pattern
logo

PRIVACY POLICY

Please read this Privacy Notice before you may become a business or personal user of The Nigerian Exchange Limited (“NGX”) and its Affiliates’ Digital Gateway Platform (hereinafter referred to as “the Platform”).

INTRODUCTION

This Privacy Notice sets out how NGX and/or its Affiliates collect, use, store, share and protect any information that you give NGX/its Affiliate when you subscribe to this Platform. It applies to this Platform and all its applications, services, tools and contents regardless of how you access or use them.

NGX and its Affiliates are committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this Platform, you can be assured that it will only be used in accordance with this Privacy Notice.

CONSENT

You accept this Privacy Notice when you sign up for access or use the products, services, content, features, technologies or functions offered on this Platform and all related sites, applications, and services.

LEGAL BASIS

You further accept that NGX and its Affiliates may process your Personal Information without explicit consent sought, given or accepted where (i) it is necessary for entering into or performance of a contract;

(ii) it is authorized or required by law (which also provides safeguards for You); or (iii) there are circumstances that may engender direct or indirect propagation of atrocities, hate, child rights violation, criminal acts and anti-social conducts.

COLLECTION OF INFORMATION

Personal Information We Collect Directly from You

NGX and/or its Affiliates collect Personal Information from you when you use this Platform. The type of Personal Information that we collect from you depends on your particular interaction with the Platform. We require you to register on the Platform to access certain features. When we do, we may collect the following information from you during the registration process:

  • Full Name;
  • Email Address;
  • Phone Number;
  • Gender;
  • House Address;
  • Bank Verification Number (BVN);
  • Bank account details;
  • Copy of means of identification;
  • Details of Next of Kin;
  • Username and password that you create.

If you choose to purchase a product or procure a service through the Platform, we may collect your credit or debit card information. Currently, we use third-party service providers to process your bank verification number, credit and debit card transactions on our behalf. The third-party service providers will collect your contact information (such as your name, address, and e-mail, bank verification number) and bank or financial information (such as debit or credit card number and expiration date) in accordance with the provisions of a written contract between NGX/its Affiliates and the third party. We will be verifying your BVN data and your bank details, and by your use of this Platform, you consent to the validation of your BVN data and bank details.

We may also collect information you provide us, including but not limited to information on web forms, account update information and correspondence with the Platform support services team. Information obtained through voluntary submissions (e.g., responses to surveys, requests for information on NGX’s/its Affiliates’ Platforms or those of NGX/its Affiliates’ advertisers/marketing partners) and review of Platform usage patterns survey responses, customer enquiries and other means may also be collected and used by us. NGX/its Affiliates will only collect information that is necessary for the provision of the product or service that you have subscribed to.

Personal Information We Collect Automatically

NGX/its Affiliates may use cookies, web beacons, and other tracking technologies to collect information about you automatically as you use the Platform. This information includes information sent to us by your computer, mobile phone, POS or other electronic access devices.

The automatically collected information includes but is not limited to data about the pages you access, computer IP address, device ID or unique identifier, device type, geo-location information, computer and connection information, mobile network information, statistics on page views, traffic to and from the sites, referral URL, ad data, the dates and times of your use of the Platform and standard web log data. We may combine this information with other information that we collect about you.

NGX/its Affiliates may engage in activities which involve the automated processing and/or profiling of information you provide us where (i) it is necessary for entering into or performance of a contract; (ii) it is authorized or required by law (which also provides safeguards for you); or (iii) it is the subject of explicit consent from you.

You hereby consent that in the circumstances not covered above, NGX/its Affiliates can engage in activities which involve the automated processing and/or profiling of your information in respect of the services for which you provided the Personal Data. Such automated processing and/or profiling in respect of the services can include, without limitation, carrying out automated processing and/or profiling for the purpose of improving the services or introducing more services.

Upon your request, we shall provide you with information about the logic involved in the automated processing of your personal information as well as the significance and envisaged consequences of such processing.

Personal Information We Collect from Third Parties

We also collect information about you from third-party sources such as identity verification services and analytics providers in accordance with the provisions of a written contract between NGX/its Affiliates and the third party. The categories of information that we collect about you from other sources include:

  • Full Name
  • Date of Birth);
  • Contact Details (e.g. phone number, email address, and/or mobile number).

Please note that we may be required by law to collect and use certain Personal Information about you. We may need to collect and use Personal Information to enter into or fulfil a contract with you. Failure to provide this information may prevent or delay the fulfilment of our obligations in these circumstances.

How NGX/its Affiliates uses Information it Collects

We primarily use your Personal Information to provide Subscription Services to you and to respond to your inquiries. We also may use your Personal Information as follows:

  • To communicate with you, including responding to your comments or requests for information, to request feedback on our products and services, and to notify you about changes to your subscriptions/ registration or to the services you use.
  • To help NGX/its Affiliates understand you, to tailor and enhance our product and service offerings, anticipate and resolve problems with any products or services supplied to you, and create products or services that may meet your needs.
  • To provide access to restricted pages or contents of the Platform.
  • To comply with legal and/or regulatory requirements and cooperate with regulators and law enforcement bodies.
  • To facilitate your activity and to identify you when you log into your account on our Platform
  • To send you marketing communications and advertising in line with your communications preferences and where permitted by applicable law about products, services and opportunities that we believe would be of interest to you, including products and services offered by third parties.
  • To protect our rights, your rights, and the rights of others, and to meet our own high standards of business practice.

The services of third parties may be employed to help us in certain areas, such as Platform hosting, marketing and market research. In some cases, that third party may receive your information.

However, at all times we will endeavour to keep in control and be responsible for the use of your information. Each time you provide us with Personal Information, we aim to let you know how we intend to use it and ask you to give your consent to such use.

NGX /its Affiliates may assign its obligations and rights under this Policy to an Affiliate or a successor entity, and your Personal Information as well as the use and processing of such Personal Information may be among the assets transferred by NGX/its Affiliates. You acknowledge and consent that such transfers may occur and are permitted by this Privacy Policy.

SECURITY AND PROTECTION

Personal Information collected will be held securely and will only be kept for as long as is reasonably necessary in the circumstances you are registered or, to use the Platform or as required by law (if applicable) or for as long as you use the service or product that you are subscribed to, unless you have provided us with your consent to use the data for any additional purposes. We take the security of the Platform and the information you provide very seriously, and we will take all appropriate technical, administrative and physical safeguards/measures using recognized security procedures and tools in accordance with good industry practice to protect your Personal Information. We have reasonable security measures in place to protect

against the loss, misuse and interception by third parties of the information under our control, but, to the extent allowed by law, NGX/its Affiliate assume no liability for any damages you may suffer as a result of interception, alteration or misuse of information transmitted over the Internet. Whilst we use all reasonable endeavors to protect your security in the manner described above, we consider that it is only appropriate to advise users that data transmission over the Internet and the World Wide Web cannot be guaranteed as 100% secure, and therefore that you use the Platform at your own risk.

What are Your Rights in relation to our Collection and Processing of your Personal Data

Users of our Site are entitled to exercise the following rights in relation to their personal data collected and processed by NGX:

  • right to withdraw consent in relation to the processing of their personal data;
  • right to be informed regarding their personal data;
  • right to request and access any personal data collected and stored by NGX;
  • right to request the deletion of their data;
  • right to be informed about appropriate safeguards in place where data is transferred abroad;
  • right to request rectification of personal data which is stored by NGX;
  • right to request the transmission of data from NGX to a third party (right to the portability of data);
  • right to object to automated decision making and processing;
  • right to object to direct marketing;
  • right to request the processing of their information; and
  • right to lodge a complaint with the NDPC.

NGX/ITS AFFILIATES’ OBLIGATIONS TO RETAIN YOUR PERSONAL INFORMATION AND YOUR ACCESS TO AND CONTROL OF SUCH PERSONAL INFORMATION

NGX/its Affiliates keep your Personal Information in line with set periods calculated using the following applicable criteria:

  • How long you have been a customer with us, the types of products or services we provide you with, and when you will stop being our customer.
  • After you have stopped being our customer, for how long it is reasonable for us to retain your records to show we have met the obligations we have to you and by law.
  • Any time limits for making a claim
  • Any period for keeping your personal information which is set by law or recommended by the relevant regulators, professional bodies or associations or is in line with best practice.
  • The nature of any contract we have in place with you.
  • The terms of any consent given by you.
  • Any relevant proceedings that apply.

The retention period is to enable NGX/its Affiliate to use the personal data for the necessary purposes identified in full compliance with the legal and regulatory requirements. When NGX/its Affiliate no longer need to use your personal information, we will delete it from our systems and records, and/or take steps to anonymize the said personal information so that you cannot be identified or linked to the said personal information.

Access to and Control over Information

In respect of your Personal Information with us, you can do at any time the following by contacting us:

  • If allowable, see what Personal Information we have about you, if any.
  • Change/correct any Personal Information we have about you after providing the required documentation and if it is within your purview to change/correct.
  • If allowable, and subject to points 1-7 above, have us delete any Personal Information we have about you.
  • Request for contact details of the data protection officer, where applicable.
  • If allowable, request for the purpose of the processing as well as the legal basis for processing.
  • If allowable, request for the categories of personal data collected, stored and processed.
  • If allowable, request for recipient(s) or categories of recipients that the data is/will be disclosed to.
  • Request for the duration of data retention.
  • Request for details and information of automated decision making, such as profiling, and any meaningful information about the logic involved, as well as the significance and expected consequences of such processing and express any concern about our use of your Personal Information.

INTERNATIONAL AND CROSS-BORDER TRANSFERS OF PERSONAL DATA

In the course of providing our services and carrying out our business, regulatory, technological and operational activities, we may transfer, store, permit access to or otherwise process your Personal Data outside the Federal Republic of Nigeria. Such transfers may arise, for example, where we engage or interact with technology and cloud infrastructure providers, financial institutions, payment service providers, identity verification providers, professional advisers, regulatory authorities and other authorised service providers or recipients located outside Nigeria.

We recognise that the transfer of Personal Data outside Nigeria is subject to specific legal and regulatory requirements. Accordingly, we will only transfer Personal Data outside Nigeria in accordance with the Nigeria Data Protection Act 2023 (“NDP Act”), the Nigeria Data Protection Act – General Application and Implementation Directive 2025 (“GAID”), applicable directives and guidance issued by the Nigeria Data Protection Commission (“NDPC” or the “Commission”), and other applicable laws.

Lawful Basis for Cross-Border Transfers

Before transferring Personal Data outside Nigeria, we will establish and document an appropriate basis for the transfer and take reasonable steps to ensure that the transfer complies with applicable data protection requirements.

In accordance with the NDP Act and GAID, we may undertake a cross-border transfer where one or more of the following applies:

  • Adequacy Decision - The Commission has determined that the country, territory, sector or other relevant jurisdiction to which the Personal Data is to be transferred affords an adequate level of protection in accordance with the NDP Act.
  • Approved Cross-Border Data Transfer Instrument - In the absence of an applicable adequacy decision, the transfer is made pursuant to a Cross-Border Data Transfer Instrument (“CBDTI”) approved by the Commission, where required. Such an instrument may include, as applicable, approved:
  • codes of conduct;
  • certification mechanisms;
  • binding corporate rules; or
  • standard contractual clauses,

or such other transfer instruments as may be recognised or approved by the Commission from time to time.

Where approval of a CBDTI by the Commission is required, we will obtain the requisite approval before relying on that instrument as the basis for the relevant transfer.

  • Other Lawful Grounds - Where there is no applicable adequacy decision or approved CBDTI, Personal Data may be transferred outside Nigeria where the transfer is permitted under the NDP Act, GAID or other applicable law, including where:
  • Consent: you have expressly consented to the proposed transfer, have not withdrawn that consent and have been appropriately informed of the possible risks associated with the transfer in the absence of an adequacy decision or approved CBDTI, in a manner that enables you to understand those risks;
  • Contract with the Data Subject: transfer is necessary in connection with a contract to which you are a party or, where applicable, pre-contractual steps or negotiations relating to such a contract, subject to the requirements of applicable law;
  • Sole Benefit of the Data Subject: the transfer is for your sole benefit in circumstances recognised under applicable law, and it is not reasonably practicable to obtain your consent, provided that the circumstances reasonably indicate that you would have given such consent;
  • Public Interest: the transfer is necessary for important reasons of public interest recognised under applicable law;
  • Legal Claims: the transfer is necessary for the establishment, exercise or defence of a legal claim;
  • Vital Interests: the transfer is necessary to protect the vital interests of a Data Subject or another person in circumstances where the relevant Data Subject is physically or legally incapable of giving consent; or
  • Other Lawful Ground: another jural, fiduciary or lawful ground expressly recognised under the NDP Act, GAID or applicable law applies.

We will not rely on any such ground unless the circumstances and applicable legal requirements for reliance on that ground have been satisfied.

For the avoidance of doubt, a commercial or business interest, including considerations relating solely to profit, convenience or organisational development, will not, by itself, be treated as a compelling legal right or duty justifying a cross-border transfer.

Adequacy and Assessment of Cross-Border Transfers

Where applicable, the adequacy of the protection afforded to Personal Data transferred outside Nigeria will be determined in accordance with the NDP Act and applicable decisions, directives or guidance of the Commission.

Relevant considerations may include:

  • the availability of enforceable rights for Data Subjects;
  • the availability and accessibility of effective administrative or judicial remedies;
  • the rule of law in the recipient jurisdiction;
  • the existence and effectiveness of applicable data protection legislation;
  • the existence and functioning of an independent and competent data protection or similar supervisory authority;
  • the circumstances and extent to which public authorities may access Personal Data;
  • the existence of appropriate arrangements between the Commission and a competent authority in the recipient jurisdiction;
  • relevant international commitments, conventions and membership of regional or multilateral organisations; and
  • any other factors prescribed or considered relevant by the Commission.

Where appropriate, we may conduct and document a transfer risk assessment or other appropriate assessment to identify and address risks associated with a proposed cross-border transfer.

Safeguards for Cross-Border Transfers

Where applicable, we will implement appropriate technical, organisational, contractual and governance safeguards designed to preserve the confidentiality, integrity and availability of Personal Data transferred outside Nigeria and to protect the rights and freedoms of Data Subjects.

Depending on the circumstances, these safeguards may include:

  • appropriate data processing and data transfer agreements;
  • approved CBDTIs;
  • confidentiality obligations;
  • encryption, pseudonymisation and other appropriate security measures;
  • appropriate access and authentication controls;
  • data minimisation and purpose limitation measures;
  • restrictions on unauthorised onward transfers;
  • information security and cybersecurity requirements;
  • audit, monitoring and compliance mechanisms;
  • Personal Data Breach notification and incident-management requirements;
  • mechanisms for the exercise of Data Subject rights; and
  • requirements relating to the retention, return, deletion, anonymisation or secure destruction of Personal Data.

These measures are intended to support appropriate monitoring and accountability in relation to cross-border data flows, access to remedies by affected Data Subjects and the protection of data sovereignty.

Transfers to Data Processors and Service Providers

Where Personal Data is transferred to, or made accessible by, a Data Processor or service provider located outside Nigeria, we will undertake appropriate due diligence and take reasonable steps to ensure that the recipient maintains appropriate technical and organisational measures for the protection of Personal Data.

Where required, the recipient will be subject to appropriate contractual obligations governing matters including:

  • the permitted purposes and scope of processing;
  • confidentiality and security;
  • compliance with our documented instructions;
  • restrictions on the use and disclosure of Personal Data;
  • engagement of sub-processors;
  • assistance with Data Subject rights;
  • Personal Data Breach and incident notification;
  • regulatory cooperation;
  • retention, return and deletion of Personal Data; and
  • restrictions applicable to onward transfers.

Onward Transfers

Where a recipient of Personal Data outside Nigeria proposes to transfer or disclose that Personal Data to another recipient or jurisdiction, we will take appropriate steps, including through contractual or other safeguards where applicable, to ensure that the onward transfer remains subject to a level of protection consistent with the NDP Act, GAID and the transfer mechanism applicable to the original transfer.

Sensitive Personal Data

Where a proposed cross-border transfer involves Sensitive Personal Data or other categories of Personal Data that may present heightened risks to the rights and freedoms of Data Subjects, we will apply enhanced safeguards appropriate to the nature, context, scope and purposes of the processing and comply with any additional requirements imposed under applicable law or by the Commission.

Documentation and Accountability

We will maintain appropriate records relating to our cross-border transfers of Personal Data in accordance with our accountability obligations under applicable data protection law.

Such records may include, where applicable:

  • the categories of Personal Data transferred;
  • the categories of Data Subjects affected;
  • the purpose of the transfer;
  • the recipient or categories of recipients;
  • the country or jurisdiction to which Personal Data is transferred;
  • the legal basis and transfer mechanism relied upon;
  • the basis upon which adequate protection has been established, where applicable;
  • the applicable CBDTI or other safeguards;
  • relevant technical and organisational measures; and
  • any applicable Data Protection Impact Assessment, transfer risk assessment or other documented assessment.

We will periodically review our cross-border transfer arrangements and the effectiveness of applicable safeguards, particularly where there is a material change in the nature or purpose of the processing, the recipient, destination jurisdiction, technology, applicable law, regulatory guidance or risks associated with the transfer.

Data Subject Rights and Transparency

Where required under applicable law, we will provide Data Subjects with appropriate information concerning cross-border transfers of their Personal Data, including relevant information about the categories of recipients and safeguards applicable to such transfers.

Where consent is relied upon as the lawful basis for a cross-border transfer, you may withdraw your consent in accordance with applicable law. Withdrawal of consent will not affect the lawfulness of any transfer undertaken before such withdrawal.

Your applicable rights under the NDP Act continue to apply in relation to Personal Data transferred outside Nigeria, subject to any limitations permitted by applicable law.

Continuing Compliance

We will periodically monitor our international data transfer arrangements and may suspend, modify or terminate a transfer where we determine that the applicable transfer mechanism is no longer valid, appropriate safeguards can no longer be maintained or continuation of the transfer would otherwise be inconsistent with applicable data protection requirements.

We will comply with applicable approval, documentation, assessment, notification and other regulatory requirements prescribed by the Commission in relation to cross-border transfers of Personal Data.

YOUR SECURITY OBLIGATIONS

Your online access to certain of your Personal Information may be protected with a password you select. We will never ask you for your password in any unsolicited communication (such as letters, phone calls or email messages). You have an obligation to keep your user ID, password and Personal Information secure. As part of maintaining this obligation, we recommend that you do the following:

  • Keep your user ID and password confidential;
  • Utilize a unique password and change it frequently;
  • Make sure others are not watching you enter your user ID and/or password on your keyboard when using protected elements of the Digital Services; and
  • Do not leave your computer unattended while logged onto the Platform. After you have finished accessing your information, exit the protected area.

SHARING AND DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES

We recognise that the sharing or disclosure of Personal Data to third parties constitutes processing of Personal Data and must therefore be undertaken lawfully, fairly, transparently and in a manner that protects the rights and interests of Data Subjects.

Accordingly, we will only share, disclose or otherwise make your Personal Data available to a third party where there is an appropriate lawful basis for doing so and where the disclosure is consistent with the purposes for which the Personal Data was collected or is otherwise permitted by applicable law.

All disclosures of Personal Data will be undertaken in accordance with the Nigeria Data Protection Act 2023 (“NDP Act”), the Nigeria Data Protection Act – General Application and Implementation Directive 2025 (“GAID”), applicable directives and guidance issued by the Nigeria Data Protection Commission (“NDPC” or the “Commission”), and other applicable laws and regulatory requirements.

Circumstances in Which We May Share Personal Data

Depending on the nature of your relationship with us, the services you use and the transaction concerned, we may share your Personal Data where the disclosure is necessary and proportionate for a specified and lawful purpose, including:

  • providing, administering, maintaining or securing NGX Invest and related services;
  • establishing, administering or performing a contract with you or taking steps at your request before entering into a contract;
  • processing, verifying, administering, reconciling or completing an investment application or transaction;
  • carrying out identity verification, Know-Your-Customer (“KYC”), anti-money laundering, fraud prevention, sanctions screening or other regulatory checks;
  • facilitating payments, settlement, allotment, registration or other activities connected with an investment or transaction;
  • complying with applicable legal, regulatory, judicial or supervisory requirements;
  • establishing, exercising or defending legal claims;
  • protecting the security and integrity of NGX Invest, our systems, Data Subjects or other persons;
  • pursuing a legitimate interest of NGX or a third party, where such interest is not overridden by the fundamental rights, freedoms and interests of the affected Data Subject;
  • protecting the vital interests of a Data Subject or another person;
  • performing a task carried out in the public interest or in the exercise of official authority, where applicable;
  • fulfilling a purpose for which you have provided valid consent, where consent is the appropriate lawful basis; or
  • fulfilling another purpose permitted under applicable law.

The necessity, desirability or convenience of sharing Personal Data with a third party will not, by itself, constitute a lawful basis for processing. We will identify and rely upon an appropriate lawful basis before making a disclosure.

Categories of Third-Party Recipients

Depending on the relevant processing activity, we may disclose Personal Data to the following categories of recipients:

  • Issuers and Transaction Parties – issuers of securities and other persons involved in public offers, rights issues, subscriptions or other investment transactions made available through NGX Invest, where disclosure is necessary for the relevant transaction;
  • Capital Market Operators and Market Infrastructure Providers – including issuing houses, registrars, receiving agents, brokers, custodians, trustees, central securities depositories, clearing and settlement institutions and other duly authorised market participants involved in processing or administering transactions;
  • Banks and Payment Service Providers – including receiving banks, payment processors, payment gateways and other authorised financial service providers involved in processing, authenticating, reconciling or settling payments and transactions;
  • Identity Verification and Compliance Service Providers – including providers engaged to verify identity, Bank Verification Number (“BVN”), account information, identification documents or other information required for KYC, fraud prevention, sanctions screening, anti-money laundering or other lawful compliance purposes;
  • Technology and Infrastructure Service Providers – including cloud, hosting, software, cybersecurity, communications, data storage, maintenance and other technology providers supporting the operation, security and functionality of NGX Invest;
  • Professional Advisers – including lawyers, auditors, accountants, consultants, insurers and other professional advisers where access to Personal Data is reasonably necessary for the provision of their services and is subject to applicable professional, contractual or confidentiality obligations;
  • Regulatory, Supervisory and Government Authorities – including the Securities and Exchange Commission, the Nigeria Data Protection Commission, judicial authorities, law-enforcement agencies and other competent governmental or regulatory bodies where disclosure is required or permitted by applicable law; and
  • Other Authorised Recipients – other persons to whom disclosure is reasonably necessary for a specified and lawful purpose, subject to applicable data protection requirements.

We will take reasonable steps to ensure that Personal Data disclosed to a third party is limited to what is adequate, relevant and reasonably necessary for the particular purpose for which the disclosure is made.

Lawful Basis for Disclosure

Before sharing Personal Data with a third party, we will ensure that the disclosure is supported by an applicable lawful basis under the NDP Act. Depending on the circumstances, we may rely on:

  • your consent;
  • performance of a contract to which you are a party or steps taken at your request before entering into a contract;
  • compliance with a legal obligation;
  • protection of your vital interests or those of another person;
  • performance of a task carried out in the public interest or in the exercise of official authority; or
  • the legitimate interests pursued by NGX or a third party, subject to the rights, freedoms and legitimate interests of the affected Data Subject.

Where we rely on legitimate interests, we will consider the nature and purpose of the processing and the potential impact on affected Data Subjects and will implement appropriate safeguards where necessary.

Where consent is relied upon, consent will be obtained in accordance with applicable law and may be withdrawn by you at any time. Withdrawal of consent will not affect the lawfulness of processing undertaken before the withdrawal.

Third-Party Data Processors

Where we appoint a third party to process Personal Data on our behalf, we will take appropriate steps to assess the processor's ability to process Personal Data securely and in accordance with applicable data protection requirements.

We will require Data Processors acting on our behalf to process Personal Data only for authorised purposes and in accordance with our documented instructions, except where otherwise required by applicable law.

Our engagement of a Data Processor will be governed by a written contract or other legally binding arrangement, as required by applicable law, which will address, as appropriate:

  • the subject matter, nature, purpose and duration of the processing;
  • the categories of Personal Data and Data Subjects concerned;
  • the rights and obligations of the parties;
  • compliance with our documented processing instructions;
  • confidentiality obligations;
  • appropriate technical and organisational security measures;
  • assistance in facilitating the exercise of Data Subject rights;
  • Personal Data Breach detection, management and notification;
  • applicable retention, return, deletion or secure destruction requirements;
  • audit, monitoring and compliance obligations;
  • engagement of other processors or sub-processors;
  • assistance with Data Protection Impact Assessments where appropriate; and
  • applicable requirements relating to cross-border transfers of Personal Data.

Due Diligence and Oversight of Data Processors

Before appointing a material Data Processor, we will undertake appropriate due diligence having regard to the nature, scope, context and risks associated with the processing.

Depending on the circumstances, such due diligence may include consideration of:

  • the processor's technical and organisational security measures;
  • its experience, competence and reliability in processing Personal Data;
  • its data protection and information-security policies and procedures;
  • its applicable registration or compliance status with the NDPC, where required;
  • relevant certifications, standards or independent assurance reports;
  • the locations in which Personal Data will be stored or processed;
  • its use of sub-processors;
  • its Personal Data Breach and incident-response procedures; and
  • any other matter reasonably necessary to assess its ability to comply with applicable data protection requirements.

We may periodically review or monitor material Data Processors, taking into account the nature and risks of the processing and any material changes to the relevant processing arrangement.

Sub-Processors

Where a Data Processor engaged by us proposes to engage another processor or sub-processor in connection with Personal Data processed on our behalf, such engagement will be subject to applicable legal and contractual requirements.

Where appropriate, we will require the original Data Processor to ensure that authorised sub-processors are subject to data protection, confidentiality and security obligations that provide an appropriate level of protection for the Personal Data concerned.

The engagement of a sub-processor will not relieve the original Data Processor of its applicable responsibilities in respect of Personal Data processed on our behalf.

Disclosures to Independent Data Controllers

Not every third party that receives Personal Data from us acts as our Data Processor. Certain recipients may process Personal Data as independent Data Controllers because they independently determine the purposes and means of their processing in accordance with their legal, regulatory, contractual or operational responsibilities.

Depending on the circumstances, such recipients may include issuers, registrars, banks and other financial institutions, capital market operators, market infrastructure providers, regulators and governmental authorities.

Where we disclose Personal Data to an independent Data Controller, we will remain responsible for ensuring that our disclosure of the Personal Data is lawful, fair, transparent, necessary and proportionate and is supported by an appropriate lawful basis.

Following a lawful disclosure, the independent Data Controller will be responsible for complying with its own obligations under applicable data protection law in relation to its subsequent processing of the Personal Data.

Regulatory and Legally Required Disclosures

We may disclose Personal Data where the disclosure is required or permitted by applicable law, regulation, court order, regulatory directive or other lawful process. This may include disclosures reasonably necessary to:

  • comply with applicable securities, capital market, financial services, anti-money laundering, counter-terrorism financing, taxation, data protection or other legal and regulatory requirements;
  • respond to lawful requests from regulatory, supervisory, judicial, law-enforcement or governmental authorities;
  • investigate, prevent or respond to fraud, financial crime, cybersecurity incidents or other unlawful activity;
  • establish, exercise or defend legal claims; or
  • protect the rights, property, security or legitimate interests of NGX, Data Subjects or other persons where permitted by law.

Where legally permissible and practicable, we will limit such disclosures to Personal Data that is adequate, relevant and reasonably necessary for the particular legal or regulatory purpose.

Sensitive Personal Data

Where the sharing or disclosure of Personal Data involves Sensitive Personal Data, we will ensure that the processing is permitted under section 30 of the NDP Act or any other applicable condition prescribed by the Commission, and that any applicable safeguards are implemented.

Where appropriate, we will apply enhanced technical and organisational measures having regard to the nature and sensitivity of the Personal Data, the purposes and circumstances of the disclosure and the risks that the processing may present to the rights and freedoms of affected Data Subjects.

We will not share or disclose Sensitive Personal Data unless the applicable requirements governing the processing of such Personal Data have been satisfied.

Purpose Limitation and Data Minimisation

We will take reasonable steps to ensure that Personal Data disclosed to a third party is adequate, relevant and limited to what is reasonably necessary for the identified purpose.

Data Processors acting on our behalf will not be authorised to use Personal Data for purposes incompatible with our documented instructions or the purposes for which the Personal Data was provided, except where processing is required by applicable law.

Where the purpose for which a third party processes Personal Data materially changes, we will assess whether the proposed processing is compatible with the original purpose and whether an additional or different lawful basis, notice or other safeguard is required.

Security and Confidentiality

We will require Data Processors acting on our behalf to implement appropriate technical and organisational measures designed to preserve the confidentiality, integrity and availability of Personal Data and to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or other unlawful processing.

The nature of the safeguards applied will be proportionate to the risks associated with the processing and may include, where appropriate, encryption, pseudonymisation, access controls, authentication mechanisms, confidentiality obligations, security monitoring, vulnerability management, business continuity measures and incident-response procedures.

Third-Party Direct Marketing

We will not disclose your Personal Data to third parties for their independent direct marketing purposes unless there is an appropriate lawful basis for doing so and any consent required under applicable law has been obtained.

Where consent is relied upon for direct marketing, you may withdraw your consent at any time. You may also exercise your applicable right to object to the processing of your Personal Data for direct marketing purposes.

International Disclosures

Where the disclosure of Personal Data to a third party involves the transfer, storage, access or other processing of Personal Data outside the Federal Republic of Nigeria, the disclosure will additionally be subject to the requirements applicable to cross-border transfers under the NDP Act and GAID and the International and Cross-Border Transfers of Personal Data section of this Privacy Policy.

A lawful basis for sharing Personal Data with a third party does not, by itself, satisfy the requirements applicable to a cross-border transfer. Where applicable, we will separately establish and document an appropriate cross-border transfer basis or mechanism.

Data Protection Impact Assessments

Where the proposed engagement of a third party, introduction of a new technology or other processing arrangement is likely to result in a high risk to the rights and freedoms of Data Subjects, we will consider the relevant third-party processing as part of a Data Protection Impact Assessment in accordance with applicable law.

Where appropriate, relevant Data Processors may be required to provide information or assistance necessary for the conduct, review or implementation of measures arising from a Data Protection Impact Assessment.

Accountability and Records

We will maintain appropriate records relating to material third-party processing arrangements as part of our accountability and data governance framework.

Depending on the nature and risk of the processing, such records may include information concerning:

  • the third party and its role as Data Processor or independent Data Controller;
  • the categories of Personal Data and Data Subjects concerned;
  • the purposes of the disclosure or processing;
  • the applicable lawful basis;
  • relevant contractual arrangements;
  • due diligence and risk assessments;
  • technical and organisational security measures;
  • use of sub-processors;
  • international transfer arrangements, where applicable; and
  • applicable retention and deletion requirements.

Your Rights and Information About Recipients

Subject to applicable law, you may request information regarding the recipients or categories of recipients to whom your Personal Data has been or may be disclosed and exercise your applicable Data Subject rights in relation to such Personal Data.

Requests relating to the disclosure of your Personal Data or the exercise of your rights may be submitted using the contact details provided in this Privacy Policy.

DO WE USE COOKIES?

Yes. A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added, and the cookie helps analyze web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences. Cookies are features included in your browser and will store small amounts of data on your computer about your visit to the Platform, in particular when you complete any form on the Platform. However, a cookie does not provide us with any Personal Information. Therefore, if you have not supplied us with any Personal Information, you can still browse our site anonymously. You do not need to have cookies turned on to visit most of the Platform. Cookies on the Platform are not used to capture or store personal data from browsers to the site, other than to log your IP address and session information such as the duration of the visit to our site and the nature of the browser used. This information is used only for administration of the platform’s system and in the compilation of statistics used by NGX/its Affiliates. Cookies may be required to allow you to access and participate in certain areas of the Platform. Once you have closed your browser, this type of cookie is deactivated. The majority of browsers will allow you to alter the settings used for cookies and to disable and enable them as you require. If you do not want cookies and for further general information on cookies you may wish to visit https://www.allaboutcookies.org/.

CONTROLLING YOUR PERSONAL INFORMATION

We will not sell, distribute or lease your Personal Information to third parties unless we have your permission or are required by law to do so.

REMEDIES FOR VIOLATION OF THIS PRIVACY POLICY

Any person subject to this Privacy Policy who is found to be in breach of this Privacy Policy by:

  • failure to implement safeguards required by the Nigeria Data Protection Act (NDPA) 2023 and the General Application and Implementation Directive (GAID) 2025 or any of the security measures provided in this Policy;
  • failure to mitigate the damage once it has occurred; or
  • failure to timely notify the affected individuals

shall be liable, in addition to any other civil liabilities, to the penalties provided in the Nigerian Data Protection Act and the General Application and Implementation Directive (GAID) 2025.

CONTACTING NGX/ITS AFFILIATES

Our customer service contact is publicoffers@ngxgroup.com or kadebayo@ngxgroup.com and +234 700 225 5673. We shall endeavour to respond to enquiries/issues sent to/made to these service contacts within 48 hours.

GOVERNING LANGUAGE

This Privacy Notice, and the contents of this Platform are available in English

GOVERNING LAW AND JURISDICTION

By accessing the services on this Platform, you agree to be governed by the laws of the Federal Republic of Nigeria, the Nigeria Data Protection Act (NDPA) 2023 and the General Application and Implementation Directive (GAID) 2025. The laws of the Federal Republic of Nigeria will govern all matters relating to this Privacy Notice and the use, or inability to use, the Platform, and shall apply without regard to the principles of conflict of laws.

You agree to submit to the exclusive jurisdiction and venue of the Courts in the Federal Republic of Nigeria.

Notwithstanding the foregoing, NGX/its Affiliates may seek recourse in any jurisdiction worldwide to restrain the unlawful use of the Platform or any material contained on the Platform.

Powered by   

ngx

© 2026 NGX. All Rights Reserved