Connect with us

News

How much personal data should you really give an app? – Technology Times

info

Published

on

There was a time when giving out personal information meant writing your name and phone number on a form, handing over a photocopy of an identity card or filling in an address on a paper document.

That world is disappearing. Today, Nigerians routinely enter personal information into banking apps, shopping platforms, ride-hailing services, social networks, entertainment platforms and government websites. Sometimes it happens several times a day, often without much thought.

A banking app may ask for identity details. A ride-hailing app wants your location. An online store needs your address. A social platform may ask for access to your photographs, microphone or contacts. And then there are the less obvious requests.

how-much-personal-data-should-you-give-an-app
Before clicking “Allow” on another app, Nigerians should ask a simple question: does the service really need all the information it is requesting? From NIN and BVN to location, contacts and photographs, personal data has become one of the most valuable assets in Nigeria’s digital economy. Image credit: AI.

That world is disappearing. Today, Nigerians routinely enter personal information into banking apps, shopping platforms, ride-hailing services, social networks, entertainment platforms and government websites. Sometimes it happens several times a day, often without much thought.

An app wants access to your entire contact list. Another wants continuous access to your location. Yet another asks for an identity number that appears to have little connection with what you are trying to do. At some point, a reasonable question arises: how much information is too much?

Nigeria’s data protection framework offers a surprisingly straightforward starting point.

The answer is not “whatever the app asks for”. The Nigeria Data Protection Commission (NDPC) says personal data should be processed fairly, lawfully and transparently. It should be collected for specified and legitimate purposes and should be “adequate, relevant, and limited to the minimum necessary” for the purpose for which it is being processed.

That last part is important. It is known as data minimisation, and it essentially means that because an organisation can collect a particular piece of information does not mean that it should.

For ordinary users, the principle offers a useful question whenever a digital service asks for information: why does it need this?

If the answer is clear and connected to the service, the request may make sense. If the explanation is vague, users may want to pause before clicking “allow”.

Personal data: Every app has a reason for collecting our information

There is no universal list of information that every digital service should be allowed to collect. The answer depends on what the service actually does.

A bank needs information that allows it to identify customers, comply with financial regulations and provide banking services. A ride-hailing platform needs a user’s location to match passengers with drivers. A delivery company needs an address if it is going to deliver something to your doorstep. Those are relatively easy to understand.

The questions become more interesting when an application begins asking for information that does not appear essential to the service.

Why does a calculator need access to your contacts?

Why does a simple application need continuous access to your location?

Why does a service unrelated to photography need access to your entire photo library?

There may sometimes be legitimate technical explanations. But the point of data minimisation is precisely that organisations should be able to connect the information they collect to a legitimate purpose.

The NDPC’s own privacy policy reflects this broader approach. Personal information should be collected for specified, explicit and legitimate purposes, retained only for as long as necessary and protected against unauthorised or unlawful processing, loss, destruction or damage.

In other words, clicking “I agree” does not turn privacy into a free-for-all.

how-much-personal-data-should-you-give-an-app
Before clicking “Allow” on another app, Nigerians should ask a simple question: does the service really need all the information it is requesting? From NIN and BVN to location, contacts and photographs, personal data has become one of the most valuable assets in Nigeria’s digital economy. Image credit: AI.

The questions become more interesting when an application begins asking for information that does not appear essential to the service. Why does a calculator need access to your contacts? Why does a simple application need continuous access to your location? Why does a service unrelated to photography need access to your entire photo library? There may sometimes be legitimate technical explanations. But the point of data minimisation is precisely that organisations should be able to connect the information they collect to a legitimate purpose.

Your NIN deserves a different level of caution

The issue becomes more serious when the information being requested is a powerful identifier such as the National Identification Number.

The National Identity Management Commission (NIMC) has warned Nigerians against indiscriminate disclosure of their NIN.

Its advice is direct: “The NIN should be closely guarded by individuals and not revealed to all and sundry except to relevant authorities when requested.” That warning matters in an economy increasingly built around digital identity.

A NIN is not simply another phone number or email address. It can serve as an important identifier linking an individual to different services and records. This means Nigerians may need to become more selective about who receives it and why.

The same thinking applies to other sensitive information, including bank verification details, biometric information, passport details and financial records.

The convenience of completing an online registration should not automatically outweigh the consequences of unnecessarily distributing information that can be difficult to replace once exposed.

The problem with data is that it can travel

When personal information is given to an organisation, most users assume it will stay within the organisation’s systems and be used for the purpose they had in mind. That is not always how the digital world works.

Information can move between systems. It can be shared with service providers. It can remain in databases for years. It can be exposed through cyberattacks or compromised through poor security practices.

In 2024, digital rights organisation Paradigm Initiative raised concerns after reporting the discovery of websites allegedly offering sensitive personal and financial information belonging to Nigerians for as little as ₦100.

The reported information included NIN, BVN, virtual NIN, driving licence, international passport, Tax Identification Number, Permanent Voter’s Card and telephone numbers.

Paradigm Initiative called for stronger measures to protect Nigerians’ personal information. The episode illustrates an uncomfortable reality of the digital economy: once information has been collected, the individual no longer has complete control over where it sits or who might eventually gain access to it.

That is why the question of privacy does not end with the user. It also belongs to the organisation holding the data.

how-much-personal-data-should-you-give-an-app
Before clicking “Allow” on another app, Nigerians should ask a simple question: does the service really need all the information it is requesting? From NIN and BVN to location, contacts and photographs, personal data has become one of the most valuable assets in Nigeria’s digital economy. Image credit: AI.

When personal information is given to an organisation, most users assume it will stay within the organisation’s systems and be used for the purpose they had in mind. That is not always how the digital world works. Information can move between systems. It can be shared with service providers. It can remain in databases for years. It can be exposed through cyberattacks or compromised through poor security practices. In 2024, digital rights organisation Paradigm Initiative raised concerns after reporting the discovery of websites allegedly offering sensitive personal and financial information belonging to Nigerians for as little as ₦100.

Privacy is not simply about secrecy

It is easy to think of data privacy as something that matters only to people who have something to hide. That is too narrow a view. Privacy is also about control.

Who knows your identity? Who knows where you live? Who knows where you travel? Who has your financial information? Who can connect several apparently unrelated pieces of information and build a detailed picture of your life?

The more information an organisation holds, the greater the potential consequences if that information is misused, exposed or retained unnecessarily.

For some categories of information, there is another problem: you cannot simply change them.

A password can be replaced. A compromised NIN is a different proposition. So is exposed biometric information.

This is one reason why data minimisation matters beyond regulatory compliance. It can also be understood as a basic form of digital risk management.

Nigerian law gives consumers more control

Nigeria’s data protection framework is anchored by the Nigeria Data Protection Act 2023, which established the NDPC as the country’s independent data protection regulator.

The framework provides data subjects with a number of rights concerning their personal information.

These include the right to know how their data is being processed, to access personal information, to request correction of inaccurate information and, in applicable circumstances, to request erasure.

There are also provisions dealing with matters such as objection to certain processing, data portability and automated decision-making.

This is worth remembering because privacy policies can sometimes feel like contracts written for someone else.

They are often long. The language can be technical. And the temptation is to scroll to the bottom and click “accept”. But accepting a privacy policy does not mean that an organisation is suddenly exempt from its obligations under Nigeria’s data protection framework.

Companies and public institutions still have responsibilities concerning how personal information is collected, processed, stored and shared.

The five-second pause

There is a simple habit that could make digital life slightly safer. Before giving an app access to something personal, pause for a few seconds. Ask what it needs the information for.

If a service asks for your location, is the location necessary for the service?

If it wants access to your contacts, does the feature genuinely require them?

If it requests your NIN, is there a legitimate reason for the organisation to have it?

If you refuse, does the service still work?

And, perhaps most importantly, what happens to the information after you have handed it over?

These questions do not require technical expertise. They are simply the digital equivalent of asking someone why they need a copy of your identity document before handing it over.

The responsibility cannot rest entirely with users

There is a danger in making privacy sound like another problem that ordinary Nigerians must solve for themselves. The person downloading an app is only one part of the equation. Organisations that collect personal information have responsibilities too.

The NDPC’s data protection principles cover purpose limitation, data minimisation, accuracy, storage limitation and security, among other requirements. The framework can also apply in specified circumstances to organisations outside Nigeria that process the personal data of people in Nigeria.

That is significant because Nigerians increasingly interact with digital companies headquartered elsewhere. A person in Lagos may bank through a local institution, shop through an international platform, communicate through a global social network and store files on an overseas cloud service, all within the same day.

Data does not respect national borders simply because the person generating it lives in Nigeria.

Digital transformation needs trust

Nigeria’s digital economy cannot function without data. Banks need customer information. Healthcare platforms need patient records. E-commerce companies need delivery details. Telecommunications operators need subscriber information. Government services increasingly depend on digital identity.

The objective, therefore, cannot realistically be to stop collecting personal information. The more useful question is whether the information being collected is necessary, proportionate, properly protected and used for the purpose for which it was obtained.

That is where the principle of data minimisation becomes particularly relevant. Personal information should be “adequate, relevant, and limited to the minimum necessary” for the purpose for which it is processed.

It is a relatively simple idea for an increasingly complicated digital economy. NIMC’s caution about protecting the NIN reinforces it from the identity-management perspective. Concerns raised by Paradigm Initiative about exposed Nigerian data demonstrate the consequences that can follow when sensitive information ends up in the wrong hands.

For consumers, the lesson is equally straightforward. The next time an app asks for access to something personal, there is no harm in pausing before clicking “allow”.

The question is not whether the app wants your data. It probably does. The better question is whether it genuinely needs it.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Cricket: Prosper Useni, Elijah Saturday Jimmy Set for Zimbabwe NPL T20 Blast Challenge

info

Published

on

IMG 20261003 WA0224.jpg

Two Nigerian cricket talents, Prosper Useni and Elijah Saturday Jimmy, are set for a new international challenge after being drafted into the Zimbabwe National Premier League (NPL) T20 Blast 2026.

Sports247 reports that the Nigerian duo will represent different franchises when the competition gets underway, giving both players an opportunity to showcase their abilities on the Zimbabwean domestic stage.

Useni has been drafted by Mbizo, while Jimmy will join Queens for the upcoming campaign.

The two players are expected to join their respective teams in Harare as preparations intensify ahead of the tournament, which is scheduled to begin on October 8, 2026.

For Useni and Jimmy, the opportunity represents another step in their respective cricket journeys, with the NPL T20 Blast providing a competitive environment in which they can test themselves against established players and emerging talents from across the region.

Useni’s inclusion with Mbizo will see him take on a new challenge as he adapts to the demands of T20 cricket in Zimbabwe, while Jimmy will be looking to make a strong impression with Queens.

The presence of the two Nigerians also provides another indication of the growing opportunities available to Nigerian cricket players beyond the domestic scene.

Their participation in Zimbabwe offers valuable international exposure and the chance to gain experience in a different cricketing environment.

With the tournament set to commence on October 8, both players will be hoping to settle quickly into their respective squads and contribute to their teams’ campaigns.

For Mbizo, Useni will be expected to bring his skills and energy to the franchise, while Queens will look to Jimmy to make a meaningful contribution throughout the competition.

As the NPL T20 Blast 2026 approaches, attention will turn to how the Nigerian duo perform once the action begins in Zimbabwe.

Their participation will be closely followed by cricket fans in Nigeria, with Useni and Jimmy carrying the hopes of their supporters as they embark on this latest international assignment.

The upcoming campaign therefore represents more than just another domestic tournament for the pair; it is an opportunity to gain valuable experience, compete at a higher level and continue building their profiles in the international cricket landscape.

Continue Reading

News

NPFL: Ejeh steps down as Enyimba assistant coach

info

Published

on

HTsCdTkXYAAFMQJ.jpg

Kelvin Okechukwu Ejeh has resigned from his position as assistant coach of nine-time Nigeria Premier Football League (NPFL) champions Enyimba, DAILY POST reports.

Ejeh tendered his resignation letter to the management of the club on Saturday.

The former Abia Comets handler cited irreconcilable differences with head coach Emmanuel Deutsch as the reason for his decision.

The experienced gaffer said it was difficult for him to function in a toxic environment.

Recommended

“Enyimba is a club after my heart. It’s a club so dear to me, but you see, I don’t function effectively well under a toxic environment,” Ejeh told Completesports.com.

“When your boss begins to listen to gossip without recourse to hearing from you, then it becomes clear that trust is gone and the working relationship has been severed. So, I had to leave.”

Enyimba have endured a poor start to the 2026/27 season, recording just one win from six games.

The Aba giants will host Plateau United in a matchday seven encounter at the Enyimba International Stadium on Sunday.

Continue Reading

Trending