One of the first things many businesses do when launching a website or mobile application is add a privacy policy. Unfortunately, many also make one of the biggest compliance mistakes at the very beginning. Instead of preparing a privacy policy that reflects how their own organization processes personal data, they simply copy one from another website, make a few cosmetic changes, and publish it. It seems harmless. After all, a privacy policy is just another legal document, right? Not quite.
A privacy policy is not a generic template or website decoration. It is a legal statement that explains how an organization collects, uses, stores, shares, and protects personal data. It tells people what happens to their information after they hand it over to a business. When that statement is copied from another organisation, it often tells the wrong story.
Under the Nigeria Data Protection Act, 2023 (NDPA), transparency and accountability are fundamental principles of data protection. A privacy policy that does not accurately describe an organization’s processing activities is more than just poorly drafted; it can become a compliance risk.
Understanding Who the NDPA Protects
Before discussing the risks, it is important to understand who the Act applies to. The NDPA protects data subjects, who are simply the individuals whose personal data is being processed. Section 65 of the NDPA defines data subjects as an individual to whom personal data relates. Every customer filling out an online form, every employee whose records are kept by an employer, every patient visiting a hospital, and every applicant submitting a job application is a data subject.
The organization deciding why and how that information should be collected is known as the data controller. The controller determines the purpose of processing, the categories of information to be collected, who will receive the data, how long it should be retained, and the safeguards that should be put in place.
There is also the data processor, which processes personal data on behalf of the controller. This could be a cloud storage provider, a payroll company, an email marketing platform, an IT vendor, or any other third party handling personal data on the controller’s instructions.
Each of these parties has a role to play under the NDPA, and each can be affected when an organisation publishes a privacy policy that does not reflect reality.
Why Every Privacy Policy Should Be Different
One of the biggest misconceptions is that businesses operating in the same industry process personal data in exactly the same way. They rarely do.
Take two hospitals, for example. Both may collect patients’ names, contact details, and medical records. However, one hospital may use cloud-based electronic health records hosted outside Nigeria, while the other stores everything locally. One may engage an external laboratory, another may operate its own. One may retain patient records for a different period because of its internal policies or regulatory obligations.
The same applies to law firms, banks, fintech companies, schools, online retailers, and virtually every other organization. Even businesses offering similar services often use different software, engage different vendors, transfer data to different countries, or collect entirely different categories of personal information.
That is why privacy policies cannot simply be copied from one organization to another. Every organization has its own data story to tell.
Transparency Is More Than a Legal Requirement
Section 24 of the NDPA establishes the principles governing the processing of personal data, one of which is transparency. Transparency means being open with people about what happens to their information. When an individual provides personal information to a business, they should know what information is being collected, why it is needed, whether it will be shared with anyone else, how long it will be kept, and what rights they have over it.
A privacy policy is one of the primary ways organizations communicate this information. If that policy has been copied from another organization, there is a strong possibility that the information being provided is inaccurate. An organization may unknowingly tell customers that it does not share information with third parties when it actually relies on payment processors, cloud hosting providers, external auditors, or marketing platforms. It may state that information is retained for six months when, in reality, it is kept for several years. It may even fail to mention international transfers simply because the organization it copied from does not transfer data outside Nigeria.
The Risks for Data Controllers
For data controllers, copying a privacy policy can create problems that extend beyond poor drafting. The privacy policy is often the first document regulators, customers, investors, and business partners review when assessing an organization’s approach to data protection. If the policy says one thing while the organization’s actual practices say another, questions immediately arise about governance and compliance.
Imagine an organization assuring customers that their personal data is never disclosed to third parties, yet its operations depend heavily on external payroll providers, cloud storage services, customer relationship management software, and outsourced IT support.
If the Nigeria Data Protection Commission investigates the organization, those inconsistencies may become evidence that the organization has failed to meet its transparency obligations under the NDPA. Ironically, what was intended to save time may end up creating a far more expensive compliance problem.
Data processors may also be affected, even though they do not determine why personal data is processed. Many processors operate entirely on the instructions of the controller. However, if the controller’s privacy policy fails to disclose their involvement, data subjects are left unaware that another organization is handling their information. This lack of transparency can damage trust and create unnecessary regulatory scrutiny. A processor may be performing its role lawfully, but if the controller fails to communicate that relationship accurately, the entire processing chain becomes less transparent.
The People Most Affected Are Data Subjects
Perhaps the greatest consequence falls on the very people the NDPA seeks to protect. One of the cornerstones of the Act is that individuals have the right to know what happens to their personal information. Section 34 of the NDPA gives data subjects important protections, including the right to be informed about how their personal data is processed, the right to access that information, the right to request corrections where information is inaccurate, the right to object to certain forms of processing, the right to withdraw consent where consent forms the basis of processing, and, in appropriate circumstances, the right to request that their personal data be erased.
These rights, however, can only be exercised effectively if people receive accurate information from the beginning. Consider a business whose copied privacy policy states that personal information is never transferred outside Nigeria. A customer reading that policy may feel comfortable sharing their information because they believe it will remain within the country. Unknown to them, the organization stores customer information on servers located overseas. The customer’s right to make an informed decision has effectively been undermined. Similarly, if a privacy policy fails to mention that personal information is shared with third-party vendors, individuals lose the opportunity to understand who else has access to their data and for what purpose. In many respects, copying a privacy policy deprives data subjects of the transparency that the NDPA was specifically enacted to guarantee.
Conclusion
The temptation to copy another organization’s privacy policy is understandable. It is quicker, easier, and often appears to save money. However, convenience should never replace compliance. A privacy policy is not simply a document added to a website because every other website has one. It is a public representation of how an organization handles one of its most valuable assets: personal data.
Businesses expose themselves to unnecessary regulatory and reputational risks. Data processors may find themselves operating within an ecosystem that lacks transparency. Most importantly, data subjects are denied clear and accurate information about what happens to their personal data, making it more difficult for them to exercise the rights guaranteed to them under the NDPA.
The best privacy policy is the one that tells your organization’s story truthfully, accurately, and transparently.
Ayomikun Oreoluwa Onabanjo Esq.
Managing Associate

