Part 4 · 2 chapters · ~12 min
Data Privacy, Retention and Deletion (NDPA, GDPR)
Nigeria's Data Protection Act 2023 and the GDPR in engineering terms, lawful bases, data maps, minimisation, retention schedules, deletion across systems (crypto-shredding, backups), data subject requests, breach notification within 72 hours, and cross-border transfers.
8
The law in engineering terms
| requirement | engineering work |
|---|---|
| lawful basis and purpose limitation | a field inventory: what, why, basis, retention, where stored |
| data subject rights (access, correction, deletion) | an export job and a deletion workflow across services |
| security of processing | encryption, access control, audit logs, testing |
| breach notification | both the NDPA and the GDPR set a 72-hour window to notify the regulator (NDPC in Nigeria) after becoming aware |
| cross-border transfers | know which vendors and regions hold data; adequacy or safeguards |
| data protection impact assessments | required for high-risk processing (biometrics, credit scoring) |
This is engineering guidance, not legal advice: confirm specifics with your data protection officer.
PERSONAL DATA THROUGH ITS LIFE
collect less, keep it for a reason, delete it everywhere
swipe the figure sideways, or tap expand for full screen
1/4
collect less
Every field needs a purpose and a lawful basis (consent, contract, legal obligation, legitimate interest). Data you never collect cannot leak or need deleting.
minimise at the sourcepurpose + lawful basis per field
9
Deleting for real
code
-- crypto-shredding: encrypt each customer's personal fields with a per-customer key; -- deleting the key makes every copy unreadable, including backups you cannot edit CREATE TABLE customer_keys (customer_id uuid PRIMARY KEY, wrapped_dek bytea NOT NULL); -- data key wrapped by KMS DELETE FROM customer_keys WHERE customer_id = $1; -- replicas, backups and exports become ciphertext -- deletion workflow (orchestrated, Workflows P6): each service confirms -- identity ✔ payments: anonymise (keep ledger rows, legal obligation) ✔ search index ✔ warehouse ✔ email vendor ✔
Ledgers and KYC records usually cannot be deleted while a legal retention duty applies: anonymise or restrict them, and delete when the period ends.