NDPR Data Compliance Report
UseOneID operates in full alignment with the Nigeria Data Protection Regulation (NDPR). Below is our annual compliance posture, data mapping inventory, and security audit transparency logs.
1. Compliance Overview
The Nigeria Data Protection Regulation (NDPR) regulates the processing of personal data in Nigeria. UseOneID is committed to ensuring that all identity processing, verification sessions, and biometric queries are handled with strict privacy safeguards.
2. Data Protection Principles
We adhere strictly to the core principles of data protection as defined in the NDPR:
- Lawfulness & Consent: We do not process data without explicit user consent captured via the SDK verify screens.
- Purpose Limitation: Personal data is processed solely for verifying the identity of the user.
- Data Minimization: We request only the minimal fields required by the partner (e.g., name, date of birth).
- Integrity & Confidentiality: Data is protected using end-to-end encryption protocols in transit and at rest.
3. Audit Scope & Frequency
UseOneID undergoes annual data protection audits conducted by a licensed Data Protection Compliance Organization (DPCO). The audit scope covers:
- Internal data flow mapping and inventory checks.
- Access control registries and encryption key rotation cycles.
- System penetration testing and vulnerability scans.
- Employee data privacy training and compliance logs.
4. Information Inventory
To provide full transparency, the table below lists the personal data processed by UseOneID, along with the processing purpose, retention period, and security controls:
| Data Category | Purpose | Security Control | Retention |
|---|---|---|---|
| User Identity Records | Confirm user legality | AES-256 Encrypted | Active Session Only |
| Biometric Snapshots | Verify face liveness | In-Memory Processing | Discarded Instantly |
| Partner Details | Billing & Account logs | Database Access Lock | Contract Duration |
5. Data Subjects' Rights
As a data subject, you hold several rights under the NDPR regarding how your personal information is processed:
- Access: You can request a summary of the personal verification records we hold about you.
- Rectification: You can request corrections to incomplete or inaccurate data entries.
- Erasure: You can request that we delete your verification history records, subject to regulatory retention mandates.
- Objection: You have the right to object to data processing activities that lack legal consent.
6. Security & Breach Response
In the event of a security incident or data breach that impacts personal information, UseOneID has established an incident response plan to notify the NDPC and affected data subjects within 72 hours, in compliance with NDPR requirements.
7. Compliance Governance
We have appointed a designated Data Protection Officer (DPO) to oversee our data privacy operations, audit cycles, and response frameworks. For any data protection inquiries, you can reach out directly via:
Email: dpo@useoneid.com
Attention: Data Protection Officer, Lagos, Nigeria.
