• Who We Are
  • Our Services
    • Outsourced DPO (Data Protection Officer) Services
    • Data Protection Advisory
    • Data Protection Training & Awareness Services
    • Onion Architecture
    • Helpline Service
  • Resources
    • Do I need a DPO (Data Protection Officer)?
    • Benefits of Outsourcing your DPO
    • Why you need GDPR Representation
  • Contact Us
DPO Placement & Consultancy Limited
  • Who We Are
  • Our Services
    • Outsourced DPO (Data Protection Officer) Services
    • Data Protection Advisory
    • Data Protection Training & Awareness Services
    • Onion Architecture
    • Helpline Service
  • Resources
    • Do I need a DPO (Data Protection Officer)?
    • Benefits of Outsourcing your DPO
    • Why you need GDPR Representation
  • Contact Us
DPO Placement & Consultancy Limited
Home / Blog / Blog / Getting the Legal Basis Right: Processing Employee Data Under the NDPA

Getting the Legal Basis Right: Processing Employee Data Under the NDPA

By admin-DPO inBlog

One of the most persistent errors I encounter in advisory work with Nigerian organisations is the reflexive reliance on consent as the legal basis for processing employee data. It is intuitive. It feels procedurally safe, and HR teams are accustomed to collecting signatures. It is also, in most employment contexts, the wrong choice and getting it wrong exposes an organisation to real compliance risk under the Nigeria Data Protection Act 2023 (NDPA).

Why Consent Is the Wrong Default

Section 25 of the NDPA sets out six lawful bases for processing including consent, contractual necessity, legal obligation, vital interest, public interest, and legitimate interest. Consent sits alongside the other five as an equal option, not a superior one, yet employers routinely reach for it first.

The problem is structural. Valid consent under the NDPA must be freely given, specific, informed, and unambiguous. In an employment relationship, the inherent power imbalance between employer and employee makes “free” consent difficult to establish. An employee who is asked to consent to data processing as a condition of employment, or under implicit pressure from a superior, has not given consent that meets the legal threshold. If an employee can withdraw consent without detriment and struggles to do so in practice within an employment context, then consent was arguably never valid to begin with.

This is not a uniquely Nigerian position. It mirrors the reasoning that has shaped GDPR guidance from European data protection authorities for years, and Nigerian practitioners should expect NDPC enforcement posture to converge in the same direction as the regulator matures.

Matching the Basis to the Processing Activity

A more defensible approach is to map each category of employee data processing to the lawful basis that actually fits the purpose:

Contractual necessity covers the bulk of routine HR processing such as payroll, statutory deductions, leave administration, performance management tied to employment terms, and onboarding documentation. If the processing is required to perform the employment contract or to take steps before entering one, this is usually the correct basis, not consent.

Legal obligation applies where processing is mandated by other laws like tax remittance to NRS, pension contributions under the Pension Reform Act, National Housing Fund deductions, or NSITF compliance. Here, the employer has no discretion; the law compels the processing, so this is the appropriate basis rather than seeking employee agreement for something that isn’t optional in the first place.

Legitimate interest is often the most defensible basis for processing that falls outside strict contractual or statutory necessity. Section 25(1)(v) permits this basis, but it is not a blank cheque. It requires a documented legitimate interest assessment (LIA) balancing the employer’s interest against the employee’s rights and reasonable expectations.

Vital interest is narrow and situational, especially when processing health data in a medical emergency. This should not be stretched to cover routine health data collection.

Consent retains a proper, narrower role where, for instance, there are optional employee wellness programmes, internal social activities, use of an employee’s image in marketing materials, or participation in initiatives genuinely outside the scope of the employment relationship. Where the processing is truly optional and refusal carries no employment consequence, consent becomes appropriate again.

Special Category Data Requires Extra Care

Where employee processing touches health data, biometric data, or other special category data under Section 30 of the NDPA, the analysis does not stop at identifying a Section 25 basis. A separate condition for processing special category data is required and employers frequently overlook this second layer, assuming that having sorted out the primary lawful basis is sufficient.

Practical Guidance for Employers

I typically advise organisations to build a data processing activity register that maps each category of employee data, including recruitment records, payroll, performance data, biometric attendance data, exit records against its specific lawful basis, retention period, and any special category condition, rather than applying a single blanket basis across the entire employment lifecycle. This activity-by-activity mapping does three things: it withstands regulatory scrutiny, it clarifies retention obligations (since retention periods often differ by basis and purpose), and it prevents the common trap of asking employees to “consent” to things the organisation is already legally entitled, or obligated, to do.

Getting the legal basis right is not a formality. It is the foundation on which every other compliance obligation is built. Organisations that get this wrong at the outset tend to discover the cost later, usually during an NDPC inquiry or an employee data subject access request that exposes the gap.

0
Like this post
909 Posts
admin-DPO
  • AI Music Generating Platform Suno Data Breach Affects over 55 Million People
    Previous PostAI Music Generating Platform Suno Data Breach Affects over 55 Million People
  • Next PostNDPC probes alleged data protection violations in three institutions
    AI Music Generating Platform Suno Data Breach Affects over 55 Million People

Related Posts

One Group, Many Entities: How to Manage Data Privacy as a DPO Across a Multi-Subsidiary African Organisation
Blog News

One Group, Many Entities: How to Manage Data Privacy as a DPO Across a Multi-Subsidiary African Organisation

Cross-Border Data Transfers Under the NDPA: What Nigerian DPOs Must Fix Now
Blog

Cross-Border Data Transfers Under the NDPA: What Nigerian DPOs Must Fix Now

Embedding Privacy by Design into Product Development
Blog

Embedding Privacy by Design into Product Development

Human Risk in Data Privacy Programs
Blog

Human Risk in Data Privacy Programs

Leave a Reply (Cancel reply)

Your email address will not be published. Required fields are marked *

*
*

Logo-03

28, Oka Akoko Street, Off Lagos Street Garki 2, Abuja.

+234 809 989 5658

contact@dpoplacement.com

Services

  • Outsourced DPO Services
  • Data Protection Advisory
  • Data Protection Training & Awareness Services
  • Helpline Service
  • Privacy Notice
  • Cookie Notice
  • Best Forex White Label Solutions

Subscribe to newsletter

© 2022 DPO Placement. Designed by ArtEkindle World

in
F.A.Q
Support Forum
Video Tutorials

Search panel can contain any widgets and shortcodes.

Call us: 0 800 255 22 55
Copy