Ash Nelson Privacy Notice
Introduction
This document is prepared in accordance with the provisions of the EU General Data Protection Regulation (GDPR) and the Nigerian Data Protection Act (NDPA). It sets out how Ash Nelson Partners Limited (ANP) applies and complies with the principles of the Act in processing the personal data of individuals, clients, vendors, and even third parties that interact with ANP.
For personal data of individuals, this document also highlights their rights and covers the data subject(s) whose personal data is collected and processed in compliance with the GDPR/NDPR.
Roles and Responsibilities
Data Protection Officer
|
All Employees/Staff who interact with personal data
|
Policy Statement
Who We Are
We are a Global Technology firm focused on solving cybercrime challenges across various sectors.
With our unwavering dedication to excellence, innovation, and technology, we have established ourselves as a leading force in the cybersecurity landscape in Africa.
At ANP, we stay vigilant in continually identifying and evaluating new and improved solutions that enhance business efficiency and competitiveness. Our expertise lies in securing systems and infrastructure, ensuring our clients stay ahead in a rapidly advancing world.
What Personal Data Do We Need?
The personal data we would collect and process, depending on the particular processing requirement, are under the following categories:
[INSERT PERSONALITIES]
Why Do We Need the Data?
ANP ensures that the personal data collected and processed is necessary for the purpose of collection, and ANP shall not collect or process more data than is reasonably required for a particular processing activity. In addition, every processing purpose has at least one lawful basis for processing to safeguard the rights of the data subjects, as listed below:
Identity verification and maintenance of records
|
Where Legitimate Interest is considered the legal basis for processing personal data, ANP shall follow the steps below in carrying out a Legitimate Interest Assessment.
1. Determine the Purpose for Processing
In carrying out the purpose test, ANP must establish the exact reason for the processing and how it benefits the organisation. Answers to the following shall be provided to determine the exact purpose for processing:
Description of the processing objective
The likelihood of meeting the objective and how to determine if the objective was met
The benefit of the processing and the significance to the organisation
Description of the possible impact of not processing and any other issues that might be relevant
2. Determine the Necessity of the Processing
ANP must establish why the processing must take place, how the processing relates to the expected benefits, and any other alternatives and why there were not considered.
3. Balance the identified interest with the Privacy Interest of the Data Subjects
The following questions will be addressed under the balance test:
Who are the data subjects (category)?
What is the relationship between ANP and the data subject
What personal data is to be processed
How will the processing impact the data subject
How will the data subject react to the processing
ANP records this information in line with this policy, data protection impact assessment, and data inventory.
4. Consent
ANP requires your explicit consent to process collected personal data. And by consenting to this privacy policy, you are giving us the permission to use/process your personal data specifically for the purpose identified before collection.
If, for any reason, ANP is requesting sensitive personal data from you, you will be rightly notified why and how the information will be used.
You may withdraw consent at any time by requesting for Withdrawal of Consent form, following the ANP Withdrawal of Consent Procedure.
5. Disclosure
Where there is a need for a third party to process the personal data of data subjects, ANP will enter into a Data Processing Agreement with the third party and be satisfied that the third party has adequate measures in place to protect the data against accidental or unauthorised access, use, disclosure, loss, or destruction.
In a case where the disclosure is to third parties outside the jurisdiction of the GDPR and NDPR, ANP will ensure that the third party meets the core regulatory standards prior to the transfer. This may include transferring the personal data to the third party where ANP has satisfied that:
the country of the recipient has adequate data protection controls established by legal or self-regulatory regime
ANP has a contract in place that uses existing or approved data protection clauses to ensure adequate protection
ANP is making the transfer under approved binding corporate rules
ANP is relying on approved codes of conduct or certification mechanisms, together with binding and enforceable commitments in the foreign country or international organisation to apply the appropriate safeguards in relation to data subject rights
Provisions inserted into administrative arrangements between public authorities or bodies authorised by the competent supervisory authority
6. Retention of Records
In compliance with the GDPR/NDPA data retention policy, ANP will process your personal data for [state how long you intend to process the personal data of data subject(s)] and will retain the personal data for [state the retention period of the personal data of data subject(s)].
This retention period has been established to enable us use the personal data for the necessary legitimate purposes identified, in full compliance with the legal and regulatory requirements. When we no longer need to use your personal information, we will delete it from our systems and records, and/or take steps to encrypt/anonymise it to protect your identity as the case may be.
7. Data Subject Rights
Data subjects, according to the provision of the GDPR/NDPA, have certain rights. At any point while ANP are in possession of or processing your personal data, you, the data subject, have the right to:
Request a copy of the information that we hold about you
Correct the data that we hold about you that is inaccurate or incomplete
Ask for the data we hold about you to be erased from our systems/record
Restrict processing of your personal data where certain conditions apply
Have the data we hold about you transferred to another organisation
Object to certain types of processing like direct marketing
Object to automated processing like profiling, as well as the right to be subject to the legal effects of automated processing or profiling
Judicial review. In the event that ANP refuses your request under rights of access, we will provide you with a reason as to why. And you have the right to complain.
All of the above requests will be forwarded on should there be a third party involved in the processing of your personal data.
8. Complaints
If for any reason you wish to make a complaint about how ANP (or any of our third parties described in 3.4 above) processes your personal data, or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and the Data Protection Officer of ANP.
Below are the details for each of these contacts:
[Contact Name]
Email@ashnelsonpartners.com [DPO Name]
|
9. Privacy statement
For more information on how we use your personal data and why, please visit this link
10. Online Privacy Statement
Personal Data
Under the EU’s General Data Protection Regulation (GDPR) and the Nigeria Data Protection Act (NDPA) personal data is defined as:
“any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
How We Use Your Information
This privacy notice tells you how we, ANP, will collect and use your personal data for relationship management, profiling, business analytics/development, communication, registration, subscription, cookies, and all-round efficient service delivery.
Why Does ANP Need to Collect and Store Personal Data?
We need to collect your personal data in order for us to provide you with our services as mentioned in clause 3.3 above. In any event, we are committed to ensuring that the information we collect and use is appropriate for this purpose(s) only, and will in no way invade your privacy. If there is a need to use your personal data for marketing purpose, ANP will ensure to seek additional consent from you
Will ANP Share My Personal Data with Anyone Else?
ANP may pass your personal data to third-party service providers contracted by us. Any third parties that we may share your personal data with is under an obligation to secure your details, and use them only to fulfil the service for which they were contracted. When they no longer need your details to fulfil this service, the data will be disposed in line with the ANP’s procedures. If we wish to pass your sensitive personal data onto a third party we will only do so once we have obtained your consent, unless we are required to do otherwise, legally.
How will ANP Use the Personal Data It Collects About Me?
We will process (collect, use and store) the information you provide in a manner that complies with the EU’s General Data Protection Regulation (GDPR) and the Nigeria Data Protection Act (NDPA). We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary. ANP is required to retain information in accordance with the law, such as information needed for income tax and audit purposes. The retention period for certain kinds of personal data may also be governed by specific business-sector requirements and agreed practices. Personal data may be held in addition to these periods depending on individual business needs.
Under what circumstances will the ANP contact me?
We do not intend to be intrusive, and we will not ask irrelevant or unnecessary questions. Moreover, we will subject the information you provide to rigorous measures and procedures to minimise the risk of unauthorised access or disclosure.
Can I Find Out the Personal Data That ANP Holds About Me?
ANP, at your request, can confirm what information we hold about you and how it is processed. If we do hold your personal data, you have the right to request the following information:
Contact details of the data protection officer, where applicable.
The purpose of the processing as well as the legal basis for processing.
Information about interests, if the processing is based on the legitimate interests of ANP or a third party.
The categories of personal data collected, stored and processed.
Recipient(s) or categories of recipients that the data is/will be disclosed to.
Information about how we intend to securely transfer the personal data to a third party or international organisation. The Attorney General of the Federation will approve sending personal data to some countries because they meet a minimum standard of data protection. In other cases, we will ensure there are specific measures in place to secure your information.
How long the data will be stored.
Details of your rights to correct, erase, restrict or object to such processing.
Information about your right to withdraw consent at any time.
How to lodge a complaint with the supervisory authority.
Whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether you are obliged to provide the personal data and the possible consequences of failing to provide such data.
The source of personal data if you didn’t provide it directly.
Any details and information of automated decision making, such as profiling, and any meaningful information about the logic involved, as well as the significance and expected consequences of such processing.
What Forms of ID Will I Need to Provide in Order to Access This?
ANP accepts the following (but not limited to) forms of ID when information on your personal data is requested: Passport, driving license, national identity card, permanent voter card.