1. Introduction
As part of our operations, Transcorp Power Plc (“Transcorp Power” or “the Company”) collects and processes certain types of information of individuals that makes them easily identifiable. These individuals include current, past, and prospective employees, vendors, customers/clients and their representatives, next-of-kin and other individuals whom Transcorp Power communicates or deals with, jointly and/or severally (“Data Subjects”). Maintaining the Data Subject’s trust and confidence requires that Data Subjects do not suffer negative consequences/effects as a result of providing Transcorp Power with their Personal Data. To this end, the Company is firmly committed to complying with applicable data protection laws, regulations, rules, and principles to ensure security of Personal Data handled by the Company.
2. Purpose
This Data Privacy & Protection Policy (“the Policy”) describes the minimum standards that must be strictly adhered to regarding the collection, storage, use, retention, transfer, and disclosure of Personal Data and indicates that the Company is dedicated to processing the Personal Data it receives or processes with absolute confidentiality and security.
3. Scope
3.1. This Policy applies to all forms of systems, operations, and processes within the Transcorp Power environment that involve the collection, storage, use, retention transmission and disposal of Personal Data.
3.2. This Policy applies to all employees of Transcorp, as well as to any external business partners (such as suppliers, contractors, vendors, and other service providers) who receive, send, collect, access, or process Personal Data in any way on behalf of the Company, including processing wholly or partly by automated means. This Policy also applies to Third Party Data Processors who process Personal Data received from Transcorp.
3.3. This Data Privacy & Protection Policy shall be applicable in conjunction with the Personal Data Breach Management Policy, the Data Protection Impact Assessment Policy, Data Governance Policy, Information Technology Policy & Procedures, the ERM Framework and the Document Management Policy.
3.4. Violations may result in disciplinary action, which may include but is not limited to suspension, restriction of access, or more severe penalties up to and including termination of employment or business relationships.
4. Responsibility
The Data Protection Officer (DPO) has the ultimate responsibility for the adherence to, and enforcement of this Policy. The DPO is also responsible for overseeing the Company’s data protection strategy and its implementation to ensure compliance with the NDPA and NDPR requirements. In carrying out these responsibilities, the DPO relies on the full cooperation and coordination of the Business Units within the Company and shall work within the Data Protection organisational structure set out in Appendix 1.
5. Definitions
‘‘Consent’’ means any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which he or she, through a statement or a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her.
“Data” means all characters, symbols, documents, records, media, either electronic or manual which pertains to an individual’s information or the Company’s information.
“Database” means a collection of data organised in a manner that allows access, retrieval, deletion, and processing of that data; it includes but not limited to structured, unstructured, cached and file system type Databases.
“Data Administrator” means a person or organisation that processes data.
“Data Controller” means a person who either alone, jointly with other persons or in common with other persons or as a statutory body determines the purposes for and the manner in which personal data is processed or is to be processed.
“Data Processor” means a person or organisation that processes Personal Data on behalf and on instructions of the Company.
“Data Subject” means any person, who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural, or social identity.
“DPIA” means Data Protection Impact Assessment
“DPCO” means an organisation registered by the NDPC to provide data protection audit, compliance and training services to public and private organisations who process Personal Data in Nigeria.
“DPO” means the Company’s Data Protection Officer
“GDPR” means the European Union (EU) General Data Protection Regulation 2018.
“HAGF” means the Honorable Attorney-General of the Federation
“NITDA” means the National Information Technology Development Agency
“NDPA” means the Nigerian Data Protection Act, 2023
“NDPR” means the Nigeria Data Protection Regulation, 2019.
“NDPC” means the Nigeria Data Protection Commission. This is the main supervisory and regulatory authority for data protection and oversees the implementation of the NDPA and matters relating to data protection in Nigeria.
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Personal Data” means any information relating to identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; It can be anything from a name, address, a photo, an email address, bank details, posts on social networking websites, medical information, and other unique identifier such as but not limited to MAC address, IP address, IMEI number, IMSI number, SIM, Personal Identifiable Information (PII) and others.
‘’Policy’’ means this Data Privacy and Protection Policy
“Sensitive Personal Data” means Personal Data relating to religious or other beliefs, sexual orientation, health, race, ethnicity, political views, trades union membership, criminal records, or any other sensitive personal information.
“Third Party” means any natural or legal person, public authority, establishment, or any other body other than the Data Subject, the Data Controller, the Data Administrator, and the persons who are engaged by the Data Controller or the Data Administrator to process personal data.
6. General Principles for Processing of Personal Data
Transcorp Power is committed to maintaining the principles in the NDPA and NDPR regarding the processing of Personal Data.
To demonstrate this commitment as well as our aim of creating a positive privacy culture within Transcorp, the Company adheres to the following basic principles relating to the processing of Personal Data:
6.1. Lawfulness, Fairness and Transparency
Personal Data must be processed lawfully, fairly and in a transparent manner at all times. This implies that Personal Data collected and processed by or on behalf of Transcorp Power must be in accordance with the specific, legitimate, and lawful purpose consented to by the Data Subject, save where the processing is otherwise allowed by law or within other legal grounds recognised in the NDPA and NDPR.
6.2. Data Accuracy
Personal Data kept by the Company must be accurate and kept up to date. In this regard, Transcorp:
a) shall ensure that any Data it collects and/or processes is accurate and not misleading in a way that could be harmful to the Data Subject.
b) will make efforts to keep Personal Data updated where reasonable and applicable; and
c) will make timely efforts to correct or erase Personal Data when inaccuracies are discovered.
6.3. Purpose Limitation
Transcorp Power collects Personal Data only for the purposes identified in the appropriate privacy notice or any other relevant document or based on any other non – written communication (where applicable), provided to the Data Subject and for which Consent has been obtained. Such Personal Data cannot be reused for another purpose that is incompatible with the original purpose, except a new Consent is obtained.
6.4. Data Minimisation
6.4.1. Transcorp Power limits Personal Data collection and usage to Data that is relevant, adequate, and absolutely necessary for carrying out the purpose for which the Data is processed.
6.4.2 The Company will evaluate whether and to what extent the processing of personal data is necessary and where the purpose allows, anonymised data must be used.
6.5. Integrity, Security and Confidentiality
6.5.1. The Company shall establish adequate controls in order to protect the integrity, security, and confidentiality of Personal Data, both in digital and physical format and to prevent Personal Data from being accidentally or deliberately compromised.
6.5.2. Personal Data of Data Subjects must be protected from unauthorised viewing or access and from unauthorised changes to ensure that it is reliable and correct.
6.5.3. Any Personal Data processing undertaken by an employee who has not been authorised to carry such out as part of their legitimate duties is un-authorised.
6.5.4. Employees may have access to Personal Data only as is appropriate for the type and scope of the task in question and are forbidden to use Personal Data for their own private or commercial purposes or to disclose them to unauthorised persons, or to make them available in any other way.
6.5.5. The Human Resources Department, as part of the induction process must inform employees at the start of the employment relationship about the obligation to maintain Personal Data privacy. This obligation shall remain in force even after employment has ended.
6.6.1. Personal Data Retention
All personal information shall be retained, stored, and destroyed by Transcorp Power in line with legislative and regulatory guidelines. For all Personal Data and records obtained, used, and stored within the Company, the Company shall perform periodical reviews of the data retained to confirm the accuracy, purpose, validity, and requirement to retain.
6.6.1. Retention Principles
The following are some of the principles to be followed by the Company with respect to retention or storage of records/data:
6.6.1.1. The Company shall store, retain, archive, and destroy Personal Data in accordance with the provisions of the Company’s Document Management Policy and the retention policy set out therein.
6.6.1.2. Certain Personal Data will be retained permanently, for business reasons including but not limited to the protection of the Company’ interest, preservation of evidence, and conformation to good business practices. All such retained records shall be archived once they are no longer in use and shall not be further processed save where permissible or required.
6.6.1.3. To the extent permitted by applicable laws and without prejudice to the Company’s retention policy, the length of storage of Personal Data shall, amongst other things, be determined by:
a) the contract terms agreed between Transcorp Power and the Data Subject or as long as it is needed for the purpose for which it was obtained; or
b) whether the transaction or relationship has statutory implication or a statutorily required retention period; or
c) an express request for deletion by the Data Subject; except where such Data Subject is under an investigation or under a subsisting contract which may require further or where the Data relates to criminal records; or
d) whether the records or Data form the subject matter of an ongoing or anticipated litigation or government proceeding or investigation. In such instance, the Company shall not alter, destroy, or conceal any records or data with the intent to impede or obstruct or influence any litigation or government proceedings or in relation to the completion of any such litigation or government proceeding or investigation.
e) whether the Company has another lawful basis for retaining the information beyond the period for which it is necessary to serve the original purpose.
Notwithstanding the foregoing and pursuant to the NDPA and the NDPR, the Company shall be entitled to retain and process Personal Data for archiving, scientific research, historical research, or statistical purposes for public interest.
6.6.2. Retention of Encrypted Data
Should any information retained under this Policy be stored in an encrypted format, consideration must be taken for secure storage of the encryption keys. Encryption keys must be retained as long as the data that the keys decrypt is retained.
6.7. Accountability
Transcorp Power demonstrates accountability in line with the NDPA and NDPR obligations by monitoring and continuously improving data privacy practices within the organisation.
7. Data Privacy Notice
7.1. The Company will ensure that the Data Subjects are provided with adequate information regarding the use of their Personal Data as well as acquire their respective Consent, where necessary.
7.2. The Company shall display a simple and conspicuous notice (Privacy Notice) on any medium through which Personal Data is being collected or processed. The following information must be considered for inclusion in the Privacy Notice, as appropriate in distinct circumstances in order to ensure fair and transparent processing:
a) Description of collectible Personal Data
b) Purposes for which Personal Data is collected, used, and disclosed
c) What constitutes Data Subject’s Consent
d) The technical methods used to collect and store the information
e) Available remedies in the event of violation of the Policy and the timeframe for remedy.
f) Adequate information in order to initiate the process of exercising their privacy rights, such as access to, rectification and deletion of Personal Data.
Transcorp Power’s Privacy Notice is available on the Company’s website via: www.transcorppower.com/tpl/data-privacy-protection-policy
8. Lawful Basis
In accordance with the NDPA, data processing shall be lawful where:
a) The data subject has given and not withdrawn consent for the specific purpose.
b) The processing is necessary –
I for the performance of a contract to which the data subject is a party.
II for compliance with a legal obligation to which the data controller or data processor is subject.
III to protect the vital interest of the data subject or another person.
IV for the performance of a task carried out in the public interest.
V in the exercise of official authority vested in the data controller or data Processor.
VI for the purposes of the legitimate interests pursued by the data controller or data processor, or by a third party to whom the data is disclosed.
9. Consent
Where processing of Personal Data is based on Consent, the Company shall obtain the requisite consent of Data Subjects at the time of collection of Personal Data. In this regard, the Company will ensure that:
a) the specific purpose of collection is made known to the Data Subject and the Consent is requested in a clear and plain language.
b) the Consent is freely given by the Data Subject and obtained without fraud, coercion, or undue influence.
c) the Consent is sufficiently distinct from other matters to which the Data Subject has agreed.
d) the Consent is explicitly provided in an affirmative manner.
e) Consent is obtained for each purpose of Personal Data collection and processing; and
f) it is clearly communicated to and understood by Data Subjects that they can update, manage, or withdraw their Consent at any time.
9.1. Valid Consent
9.1.1. for Consent to be valid, it must be given voluntarily by an appropriately informed Data Subject. In line with regulatory requirements, Consent cannot be implied. Silence, pre-ticked boxes, or inactivity does not constitute Consent under the NDPA and shall not be a practice of the Company.
9.1.2 Consent in respect of Sensitive Personal Data must be explicit. A tick of the box would not suffice. In accordance with the NDPA, A data controller or data processor shall not process, or permit a data processor to process on its behalf, sensitive personal data, unless the –
a) data subject has given and not withdrawn consent to the processing for the specific purpose or purposes for which it will be processed.
b) processing is necessary for the purposes of performing the obligations of the data controller or exercising rights of the data subject under employment or social security laws or any other similar laws.
c) processing is necessary to protect the vital interests of the data subject or of another person, where the data subject is physically or legally incapable of giving consent.
d) processing is carried out in the course of its legitimate activities, with appropriate safeguards, by a foundation, association, or such other non-profit organisation with charitable, educational, literary, artistic, philosophical, religious, or trade union purposes, and the –
I. processing relates solely to the members or former members of the entity, or to persons, who have regular contact with it in connection with its purposes,
II. sensitive personal data is not disclosed outside of the entity without the explicit consent of the data subject.
e) processing is necessary for the establishment, exercise, or defence of a legal claim, obtaining legal advice, or conduct of a legal proceeding.
f) processing is necessary for reasons of substantial public interest, on the basis of a law, which shall be proportionate to the aim pursued, and provides for suitable and specific measures to safeguard the fundamental rights, freedoms, and interests of the data subject.
g) processing is carried out for purposes of medical care or community welfare and undertaken by or under the responsibility of a professional or similar service provider owing a duty of confidentiality.
h) processing is necessary for reasons of public health and provides for suitable and specific measures to safeguard the fundamental rights, freedoms, and interests of the data subject; or
i) processing is necessary for archiving purposes in the public interest, or historical, statistical, or scientific research, in each case on the basis of a law, which shall be proportionate to the aim pursued, and provides for suitable and specific measures to safeguard the fundamental rights and freedoms and the interests of the data subject.
9.2 Consent of Minors
Where a data subject is a child or a person lacking the legal capacity to consent, Transcorp Power shall obtain the consent of the parent or legal guardian, as applicable, to rely on consent under the NDPA.
The above requirement shall however not be applicable, where the processing is:
a) necessary to protect the vital interests of the child or person lacking the legal capacity to consent.
b) carried out for purposes of education, medical, or social care, and undertaken by or under the responsibility of a professional or similar service provider owing a duty of confidentiality; or
c) necessary for proceedings before a court relating to the individual
The Consents of minors (under the age of 18) will always be protected and obtained from minor’s representatives in accordance with all applicable regulatory requirements.
10. Data Subject Rights
10.1. All individuals who are the subject of Personal Data held by Transcorp Power are entitled to the following rights:
10.1.1. Right to request for and access their Personal Data collected and stored. Where Data is held electronically in a structured form, such as in a Database, the Data Subject has a right to receive that data in a common electronic format.
10.1.2. Right to information on their Personal Data collected and stored.
10.1.3. Right to objection or request for restriction.
10.1.4. Right to object to automated decision making.
10.1.5. Right to request rectification and modification of their Data which the Company keeps.
10.1.6. Right to request for deletion of their data, except as restricted by law or the Company’s statutory obligations.
10.1.7. Right to request the movement of data from the Company to a Third Party; this is the right to the portability of data.
10.1.8. Right to opt out of marketing and unsolicited messages.
10.1.9. Right to object to, and to request that the Company restricts the processing of their information except as required by law or the Company’s statutory obligations.
10.2. The Company shall publish a Data Subject Access Request Procedure on its website, in the form set out in Appendix 2, which sets out the Company’s well-defined procedure regarding how to handle and answer Data Subjects’ requests.
10.3. Data Subjects can exercise any of their rights by completing the Transcorp Power’s Subject Access Request (SAR) Form and submitting to the Company via privacy@transcorppower.com
11. Transfer of Personal Data
11.1. Regulatory Procedures for Transfer of Personal Data Outside Nigeria
11.1.1 Where Personal Data is to be transferred to a country outside Nigeria, the Company shall put adequate measures in place to ensure the security of such Personal Data. In particular, the Company shall, among other things, conduct a detailed assessment and seek to ascertain adequacy of data protection laws.
11.1.2 The transfer of Personal Data out of Nigeria would be in accordance with the provisions of the NDPA. Transcorp Power will therefore only transfer Personal Data out of Nigeria on one of the following conditions:
a) The recipient of the personal data is subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism that affords an adequate level of protection with respect to the personal data in accordance with the NDPA.
b) The consent of the Data Subject has been obtained.
c) The transfer is necessary for the performance of a contract between Transcorp Power and the Data Subject or, implementation of pre-contractual measures taken at the Data Subject’s request.
d) The transfer is necessary to conclude a contract between Transcorp Power and a third party in the interest of the Data Subject.
e) The transfer is necessary for reason of public interest.
f) The transfer is for the establishment, exercise, or defence of legal claims; and
g) The transfer is necessary in order to protect the vital interests of the Data Subjects or other persons, where the Data Subject is physically or legally incapable of giving consent.
Provided in all circumstances, that the Data Subject has been manifestly made to understand through clear warnings, of the specific principle(s) of data protection that are likely to be violated in the event of transfer to a third country. This provision shall however not apply to any instance where the Data Subject is answerable in duly established legal action for any civil or criminal claim in a third country.
11.1.3. For transfer of data outside Nigeria, the Company will engage with the NDPC for guidance and approval with respect to such transfer. Transcorp Power will provide the NDPC with the following information:
a) A list of countries where the Personal Data of Nigerian citizens are transferred in the regular course of business.
b) The Data Protection Laws and contact of National Data Protection Office/Administration of such countries where Personal Data is transferred to.
c) The Privacy Policy of Transcorp Power which is compliant with the provisions of the NDPA.
d) An overview of encryption methods and data security standards; and
e) Any other detail that assures the privacy of Personal Data is adequately protected in the target country.
11.1.4. Where Personal Data is transferred out of Nigeria pursuant to Section 11.1.3. above, Transcorp Power will work with NDPC to coordinate transfer requests.
11.2. Transfer of Personal Data from Nigeria to other Entities within the Transcorp Group
In addition to the procedure stated in Section 11.1 of this document, where the Company transfers Personal Data to any other entity within the Transcorp Group, Transcorp Power will execute an Intra Group Transfer Agreement or a Third-Party Processing Agreement with such company.
12. Data Breach Management
The Company shall establish and maintain a data breach management procedure in order to deal with incidents concerning Personal Data or privacy practices leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed. All personal data breach management shall be done in line with the procedures laid down in the Company’s Personal Data Breach Management Policy.
13. Data Protection Impact Assessment
The Company shall carry out a Data Protection Impact Assessment (DPIA) in respect of any new project or IT system involving the processing of Personal Data to determine whenever a type of processing is likely to result in any risk to the rights and freedoms of Data Subjects.
Transcorp Power shall carry out the DPIA in line with the procedures laid down in the Company’s Data Protection Impact Assessment Policy
14. Data Security
14.1 All Personal Data must be kept securely and should not be stored any longer than necessary. Transcorp Power will ensure that appropriate measures are employed against unauthorised access, accidental loss, damage, and destruction to Data. This includes the use of password-encrypted databases for digital storage and locked cabinets for those using paper form.
14.2. To ensure security of Personal Data, Transcorp Power will, among other things, implement any of the following appropriate technical controls:
a) Industry-accepted hardening standards, for workstations, servers, and databases.
b) Full disk software encryption on all corporate workstation/laptops operating systems drives storing Personal and Personal/Sensitive Data.
c) Encryption at rest including key management of key databases.
d) Enable Security Audit Logging across all systems managing Personal Data.
e) Restrict the use of removable media such as USB flash, disk drives.
f) Anonymization techniques on testing environments; and
g) Physical access control where Personal Data are stored in hardcopy.
14.3. In cases where data protection breaches such as illegal activities or theft of Company property, either physical or intellectual is suspected, the Company may report such activities to the Nigeria Data Protection Commission (NDPC).
15. Training
Transcorp Power shall ensure that its employees who collect, access and process Personal Data receive adequate data privacy and protection training in order to develop the necessary knowledge, skills and competence required to effectively manage the compliance framework under this Policy and the NDPA with regard to the protection of Personal Data. On an annual basis, the DPO shall develop a capacity building plan for employees on data privacy and protection in line with the NDPA.
16. Data Protection Audit
In line with the NDPA, where the Company processes Personal Data of more than 2000 Data Subjects annually, the Company shall within the first 3 months of the following year, conduct a data protection audit through a licensed Data Protection Compliance Organisation (DPCOs) to verify the Company’s compliance with the provisions of the NDPA and other applicable data protection laws. The audit report will be certified and filed by the DPCO to the NDPC as required under the NDPA.
17. Consequences of Non Compliance
Non-compliance with the provisions of this Framework by a staff in any business unit or functional area shall be handled in line with the Company’s Disciplinary Process and Sanctions Grid Policy.
18. Delegation
Any delegation of authority conferred by this Policy shall be in accordance with the approved procedure for the delegation of authority as set out in the Delegation of Authority & Empowerment Policy.
19. Waivers
The Board shall approve all requests for any waiver to this Policy. All such waiver approvals shall be obtained in writing and kept as a record by the policy owner.
20. Review and Amendment
This Policy shall be reviewed every three years by the policy owner, and may be amended, subject to approval, if deemed necessary. The Company however reserves the right to change any of the provisions of this policy as it deems fit or required from time to time and such change shall apply to all Staff of the Company from the date of change as it relates to the subject-matter.