Dr. Vincent Olatunji, DG, NDPC
…Explains Why Meta Opted for Out-of-Court Settlement
The Chief Executive Officer of Nigeria Data Protection Commission (NDPC), Dr Vincent Olatunji has opened up on the critical issues concerning the Commission and how the agency has been fighting to protect data privacy in the country.
According to him, the primary target of the agency is not revenue, but “We want organisations to respect Nigerians’ privacy rights and comply with the law. If they are willing to do that and improve their systems, that serves the best interest of Nigerians. That has been our approach from the beginning.”
Speaking in an interview recently on the Commission’s case with Meta after the international digital firm was fined, he said “The Meta matter was the only major case that eventually went to court after we imposed a penalty. When the matter got to court, and they saw our position and the evidence we presented, they approached us for discussions outside the courtroom.
“I always remind my colleagues that Nigeria’s economy is fragile. We must not do anything that will unnecessarily drive away investment. Think about the millions of Nigerians who depend on Facebook, Instagram, and WhatsApp every day. Students use these platforms, market women use them, small businesses rely on them, and entrepreneurs buy and sell products through them. If you remove such platforms from Nigeria, people will feel the impact immediately.
According to him, “The question, therefore, becomes: what exactly are we trying to achieve? Is it to collect money? Is it to embarrass companies? Is it to drive them away? No. The objective is compliance.
Continuing, Olatunji revealed that “regulators around the world now ask us how we are doing it. They want to understand the strategy we have adopted and how we engage stakeholders. We see everyone as a stakeholder in the privacy ecosystem, including regulators, businesses, financial institutions, telecommunications companies, media organisations, and ordinary citizens. The goal is for all of us to do what is right for the country.”
Giving insights on how organisations respond to their invitations during investigations relating to data breach, he said he cannot remember any organisation that NDPC invited and it failed to show up, adding that “Every organisation that has received an invitation from the commission has cooperated with us and appeared before us.
“However, our model is different from what many people assume. People often think the first thing a regulator should do is impose fines. That is not our approach.
“When a breach is reported, we do not focus only on the incident itself. We conduct a complete evaluation of the organisation. We examine whether they are registered with us, whether they have filed their audit reports, whether they have appointed a Data Protection Officer, whether they have a privacy policy, whether they maintain records of processing activities, and whether they have adequate organisational and technical safeguards.
“We look at the entire compliance structure. If we discover that an organisation has complied with most requirements but still has some gaps, we may ask it to address those gaps and monitor it for a period of time. That is why, in most cases, what we impose are remediation fees rather than punitive fines.
“Nobody is perfect. Breaches can happen. What matters is the level of preparedness, the safeguards already in place, and the willingness to comply with the law. If an organisation has complied with eight out of ten requirements, we may ask it to complete the remaining two and continue improving its systems. Our objective is compliance. That is the most important thing.
