The enactment of the Nigeria Data Protection Act (NDPA) 2023 marked a milestone in Nigeria's regulatory landscape. It established a comprehensive framework for safeguarding personal data, imposing strict obligations on any organization that collects, stores, or processes the personal information of individuals within Nigeria. This includes visitor logs at your front desk.
Under the NDPA, visitor logs - whether paper or digital - contain personal data such as names, phone numbers, and photos. To comply with the Act, organizations must adhere to several key principles:
- Lawful Basis: You must have a lawful basis for collecting visitor data. This is typically consent or legitimate interest in maintaining facility security.
- Data Minimization: Only collect the information strictly necessary for the purpose of security and check-in. Avoid asking for excessive personal details.
- Security & Access Control: Personal data must be protected against unauthorized access. Digital records should be encrypted, and access restricted to authorized security staff.
- Data Retention Limits: Personal data should not be kept indefinitely. Define a retention period (e.g., 30 or 90 days) after which visitor logs and photos are automatically deleted.