1. Introduction
The Amaefule and Astudillo Empowerment Foundation (T.A.A.E Foundation) collects, holds, and uses personal data about beneficiaries, donors, volunteers, staff, partners, and community members in the course of delivering its programmes and managing its operations. This data is entrusted to us and we take that responsibility with the utmost seriousness.
This policy sets out how the Foundation collects, uses, stores, protects, shares, and disposes of personal data, and the rights of individuals in relation to their data. It applies to all personal data processed by or on behalf of the Foundation, whether held in paper or digital form.
This policy is grounded in and consistent with the Nigeria Data Protection Act 2023 (NDPA), which is the primary legislation governing data protection in Nigeria, administered by the Nigeria Data Protection Commission (NDPC). The Foundation is committed to full compliance with the NDPA and to treating the privacy of every individual connected to our work with the respect it deserves.
2. Purpose of This Policy
The purpose of this policy is to:
- Establish clear principles and rules for how the Foundation collects and uses personal data
- Ensure that personal data is processed lawfully, fairly, and transparently
- Protect the privacy and dignity of all individuals whose data the Foundation holds
- Define the rights of individuals in relation to their personal data and how the Foundation will uphold those rights
- Ensure that data relating to children and persons with disabilities is handled with particular care
- Assign clear responsibility for data protection within the Foundation
- Ensure compliance with the Nigeria Data Protection Act 2023
3. Scope of This Policy
This policy applies to all personal data processed by the Foundation, including data relating to:
- Beneficiaries, including children and persons with disabilities
- Donors and financial contributors
- Volunteers
- Staff and trustees
- Community partners and partner organisations
- Members of the public who contact or engage with the Foundation
This policy applies to all persons who handle personal data on behalf of the Foundation, including trustees, staff, volunteers, consultants, and any third party processors engaged by the Foundation.
4. Key Definitions
| Term | Meaning |
|---|---|
| Personal Data | Any information that identifies or can identify a living individual, including names, addresses, phone numbers, photographs, health information, disability status, and any other identifying details. |
| Sensitive Personal Data | Personal data revealing health conditions, disability, race or ethnicity, religious belief, political opinion, biometric data, or other categories that carry heightened risk if mishandled. |
| Data Subject | The individual to whom the personal data relates. |
| Data Controller | The Foundation, as the entity that determines the purpose and means of processing personal data. |
| Data Processor | A third party that processes personal data on behalf of the Foundation. |
| Processing | Any operation performed on personal data, including collection, storage, use, sharing, and deletion. |
| Consent | A freely given, specific, informed, and unambiguous agreement by a data subject to the processing of their personal data. |
5. Data Protection Principles
The Foundation commits to processing all personal data in accordance with the following principles, which reflect the requirements of the Nigeria Data Protection Act 2023:
| Principle 1: Lawfulness, Fairness, and Transparency Personal data shall be processed lawfully, fairly, and in a transparent manner. Data subjects shall know what data is collected about them and why. |
|---|
| Principle 2: Purpose Limitation Personal data shall be collected for specified, explicit, and legitimate purposes and shall not be processed in ways incompatible with those purposes. |
|---|
| Principle 3: Data Minimisation Only the personal data that is necessary for the stated purpose shall be collected. The Foundation shall not collect more data than it needs. |
|---|
| Principle 4: Accuracy Personal data shall be accurate and kept up to date. Inaccurate data shall be corrected or deleted without delay. |
|---|
| Principle 5: Storage Limitation Personal data shall be kept for no longer than is necessary for the purpose for which it was collected. Data that is no longer needed shall be securely deleted or destroyed. |
|---|
| Principle 6: Security and Integrity Personal data shall be processed in a manner that ensures its security, including protection against unauthorised access, accidental loss, destruction, or damage. |
|---|
| Principle 7: Accountability The Foundation, as data controller, is responsible for demonstrating compliance with these principles and shall maintain records to show how data is being handled. |
|---|
6. Lawful Basis for Processing
The Foundation shall only process personal data where it has a lawful basis for doing so. The lawful bases the Foundation relies on include:
- Consent: where the data subject has freely given clear and informed consent to the processing of their data for a specific purpose
- Contractual necessity: where processing is necessary to fulfil an agreement with the data subject, such as a volunteer agreement
- Legal obligation: where processing is required to comply with a legal requirement, such as SCUML reporting or CAC annual returns
- Legitimate interests: where processing is necessary for the Foundation's legitimate organisational interests, provided those interests are not overridden by the rights and freedoms of the data subject
For sensitive personal data, including health information and disability status, the Foundation will in all cases obtain explicit consent from the data subject before processing, unless processing is required by law.
7. Data We Collect and Why
| Category of Data Subject | Types of Data Collected | Purpose |
|---|---|---|
| Beneficiaries | Name, age, gender, disability type, health information, location, photographs | Programme delivery, impact reporting, media documentation |
| Children | Name, age, gender, disability status, guardian contact details, photographs | Programme delivery, safeguarding, media documentation with consent |
| Donors and Contributors | Name, contact details, bank or payment information, contribution amounts | Financial records, donor communications, compliance reporting |
| Volunteers | Name, contact details, identity documents, references, role history | Volunteer management, safeguarding compliance, communications |
| Staff and Trustees | Name, contact details, identity documents, qualifications, financial details | Employment, governance, regulatory compliance |
| Partner Organisations | Organisation name, contact persons, contact details, agreement details | Partnership management and communications |
8. Consent
Where the Foundation relies on consent as the lawful basis for processing personal data, that consent must be:
- Freely given, meaning not conditional on receiving a service or benefit
- Specific, meaning given for a clearly defined purpose
- Informed, meaning the individual understands what they are consenting to and why
- Unambiguous, meaning given through a clear affirmative action rather than silence or inaction
For children below the age of 18, consent must be obtained from a parent or legal guardian. For persons with intellectual disabilities or limited capacity, consent must be sought in an accessible format and with appropriate support.
Any individual may withdraw their consent at any time. Withdrawal of consent will not affect the lawfulness of any processing that took place before the withdrawal. Upon withdrawal, the Foundation will cease processing the relevant data for the purpose to which consent related.
9. Special Provisions for Children and Persons with Disabilities
The Foundation works extensively with children and persons with disabilities. Both groups require heightened data protection consideration.
Children
The Foundation treats all data relating to children with the highest level of care. Photographs, case stories, names, and any other identifying information relating to a child shall only be collected and used with the explicit written consent of a parent or legal guardian. Where such consent is withdrawn, the data shall be removed from all Foundation materials and records without delay.
Persons with Disabilities
Health information, disability type, and related personal data are sensitive personal data under the NDPA 2023. The Foundation shall only collect and process this data with explicit consent and shall use it solely for the purpose of designing and delivering appropriate support. This data shall never be used in ways that could stigmatise, expose, or disadvantage the individual concerned.
10. Data Security
The Foundation shall take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or damage. These measures include:
- Restricting access to personal data to authorised persons only, on a need-to-know basis
- Storing physical records containing personal data in secure, locked locations
- Using password protection and, where possible, encryption for digital records containing personal data
- Ensuring that volunteers and staff who handle personal data understand their data protection responsibilities
- Not transferring personal data via insecure channels such as unencrypted email where alternatives are available
- Securely disposing of personal data that is no longer needed, including shredding paper records and permanently deleting digital files
In the event of a data breach, meaning any accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data, the Foundation shall assess the risk to affected individuals and, where required by the NDPA 2023, report the breach to the Nigeria Data Protection Commission within 72 hours of becoming aware of it.
11. Data Sharing
The Foundation shall not share personal data with third parties without a lawful basis for doing so. Personal data may be shared in the following circumstances:
- With the explicit consent of the data subject
- Where required by law, for example in response to a lawful order from a regulatory authority or the Nigerian Police Force
- With partner organisations where necessary for programme delivery, provided a data sharing agreement is in place
- With grant funders where required for reporting purposes, in which case data will be anonymised wherever possible
The Foundation shall never sell personal data or share it with commercial third parties for marketing purposes.
Where the Foundation engages a third party to process data on its behalf, it shall ensure that the third party provides sufficient guarantees about data protection and shall put in place a written agreement requiring the third party to process data only in accordance with the Foundation's instructions.
12. Photographs, Video, and Media Content
Photographs and video recordings of beneficiaries, particularly children and persons with disabilities, constitute personal data and in many cases sensitive personal data. The following rules apply to all media content involving individuals connected to the Foundation:
- Explicit consent must be obtained before taking or using any photograph or video recording of an individual for Foundation purposes
- For children, written consent must be obtained from a parent or legal guardian
- Consent is specific to the stated use. Using an image for a different purpose requires fresh consent
- Individuals may withdraw consent for the use of their image at any time, and any published material featuring their image shall be removed as promptly as is practically possible
- Images shall not be used in ways that are degrading, exploitative, or that expose individuals to risk
- Location data embedded in photographs shall be reviewed and removed where it could compromise the safety or privacy of the individual pictured
- Images of children shall not be published on any platform without parental consent, and shall never be used in a manner that could identify the child's home, school, or location
13. Rights of Data Subjects
Under the Nigeria Data Protection Act 2023, every individual whose data the Foundation holds has the following rights:
| Right | What It Means |
|---|---|
| Right to be Informed | The right to know what data is collected, why, and how it is used. |
| Right of Access | The right to request a copy of the personal data the Foundation holds about you. |
| Right to Rectification | The right to have inaccurate or incomplete data corrected. |
| Right to Erasure | The right to request that your data be deleted where there is no longer a legitimate reason to hold it. |
| Right to Restrict Processing | The right to request that the Foundation limits how it uses your data in certain circumstances. |
| Right to Object | The right to object to processing based on legitimate interests. |
| Right to Withdraw Consent | The right to withdraw consent at any time where consent is the basis for processing. |
14. Retention of Personal Data
The Foundation shall not retain personal data for longer than is necessary for the purpose for which it was collected. The following general retention periods apply:
| Category of Data | Retention Period |
|---|---|
| Beneficiary programme records | Five years from date of last programme contact |
| Financial and donation records | Seven years, consistent with regulatory requirements |
| Safeguarding records | Seven years minimum |
| Volunteer and staff records | Five years after end of engagement |
| Photographs and media content | Duration of active consent or five years, whichever is shorter |
| Correspondence and communications | Three years |
At the end of the applicable retention period, personal data shall be securely deleted or destroyed. The Foundation shall maintain a record of data disposed of, including the date and method of disposal.
15. Responsibilities
Chief Executive Officer
The CEO has overall responsibility for ensuring that the Foundation complies with this policy and with the NDPA 2023. The CEO shall ensure that all staff and volunteers who handle personal data are aware of their responsibilities under this policy.
All Staff and Volunteers
Every person who handles personal data on behalf of the Foundation is personally responsible for handling that data in accordance with this policy. Any data breach or suspected breach must be reported to the CEO immediately.
Board of Trustees
The Board is responsible for ensuring that this policy is adopted, reviewed, and resourced appropriately. The Board shall receive an annual report on data protection compliance.
16. Training
The Foundation will ensure that all trustees, staff, and volunteers who handle personal data receive appropriate data protection awareness as part of their induction. Refresher training will be provided as needed and whenever significant changes to data protection law or Foundation practice occur.
17. Policy Review
This policy will be reviewed annually by the CEO and approved by the Board of Trustees. An earlier review may be triggered by changes to the NDPA 2023 or related regulations, a data breach, or significant changes in the Foundation's data processing activities.