Governance
Data Governance and Sovereignty
The legal basis Basani operates under, how the programme handles cross-border transfer, research ethics, consent and data residency, and the status of our own compliance.
Statute
The Law That Applies
Genetic data, biometric data and health status are sensitive personal data under the Nigeria Data Protection Act 2023, and attract heightened requirements for lawful processing. The NDPC’s General Application and Implementation Directive, issued in March 2025 and effective from 19 September 2025, sets the operational framework. It requires registration of data controllers and processors of major importance, data privacy impact assessments in defined high-risk circumstances, breach notification to the Commission within seventy-two hours, data processing agreements with third parties, and data protection by design. A DPIA must be signed by a certified Data Protection Officer and filed with the Commission.
The GAID replaced the 2019 NDPR as the operative instrument. Any framework still drafted against the NDPR is out of date.
Part VIII
Moving Data Out of Nigeria
Part VIII of the Act, sections 41 to 43, governs the movement of personal data out of Nigeria. A transfer is permitted where the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism affording adequate protection, or where one of the conditions in section 43 applies. Controllers must record the basis for every transfer and the adequacy of protection relied on. For genomic data at population scale, these rules shape the architecture, and we treat them as a design input.
Ethics
Research Ethics Approval
Participants
How Consent Works
Residency
Where the Data Is Held
Register
Our Compliance Status
| Obligation | What is recorded | Status |
|---|---|---|
| NDPC registration | Data controller of major importance registration number | |
| Data Protection Officer | Named certified DPO and contact address | |
| Data privacy impact assessment | DPIA status and filing date with the Commission | |
| ISO/IEC 27001 | Certification scope and target date |
Contact