correct.
6.5.3 Any Personal Data processing undertaken by an employee who has not been authorised to carry such out as part of their legitimate duties is unauthorised.
6.5.4 Employees may have access to Personal Data only as is appropriate for the type and scope of the task in question and are forbidden to use Personal Data for their own private or commercial purposes or to disclose them to unauthorised persons, or to make them available in any other way.
6.5.5 The Human Resources Department as part of the induction process must inform employees at the start of the employment relationship about the obligation to maintain Personal Data privacy. This obligation shall remain in force even after employment has ended.
All personal information shall be retained, stored, and destroyed by Afam Power in line with legislative and regulatory guidelines. For all Personal Data and records obtained, used, and stored within the Company, the Company shall perform periodical reviews of the data retained to confirm the accuracy, purpose, validity, and requirement to retain.
The following are some of the principles to be followed by the Company with respect to retention or storage of records/data:
6.6.1.1 The Company shall store, retain, archive, and destroy Personal Data in accordance with the provisions of the Company’s Document Management Policy and the retention policy set out therein.
6.6.1.2 Certain Personal Data will be retained permanently, for business reasons including but not limited to the protection of the Company’s interest, preservation of evidence, and conformation to good business practices. All such retained records shall be archived once they are no longer in use and shall not be further processed save where permissible or required.
6.6.1.3 To the extent permitted by applicable laws and without prejudice to the Company’s retention policy, the length of storage of Personal Data shall, amongst other things, be determined by:
Notwithstanding the foregoing and pursuant to the NDPA and the NDPR, the Company shall be entitled to retain and process Personal Data for archiving, scientific research, historical research, or statistical purposes for public interest.
Should any information retained under this Policy be stored in an encrypted format, consideration must be taken for secure storage of the encryption keys. Encryption keys must be retained as long as the data that the keys decrypt is retained.
Afam Power demonstrates accountability in line with the NDPA and NDPR obligations by monitoring and continuously improving data privacy practices within the organisation.
7.1 The Company will ensure that the Data Subjects are provided with adequate information regarding the use of their Personal Data as well as acquire their respective Consent, where necessary.
7.2 The Company shall display a simple and conspicuous notice (Privacy Notice) on any medium through which Personal Data is being collected or processed. The following information must be considered for inclusion in the Privacy Notice, as appropriate in distinct circumstances, in order to ensure fair and transparent processing:
Afam Power’s Privacy Notice is available on the Company’s website via: www.transcorppower.com/privacy-policy/
In accordance with the NDPA, data processing shall be lawful where:
Where processing of Personal Data is based on Consent, the Company shall obtain the requisite consent of Data Subjects at the time of collection of Personal Data. In this regard, the Company will ensure that:
9.1.1 For Consent to be valid, it must be given voluntarily by an appropriately informed Data Subject. In line with regulatory requirements, Consent cannot be implied. Silence, pre-ticked boxes, or inactivity does not constitute Consent under the NDPA and shall not be a practice of the Company.
9.1.2 Consent in respect of Sensitive Personal Data must be explicit. A tick of the box would not suffice. In accordance with the NDPA, a data controller or data processor shall not process, or permit a data processor to process on its behalf, sensitive personal data, unless the –
Where a data subject is a child or a person lacking the legal capacity to consent, Afam Power shall obtain the consent of the parent or legal guardian, as applicable, to rely on consent under the NDPA.
The above requirement shall however not be applicable, where the processing is:
The Consents of minors (under the age of 18) will always be protected and obtained from minor’s representatives in accordance with all applicable regulatory requirements.
10.1 All individuals who are the subject of Personal Data held by Afam Power are entitled to the following rights:
10.1.1 Right to request for and access their Personal Data collected and stored. Where Data is held electronically in a structured form, such as in a Database, the Data Subject has a right to receive that data in a common electronic format.
10.1.2 Right to information on their Personal Data collected and stored.
10.1.3 Right to objection or request for restriction.
10.1.4 Right to object to automated decision making.
10.1.5 Right to request rectification and modification of their Data which the Company keeps.
10.1.6 Right to request for deletion of their data, except as restricted by law or the Company’s statutory obligations.
10.1.7 Right to request the movement of data from the Company to a Third Party; this is the right to the portability of data.
10.1.8 Right to opt out of marketing and unsolicited messages.
10.1.9 Right to object to, and to request that the Company restricts the processing of their information except as required by law or the Company’s statutory obligations.
10.2 The Company shall publish a Data Subject Access Request Procedure on its website, in the form set out in Appendix 2, which sets out the Company’s well-defined procedure regarding how to handle and answer Data Subjects’ requests.
10.3 Data Subjects can exercise any of their rights by completing the Afam Power’s Subject Access Request (SAR) Form and submitting to the Company via privacy_Afam@transcorppower.com.
11.1.1 Where Personal Data is to be transferred to a country outside Nigeria, the Company shall put adequate measures in place to ensure the security of such Personal Data. In particular, the Company shall, among other things, conduct a detailed assessment and seek to ascertain adequacy of data protection laws.
11.1.2 The transfer of Personal Data out of Nigeria would be in accordance with the provisions of the NDPA. Afam Power will therefore only transfer Personal Data out of Nigeria on one of the following conditions:
Provided in all circumstances, that the Data Subject has been manifestly made to understand through clear warnings, of the specific principle(s) of data protection that are likely to be violated in the event of transfer to a third country. This provision shall however not apply to any instance where the Data Subject is answerable in duly established legal action for any civil or criminal claim in a third country.
11.1.3 For transfer of data outside Nigeria, the Company will engage with the NDPC for guidance and approval with respect to such transfer. Afam Power will provide the NDPC with the following information:
11.1.4 Where Personal Data is transferred out of Nigeria pursuant to Section 11.1.3 above, Afam Power will work with NDPC to coordinate transfer requests.
In addition to the procedure stated in Section 11.1 of this document, where the Company transfers Personal Data to any other entity within the Afam Power Group, Afam Power will execute an Intra Group Transfer Agreement or a Third-Party Processing Agreement with such company.
The Company shall establish and maintain a data breach management procedure in order to deal with incidents concerning Personal Data or privacy practices leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed. All personal data breach management shall be done in line with the procedures laid down in the Company’s Personal Data Breach Management Policy.
The Company shall carry out a Data Protection Impact Assessment (DPIA) in respect of any new project or IT system involving the processing of Personal Data to determine whenever a type of processing is likely to result in any risk to the rights and freedoms of Data Subjects.
Afam Power shall carry out the DPIA in line with the procedures laid down in the Company’s Data Protection Impact Assessment Policy.
14.1 All Personal Data must be kept securely and should not be stored any longer than necessary. Afam Power will ensure that appropriate measures are employed against unauthorised access, accidental loss, damage, and destruction to Data. This includes the use of password-encrypted databases for digital storage and locked cabinets for those using paper form.
14.2 To ensure security of Personal Data, Afam Power will, among other things, implement any of the following appropriate technical controls:
14.3 In cases where data protection breaches such as illegal activities or theft of Company property, either physical or intellectual, is suspected, the Company may report such activities to the Nigeria Data Protection Commission (NDPC).
Afam Power shall ensure that its employees who collect, access, and process Personal Data receive adequate data privacy and protection training in order to develop the necessary knowledge, skills, and competence required to effectively manage the compliance framework under this Policy and the NDPA with regard to the protection of Personal Data. On an annual basis, the DPO shall develop a capacity building plan for employees on data privacy and protection in line with the NDPA.
In line with the NDPA, where the Company processes Personal Data of more than 2000 Data Subjects annually, the Company shall within the first 3 months of the following year, conduct a data protection audit through a licensed Data Protection Compliance Organisation (DPCO) to verify the Company’s compliance with the provisions of the NDPA and other applicable data protection laws. The audit report will be certified and filed by the DPCO to the NDPC as required under the NDPA.
Non-compliance with the provisions of this Framework by a staff in any business unit or functional area shall be handled in line with the Company’s Disciplinary Process and Sanctions Grid Policy.
Any delegation of authority conferred by this Policy shall be in accordance with the approved procedure for the delegation of authority as set out in the Delegation of Authority & Empowerment Policy.
The Board shall approve all requests for any waiver to this Policy. All such waiver approvals shall be obtained in writing and kept as a record by the policy owner.
This Policy shall be reviewed every three years by the policy owner, and may be amended, subject to approval, if deemed necessary. The Company however reserves the right to change any of the provisions of this policy as it deems fit or required from time to time and such change shall apply to all Staff of the Company from the date of change as it relates to the subject-matter.
The Data Protection Officer (DPO) would report directly to the Management and should be in constant and direct communication with the Data Champions within the various Business Units for the implementation of the data privacy framework within the Company.
The Data Protection Officer has the responsibility of acting as a central authority for the implementation of Afam Power’s privacy program and is responsible for the protection of the personal data within the organisation.
The main responsibilities of the DPO include, but are not limited to:
Each Data Champion is responsible for the protection of the personal data within their respective business units.
The main responsibilities of the Data Champions include but are not limited to:
The Management is responsible for defining the general principles, vetting the strategy for the protection of personal data, and making the ultimate decisions on matters concerning the compliance of the Company’s personal data protection framework, subject to Board approval.
The main responsibilities of the Management include, but are not limited to:
1.1 Afam Power collects and processes Personal Data of Data Subjects in furtherance of its business operations.
1.2 In line with the provisions of the NDPA, Data Subjects are entitled to the rights below:
2.1 Where a Data Subject wishes to exercise any of the rights guaranteed under the NDPR, they shall make a formal request by completing the Subject Access Request Form (SAR Form) and sending the completed form via email to the Data Protection Officer (DPO) at privacy_Afam@transcorppower.com.
2.2 Afam Power shall contact the Data Subject within 5 working days of the receipt of the SAR Form to confirm receipt of the subject access request and may request additional information to verify and confirm the identity of the individual making the request.
2.3 The DPO, on receiving any request from a Data Subject, shall record the request and carry out verification of the identity of the individual making the request using the details provided in the SAR Form and a valid means of identification such as international passport, driver’s license, national identification card or any other acceptable means of identification.
2.4 Where the request is from a third party (such as a relative or representative of the Data Subject), the DPO will verify their authority to act for the Data Subject and may contact the Data Subject to confirm their identity and request the Data Subject’s consent to disclose the information.
2.5 When the identity of the individual making the request is verified, the DPO shall coordinate the gathering of all information collected with respect to the individual in a concise, transparent, intelligible, and easily accessible form, using clear and plain language with a view to responding to the specific request. The information may be provided in writing, or by other means, including, where appropriate, by electronic means or orally provided that the identity of the Data Subject is proven by other means.
2.6 Where the information requested relates directly or indirectly to another person, the DPO will seek the consent of that person before processing the request. However, where disclosure would adversely affect the rights and freedoms of others and the DPO is unable to disclose the information, the DPO will inform the requestor promptly, with reasons for that decision.
3.1 Afam Power shall ensure that it provides the information required by a Data Subject or respond to the request by the Data Subject within a period of one month from the receipt of the request. However, where Afam Power is unable to act on the request of the Data Subject, it shall inform the Data Subject promptly at least within one month of receipt of the request of the reasons for not taking action and notify them of the option of lodging a complaint with the Nigeria Data Protection Commission (NDPC), in line with the NDPA.
Any information provided to the Data Subject by Afam Power shall be provided free of charge. However, where requests from a Data Subject are manifestly unfounded or excessive in particular because of their repetitive or cumbersome nature, Afam Power may:
To the extent permitted by applicable laws, Afam Power may refuse to act on a Data Subject’s request, if at least one of the following applies:
Afam Power reserves the right to change, amend, or alter this Policy at any point in time. If we amend this Policy, an updated version will be issued.
Afam Power has appointed a DPO responsible for overseeing the Company’s data protection strategy and its implementation to ensure compliance with NDPA requirements.
The DPO should be contacted via email at privacy_Afam@transcorppower.com if you have any queries or clarifications regarding the operation of this Policy.