By Paul Joseph
The Nigerian government, via the Nigeria Data Protection Commission (NDPC), has initiated an immediate inquiry into the data handling practices of the Chinese-owned e-commerce platform Temu due to suspected breaches of the Nigeria Data Protection Act (NDPA).
This action has sparked renewed concerns regarding how foreign tech companies manage the collection, storage, and transfer of personal data belonging to Nigerians.
In a press release issued on February 16, NDPC’s National Commissioner and Chief Executive Officer, Vincent Olatunji, approved the investigation in response to growing worries about online surveillance, excessive data collection, lack of transparency, inadequate accountability measures, and international data transfers.
“The investigation into Temu was prompted by issues related to online surveillance through personal data processing, accountability, data minimization, transparency, duty of care, and cross-border data transfers,” the statement noted.
Initial findings from the Commission suggest that Temu processes personal data for approximately 12.7 million Nigerian users while catering to around 70 million active users worldwide, raising significant concerns about the methods used to collect, store, share, and safeguard Nigerians’ data.
“The National Commissioner cautioned that data processors working on behalf of data controllers without confirming their compliance with the NDPA could face liability under the Act,” the Commission stated.
Data indicates that Nigeria is the most populous nation in Africa and one of the continent’s rapidly expanding digital markets, with millions of citizens depending on mobile applications, social media, fintech services, and e-commerce platforms for daily transactions, often without fully understanding how their personal information is utilized.
Civil society organizations and digital rights advocates argue that the investigation into Temu is a critical test of Nigeria’s commitment to enforcing its data protection laws against influential global tech firms.
According to reports from ICIR, in January 2019, the National Information Technology Development Agency (NITDA) established the Nigeria Data Protection Regulation (NDPR), which serves as the country’s first comprehensive framework for how organizations handle personal data.
The NDPR introduced requirements for obtaining consent for data collection, established rights for data subjects, mandated organizations to implement security measures, and set penalties for data breaches and non-compliance. However, since the NDPR is a regulation rather than a parliamentary act, its enforcement powers were limited, and penalties were frequently challenged.
In February 2022, the Federal Government created the Nigeria Data Protection Commission to take over from NITDA as the main authority for data protection, a move intended to enhance independence and enforcement capabilities.

Leave a Reply