Legal News

Nigeria Data Protection Commission Warns Against Malicious Electronic Messages

Nigeria·Wire Summary⏱️ 3 min read

The Nigeria Data Protection Commission (NDPC) on Friday warned Nigerians against malicious electronic messages falsely claiming traffic rule violations or related offences, which are designed to create fear and prompt unsuspecting recipients to click on links, disclose personal information, or follow harmful instructions.

This advisory from the NDPC is legally significant as it underscores the commission's proactive role in safeguarding personal data and combating cybercrime in Nigeria. It highlights the evolving tactics of cybercriminals, moving beyond traditional phishing emails to various electronic channels, and emphasizes the critical need for public awareness and vigilance. For practitioners, this signals the NDPC's commitment to enforcing data protection principles and its expectation that individuals and organizations will take necessary precautions against such threats. The prevalence of these scams also indicates a growing risk landscape for data breaches and identity theft, which can have severe legal and financial consequences for victims and implicated entities.

The legal context for this warning is primarily the Nigeria Data Protection Act (NDPA) 2023, which established the NDPC as the principal regulatory body for data protection in the country. The NDPA mandates data controllers and processors to implement appropriate technical and organizational measures to protect personal data and empowers the NDPC to issue guidelines, advisories, and enforce compliance. Additionally, the Cybercrime Act 2015 (as amended) criminalizes various forms of cyber fraud, identity theft, and malicious communications, providing a legal basis for prosecuting perpetrators of such scams. The NDPC's advisory, signed by Itunu Dosekun, Head of the Media Unit, falls squarely within its statutory mandate to promote public awareness and education on data protection issues and best practices.

Key parties involved in this development include the Nigeria Data Protection Commission (NDPC) as the issuing authority, the general Nigerian public as the target of both the warning and the malicious messages, and Gilbert Ekugbe, the reporter from Punch Nigeria. While specific perpetrators of the malicious messages are not identified in the excerpt, they represent the anonymous threat actors against whom the NDPC is advising caution. The advisory also implicitly involves various organizations or authorities whose identities are being impersonated by these malicious messages.

Practitioners, particularly those advising businesses and individuals, should take this advisory seriously. Attorneys should counsel clients on the importance of robust cybersecurity protocols, employee training on identifying and reporting phishing attempts, and strict adherence to data protection principles outlined in the NDPA 2023. Businesses must ensure their data processing activities are secure and that they do not inadvertently become vectors for such attacks. Furthermore, legal professionals should be prepared to assist individuals or organizations affected by these scams, including guiding them on reporting incidents to the NDPC and relevant law enforcement agencies, and advising on potential remedies for data breaches or financial losses incurred due to such fraudulent activities.

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Finish Reading the Full Story and the Expert Analysis.

Get the latest legal & regulatory intelligence in Nigeria

Instant access to full analysis, cited statutes & expert commentary
Customize your dashboard to track what matters to your business operations

Already have an account? Log in

Wansom is AI and can make mistakes.