Term | Definition |
---|---|
Institute | means The Chartered Institute of Bankers of Nigeria |
NITDA | means the National Information Technology Development Agency |
The Regulation | means the Nigeria Data Protection Regulation 2019. |
Computer | means Information Technology systems and devices, networked or not; |
Consent of the Data Subject | means any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which he or she, through a statement or a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her; |
Data | means characters, symbols and binary on which operations are performed by a computer, which may be stored or transmitted in the form of electronic signals, stored in any format or any device; |
Database | means a collection of data organized in a manner that allows access, retrieval, deletion and processing of that data; it includes but not limited to structured, unstructured, cached and file system type databases; |
Database Management System | means a software that allows a computer to create a database; add, change or delete data in the database; allows data in the database to be processed, sorted or retrieved; |
Data Subject | means any person, who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity; |
Processing | means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; |
Personal Data | means any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; It can be anything from a name, address, a photo, an email address, bank details, posts on social networking websites, medical information, and other unique identifier such as but not limited to Media Access Control(MAC) address, Internet Protocol(IP) address, International Mobile Equipment Identity(IMEI) number, International Mobile Subscriber Identity(IMSI) number, subscriber identification module (SIM), Personal Identifiable Information(PII) and others; |
Personal Data Breach | means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed; |
Data Controller | Is the Chartered Institute of Bankers of Nigeria. |
Data Administrator | Is the Head, Information Communications Technology |
Data Protection Officer | Is the Head, Internal Audit and Compliance |
Register of Systems | means a register of all systems or contexts in which personal data is processed by The Chartered Institute of Bankers of Nigeria. |
Last updated: January 2021
The Institute is committed to processing data in accordance with its responsibilities under the Regulation.
1.1 Personal data shall be:
1.2 Duty of Care
Without prejudice to the principles set out in this Policy, the Institute shall:
All data processed must be done on one of the following lawful bases
The Institute shall develop security measures to protect data; such measures include but not limited to protecting systems from hackers, setting up firewalls, storing data securely with access to specific authorized individuals, developing organizational policy for handling Personal Data (and other sensitive or confidential data), protection of emailing systems and continuous capacity building for staff.
Data processing by a third party shall be governed by a written contract between the third party and the Institute.
The right of a Data Subject to object to the processing of his data shall always be safeguarded. Accordingly, a Data Subject shall have the option to:
Notwithstanding anything to the contrary in this Policy, the privacy right of a Data Subject shall be interpreted for the purpose of advancing and never for the purpose of restricting the safeguards Data Subject is entitled to under any data protection instrument made in furtherance of fundamental rights and the Nigerian laws.
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, the Institute shall promptly assess the risk to people’s rights and freedoms and if appropriate report this breach to the NITDA (more information on the NITDA website).