Legal

NDPR Compliance

Our approach to Nigerian data protection obligations under NDPR and related guidance.

This page outlines how Reerac aligns operational practices with NDPR principles for recruitment-related processing.

Last updated: April 28, 2026

Data minimization practices
Purpose limitation for hiring workflows
Access controls and processing records
Incident response and reporting posture
Controller and processor role clarity
Operational accountability framework

1. Compliance Framework

Reerac implements governance, process controls, and technical safeguards intended to align with NDPR principles and related guidance.

Compliance is treated as an operational discipline supported by policy review and process oversight.

2. Lawful and Fair Processing

Processing activities are expected to be tied to explicit recruitment purposes and legitimate legal grounds.

Customers are responsible for ensuring candidate notices and lawful basis at the point of data collection.

3. Data Minimization and Purpose Limitation

Platform workflows are designed to limit collection to information relevant for hiring operations.

Data should not be repurposed for unrelated objectives without an appropriate legal basis and notice.

4. Transparency and User Awareness

We support policy transparency through clear documentation of processing categories and controls.

Customers should provide candidates with role-appropriate privacy information and consent notices where required.

5. Security and Access Controls

Operational access is restricted according to role responsibilities and security need-to-know principles.

Security practices include monitoring, incident workflows, and periodic control review.

6. Data Subject Rights Enablement

We support mechanisms to help customers address access, correction, and deletion requests as required by law.

Execution of rights requests may require identity verification and lawful exceptions review.

7. Records, Accountability, and Audits

Processing accountability is supported through documented procedures and operational records where applicable.

Customers may be required to maintain their own records to meet internal and regulatory obligations.

8. Incident Response and Regulatory Cooperation

Security incidents are managed under defined response processes, including investigation, containment, and communication steps.

Where required, notifications are coordinated in line with legal and contractual obligations.

9. Shared Responsibility

Reerac and customer organizations each have compliance responsibilities based on their roles in data processing.

Customers remain responsible for lawful hiring policies, candidate communications, and internal approval controls.

Need NDPR readiness support?

Reach out to discuss your compliance workflow, policy requirements, and implementation controls.