UseOneID LogoNDPR Data Audits
Privacy Policy →

NDPR Data Compliance Report

UseOneID operates in full alignment with the Nigeria Data Protection Regulation (NDPR). Below is our annual compliance posture, data mapping inventory, and security audit transparency logs.

1. Compliance Overview

The Nigeria Data Protection Regulation (NDPR) regulates the processing of personal data in Nigeria. UseOneID is committed to ensuring that all identity processing, verification sessions, and biometric queries are handled with strict privacy safeguards.

NDPR Audit Status: Compliant. Annual filing successfully submitted to the National Data Protection Commission (NDPC).

2. Data Protection Principles

We adhere strictly to the core principles of data protection as defined in the NDPR:

  • Lawfulness & Consent: We do not process data without explicit user consent captured via the SDK verify screens.
  • Purpose Limitation: Personal data is processed solely for verifying the identity of the user.
  • Data Minimization: We request only the minimal fields required by the partner (e.g., name, date of birth).
  • Integrity & Confidentiality: Data is protected using end-to-end encryption protocols in transit and at rest.

3. Audit Scope & Frequency

UseOneID undergoes annual data protection audits conducted by a licensed Data Protection Compliance Organization (DPCO). The audit scope covers:

  • Internal data flow mapping and inventory checks.
  • Access control registries and encryption key rotation cycles.
  • System penetration testing and vulnerability scans.
  • Employee data privacy training and compliance logs.

4. Information Inventory

To provide full transparency, the table below lists the personal data processed by UseOneID, along with the processing purpose, retention period, and security controls:

Data CategoryPurposeSecurity ControlRetention
User Identity RecordsConfirm user legalityAES-256 EncryptedActive Session Only
Biometric SnapshotsVerify face livenessIn-Memory ProcessingDiscarded Instantly
Partner DetailsBilling & Account logsDatabase Access LockContract Duration

5. Data Subjects' Rights

As a data subject, you hold several rights under the NDPR regarding how your personal information is processed:

  • Access: You can request a summary of the personal verification records we hold about you.
  • Rectification: You can request corrections to incomplete or inaccurate data entries.
  • Erasure: You can request that we delete your verification history records, subject to regulatory retention mandates.
  • Objection: You have the right to object to data processing activities that lack legal consent.

6. Security & Breach Response

In the event of a security incident or data breach that impacts personal information, UseOneID has established an incident response plan to notify the NDPC and affected data subjects within 72 hours, in compliance with NDPR requirements.


7. Compliance Governance

We have appointed a designated Data Protection Officer (DPO) to oversee our data privacy operations, audit cycles, and response frameworks. For any data protection inquiries, you can reach out directly via:

Email: dpo@useoneid.com
Attention: Data Protection Officer, Lagos, Nigeria.