In a significant development, the Nigeria Data Protection Commission (NDPC) has announced enhanced scrutiny measures for the licensees of the National Identity Management Commission (NIMC) following a data breach incident. This move comes after a website, expressverify.com, was found accessing National Identification Number (NIN) verification credentials without proper authorization, sparking widespread concern over data protection protocols.

Investigation and Immediate Actions

The breach was first brought to light by the Foundation for Investigative Journalism on March 16, highlighting the website's unauthorized access to NINs and personal details of individuals registered in Nigeria's identity database. The NDPC's investigation into the incident revealed that a third-party entity, previously authorized to provide verification services, may have improperly allowed expressverify.com access to these sensitive credentials. To mitigate the breach, NIMC has temporarily suspended all access to its database, reinstating limited access to select establishments providing essential public services after a careful review.

Enhanced Scrutiny and Compliance Measures

In response to the breach, the NDPC has declared that data processing activities by NIMC's licensees will now face increased scrutiny, with only entities compliant with existing laws permitted to conduct NIN verifications. Moreover, NIMC plans to conduct intensive training sessions aimed at ensuring that both personnel and licensees are fully aware of their regulatory obligations under the Nigeria Data Protection Act. This is a clear move to tighten data protection measures and prevent future breaches.

Public Awareness and Ongoing Vigilance

The NDPC has also emphasized the importance of the NIN for sustainable development and urged the public to exercise caution when sharing personal information online. The commission's proactive stance, including the swift investigation and the call for increased vigilance, highlights the growing recognition of data privacy as a fundamental right. Meanwhile, civil society organizations like Paradigm Initiative have urged immediate action from NIMC and NDPC to address privacy violations and secure the National Identity Database against unauthorized access.

As the investigations continue, the NDPC's commitment to upholding data protection standards and ensuring the integrity of Nigeria's identity management system remains critical. This incident serves as a reminder of the challenges posed by digital identity management and the need for robust security protocols to protect against data breaches. The ongoing efforts by NDPC and NIMC to enhance data protection measures and educate stakeholders on their responsibilities signify an important step towards safeguarding personal information in the digital age.