Ethica Capital LTD · Version 1.0 · Developed by the Information Technology Department, 1 February 2026 · Approved by the Board of Directors
Document Information
This Policy outlines how Ethica Capital Ltd (“the Company” or “Ethica Capital”) collects, processes, stores, uses, shares, retains, and protects personal data in accordance with the Nigeria Data Protection Act (NDPA) 2023, applicable regulations and guidelines issued by the Nigeria Data Protection Commission (NDPC), the NDPC General Application and Implementation Directive (GAID) 2025, the Investments and Securities Act 2025, relevant Securities and Exchange Commission (SEC) Rules and Regulations, the Nigerian Code of Corporate Governance (NCCG) 2018, and recognized international data protection standards.
- Purpose and Scope
- Legal and Regulatory Framework
- Definitions
- Data Protection Principles
- Shariah Compliance Framework
- Categories of Personal Data Collected
- Lawful Basis for Processing
- Data Subject Rights
- Registration and Compliance Obligations
- Governance and Accountability
- Training and Awareness
- Policy Review and Updates
- Contact Information
- Annexes
1. Purpose and Scope
1.1 Purpose
This Data Privacy and Protection Policy (“the Policy”) establishes the comprehensive framework through which Ethica Capital Ltd (“the Company” or “Ethica Capital”), as a Shariah-compliant fund and portfolio management company, collects, processes, stores, uses, shares, and protects personal data in accordance with the Nigeria Data Protection Act (NDPA) 2023, the NDPC General Application and Implementation Directive (GAID) 2025, the Investments and Securities Act 2025, relevant Securities and Exchange Commission (SEC) Rules and Regulations, the Nigerian Code of Corporate Governance (NCCG) 2018, and recognized international data protection standards.
The objective of this Policy is to ensure lawful, fair, transparent, secure, and Shariah-compliant handling of personal data belonging to clients, investors, employees, fund participants, and all other stakeholders, while upholding the principles of amanah (trust), transparency, and accountability inherent in Islamic finance.
1.2 Scope of Application
This Policy applies comprehensively to all personal data processed by Ethica Capital Ltd, irrespective of the form, medium, or location in which such data is held, including electronic systems, physical records, cloud-based infrastructure, and any other storage or processing environment used by or on behalf of the Company.
The Policy applies to all categories of data subjects whose personal data the Company processes, including:
- Clients and investors (retail and institutional)
- Fund participants and beneficiaries
- Prospective clients and investors
- Employees, officers, directors, and contractors
- Members of the Shariah Supervisory Board
- Vendors, service providers, and business partners
- Visitors to the Company’s premises or digital platforms, and
- Any other individuals whose personal data is collected or processed in the course of the Company’s operations.
This Policy further applies to all persons and entities involved in the processing of personal data on behalf of or under the authority of the Company, including:
- Full-time, part-time, and contract employees
- Directors, officers, and senior management
- Third-party service providers, data processors and sub-processors
- Agents, delegates, and representatives
- Custodians, Trustees, Registrars, and Fund administrators
- As well as technology vendors, cloud service providers, and software platforms engaged by the Company.
The Policy covers all data processing activities carried out by or on behalf of the Company, including:
- The collection, recording, organisation, storage, use, analysis, and profiling of personal data
- The disclosure, sharing, and transfer of personal data within Nigeria and across borders
- The retention, archiving, anonymisation, and deletion of personal data; and
- The implementation of security, backup, business continuity, and data recovery measures.
1.3 Regulatory Status
Ethica Capital Ltd is registered as a Data Controller and Data Processor of Major Importance with the Nigeria Data Protection Commission (NDPC) in accordance with Section 44 of the NDPA 2023 and the Guidance Notice on Registration of Data Controllers and Processors of Major Importance (Updated December 2024).
As a fund and portfolio management company licensed and regulated by the Securities and Exchange Commission Nigeria (SEC), the Company processes personal data of significant value to Nigeria’s economy and financial system, and therefore qualifies as a Data Controller of Major Importance under the criteria established by the NDPC.
2. Legal and Regulatory Framework
This Policy is developed, implemented, and maintained in full compliance with the following laws, regulations, directives, and governance frameworks:
Primary Legislation and Regulations
- Nigeria Data Protection Act 2023 (NDPA): The principal statutory framework governing the protection of personal data and privacy rights in Nigeria, establishing the Nigeria Data Protection Commission and comprehensive data subject rights.
- NDPC General Application and Implementation Directive (GAID) 2025: Issued on 20 March 2025 and effective from 19 September 2025, the GAID provides detailed operational guidance for implementing the NDPA, including registration requirements, compliance audit returns, data protection impact assessments, and breach notification procedures.
- Investments and Securities Act 2025 (ISA 2025): The comprehensive statutory framework for regulating capital markets in Nigeria, which replaced the ISA 2007 and establishes enhanced disclosure, investor protection, and operational requirements for fund and portfolio managers.
- Companies and Allied Matters Act 2020 (CAMA): Nigeria’s principal corporate law framework, establishing fiduciary duties, corporate governance standards, and record-keeping obligations.
- Nigerian Code of Corporate Governance 2018 (NCCG): The governance code issued by the Financial Reporting Council of Nigeria, establishing board responsibilities for data protection and stakeholder rights.
- Constitution of the Federal Republic of Nigeria 1999 (as amended): Section 37 guarantees the right to privacy for all citizens, including privacy of communications and personal correspondence.
Sector-Specific Regulations and Guidelines
- SEC Rules and Regulations for Fund/Portfolio Managers (as updated through 2025): Establishing operational standards, disclosure requirements, custody arrangements, KYC obligations, and investor reporting requirements for collective investment schemes.
- SEC Code of Conduct for Capital Market Operators: Establishing professional and ethical standards for market participants, including confidentiality obligations and investor protection requirements.
- Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) Regulations: Requiring collection, verification, and retention of customer identification and transaction data for compliance purposes.
- Central Bank of Nigeria (CBN) Cybersecurity Framework: Applicable to financial institutions processing electronic payments and financial data.
- Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (as amended 2024): Establishing criminal offences relating to unauthorized access, data breaches, and cybersecurity incidents, including mandatory 72-hour incident reporting requirements.
- Freedom of Information Act 2011: Establishing rights of access to information held by public institutions and certain private entities.
International Standards and Best Practices
While the NDPA 2023 establishes Nigeria’s sovereign data protection framework, the Company draws upon internationally recognized best practices where such practices enhance data protection and do not conflict with Nigerian law, including:
- ISO/IEC 27001 Information Security Management Systems
- ISO/IEC 27701 Privacy Information Management Systems
- NIST Cybersecurity Framework
- AAOIFI Shariah Standards for Islamic Financial Institutions (particularly regarding confidentiality and data protection)
- Principles of the EU General Data Protection Regulation (GDPR) where aligned with Nigerian requirements
Application and Interpretation
In the event of any conflict or inconsistency between the provisions of different laws or regulations, the following hierarchy shall apply:
- Constitutional provisions (Section 37 of the 1999 Constitution)
- Nigeria Data Protection Act 2023 and GAID 2025
- Investments and Securities Act 2025 and SEC Rules
- Other applicable Nigerian legislation
- International standards and best practices (for guidance only)
Where regulatory requirements impose higher or more specific obligations than this Policy, such requirements shall prevail and be deemed incorporated into this Policy.
3. Definitions
For the purposes of this Policy, the following terms shall have the meanings assigned below. Where a term is defined in the NDPA 2023 or GAID 2025, such statutory definition shall apply unless otherwise specified herein.
“Anonymization” means the irreversible process of transforming personal data in such a manner that the data subject can no longer be identified directly or indirectly, rendering the data no longer “personal data” within the meaning of the NDPA.
“Amanah” means the Islamic principle of trust and trustworthiness, requiring honesty, diligence, and faithfulness in handling entrusted responsibilities, including the protection of personal information.
“Automated Processing” means processing of personal data by automated means, without human intervention, including profiling, algorithmic decision-making, and artificial intelligence applications.
“Biometric Data” means personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of an individual, including facial recognition, fingerprints, voice patterns, and retinal scans.
“Compliance Audit Return (CAR)” means the annual compliance report required to be filed with the NDPC by Data Controllers and Processors of Major Importance, documenting compliance with the NDPA and this Policy.
“Consent” means any freely given, specific, informed, and unambiguous indication of a data subject’s agreement to the processing of their personal data, expressed through a clear affirmative action.
“Cross-Border Data Transfer” means the transfer, transmission, or disclosure of personal data from Nigeria to a recipient located outside the Federal Republic of Nigeria, whether to another country, territory, or international organization.
“Data Breach” or “Personal Data Breach” means a breach of security leading to or likely to lead to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
“Data Controller” means an individual, private entity, public authority, agency, or any other body which, alone or jointly with others, determines the purposes and means of processing personal data. Ethica Capital acts as a Data Controller for most of its data processing activities.
“Data Controller of Major Importance (DCPMI)” means a data controller that processes personal data of more than 200 data subjects within six months, carries out commercial ICT services on devices belonging to others, operates in sectors of major economic importance, or handles confidential data in a fiduciary capacity.
“Data Minimization” means the principle requiring that personal data collected and processed be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
“Data Portability” means the right of a data subject to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another data controller.
“Data Processor” means an individual, private entity, public authority, or any other body which processes personal data on behalf of or at the direction of a data controller. Third-party service providers engaged by Ethica Capital typically act as Data Processors.
“Data Protection Compliance Organisation (DPCO)” means a licensed entity authorized by the NDPC to provide data protection compliance services, including conducting compliance audits and filing Compliance Audit Returns.
“Data Protection Impact Assessment (DPIA)” means a systematic assessment of the potential impact of proposed data processing operations on the privacy and rights of data subjects, required for high-risk processing activities under Article 11 of the GAID.
“Data Protection Officer (DPO)” means the individual appointed by the Company to oversee data protection strategy, implementation, and compliance with the NDPA, GAID, and this Policy.
“Data Subject” means an identified or identifiable natural person whose personal data is processed by or on behalf of the Company.
“Filing System” means any structured set of personal data, whether centralized, decentralized, or dispersed, which is accessible according to specific criteria, whether manual, electronic, or automated.
“Genetic Data” means personal data relating to the inherited or acquired genetic characteristics of an individual which give unique information about their physiology or health.
“Legitimate Interest” means a lawful basis for processing personal data where such processing is necessary for the purposes of legitimate interests pursued by the Company, provided that such interests are not overridden by the rights, freedoms, and privacy of the data subject.
“Personal Data” means any information relating to an identified or identifiable individual (data subject), including name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that individual.
“Privacy by Design” means the principle requiring that data protection measures be integrated into the design and architecture of systems, processes, and technologies from the outset, rather than added as an afterthought.
“Privacy by Default” means the principle requiring that only personal data necessary for each specific purpose of processing is processed by default, with respect to the amount of data collected, extent of processing, period of storage, and accessibility.
“Profiling” means any form of automated processing of personal data to evaluate, analyze, or predict aspects concerning an individual’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
“Pseudonymization” means the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, which is kept separately and subject to technical and organizational measures.
“Sensitive Personal Data” means personal data revealing or relating to religious or philosophical beliefs, racial or ethnic origin, political opinions, trade union membership, health status, sex life, biometric data, genetic data, criminal convictions, or any data which may subject the data subject to discrimination, harm, or disadvantage if disclosed.
“Shariah Compliance” means adherence to Islamic law principles and rulings issued by the Company’s Shariah Supervisory Board, including requirements regarding confidentiality, trustworthiness, and protection of client information.
“Third Party” means any individual, entity, or organization other than the data subject, the Company, or persons authorized to process personal data under the direct authority of the Company.
4. Data Protection Principles
In carrying out its principal objectives and business operations as a Shariah-compliant fund and portfolio management company, Ethica Capital is committed to protecting the privacy and personal data of all individuals whose information it processes, in full compliance with the NDPA 2023, GAID 2025, and all applicable data protection laws and regulations.
Accordingly, the Company adheres to the following fundamental principles when collecting, storing, using, sharing, or otherwise processing personal data:
4.1 Lawfulness, Fairness, and Transparency
The Company ensures that all processing of personal data is carried out lawfully, fairly, and in a transparent manner in relation to the data subject.
Personal data is processed only on the basis of a valid and appropriate legal ground recognized under Section 25 of the NDPA 2023, including:
- Consent of the data subject (explicit, informed, and freely given)
- Performance of a contract to which the data subject is party
- Compliance with a legal or regulatory obligation
- Protection of the vital interests of the data subject or another person
- Performance of a task carried out in the public interest
- Legitimate interests pursued by the Company (provided not overridden by data subject rights)
Data subjects are provided with clear, accessible, and comprehensive information about how their personal data is collected, used, shared, stored, and protected, through privacy notices, terms and conditions, and direct communications.
4.2 Purpose Limitation
Personal data is collected only for specific, explicit, and legitimate purposes related to the Company’s business operations, regulatory obligations, and Shariah-compliant investment activities.
Such data shall not be processed further in a manner incompatible with those original purposes unless:
- The Company obtains fresh consent from the data subject for the new purpose
- Further processing is required or authorized by law or regulation
- Further processing is necessary for archiving purposes in the public interest, scientific or historical research, or statistical purposes, subject to appropriate safeguards
The Company maintains a comprehensive Data Processing Register documenting the specific purposes for which each category of personal data is collected and processed.
4.3 Data Minimization
The Company limits the collection and processing of personal data to what is adequate, relevant, and necessary in relation to the purposes for which it is collected.
Unnecessary, excessive, or irrelevant data is not requested, collected, or retained. Data collection forms, onboarding processes, and system configurations are designed to request only the minimum data required to fulfill specified purposes and comply with legal and regulatory obligations.
Regular data audits are conducted to identify and delete or anonymize data that is no longer necessary for the purposes for which it was collected.
4.4 Accuracy
The Company takes all reasonable steps to ensure that personal data is accurate, complete, and kept up to date, particularly where inaccurate data could adversely affect the data subject or lead to non-compliance with legal or regulatory obligations.
Data subjects may request corrections or updates to their information at any time through designated channels (see Section 13: Contact Information), and the Company will act promptly to rectify inaccuracies or complete incomplete data.
For KYC/AML purposes, the Company conducts periodic reviews and updates of client information in accordance with SEC regulations and risk-based customer due diligence requirements.
4.5 Storage Limitation
Personal data is retained for legal, regulatory, audit, or contractual obligations. Once personal data is no longer required for the specified purposes and retention periods have expired, it is securely deleted, destroyed, anonymized, or pseudonymized in accordance with the Company’s Data Retention and Disposal Schedule (Annex 1) and industry best practices.
Retention periods are determined based on:
- Nature and sensitivity of the personal data.
- Purpose of processing and ongoing business need
- Legal, regulatory, and contractual retention requirements (e.g., SEC requirement to retain fund records for 7 years)
- Risk of harm to data subjects from continued storage
- Ease or difficulty of anonymization
Personal data may be retained for longer periods solely for archiving purposes in public interest, scientific or historical research, or statistical purposes, provided appropriate technical and organizational safeguards are implemented.
4.6 Integrity and Confidentiality (Security)
The Company implements appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure.
Security measures are designed to ensure a level of protection appropriate to the risks presented by processing activities and the nature of the personal data to be protected, taking into account:
- State of the art security technologies and industry best practices
- Costs of implementation and operational feasibility
- Nature, scope, context, and purposes of processing
- Risk of varying likelihood and severity for the rights and freedoms of data subjects
Security controls include (but are not limited to):
- Encryption of data in transit and at rest
- Multi-factor authentication and strong password policies
- Role-based access controls and principle of least privilege
- Network security measures (firewalls, intrusion detection/prevention systems)
- Regular security assessments, vulnerability scans, and penetration testing
- Secure backup and disaster recovery procedures
- Staff confidentiality and non-disclosure obligations
- Physical security measures for premises and data centers
- Vendor security assessments and contractual obligations
All employees, contractors, and third parties with access to personal data are bound by strict confidentiality obligations and employees shall receive regular data protection and cybersecurity training.
4.7 Accountability
The Company is accountable for complying with all data protection principles and demonstrating such compliance through documented policies, procedures, records, and reports.
Accountability measures include:
- Appointment of a qualified Data Protection Officer (DPO) with appropriate authority and resources
- Maintenance of comprehensive records of all data processing activities (Records of Processing Activities — ROPA)
- Implementation of Privacy by Design and Privacy by Default principles in all systems and processes
- Conduct of Data Protection Impact Assessments (DPIAs) for high-risk processing activities
- Regular internal data protection audits and compliance reviews
- Filing of annual Compliance Audit Returns (CAR) with the NDPC
- Training and awareness programs for all staff
- Establishment of clear lines of responsibility and escalation for data protection matters
- Cooperation with the NDPC and other regulatory authorities on data protection matters
The Board of Directors bears ultimate responsibility for ensuring the Company’s compliance with data protection laws and for demonstrating such compliance to stakeholders and regulators.
5. Shariah Compliance Framework
As a Shariah-compliant fund and portfolio management company, Ethica Capital recognizes that data protection is not solely a legal and regulatory obligation, but also a fundamental ethical and religious duty rooted in Islamic principles of amanah (trust), confidentiality, and respect for individual dignity.
This Policy is grounded in the following Shariah principles and governance standards:
5.1 Amanah (Trustworthiness and Fiduciary Duty)
The Qur’anic principle of amanah requires that all trusts and responsibilities be discharged with honesty, diligence, and faithfulness. Personal data entrusted to the Company by clients, investors, and employees constitutes an amanah that must be protected with the utmost care and confidentiality.
The Company views personal data as a sacred trust (amanah) and shall ensure that all data processing activities are conducted with integrity, transparency, and in the best interests of data subjects.
5.2 Sitr (Confidentiality and Privacy)
Islamic law strongly emphasizes the protection of privacy and confidentiality. Unauthorized disclosure of personal information, particularly sensitive or confidential matters, is prohibited under Shariah principles.
The Company shall maintain strict confidentiality of all personal data and shall not disclose such information except:
- With explicit consent of the data subject
- As required by law, regulation, or valid court order
- To the extent necessary for Shariah compliance review by the Shariah Supervisory Board
- As specifically authorized under this Policy and applicable law
5.3 Transparency and Accountability (Amanah and Sidq)
Transparency (sidq — truthfulness) is a core Islamic value. The Company shall be transparent with data subjects regarding how their personal data is collected, used, and shared, and shall be accountable to Allah, regulators, and stakeholders for proper handling of personal information.
All privacy notices, consent forms, and data processing disclosures shall be clear, honest, and not misleading.
5.4 Protection Against Harm (La Darar wa la Dirar)
The Islamic legal maxim “la darar wa la dirar” (there shall be no harm or reciprocal harm) requires that the Company take all reasonable measures to prevent harm to data subjects through data breaches, unauthorized access, identity theft, fraud, or misuse of personal information.
The Company shall implement robust security measures and breach response procedures to prevent and mitigate potential harm to data subjects.
5.5 Shariah Supervisory Board Review
The Company’s Shariah Supervisory Board shall have oversight authority over data processing activities to ensure compliance with Islamic ethical principles, particularly regarding:
- Confidentiality of client investment details and Shariah compliance status
- Protection of sensitive religious information (e.g., zakat contributions, purification calculations)
- Ethical use of client data in marketing and product development
- Cross-border transfers to jurisdictions with different privacy standards
Any data processing activity that may raise Shariah concerns shall be referred to the Shariah Supervisory Board for review and guidance.
6. Categories of Personal Data Collected
In the ordinary course of its business as a Shariah-compliant fund and portfolio management company, Ethica Capital may collect and process the following categories of personal data from various data subjects:
6.1 Client and Investor Data
- Identity Information: Full legal name, date of birth, place of birth, nationality, gender, photographs, signature specimens
- Contact Information: Residential and business addresses, telephone numbers, email addresses, preferred communication methods
- Identification Documents: National Identification Number (NIN), Bank Verification Number (BVN), International Passport, Driver’s License, Voter’s Card
- Financial Information: Bank account details, payment card information, source of funds/wealth, income level, net worth, tax identification number (TIN), pension fund administrator (PFA) details
- Investment Profile: Investment objectives, risk tolerance, investment experience, time horizon, liquidity needs
- Transaction Data: Account opening documentation, investment subscriptions and redemptions, transaction history, portfolio holdings, asset allocations
- KYC/AML Data: Proof of address, politically exposed person (PEP) status, source of wealth declarations, beneficial ownership information, related party relationships
- Shariah Preferences: Specific Shariah requirements or preferences, prohibited sectors or activities, zakat calculation requests, purification preferences
- Communication Records: Email correspondence, phone call recordings (where legally permitted and disclosed), meeting notes, customer service interactions
6.2 Employee and Staff Data
- Personal and Biographical Data: Full name, date of birth, place of birth, nationality, gender, marital status, dependents, next of kin
- Contact Information: Home address, personal phone number, personal email address, emergency contact details
- Employment Information: Job title, department, employment dates, employment status, work location, reporting line, performance evaluations
- Compensation and Benefits: Salary, bonuses, commission, pension contributions, tax withholdings, payroll deductions, benefits enrollment
- Financial and Tax Data: Bank account details for salary payments, tax identification number (TIN), pension RSA PIN
- Identification Documents: NIN, BVN, International Passport, professional certifications
- Health and Medical Data (where applicable): Occupational health assessments, medical fitness certificates, insurance claims, COVID-19 vaccination status (if required by law or workplace safety policies)
- Background Checks: Educational qualifications verification, employment history verification, criminal record checks (where permitted by law), professional licensing status
- IT and Security Data: Computer login credentials, access logs, email and internet usage records (in accordance with Company IT policies), biometric access records
6.3 Vendor, Supplier, and Business Partner Data
- Entity Information: Company name, registration number, registered address, nature of business, ownership structure
- Contact Persons: Names, titles, email addresses, phone numbers of key contacts and authorized representatives
- Banking and Payment Information: Bank account details, payment terms, tax identification numbers
- Contractual and Compliance Data: Service agreements, licenses, certifications, insurance policies, AML/KYC documentation
- Performance and Evaluation Records: Service quality assessments, compliance with contractual obligations, dispute resolution records.
6.4 Shariah Supervisory Board Members
- Personal Data: Full name, contact details, biographical information, scholarly credentials
- Professional Information: Academic qualifications, Shariah certifications, professional affiliations, previous Shariah board experience
- Compensation Data: Fee arrangements, payment schedules, tax documentation
- Meeting and Deliberation Records: Attendance records, Shariah rulings and opinions, meeting minutes (subject to confidentiality)
6.5 Website Visitors and Digital Platform Users
- Technical Data: IP addresses, browser type and version, device type, operating system, time zone settings, browser plug-ins, screen resolution
- Usage Data: Pages visited, time spent on pages, navigation paths, clickstream data, search queries, downloads
- Marketing Data: Cookie preferences, marketing consent status, campaign response data
- Location Data: Geolocation data derived from IP address (approximate location only).
6.6 Sensitive Personal Data
The Company may process the following categories of Sensitive Personal Data only where legally permissible and with appropriate safeguards:
- Religious Information: Shariah compliance preferences, Islamic investment restrictions, zakat contribution requests, religious accommodations
- Health Data: Medical certificates (for employment purposes), occupational health records, pandemic-related health declarations (if required by law)
- Biometric Data: Fingerprints or facial recognition for secure facility access (if implemented)
- Criminal Convictions: Background check results for employees in sensitive positions (where permitted by law and necessary for compliance)
Sensitive Personal Data is processed only:
- With explicit consent of the data subject (where consent is the legal basis)
- Where necessary for compliance with legal obligations (e.g., AML/CFT screening)
- Where necessary for employment, health, or social security purposes
- In accordance with specific provisions of the NDPA 2023 permitting such processing.
Additional security measures and access restrictions apply to all Sensitive Personal Data.
7. Lawful Basis for Processing
The Company processes personal data only where it has established a valid lawful basis under Section 25 of the NDPA 2023. Personal data shall not be collected, used, disclosed, transferred, or retained unless such processing is justified under one or more of the following legal grounds:
7.1 Consent
Processing is based on the freely given, specific, informed, and unambiguous consent of the data subject, obtained through a clear affirmative action.
Applicable to: Marketing communications, optional data collection, non-essential cookies, research and surveys, photographs and testimonials.
Requirements for Valid Consent
- Must be freely given (no coercion, penalty, or detriment for refusing)
- Must be specific to identified purposes
- Must be informed (data subject understands what they are consenting to)
- Must be unambiguous (clear affirmative action required, silence or pre-ticked boxes not sufficient)
- Data subjects may withdraw consent at any time (withdrawal does not affect lawfulness of prior processing)
- Consent requests must be clear, concise, and separate from other terms and conditions.
- Burden of proof of valid consent rests with the Company.
The Company maintains records of all consents obtained, including who consented, when, to what, and how.
7.2 Performance of Contract
Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract.
Applicable to:
- Client onboarding and account opening processes
- Investment mandate execution and portfolio management services
- Fund subscriptions, redemptions, and transfers
- Communication regarding investment performance and account status
- Provision of investment statements and tax documentation
- Processing of payments and distribution
This legal basis applies only to data that is objectively necessary for contractual relationships. Data collection that goes beyond contractual necessity requires an additional legal basis (typically consent or legitimate interests).
7.3 Legal and Regulatory Obligations
Processing is necessary for compliance with legal or regulatory obligations imposed on the Company by Nigerian or international law.
Applicable to:
- Know Your Customer (KYC) and Customer Due Diligence (CDD) requirements under AML/CFT regulations
- Suspicious Transaction Reporting (STR) to the Nigerian Financial Intelligence Unit (NFIU)
- Tax reporting and withholding obligations (NRS, foreign tax authorities)
- Regulatory reporting and filings to SEC Nigeria
- Record retention requirements for fund managers (7 years under SEC regulations)
- Compliance with court orders, subpoenas, and valid regulatory requests
- Data breach notifications to NDPC and affected data subjects
- Filing of annual Compliance Audit Returns (CAR) with NDPC
- Anti-corruption and sanctions screening.
Processing based on legal obligation does not require consent of the data subject. However, the Company shall inform data subjects of such processing through privacy notices and terms of service.
7.4 Vital Interests
Processing is necessary to protect the vital interests of the data subject or another person, particularly in situations involving threats to life, health, or physical safety.
Applicable to:
- Emergency medical situations requiring disclosure of employee health information
- Life-threatening situations requiring contact with emergency services or next of kin
- Public health emergencies or pandemic response measures (if legally required)
- Prevention of serious harm or criminal activity
This legal basis is applied only in exceptional circumstances where no other legal basis is available and urgent action is required.
7.5 Public Interest and Official Authority
Processing is necessary for the performance of tasks carried out in the public interest or in the exercise of official authority vested in the Company.
While Ethica Capital is a private entity, certain processing activities may fall within this category, including:
- Cooperation with law enforcement and regulatory investigations
- Assistance with national security or public safety matters
- Participation in government-mandated economic programs or initiatives.
Processing under this basis requires that the task be clearly established in Nigerian law or that the Company be explicitly vested with public authority for the specific purpose.
7.6 Legitimate Interests
Processing is necessary for the purposes of legitimate interests pursued by the Company or a third party, except where such interests are overridden by the rights, freedoms, and privacy of the data subject.
Applicable to:
- Fraud prevention and detection
- Network and information security (cybersecurity measures)
- Internal administration and corporate governance
- Business continuity and disaster recovery
- Vendor management and due diligence
- Mergers, acquisitions, and corporate restructuring
- Legal claims and dispute resolution
- Direct marketing to existing customers (with opt-out rights)
- Analytics and service improvement
Legitimate Interest Assessment (LIA)
Before relying on legitimate interests as a legal basis, the Company conducts a Legitimate Interest Assessment to balance:
- Purpose: Is there a genuine, specific, and lawful purpose?
- Necessity: Is the processing necessary for that purpose, or are there less intrusive alternatives?
- Balancing: Do the Company’s legitimate interests override the data subject’s rights and freedoms?
Data subjects have the right to object to processing based on legitimate interests. The Company shall cease processing upon such objection unless it can demonstrate compelling legitimate grounds that override the data subject’s interests, rights, and freedoms.
7.7 Special Categories of Personal Data (Sensitive Data)
For Sensitive Personal Data (religious beliefs, health information, biometric data, criminal convictions), processing is permitted only where:
- Explicit consent has been obtained (where consent is a valid basis)
- Processing is necessary for employment, social security, or social protection law purposes
- Processing is necessary to protect the vital interests of the data subject or another person
- Processing relates to personal data manifestly made public by the data subject
- Processing is necessary for legal claims or judicial proceedings
- Processing is necessary for substantial public interest reasons
- Processing is necessary for health or social care purposes
- Processing is necessary for public health purposes in public interest.
The Company processes Sensitive Personal Data only in strict accordance with applicable law and with enhanced security and confidentiality measures.
8. Data Subject Rights
In accordance with Sections 27–35 of the NDPA 2023 and Article 6 of the GAID 2025, every individual whose personal data is processed by the Company (referred to as a data subject) is entitled to exercise specific rights in relation to their personal information.
Ethica Capital recognizes and upholds these rights, ensuring that all data subjects can exercise them freely, fairly, and without discrimination. The Company shall respond to all data subject requests within the statutory timeframes specified in the NDPA and GAID.
8.1 Right of Access (Subject Access Request)
Data subjects have the right to obtain confirmation as to whether the Company processes their personal data and, if so, to request access to such data and information about the processing.
What Data Subjects Can Request
- Confirmation of whether their personal data is being processed
- Copy of their personal data undergoing processing
- Information on the purposes of processing
- Categories of personal data processed
- Recipients or categories of recipients to whom data has been or will be disclosed
- Retention period or criteria for determining retention period
- Source of the data (if not collected directly from the data subject)
- Existence of automated decision-making, including profiling, and meaningful information about the logic involved
How to Exercise the Rights
Data subjects may submit a Subject Access Request (SAR) using the Data Subject Request Form (Annex 2) via:
- Email: dpo@ethicacapitalltd.com or compliance@ethicacapitalltd.com
- Post: Data Protection Officer, Ethica Capital Ltd, Suite 413 NAWA Complex, Plot 106/107 Ahmadu Bello Way, Kado, FCT-Abuja.
- In person at Company offices
Response Timeline
The Company shall respond to SARs within 30 days of receipt, unless the request is complex or voluminous, in which case the period may be extended by a further 30 days with notification to the data subject.
Fees
Access requests are provided free of charge. The Company shall verify the identity of the requestor before disclosing personal data and may request additional information to locate the requested data.
8.2 Right to Rectification
Data subjects have the right to request that inaccurate, incomplete, or outdated personal data held by the Company be corrected, completed, or updated without undue delay.
The Company shall verify the accuracy of any corrected information and may request supporting documentation (e.g., updated ID card, proof of address) before making amendments.
Timeline: Rectification requests shall be processed within 30 days.
Notification: Where personal data has been disclosed to third parties, the Company shall notify such recipients of the rectification unless this proves impossible or involves disproportionate effort.
8.3 Right to Withdraw Consent
Where processing is based on consent, data subjects may withdraw that consent at any time, as easily as it was given.
Withdrawal of consent does not affect:
- The lawfulness of processing carried out before the consent was withdrawn
- Processing based on lawful grounds other than consent
How to Withdraw Consent
- For marketing communications: Click “unsubscribe” link in emails or contact info@ethicacapitalltd.com
- For other consent-based processing: Submit request via Data Subject Request Form (Annex 2).
The Company shall process consent withdrawals within 5 business days and cease all processing based solely on the withdrawn consent.
8.4 Right to Erasure (“Right to be Forgotten”)
Data subjects may request the deletion or removal of their personal data where:
- The data is no longer necessary for the purposes for which it was collected
- The data subject withdraws consent (where consent was the legal basis) and there is no other lawful ground for processing
- The data subject objects to processing based on legitimate interests and there are no overriding legitimate grounds for continued processing
- The personal data has been unlawfully processed
- Erasure is required to comply with a legal obligation
Limitations on Right to Erasure
The Company may refuse erasure requests where retention is necessary for:
- Compliance with legal or regulatory obligations (e.g., SEC 7-year retention requirement for fund records)
- Establishment, exercise, or defense of legal claims
- Archiving purposes in public interest, scientific or historical research, or statistical purposes
- Performance of ongoing contractual obligations
Where erasure is not possible due to legal retention requirements, the Company shall restrict processing of the data and retain it only for the minimum period required by law.
Timeline: Erasure requests shall be processed within 30 days, with notification to the data subject explaining the action taken or reasons for refusal.
8.5 Right to Restriction of Processing
Data subjects have the right to request restriction (temporary suspension) of processing of their personal data where:
- The accuracy of the personal data is contested (restriction applies while verification is ongoing)
- The processing is unlawful, but the data subject prefers restriction to erasure
- The Company no longer needs the data for original purposes but the data subject requires it for legal claims
- The data subject has objected to processing pending verification of whether legitimate grounds override the objection.
When processing is restricted, the Company shall:
- Store the personal data securely but not further process it (except with consent or for legal claims)
- Mark restricted data clearly in systems to prevent inadvertent processing
- Notify the data subject before lifting the restriction
- Inform third-party recipients of the restriction (unless impossible or involving disproportionate effort)
Timeline: Restriction requests shall be processed within 30 days.
8.6 Right to Object
Data subjects have the right to object, on grounds relating to their particular situation, to processing of their personal data based on:
- Legitimate interests of the Company
- Performance of tasks in the public interest or exercise of official authority
Upon receiving an objection, the Company shall cease processing unless it can demonstrate compelling legitimate grounds for continued processing that override the interests, rights, and freedoms of the data subject, or processing is necessary for establishment, exercise, or defense of legal claims.
Direct Marketing
Data subjects have an absolute right to object to processing for direct marketing purposes (including profiling for marketing). The Company shall cease all marketing processing immediately upon receipt of such objection, without requirement to demonstrate legitimate grounds.
How to Object
- For marketing: Click “unsubscribe” link or email info@ethicacapitalltd.com
- For other processing: Submit Data Subject Request Form (Annex 2) stating grounds for objection.
Timeline: Marketing objections are processed immediately (within 24 hours). Other objections are processed within 30 days.
8.7 Right to Data Portability
Data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another data controller where:
- Processing is based on consent or contract (not applicable to processing based on legal obligation or legitimate interests)
- Processing is carried out by automated means
The Company shall provide portable data in industry-standard formats such as CSV, JSON, or PDF, depending on the nature of the data.
Scope of Portable Data
- Personal data provided by the data subject to the Company (not inferred or derived data)
- Investment transaction history, portfolio holdings, communication records
- Does not include proprietary analytics, risk assessments, or Company-generated insights
Where technically feasible, the Company may transmit the data directly to another data controller at the data subject’s request.
Timeline: Portability requests shall be processed within 30 days.
Fee: Data portability requests are provided free of charge for the first request within a 12-month period.
8.8 Rights Related to Automated Decision-Making and Profiling
Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect them, unless:
- The decision is necessary for entering into or performance of a contract
- The decision is authorized by law with suitable safeguards for data subject rights
- The data subject has given explicit consent
Where automated decision-making is used, the Company shall:
- Inform data subjects of the logic involved and significance and envisaged consequences
- Implement suitable measures to safeguard data subject rights (human intervention, right to contest)
- Provide meaningful information about the criteria and factors used in automated decisions.
Current Use of Automated Processing
As at the effective date of this Policy, the Company uses automated processing for:
- Risk profiling and investment suitability assessments (subject to human review)
- AML/CFT screening and sanctions checks (subject to human review and escalation)
- Portfolio rebalancing recommendations (final decisions require human approval)
Data subjects have the right to obtain human intervention, express their point of view, and contest any automated decision.
8.9 Right to Lodge Complaints
If a data subject believes that the Company has violated their data protection rights or has processed their personal data unlawfully, they have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or any other competent authority.
NDPC Contact Information
Nigeria Data Protection CommissionPlot 1172 Cadastral Zone B05, Mabushi District, Abuja
Email: info@ndpc.gov.ng
Website: www.ndpc.gov.ng
Phone: +234 (0) 9 461 9361
The Company encourages data subjects to first contact the Data Protection Officer to resolve any issues amicably before approaching the NDPC:
Data Protection Officer, Ethica Capital LtdEmail: info@ethicacapitalltd.com
Phone: 09168189500
However, data subjects are free to lodge complaints directly with the NDPC at any time without prior contact with the Company.
The Company shall cooperate fully with NDPC investigations and shall not retaliate against any data subject for exercising their right to lodge a complaint.
8.10 Procedure for Exercising Data Subject Rights
General Procedure
- Submission: Data subjects may exercise their rights by:
- Completing the Data Subject Request Form (Annex 2)
- Sending an email to info@ethicacapitalltd.com or compliance@ethicacapitalltd.com
- Submitting a written request by post
- Making a request in person at Company offices (with appointment)
- Identity Verification: The Company may request reasonable information to verify the identity of the requestor to prevent unauthorized disclosure of personal data, particularly for access requests.
- Acknowledgment: The Company shall acknowledge receipt of the request within 3 business days.
- Processing: The Company shall assess the request, verify identity, locate the relevant data, and take appropriate action.
- Response: The Company shall provide a substantive response within 30 days (extendable by 30 days for complex requests with notification to the data subject).
- Fee (if applicable): Where a reasonable fee applies, the Company shall inform the data subject and request payment before processing the request.
- Refusal: If a request is refused (in whole or in part), the Company shall inform the data subject of the reasons for refusal and their right to lodge a complaint with the NDPC.
All data subject requests and responses are logged in the Company’s Data Subject Rights Register for compliance monitoring and audit purposes.
9. Registration and Compliance Obligations
As a Data Controller of Major Importance, Ethica Capital has registered with the Nigeria Data Protection Commission (NDPC) and maintains current registration status.
Registration Details
- Category: Data Controller/Processor of Major Importance
- Registration Number: NDPC/DCP/09873
- Registration Date: 20th November 2025
- Renewal Date: 20th November 2027
9.1 Compliance Audit Return (CAR)
The Company files annual Compliance Audit Returns with the NDPC by 31 March each year, verified by a licensed Data Protection Compliance Organization (DPCO).
The CAR documents:
- Compliance status with all NDPA requirements
- Data processing activities and legal bases
- Data subject rights requests and responses
- Data breaches and incidents
- Cross-border data transfers
- DPIAs conducted
- Security measures implemented
- Staff training completed.
9.2 Annual Credential Assessment of DPO
The Company’s Data Protection Officer undergoes annual credential assessment by the NDPC to ensure ongoing competence and professional standing.
9.3 Periodic Reporting
The DPO prepares semi-annual data protection reports for the Board and senior management, documenting policy compliance, risks, incidents, and recommendations for improvement.
10. Governance and Accountability
10.1 Board of Directors
The Board bears ultimate responsibility for:
- Approving this Data Privacy and Protection Policy
- Ensuring adequate resources for data protection compliance
- Overseeing implementation and effectiveness of data protection framework
- Reviewing data protection reports and audit findings
- Ensuring data protection is embedded in corporate strategy and risk management
10.2 Data Protection Officer (DPO)
Name: Okwilague Simbiat Abubakar
Email: Simbiat.abubakar@ethicacapitalltd.com
Responsibilities include:
- Overseeing implementation and monitoring of this Policy
- Advising management and staff on data protection obligations
- Serving as primary contact for NDPC and data subjects on data protection matters
- Conducting data protection impact assessments
- Maintaining records of processing activities (ROPA)
- Coordinating data breach response and notifications
- Conducting internal data protection audits
- Providing training and awareness programs
- Reporting directly to Board on data protection matters
The DPO has independence, authority, and resources to discharge duties effectively.
10.3 Management Responsibilities
- MD/CEO: Overall accountability for data protection compliance
- Chief Compliance Officer: Regulatory compliance and reporting
- Head, Information Technology: Technical security controls and incident response
- Head of HR: Employee data protection and training
- Head of Operations: Vendor management and third-party compliance
- Legal Counsel: Legal advice and guidance on data protection matters.
10.4 All Staff
Every employee, director, contractor, and agent is responsible for:
- Complying with this Policy and related procedures
- Protecting personal data in their custody or control
- Reporting suspected data breaches immediately
- Completing mandatory data protection training
- Seeking guidance from DPO when uncertain.
11. Training and Awareness
All personnel with access to personal data receive comprehensive data protection training.
11.1 Mandatory Training
- New Employee Onboarding: Data Protection Module within first 6 months of employment
- Annual Refresher Training: All staff complete annual update
- Role-Specific Training: Additional training for IT, HR, compliance, customer-facing roles
- Incident Response Training: Annual drills for incident response team
- Specialized Training: DPO and security personnel receive professional certification training.
11.2 Training Content
- Overview of NDPA 2023 and GAID 2025
- Company data protection policies and procedures
- Data subject rights and how to handle requests
- Security best practices and threat awareness
- Breach detection and reporting
- Privacy by Design principles
- Shariah principles relating to confidentiality and data protection
- Case studies and real-world scenarios.
11.3 Awareness Campaigns
- Quarterly data protection newsletters
- Posters and reminders in offices
- Email tips and alerts on emerging threats
- Data Protection Week annual campaign
- Recognition for exemplary data protection practices.
11.4 Training Records
All training completion is documented and tracked for compliance audits and CAR filing.
12. Policy Review and Updates
This Policy shall be reviewed and updated regularly to ensure continued effectiveness and compliance.
12.1 Regular Reviews
- Annual Review: Full policy review conducted each year
- Legislative Review: Updated whenever NDPA, GAID, or SEC regulations are amended
- Incident-Triggered Review: Updated following material data breaches or compliance failures
- Audit-Triggered Review: Updated based on internal/external audit findings.
12.2 Approval and Communication
Policy updates require:
- Review by Data Protection Officer
- Legal and compliance review
- Approval by Board of Directors
- Communication to all staff and relevant stakeholders
- Publication on company website and intranet
- Training on material changes.
13. Contact Information
For any questions, concerns, or requests relating to data protection and privacy:
Data Protection OfficerEthica Capital Ltd
Suite 413 NAWA Complex, Plot 106/107 Ahmadu Bello Way, Kado, Abuja
Email: info@ethicacapitalltd.com
Phone: 07014661477 Compliance Department
Email: compliance@ethicacapitalltd.com
Phone: 09168189500 Nigeria Data Protection Commission
Plot 1172 Cadastral Zone B05, Mabushi District, Abuja
Email: info@ndpc.gov.ng
Website: www.ndpc.gov.ng
Phone: +234 (0) 9 461 9361
Data subjects may contact the DPO to:
- Exercise data subject rights
- Request information about data processing
- Submit complaints or concerns
- Report suspected data breaches
- Request copies of this Policy or related procedures
The Company is committed to responding to all inquiries within 5 business days.
Annexes
Annex 1: Data Inventory and Retention Schedule
| S/N | Data Category | Description | Retention Period | Legal Basis | Disposal Method |
|---|---|---|---|---|---|
| 1 | Client KYC Records | Full name, contact details, ID documents (BVN, NIN, passport), bank account details, investment history, financial information, KYC data | 7 years after end of relationship | SEC Regulations, AML/CFT Requirements, NDPA 2023 | Secure deletion for electronic; cross-cut shredding for physical |
| 2 | Investment Records | Portfolio details, transactions, subscriptions, redemptions, valuations, asset allocations | 7 years from transaction date | SEC Regulations, ISA 2025 | Secure deletion for electronic; cross-cut shredding for physical |
| 3 | Employee Records | HR data, payroll, performance reviews, disciplinary records, attendance | Duration of employment + 7 years | Labour Laws, Tax Requirements, NDPA 2023 | Secure deletion for electronic; cross-cut shredding for physical |
| 4 | Vendor and Supplier Records | Contracts, invoices, payment records, compliance documentation | Duration of contract + 7 years | Accounting Standards, Contract Law, CAMA 2020 | Secure deletion for electronic; cross-cut shredding for physical |
| 5 | Marketing and Consent Data | Contact info for prospects, marketing preferences, consent records | Until consent withdrawn + 7 years | Consent, Legitimate Interest, NDPA 2023 | Deletion upon request or expiry |
| 6 | Tax and Financial Records | Tax returns, financial statements, audit reports | 7 years from filing/financial year end | FIRS Regulations, CAMA 2020 | Secure deletion; archived copies retained |
| 7 | AML/CFT Records | Suspicious transaction reports, enhanced due diligence, PEP screening | 7 years after relationship termination | AML/CFT Regulations, NFIU Requirements | Secure deletion with NFIU consultation if needed |
| 8 | Legal and Litigation Records | Contracts, legal opinions, court filings, dispute documentation | 7 years after matter conclusion | Limitation Period, Legal Obligation | Secure deletion after litigation hold expires |
| 9 | CCTV and Access Logs | Video surveillance, building access records | 6 months (unless investigation required) | Legitimate Interest, Security | Automatic overwrite or secure deletion |
| 10 | IT Logs and System Data | Server logs, access logs, email metadata, security events | 3 years (unless breach investigation) | Legitimate Interest, Security, NDPA 2023 | Automated archival and deletion |
| 11 | Website Analytics and Cookies | Usage data, clickstream, device information | 7 years depending on cookie type | Consent, Legitimate Interest | Automated expiration and deletion |
| 12 | Communication Records | Emails, letters, meeting notes, call recordings | 7 years depending on content | Contract, Compliance, Legitimate Interest | Secure deletion for electronic; shredding for physical |
Note: Retention periods may be extended where data is subject to legal hold, ongoing litigation, regulatory investigation, or where deletion would violate legal obligations. All disposals require DPO approval.
Annex 2: Data Subject Request Form
Data subjects may use this form to exercise their rights under the NDPA 2023.
Submit completed form to:
- Email: info@ethicacapitalltd.com
- Post: Data Protection Officer, Ethica Capital Ltd, Suite 413, NAWA Complex, Plot 106/107 Ahmadu Bello Way, Kado, Abuja.
- In Person: Ethica Capital Ltd, Suite 413 NAWA Complex, Plot 106/107 Ahmadu Bello Way, Kado, Abuja
The form includes fields for:
- Data subject details (name, contact, relationship to Company)
- Type of request (access, rectification, erasure, restriction, portability, objection)
- Specific data or processing concerned
- Reason for request (if applicable)
- Identity verification documents
- Signature and date
Annex 3: Third-Party Data Processing Agreement Template
All third-party processors engaged by Ethica Capital must execute a Data Processing Agreement containing minimum provisions required by Section 42 of the NDPA 2023 and Article 10 of the GAID 2025.
Key contractual clauses include:
- Scope and nature of processing
- Categories of data and data subjects
- Processor obligations (confidentiality, security, compliance)
- Sub-processor authorization requirements
- Data subject rights assistance
- Breach notification requirements (within 24–72 hours)
- Audit and inspection rights
- Data return/deletion upon termination
- Liability and indemnification
- Cross-border transfer provisions (if applicable)
- NDPC cooperation obligations.