What privacy policy means
A privacy policy is a promise about how you will treat somebody's information, published before they give it to you.
It is often called a privacy notice, and that is the more accurate name. It is not a contract you negotiate. It is a notice you publish, and the law requires it because people cannot exercise rights over data if they do not know what you are doing with it.
It is separate from your terms and conditions. Terms govern the commercial relationship between you and the user. The privacy policy governs your handling of their personal data, and it is required whether or not you sell anything.
Under the Nigeria Data Protection Act, the information it must convey is set out in the transparency requirements, so the content is not really a matter of style.
How it is used
A usable Nigerian privacy policy answers a fixed set of questions.
Who you are, with a real business name and contact details. What personal data you collect, described specifically rather than as information about you. Why you collect each category. The lawful basis for each use. Who you share it with, including payment processors, delivery partners, analytics providers and cloud hosts. Whether it leaves Nigeria and on what basis. How long you keep it. What rights the person has and how to exercise them. How to complain, including to the Nigeria Data Protection Commission. When the policy was last updated.
Where to put it depends on where you actually collect data. On a website, link it in the footer and at every point of collection. On a mobile app, in the store listing and in the app. For an Instagram or WhatsApp business, a link in the bio to a page holding the policy works, and is far better than nothing.
The part businesses skip is the last one: doing what it says. A policy promising deletion on request, from a business with no way to delete anything, is worse than no policy at all.
Key features
- A published notice, not a negotiated contract
- Required under the Nigeria Data Protection Act wherever personal data is collected
- Must state what is collected, why, the lawful basis, and who it is shared with
- Must explain data subject rights and how to exercise them
- Should state retention periods and cross border transfer arrangements
- Separate from terms and conditions, and both are usually needed
How this works in Nigeria
The most common Nigerian misconception is that this applies only to big technology companies.
It does not. A business taking a customer's name, phone number and delivery address is processing personal data. That includes the Instagram shop, the food vendor taking orders on WhatsApp, the school collecting parent details, the gym with a membership register and the estate agent with a list of enquiries.
Payment processors are the other point people miss. Where a Nigerian business uses a payment gateway, the gateway is processing customer data, and the privacy policy should say so and name the categories shared.
A further practical point: copying a foreign privacy policy is a common shortcut and a poor one. Policies drafted for other jurisdictions reference the wrong regulator, the wrong legislation and rights framed under a different law, which is obvious to anybody who reads it and unhelpful if the Commission ever asks.
The Commission has published guidance and has been active, so having a policy that matches the Act and matches what you actually do is worth the afternoon it takes.
Privacy policy vs terms and conditions vs cookie policy
Three documents that live in the same website footer and do different jobs.
A privacy policy explains how you handle personal data. It is required by data protection law, it is a notice rather than an agreement, and you need it even if your site sells nothing.
Terms and conditions form the contract between you and the user. What the service is, what it costs, what each side may and may not do, limits on liability, and how disputes are resolved. They bind because the user accepts them.
A cookie policy explains the small files your site places on visitors' devices, what each does and how to control them. It is often folded into the privacy policy, though a separate one is clearer where the site uses analytics and advertising tools.
Most Nigerian websites need at least the first two. A site with analytics or advertising needs the third.
Limits and risks
A policy is a notice, not a shield. Publishing one does not make unlawful processing lawful, and a business that collects more than it needs is not protected by having disclosed that it does.
It also has to match reality. A policy describing security measures the business does not have is evidence against it rather than for it.
Generic templates go stale. Adding a new payment processor, a new analytics tool or a new marketing channel changes what the policy should say, and almost nobody updates it.
And a policy nobody can find achieves nothing. Transparency means the information is actually available at the point of collection, not buried three clicks away.
Worth knowing
Name the third parties you actually share data with, including your payment gateway, delivery partners and analytics tools. A privacy policy that says data may be shared with service providers and stops there is the version that will not survive a question from a customer or the Commission.
Questions people ask
Do I need a privacy policy in Nigeria?
If you collect personal data, yes. The Nigeria Data Protection Act requires transparency about what you collect and why, and that applies to small businesses, Instagram shops and WhatsApp sellers as much as to websites.
What must a Nigerian privacy policy contain?
Who you are, what personal data you collect, why, the lawful basis for each use, who you share it with, whether it leaves Nigeria, how long you keep it, the rights people have and how to exercise them, and how to complain.
What is the difference between a privacy policy and terms and conditions?
A privacy policy is a notice about how you handle personal data, required by data protection law. Terms and conditions form the contract governing the commercial relationship. Most businesses need both.
Can I copy a privacy policy from another website?
It is a poor idea. Policies drafted for other jurisdictions cite the wrong law and the wrong regulator, and a policy that does not describe what your business actually does is evidence against you rather than protection.
Where should I put my privacy policy?
Wherever you collect data. In a website footer and at each collection point, in an app store listing and the app itself, and for social commerce, a link in the bio pointing to a page that holds it.
Does an Instagram shop need a privacy policy?
Yes. Taking a customer's name, phone number and delivery address is processing personal data, and the obligations under the Act do not depend on having a website.