…Warns Against Unauthorised Disclosure of Citizens’ Data
Abia State Government has commenced a Data Protection Compliance Awareness Training for directors and senior government officials, with a call for strict adherence to laws governing the collection, processing, storage and disclosure of citizens’ personal information.
The four-day training, organised through the Office of the Chief Information Officer to the Governor, is aimed at equipping senior civil servants with the knowledge required to protect personal data handled by government institutions and ensure compliance with the Nigeria Data Protection Act 2023.

Declaring the training open in Umuahia, the Commissioner for Budget and Planning, Mr Kingsley Anosike, said the protection of personal information is fundamentally a matter of trust between government and citizens.
Anosike said citizens who provided sensitive information such as their dates of birth and Bank Verification Numbers (BVNs) to government agencies did so on the understanding that such information would be kept confidential and used responsibly.

The commissioner added that government has a responsibility to treat citizens’ data as “sacred” and protect it from unauthorised access or disclosure.
“If you breach your data trust, you can be sued for breach and there are consequences to it”, Anosike stated.

He noted that the state government had entered into a memoranda of understanding with organisations with which it shared data, stressing that such third parties must be bound by the same privacy obligations.
Anosike disclosed that the state was in the process of “rejigging our data architecture completely”, to incorporate data privacy requirements, but stressed that technological safeguards alone would not guarantee effective protection.

According to him, government officials who handle personal information were the “gatekeepers” responsible for preventing unauthorised persons from gaining access to sensitive data.
The commissioner therefore urged the participants to take the training seriously and become advocates of data privacy within their respective institutions.

The resource person and Founder of Rainbow Strategy, a data protection compliance firm licensed by the Nigeria Data Protection Commission (NDPC), Dr Franklin Eke, said the Nigeria Data Protection Act 2023 was founded on the constitutional right to privacy guaranteed under Section 37 of the Constitution.

Eke explained that the Act, signed into law on June 22, 2023, was designed to strengthen the rights of data subjects and establish safeguards against the misuse of personal information.
He said the training was approved by Governor Alex Otti to empower government officials responsible for handling citizens’ data to understand their obligations under the law.

According to him, state governments are among the largest collectors of personal data, obtaining information from citizens through various sectors, including education, healthcare, taxation and community administration.
He said the training would enable directors, heads of departments and other senior officials to better understand the environment in which they collect, store, manage and process personal information.

Eke also stressed the importance of extending data protection obligations to third-party service providers engaged by government institutions, adding that such vendors must be brought into the data protection compliance framework.
Eke further called for wider public awareness, particularly among young people who increasingly share personal information through mobile phones, social media platforms and digital services.

He said his organisation participates in the NDPC’s Adopt-A-School initiative, through which students are educated on how to protect their personal information both online and offline.
Also speaking, the Director of Information Technology in the Office of the Chief Information Officer, Mr Chima Ogwo, said the training was timely, given the growing incidence of unauthorised disclosure of information.

Ogwo said government officials should understand that access to information did not automatically confer the right to disclose it to third parties.
He stressed that personal information, including dates of birth and other sensitive details, should not be released without appropriate authorisation or consent, in line with the provisions of the data protection law.

























