1. NDPR overview
The Nigeria Data Protection Regulation, 2019 ("NDPR") and the Nigeria Data Protection Act, 2023 ("NDPA") together form the primary framework governing the collection, storage, use, and transfer of personal data in Nigeria. They set out data subject rights, controller and processor obligations, breach notification duties, and the enforcement powers of the Nigeria Data Protection Commission ("NDPC").
KarVerifi is designed from the ground up to help both us and our tenants meet these obligations without friction.
2. Our role
In almost every processing scenario, KarVerifi is a data processor — we process end-user personal data on behalf of the tenant that has onboarded them. The tenant remains the data controller and decides which checks are run, on which end-users, and why.
For our own operations — payroll, sales pipeline, internal tooling — we are the data controller with respect to our staff, prospects, and dashboard users. For those relationships the details are in our Privacy policy.
3. Processing purposes
We process personal data for the following purposes:
- Executing verification checks against Nigerian identity registries and third-party KYC providers on the tenant's instructions.
- Producing verification outcomes, audit records, and webhook events that the tenant needs for its own compliance obligations.
- Preventing fraud and abuse of the platform (rate-limit tracking, anomalous access detection, IP-based session revocation).
- Retaining records for the minimum periods required by NDPR, CBN circulars, and other applicable law.
4. Legal basis
We rely on the following lawful bases under NDPR:
- Performance of a contract — with the tenant, whose contract with the end-user requires identity verification.
- Legal obligation — including CBN KYC requirements applicable to financial-services tenants.
- Legitimate interests — fraud prevention, security monitoring, and service improvement.
- Consent— collected by the tenant's onboarding flow before any check is triggered.
5. Data subject rights
End-users can exercise their NDPR rights (access, rectification, erasure, portability, objection, and withdrawal of consent) by contacting the tenant that onboarded them — the tenant is the data controller. Tenants can raise those requests to KarVerifi via the dashboard or by emailing dsar@karverifi.com.
Where a data subject contacts KarVerifi directly, we will route the request to the responsible tenant within 3 business days and support the tenant in responding within the 30-day statutory window.
6. Consent management
Our hosted onboarding flow captures explicit end-user consent at the first step of every workflow, displaying the tenant's privacy statement and the specific checks about to be executed. Consent is recorded with:
- A timestamp and hashed IP address to demonstrate when consent was given.
- The exact workflow version and list of checks consented to.
- The tenant's privacy statement version displayed at the point of consent.
End-users can withdraw consent at any point during a workflow; withdrawal halts the flow and marks the verification as cancelled. Tenants remain responsible for capturing consent in their own onboarding surfaces when they use the direct API rather than the hosted UI.
7. Breach notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, KarVerifi will:
- Notify affected tenants without undue delay and, in any event, within 72 hours of becoming aware of the breach.
- Provide affected tenants with all information reasonably needed to comply with their own NDPR notification obligations to the NDPC.
- Support any subsequent regulatory investigation and cooperate with our sub-processors' incident teams.
8. Data Protection Officer
Our Data Protection Officer can be reached at dpo@karverifi.com. Written correspondence:
Data Protection Officer
Karrabo Financial Solutions Limited
85–86 Terrace Wing, Tafawa Balewa Square
Lagos Island, Lagos, Nigeria
9. NITDA registration
KarVerifi files annual data-audit returns with the Nigeria Data Protection Commission through a NITDA-licensed Data Protection Compliance Organisation. Our NITDA licence reference will be published here once issued.
10. Audit and certification
We conduct annual internal privacy audits and quarterly access reviews of production data. External certifications on our roadmap (targets, not current certifications):
- ISO/IEC 27001 — Information Security Management System (target).
- SOC 2 Type II — trust services criteria (target).
- PCI DSS SAQ-A — for wallet top-ups, via our processor (target).