By Bibitayo Ojo cDPO

Factual Background

The case of Emmanuel Haruna v Nigeria Data Protection Commission (the Commission) (Suit No. FHC/L/CS/1116/2024) appears, at first glance, to be a straightforward win for the Commission. The Court held that POS operators fall within the Commission’s registration regime for Data Controllers and Data Processors of Major Importance. On the surface, that sounds conclusive. However, on closer analysis of the judgment, the common reading of data protection law and directives, and the state of compliance maturity in Nigeria, a POS operator should not be considered a Data Controller or Data Processor of Major Importance (DCMI) for the purpose of registration.

The applicant, a POS agent, has prayed the Federal High Court in the Lagos Division for a declaration that a POS does not qualify to be a Data Controller or Processor of Major Importance (DCMI) under the NDPA Guidance Notice on a DCMI. The court entered judgment in favour of the respondent on 17th July 2026.

The Undisputed Position

Without doubt, a POS agent onboarded by a financial institution of choice, such as Capricorn Limited in the case of Emmanuel Haruna, processes customers’ personal data, including names, card details and account details, through POS terminals. Although Emmanuel claimed that he neither collects, records, shares nor stores data, that claim may not reflect the reality of all POS terminals. This was confirmed during a data protection audit I conducted for a fintech in Nigeria. The real issue here goes beyond registration with the Commission; other obligations, including the appointment of a DPO, may follow. The questions that come to mind concern the scale of processing, the data privacy risk arising from a POS operator’s processing activities, and the proportionality of the current compliance framework. The judgment does not adequately engage with this reality.

Privacy Risk Metrics

The respondent’s case for full regulatory treatment is that unregulated processing activities create privacy risk. However, for a POS agent today, the risk should be modest. Typically, there is no independent database, no broad profiling function, no long-term retention, and only infrequent collection of excessive personal data. This assessment may shift if viewed through the lens of the volume of data being processed daily.  Even so, volume should not be conflated with the risk indicator that DCMI is meant to capture; the real vulnerability is not POS agents acting as data warehouses but rather the absence of accountability infrastructure, which could affect the economy and security of Nigerians. This gap is better addressed through the sponsored financial institutions than the classification of the Agents as DCMIs.

The Silence and Unexamined Conflict Between Paragraphs 4 and 3(1)(e)(iv) of the NDPC Guidance Notice on Registration of DCMIs

While I do not consider the Court’s position to be wrong, a major concern is the omitted exemption in Paragraph 4 of the Guidance Notice. This paragraph exempts artisans who do not transmit personal data as an object of trade or business to other data controllers or processors that may process the transmitted personal data for their own business purposes. It also covers traders with fewer than fifteen (15) employees, or artisans who do not keep any specific filing system of personal data relating to their customers, except routine phone contacts, files, receipts, contact addresses and electronic mail addresses. POS agents are most likely to fall within the latter category.

Conversely, the respondent contended that Paragraph 3(1)(e)(iv) of the Guidance Notice provides that agents, contractors and vendors who engage with data subjects on behalf of other organisations designated as data controllers or processors will be categorised as DCMIs, considering the level of significance of their business to those organisations. This does not reflect the actual text of that paragraph, which touches on the companies that fall under the Ordinary High-Level Category.  If POS agent is to be categorised under the category that processes up to 200 data or sensitive data, would it suffice to conclude that transaction details on POS amount to sensitive data?. Not really!

On this issue, I contend that the NDPC should move beyond the binary of “registered” or “Major Importance” to a tiered minimum compliance standard for micro and small businesses, including POS agents.

Looking Forward, Not Backward

Based on the analysis above, the definitional threshold, the dual-hat reality of controllers and processors, and the risk profile all point to one conclusion: Nigeria needs a simplified compliance framework for SMEs and micro-operators, such as POS agents, that currently sit beneath the full DCMI regime. A short registration attestation, without the implied burden of appointing a DPO, conducting elaborate risk assessments and preparing comprehensive policy documentation, would be a more proportionate way to ensure accountability. Secondly, a heavier accountability burden should rest with the sponsoring financial institution that designs, assigns and controls the infrastructure through which data flows. Banks and fintechs are better placed to ensure full compliance maturity, including appointing a DPO and conducting the necessary risk assessments, among other obligations. A lighter duty can then flow to individual agents through onboarding, periodic training and continuous monitoring. For reference purposes, inspiration can be gleaned from the Resolution CD/ANPD No. 2/2022 of Brazil, which exempts SMEs from appointing a DPO. China and Singapore also embrace simplified data protection compliance frameworks.

The Nigerian agency banking sector is growing rapidly. A compliance model built around a broad category will struggle to hold if it is not properly tailored to business capacity, market structure and the data privacy risk profiles of different business scales. It is therefore imperative to publish a simplified SME compliance framework that treats POS operators neither as invisible actors nor as financial institutions, but as high-volume, lower-risk and low-capacity actors within an economy and system that require accountability and trust to thrive.

Bibitayo Ojo is a corporate lawyer and a Data Protection Officer with 5 years of experience supporting organisations across all sectors with data protection compliance through data protection audits, privacy risk assessments, and advisory services. He holds the CDPO certification and helps organisations navigate regulatory compliance without stifling innovation.

Follow Our WhatsApp Channel ______________________________________________________________________ Groundbreaking Guide For Lawyers: Adigwe Publishes ‘Artificial Intelligence For Lawyers’ With Free Research eBook The book also examines Nigeria's legal ecosystem, focusing on the LPELR and NBA AI Guidelines. As a bonus, every purchase comes with a FREE eBook titled: How to Use the AI Features in LegalPedia and LawPavilion. Ohio Books Ltd praises the publication, stating: "....this is the only Nigerian book I know of on the topic." How to Order: 📞 Call, Text, or WhatsApp: 08034917063 | 07055285878 📧 Email: benadigwe1@gmail.com 🌎 Website: www.benadigwe.com Ebook Version: Access it directly online at https://selar.com/prv626 Authored by Ben Ijeoma Adigwe Esq., ACIarb (UK), LL.M, Dip. in Artificial Intelligence, Director at the Delta State Ministry of Justice, Asaba, Nigeria. _______________________________________________________________________

“Order Justice Omolaye-Ajileye’s Electronic Evidence Books Now” — Essential Guides On Evidence Act, Case Law And Digital Proof

Two leading books on electronic evidence by Hon. Justice Professor Alaba Omolaye-Ajileye, Rtd., PhD, FICMC, are now available for purchase. The publications, Electronic Evidence (Second Edition), With The Evidence Act, 2011 and Compendium Of Cases On Electronic Evidence, Volume II, 2020–2025, provide practical guidance, legal analysis and recent judicial authorities on electronic evidence in Nigeria.Order directly from the author here: https://velvety-cendol-7387ed.netlify.app/ _______________________________________________________________________ “Enhance Legal Practice With Authoritative Reports” — Alexander Payne Offers Comprehensive Law Reports, Spanning Over A Century Of Nigerian Jurisprudence

Interested buyers are encouraged to place their orders and enquiries via: 0704 444 4777, 0704 444 4999, 0818 199 9888 Website: www.alexandernigeria.com

________________________________________________________________________ [A MUST HAVE] Evidence Act Demystified With Recent And Contemporary Cases And Materials
“Evidence Act: Complete Annotation” by renowned legal experts Sanni & Etti.
Available now for NGN 40,000 at ASC Publications, 10, Boyle Street, Onikan, Lagos. Beside High Court, TBS. Email publications@ayindesanni.com or WhatsApp +2347056667384. Purchase Link: https://paystack.com/buy/evidence-act-complete-annotation _______________________________________________________________________ LAWBREED NEW WIG SPECIAL OFFER — Give a newly called lawyer a lasting professional gift. Get up to 20% off selected LAWBREED Supreme Court Reports, plus access to My S.C Extra, featuring Supreme Court judgments from 1972 to date. Call/WhatsApp: 08077011741 | 08077011755 | 08077011730 | 08023269613 Email: orders@lawbreed.com | mails@lawbreed.com LAWBREED — Equipping You For Greater Success! _______________________________________________________________________