Section 27 Nigeria Data Protection Act 2023
Section 27 of the Nigeria Data Protection Act 2023 is about Provision of information to the data subject. It is under Part V (Principles and Lawful Basis Governing Processing of Personal Data) of the Act.
(1) Before a data controller collects personal data directly from a data subject, the data controller shall inform the data subject of the —
(a) identity, residence or place of business of, and means of communication with the data controller and its representatives, where necessary ;
(b) specific lawful basis of processing under section 25(1) or 30(1) of this Act, and the purposes of the processing for which the personal data are intended ;
(c) recipients or categories of recipients of the personal data, if any ;
(d) existence of the rights of the data subject under Part VI ;
(e) retention period for the personal data ;
(f) right to lodge a complaint with the Commission in accordance with section 46 (1) of this Act ; and
(g) existence of automated decision-making, including profiling, the significance and envisaged consequences of such processing for the data subject, and the right to object to and challenge such processing.
(2) Before a data controller collects personal data, other than directly from the data subject, the data controller shall inform the data subject of the matters set out in subsection (1), except where the —
(a) data subject already has been provided with such information ; or
(b) provision of such information is impossible or would involve a disproportionate effort or expense.
(3) The information referred to in subsection (1) shall be contained in a privacy policy and expressed in clear, concise, transparent, intelligible, and easily accessible format, taking into consideration the class of data subjects targeted by the data processing.