By Bibitayo Ojo cDPO
Factual Background
The case of Emmanuel Haruna v Nigeria Data Protection Commission (the Commission) (Suit No. FHC/L/CS/1116/2024) appears, at first glance, to be a straightforward win for the Commission. The Court held that POS operators fall within the Commission’s registration regime for Data Controllers and Data Processors of Major Importance. On the surface, that sounds conclusive. However, on closer analysis of the judgment, the common reading of data protection law and directives, and the state of compliance maturity in Nigeria, a POS operator should not be considered a Data Controller or Data Processor of Major Importance (DCMI) for the purpose of registration.
The applicant, a POS agent, has prayed the Federal High Court in the Lagos Division for a declaration that a POS does not qualify to be a Data Controller or Processor of Major Importance (DCMI) under the NDPA Guidance Notice on a DCMI. The court entered judgment in favour of the respondent on 17th July 2026.
The Undisputed Position
Without doubt, a POS agent onboarded by a financial institution of choice, such as Capricorn Limited in the case of Emmanuel Haruna, processes customers’ personal data, including names, card details and account details, through POS terminals. Although Emmanuel claimed that he neither collects, records, shares nor stores data, that claim may not reflect the reality of all POS terminals. This was confirmed during a data protection audit I conducted for a fintech in Nigeria. The real issue here goes beyond registration with the Commission; other obligations, including the appointment of a DPO, may follow. The questions that come to mind concern the scale of processing, the data privacy risk arising from a POS operator’s processing activities, and the proportionality of the current compliance framework. The judgment does not adequately engage with this reality.
Privacy Risk Metrics
The respondent’s case for full regulatory treatment is that unregulated processing activities create privacy risk. However, for a POS agent today, the risk should be modest. Typically, there is no independent database, no broad profiling function, no long-term retention, and only infrequent collection of excessive personal data. This assessment may shift if viewed through the lens of the volume of data being processed daily. Even so, volume should not be conflated with the risk indicator that DCMI is meant to capture; the real vulnerability is not POS agents acting as data warehouses but rather the absence of accountability infrastructure, which could affect the economy and security of Nigerians. This gap is better addressed through the sponsored financial institutions than the classification of the Agents as DCMIs.
The Silence and Unexamined Conflict Between Paragraphs 4 and 3(1)(e)(iv) of the NDPC Guidance Notice on Registration of DCMIs
While I do not consider the Court’s position to be wrong, a major concern is the omitted exemption in Paragraph 4 of the Guidance Notice. This paragraph exempts artisans who do not transmit personal data as an object of trade or business to other data controllers or processors that may process the transmitted personal data for their own business purposes. It also covers traders with fewer than fifteen (15) employees, or artisans who do not keep any specific filing system of personal data relating to their customers, except routine phone contacts, files, receipts, contact addresses and electronic mail addresses. POS agents are most likely to fall within the latter category.
Conversely, the respondent contended that Paragraph 3(1)(e)(iv) of the Guidance Notice provides that agents, contractors and vendors who engage with data subjects on behalf of other organisations designated as data controllers or processors will be categorised as DCMIs, considering the level of significance of their business to those organisations. This does not reflect the actual text of that paragraph, which touches on the companies that fall under the Ordinary High-Level Category. If POS agent is to be categorised under the category that processes up to 200 data or sensitive data, would it suffice to conclude that transaction details on POS amount to sensitive data?. Not really!
On this issue, I contend that the NDPC should move beyond the binary of “registered” or “Major Importance” to a tiered minimum compliance standard for micro and small businesses, including POS agents.
Looking Forward, Not Backward
Based on the analysis above, the definitional threshold, the dual-hat reality of controllers and processors, and the risk profile all point to one conclusion: Nigeria needs a simplified compliance framework for SMEs and micro-operators, such as POS agents, that currently sit beneath the full DCMI regime. A short registration attestation, without the implied burden of appointing a DPO, conducting elaborate risk assessments and preparing comprehensive policy documentation, would be a more proportionate way to ensure accountability. Secondly, a heavier accountability burden should rest with the sponsoring financial institution that designs, assigns and controls the infrastructure through which data flows. Banks and fintechs are better placed to ensure full compliance maturity, including appointing a DPO and conducting the necessary risk assessments, among other obligations. A lighter duty can then flow to individual agents through onboarding, periodic training and continuous monitoring. For reference purposes, inspiration can be gleaned from the Resolution CD/ANPD No. 2/2022 of Brazil, which exempts SMEs from appointing a DPO. China and Singapore also embrace simplified data protection compliance frameworks.
The Nigerian agency banking sector is growing rapidly. A compliance model built around a broad category will struggle to hold if it is not properly tailored to business capacity, market structure and the data privacy risk profiles of different business scales. It is therefore imperative to publish a simplified SME compliance framework that treats POS operators neither as invisible actors nor as financial institutions, but as high-volume, lower-risk and low-capacity actors within an economy and system that require accountability and trust to thrive.
Bibitayo Ojo is a corporate lawyer and a Data Protection Officer with 5 years of experience supporting organisations across all sectors with data protection compliance through data protection audits, privacy risk assessments, and advisory services. He holds the CDPO certification and helps organisations navigate regulatory compliance without stifling innovation.
The post How Emmanuel Haruna V NDPC Should Redefine Data Protection Compliance For SMEs In Nigeria appeared first on TheNigeriaLawyer.
