About this document
This Policy sets the mandatory governance, security and accountability standards applied by Syrol Technologies Limited when operating Identro and processing Personal Data.
1. Purpose and scope
The purpose is to ensure lawful, fair, transparent, secure and accountable processing under the Nigeria Data Protection Act 2023, the NDP Act General Application and Implementation Directive 2025, and other applicable Nigerian requirements.
This Policy applies to directors, employees, interns, consultants, contractors, agents, vendors and sub-processors; and to all systems, APIs, SDKs, applications, cloud services, physical records and development environments used for Identro.
2. Core principles
- Lawfulness, fairness and transparency.
- Purpose limitation and compatible use.
- Data minimisation.
- Accuracy and correction.
- Storage limitation and secure disposal.
- Integrity, confidentiality and resilience.
- Accountability and demonstrable compliance.
- Privacy by design and by default.
3. Governance and responsibilities
The Board or senior management approves this Policy, provides resources and receives material risk and incident reports. The Data Protection Officer advises independently, monitors compliance, maintains contact with the NDPC and reports significant concerns to senior management.
Engineering and Product must apply privacy-by-design, minimise data, implement secure defaults and complete required DPIAs before release. Information Security manages controls, testing and incident response. Legal/Compliance maintains lawful-basis, regulatory and contract requirements. Vendor Management conducts due diligence and ensures appropriate agreements. Customer Support authenticates rights requesters and follows approved workflows. All personnel must report suspected breaches immediately.
4. Records and accountability
- Record of Processing Activities.
- Lawful-basis and consent register.
- DPIA register and remediation tracking.
- Sub-processor and vendor register.
- Cross-border transfer register and assessments.
- Data-subject request log.
- Personal Data Breach register.
- Retention and deletion schedule.
- Access-review and privileged-access records.
- Training, audit and compliance-return evidence.
5. Lawful basis and consent
No processing may begin without an identified and documented lawful basis. Where Identro acts as Processor, processing must remain within documented Controller instructions except where law requires otherwise.
Consent must be freely given, specific, informed, unambiguous, demonstrable and as easy to withdraw as to give. Explicit consent or another lawful condition must be documented for sensitive processing where required. Consent shall not be bundled into unrelated terms or used where a power imbalance makes it inappropriate.
6. Controller and Processor roles
Product owners and Legal/Compliance shall determine and record Identro’s role for each processing activity. Identro may be Processor for merchant-submitted verification data and independent Controller for account management, security, fraud prevention, billing, audit, legal compliance, service integrity and disputes.
Processor activities require a compliant Data Processing Addendum. Personnel shall not accept customer instructions that are manifestly unlawful and must escalate them to the DPO or Legal/Compliance.
7. Sensitive data, biometrics and automated systems
Access to BVN, NIN, facial images, templates, liveness data and other sensitive records is restricted by role and business need. Raw biometric captures shall be retained for the shortest practical period. Production Personal Data must not be copied into development or testing environments unless formally approved, minimised and protected.
Automated decision-support systems must be tested for accuracy, bias, security and explainability proportionate to risk. High-impact use cases require a DPIA, defined human oversight and a means to contest qualifying significant decisions. Identifiable customer data must not be used to train general-purpose AI models without separate approval, lawful basis and transparency.
8. Privacy by design and DPIAs
A DPIA is mandatory before high-risk processing, including large-scale identity or biometric verification, liveness, systematic fraud scoring, loan decision-support, material profiling, new cross-border processing, large-scale monitoring or a significant new provider integration.
The DPIA must describe the processing, necessity and proportionality, data flows, risks, safeguards, residual risk, owners and approval. High residual risk shall be escalated to the DPO and senior management and, where required, the NDPC before launch.
9. Security requirements
- Least privilege, MFA and periodic access reviews.
- Encryption in transit and at rest where appropriate.
- Secrets management and credential rotation.
- Network segmentation, API allowlisting and rate controls.
- Secure development, code review, dependency and vulnerability management.
- Centralised logging, monitoring and tamper-resistant audit trails.
- Backups, recovery testing and business continuity.
- Endpoint, physical and environmental safeguards.
- Incident response exercises and evidence preservation.
10. Vendors and sub-processors
Vendors must undergo privacy, security, regulatory, financial and operational due diligence proportionate to risk. Contracts must address instructions, confidentiality, security, breach notification, sub-processing, rights assistance, audit evidence, international transfers, deletion or return, and termination.
No new high-risk vendor may receive production Personal Data without Security, Legal/Compliance and DPO approval. A material sub-processor change must be communicated as required by customer contracts.
11. International transfers
Cross-border access or storage requires a documented lawful transfer mechanism and transfer assessment before processing begins. User acknowledgement or general terms alone do not constitute a transfer mechanism. Technical and contractual supplementary measures shall be applied where appropriate.
12. Retention and disposal
Data owners shall apply the approved retention schedule. Legal holds override routine deletion only for the affected records and duration. Disposal must be secure, auditable and applied to primary systems, object stores, logs, support systems and vendor systems where applicable. Backups shall expire through controlled rotation and remain isolated from ordinary processing.
13. Data-subject rights
Rights requests shall be logged, authenticated, assessed and answered without undue delay. Where Identro acts as Processor, the relevant Controller shall be informed and assisted. No requester shall be disadvantaged for exercising a right. Exceptions must be documented and approved by Legal/Compliance or the DPO.
14. Personal Data Breach management
All suspected incidents must be reported immediately through the designated incident channel. The response team shall contain the incident, preserve evidence, assess affected data and individuals, evaluate risk, document decisions and remediate root causes.
As Processor, Identro shall notify the affected Controller without undue delay after awareness and provide available information. As Controller, Identro shall notify the NDPC within 72 hours where the breach is likely to result in risk to individuals. Affected individuals shall be notified without undue delay where high risk is likely, unless a lawful exception applies. The 72-hour assessment shall not be delayed merely to achieve complete certainty.
15. Training, monitoring and enforcement
Personnel with access to Personal Data must receive induction and periodic refresher training. High-risk teams receive role-specific training. Compliance shall be monitored through access reviews, control testing, vendor reviews, DPIA follow-up, audits and annual compliance activities.
Violations may result in access removal, disciplinary action, contract termination, remediation, reporting to authorities or legal action. Good-faith reporting of suspected violations is protected from retaliation.
17. Review, ownership and contact
The Policy Owner is the Data Protection Officer or a senior officer formally designated by Syrol Technologies Limited. The Policy shall be reviewed at least annually and after material legal, product, provider or security changes.
Questions and reports: info@identro.ng (Attention: Data Protection Officer). Security incidents: security@identro.ng. Operator address: Ihesiaba Court, Ishaya Shekari Crescent, Gwarinpa, Abuja, FCT, Nigeria.
Questions, complaints or rights requests
Contact Identro at support@identro.ng. Security incidents should be sent to security@identro.ng. Identro, Ihesiaba Court, Ishaya Shekari Crescent, Gwarinpa, Abuja, FCT, Nigeria.