The NIN You Handed Over Today Could Be Travelling Somewhere Else Tomorrow
Abstract A Lagos PoS operator challenged the regulator over the collection of his own identity details. The court rejected his case. But his fight raises a question millions of Nigerians rarely ask:...
Abstract
- Everyday Nigerians hand over their NIN, BVN, phone numbers, photographs, addresses and fingerprints to banks, PoS agents, employers, hospitals and government offices. Most people rarely ask what happens next. The case of PoS operator Emmanuel Haruna shows why that question is becoming harder to avoid.
A Lagos PoS operator challenged the regulator over the collection of his own identity details. The court rejected his case. But his fight raises a question millions of Nigerians rarely ask: once personal data leaves your hands, who controls it?
Analysis
The man at the centre of this story is not a bank chief executive or a technology founder. His name is Emmanuel Haruna. He is a PoS operator in Lagos.
For people who use PoS terminals every day, his work is familiar. A customer walks up, hands over a card or provides an account number, asks for cash, checks a balance or carries out a transfer. The machine beeps. The transaction either succeeds or fails. Life moves on.
But behind that five-minute transaction sits a growing pile of personal information.
Haruna challenged the Nigeria Data Protection Commission over a requirement that he registers as a Data Controller and Processor of Major Importance. His objection was not difficult to understand. He argued that requiring him to submit personal information, including his name, National Identification Number and contact details, interfered with his constitutional right to privacy. He also argued that a PoS agent who simply operates a terminal should not automatically be treated as a major data processor.
On 17 July 2026, the Federal High Court in Lagos dismissed his case.
That decision matters far beyond Haruna. It brings the Nigerian data protection debate down from the boardroom and into the roadside shop. Because Nigerians are giving away pieces of their identity all day.
Start with a bank account
Take something as ordinary as opening a bank account.
A customer may provide a name, NIN, phone number, address, date of birth, photograph and biometric information. The information goes into the bank’s systems. It may also be handled by technology companies, verification providers, cloud service providers, payment processors and other contractors working behind the scenes.
The customer may never know their names. That is the part worth thinking about.
A person may believe, quite reasonably, that they gave their NIN to a bank. In reality, the information can enter a much larger chain of systems.
The same thing happens with fintech applications, SIM registration, online shopping, hospital records, employment forms and government services.
Nobody wakes up in the morning thinking, “Today I am going to distribute my identity to six companies.” It happens one transaction at a time.
Haruna’s case exposes the uncomfortable bit
The Haruna case is useful because it puts a name and a face to an issue that normally appears in compliance documents as “data controller registration”.
The court found against him and upheld the NDPC’s position on the registration requirement. According to the published account of the judgment, the court held that the Commission’s registration requirement had statutory backing under the Nigeria Data Protection Act 2023.
There is a practical lesson here. The law is no longer treating data handling as something that happens only inside large technology companies.
A PoS operator can become part of the data protection chain. That makes sense when the everyday transaction is considered carefully. A PoS agent is not simply passing cash across a counter. Depending on the service and circumstances, the agent can be handling names, account details, transaction information and other personal data.
The person behind the terminal may therefore be sitting on information that can tell a surprisingly detailed story about other people.
The data trail is longer than most people realise
Consider a customer buying something online. The retailer gets a name, phone number and delivery address. The payment company gets transaction information. The courier gets the recipient’s name, address and telephone number. The retailer’s software provider may hold parts of the customer record.
A cloud provider may host the database. Customer service staff may see the order. If there is a return, even more information can be generated. None of these organisations necessarily feels like the “owner” of the customer’s identity. But all of them may have responsibilities under Nigeria’s data protection regime. That is why the Nigeria Data Protection Act matters.
It is not simply about stopping hackers. It is also about purpose, transparency, lawful processing, security, accountability and the rights of the person whose information is being processed.
The NDPC has previously been particularly critical of digital lenders for excessive access to contacts, pictures and messages. Its 2023 annual report described loan apps as overly intrusive and said many violated data protection principles through access to information that was not necessary for the lending relationship. That should sound familiar to anyone who has ever downloaded an app and been confronted with a long list of permissions.
Most people click “allow”. They want the service. They do not want a lecture on privacy law.
The vendor problem
There is another question that gets less attention. What happens after the contract ends?
Suppose a company outsources customer verification to another company. Three years later, the contract ends. Does the vendor still have the information? Has it been deleted? Was it copied somewhere else? Who checked?
The same question applies when an employee leaves, when a company changes software or when a database is migrated from one cloud provider to another.
A privacy policy may say that information is protected. That is not the same thing as proving that it is protected.
Good compliance requires organisations to know where data sits and who can touch it. That sounds obvious until a company has hundreds of thousands or millions of customers.
The public sector has the same problem
Government is perhaps the clearest example. Citizens give government agencies an extraordinary amount of information.
Identity documents. Tax records. Health information. Education records. Employment details. Property information. Phone numbers. Bank details.
The Federal Government has been pushing MDAs towards fuller implementation of the Nigeria Data Protection Act, while the NDPC has been stepping up implementation work. In August 2026, the Commission held a two-day implementation workshop for state governments focused on the NDPA, the 2025 implementation directive, compliance audits and implementation roadmaps.
The point is not that every government worker is looking at people’s private information. The point is that systems must be designed so that they do not have to rely on everyone behaving perfectly.
A good data protection system assumes that mistakes happen. It limits access, records activity, removes unnecessary information. It has a process for breaches. It gives people somewhere to complain.
The question Nigerians should start asking
The next time a form asks for a NIN, there is a perfectly reasonable question to ask.
Why? Not every request is improper. Some organisations have clear legal reasons for collecting identification information. But a customer should not have to accept “we need it” as the end of the conversation.
What is being collected? Why is it necessary? Who will receive it? How long will it be kept? What happens if something goes wrong? Those questions are not anti-business.
They are what a functioning data economy should make normal.
The NDPA gives data subjects rights around their personal information, including rights to access, correction, objection and, in certain circumstances, deletion. The law also places obligations on organisations processing personal data.
The bigger change is cultural.
For years, Nigerians have tended to think of privacy as something that belongs to celebrities, politicians or people with something to hide.
That is the wrong way to see it. Privacy is also about ordinary life. Who knows where someone lives. Who knows their bank details. Who knows their medical history. Who has their photograph. Who can see their transaction history. Who can contact their relatives. Who can combine all those pieces and build a picture of them.
Emmanuel Haruna’s case did not answer every one of those questions. It did something more useful.
It showed that the argument over personal data is no longer theoretical. It is already happening at the PoS terminal, inside the bank, in the fintech app and across government databases.
The NIN may look like just eleven digits. It is not.
For the person behind those digits, it can be the key that connects many different parts of life.
And once that key is copied, shared or stored in another system, getting it back is much harder than handing it over.
Compliance implications
The practical issue for organisations is data mapping.
A business should be able to explain what personal information it collects, why it needs it, where it stores it, who processes it, who can access it and when it is deleted.
That becomes especially important for organisations using vendors.
A company cannot simply hand customer information to a contractor and assume that the contractor’s privacy policy solves the problem. Contracts, access controls, retention rules, breach procedures and monitoring all matter.
The Haruna judgment also shows that smaller operators are increasingly part of the regulatory conversation. The court’s decision reinforces the NDPC’s authority to require qualifying PoS operators to register under the data protection framework.
For customers, the compliance question is simpler. Before handing over sensitive information, ask what it is for. That small question may become one of the most important privacy habits in Nigeria’s digital economy.
Compliance Takeaway
The most revealing part of Emmanuel Haruna’s case is not the legal argument.
It is the setting. A PoS operator. A terminalA customer’s transaction.
Personal information moving through an ordinary Nigerian business. That is where data protection has to work.
Not just in policy documents. Not just in corporate boardrooms. At the counter where someone hands over an ID card and assumes it will be used for the reason they were told.
Nigeria has built an economy around collecting more information about people.
The next stage is learning how to look after it.



No Comment! Be the first one.