Privacy Policy
National Digital Alphanumeric Postcode System (NDAPS)
1. Introduction and scope
The Nigerian Postal Service (“NIPOST”, “we”, “us” or “our”) respects the privacy of individuals whose Personal Data we process. This Privacy Policy explains how NIPOST collects, uses, stores, protects and discloses Personal Data in connection with the National Digital Alphanumeric Postcode System (“NDAPS”), including its websites, applications, portals, postcode and address services, APIs, account services and related communications.
This Privacy Policy applies to Personal Data processed through NDAPS. It should be read together with:
- The NDAPS Terms and Conditions of Use;
- The NDAPS Acceptable Use Policy;
- The NDAPS Cookie Policy; and
- Applicable service-specific agreements.
NIPOST processes Personal Data in accordance with applicable Nigerian data protection legislation and regulatory requirements.
2. Definitions
2.1 Personal Data means information relating to an identified or identifiable individual as defined under applicable Nigerian data protection law.
2.2 Processing means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, transmission, alteration or deletion.
2.3 Data Subject means an identified or identifiable individual to whom Personal Data relates.
2.4 Data Controller means the person or organization that determines the purposes and means of processing Personal Data.
2.5 Data Processor means a person or organization that processes Personal Data on behalf of a Data Controller.
2.6 Sensitive Personal Data means categories of Personal Data receiving enhanced protection under applicable Nigerian data protection law.
2.7 NDAPS means the National Digital Alphanumeric Postcode System operated, administered or authorized by NIPOST, including its associated databases, applications, websites, APIs, infrastructure, postcode services and related digital services.
3. Data controller and Data Protection Officer
3.1 Data Controller
Nigerian Postal Service (NIPOST)
Address: No 1 Nkwere Street, Off Mohammadu Buhari Way, Garki II, Abuja
Privacy Email: privacy@nipost.gov.ng
Website: www.nipost.gov.ng
3.2 Data Protection Officer
Nigerian Postal Service (NIPOST)
Name: Peace Abah
Email: dpo@nipost.gov.ng
Office: NIPOST Headquarters / Data Protection Unit.
4. Personal Data we may process
Depending on the NDAPS Service used and the nature of the User's interaction with NDAPS, NIPOST may process the following categories of Personal Data.
4.1 Identity and contact information
- Name;
- Email address;
- Telephone number;
- Organization or employer;
- Job title; and
- Other information reasonably necessary to provide an authorized service.
4.2 Address and location information
- Submitted addresses;
- Postcode information;
- Address validation information;
- Address correction information;
- Geographic coordinates;
- Location-reference information;
- Postcode assignment history; and
- Related geographic information.
4.3 Account and authentication information
- Username;
- Authentication records;
- Login information;
- Security logs;
- API credentials and related security information.
Passwords are stored using appropriate secure password-hashing mechanisms and are not stored in plaintext.
4.4 Technical and usage information
- IP address;
- Browser type;
- Device information;
- Operating system;
- Timestamps;
- System logs;
- Pages or services accessed;
- Referral information;
- Cookie identifiers; and
- Other technical information reasonably necessary for service operation and security.
4.5 Transaction and billing information
Where Users purchase paid NDAPS Services, NIPOST may process:
- Transaction records;
- Billing information;
- Billing address;
- Applicable tax information; and
- Payment status.
Where practicable, payment-card information is processed directly by appropriately authorized payment service providers rather than stored by NIPOST.
4.6 Communications and User submissions
- Correspondence;
- Support requests;
- Complaints;
- Feedback;
- Address-correction submissions;
- Survey responses; and
- Other information voluntarily submitted through NDAPS.
5. National Identification Number (NIN)
Where a National Identification Number (“NIN”) or information derived from a NIN is required for an authorized NDAPS service or integration, NIPOST processes it only where permitted by applicable law and where reasonably necessary for the stated purpose. NIPOST applies appropriate access, security, retention and disclosure controls, and will consider minimizing storage or disclosure of the full NIN where the intended purpose can reasonably be achieved through a less intrusive identifier, token, reference number or verification mechanism.
6. Sensitive Personal Data
NIPOST does not intentionally collect Sensitive Personal Data through NDAPS unless such processing is necessary for a specific authorized purpose and permitted under applicable law, in which case the additional safeguards required by applicable law apply. Users must not submit Sensitive Personal Data through NDAPS unless the relevant Service expressly permits it and the User has appropriate authority and lawful basis.
7. How Personal Data is collected
7.1 Directly from Users
For example, when Users register an account, use postcode or address services, submit address corrections, contact support, submit feedback, or subscribe to authorized communications.
7.2 Automatically
Through system logs, cookies, security monitoring, analytics, device information and other technical mechanisms.
7.3 From authorized third parties
NIPOST may receive Personal Data from authorized government agencies, public authorities, service providers, business partners, data sources, payment providers and other lawful sources.
7.4 Through APIs and integrations
Enterprise and API integrations may provide data to NDAPS or receive authorized NDAPS information, subject to the applicable agreement, API license, security controls and data protection requirements.
8. Purposes of processing
NIPOST may process Personal Data for purposes including:
- Providing postcode and address services;
- Validating and standardizing addresses;
- Administering user accounts;
- Processing authorized API requests;
- Maintaining database integrity and quality;
- Detecting and preventing fraud, abuse and security incidents;
- Maintaining system security;
- Processing payments for paid services;
- Providing customer support;
- Responding to complaints and enquiries;
- Complying with legal and regulatory obligations;
- Responding to lawful requests from competent authorities;
- Resolving disputes;
- Maintaining business and operational records;
- Improving service quality and functionality; and
- Sending marketing communications where legally permitted and where required consent has been obtained.
9. Lawful basis for processing
NIPOST determines and documents the lawful basis for each relevant processing activity in accordance with applicable Nigerian data protection law. Depending on the circumstances, lawful bases may include performance of a contract, compliance with a legal obligation, performance of a public function, legitimate interests, consent where required, protection of vital interests, and other lawful grounds recognized by applicable law.
10. Data minimisation
NIPOST seeks to collect and process only Personal Data that is reasonably necessary and relevant for the identified purpose, and periodically reviews whether Personal Data remains necessary for the purpose for which it was collected, taking appropriate action where data is no longer required, subject to applicable retention obligations.
11. Data sharing and disclosure
NIPOST may disclose or make Personal Data available to authorized:
- NIPOST personnel;
- Data Processors;
- Cloud and technology service providers;
- Payment service providers;
- Cybersecurity providers;
- Government agencies;
- Regulatory authorities;
- Law-enforcement authorities;
- Courts;
- Professional advisers;
- Enterprise customers;
- API customers; and
- Partners.
Such disclosure or access is limited to the purpose and scope authorized under applicable law and contractual arrangements. An organization does not obtain unrestricted access to Personal Data merely because it has an NDAPS integration. NIPOST does not sell or rent Personal Data for third-party marketing purposes.
12. Data Processors
Where NIPOST appoints a Data Processor, NIPOST seeks to ensure that the Processor:
- Processes Personal Data only for authorized purposes;
- Maintains appropriate confidentiality obligations;
- Implements appropriate technical and organizational security measures;
- Assists NIPOST with applicable data protection obligations;
- Reports on relevant security incidents;
- Complies with applicable restrictions on sub-processing; and
- Returns or securely deletes Personal Data where required.
Where applicable, NIPOST enters into an appropriate Data Processing Agreement.
13. International data transfers
Where Personal Data is transferred to, accessed from or processed in a jurisdiction outside Nigeria, NIPOST implements the safeguards and conditions required by applicable Nigerian data protection law — which may include an applicable adequacy mechanism, appropriate contractual safeguards, another legally recognized transfer mechanism, or another lawful mechanism permitted by applicable law.
14. Data retention
NIPOST retains Personal Data only for as long as reasonably necessary to fulfil the purpose for which it was collected, comply with legal and regulatory obligations, resolve disputes, maintain security, enforce agreements or protect legitimate operational interests. Specific retention periods are established under NIPOST's approved Data Retention and Disposal Schedule. When Personal Data is no longer required, NIPOST takes appropriate steps to securely delete, anonymize or otherwise dispose of it, subject to applicable legal requirements.
15. Data security
NIPOST implements appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, loss, destruction and other unlawful or unauthorized processing — including encryption, access controls, authentication mechanisms, role-based access control, least-privilege principles, logging and monitoring, vulnerability management, backup and recovery controls, network and physical security, staff confidentiality obligations and training, incident-response procedures, and oversight of third-party service providers. No electronic system can be guaranteed to be completely secure.
16. Data breach and security incidents
NIPOST maintains procedures for identifying, assessing, containing, investigating and responding to Personal Data breaches and other security incidents. Where a breach triggers notification obligations under applicable law, NIPOST will make the required notifications to the relevant regulatory authority and affected individuals where legally required. Users, employees, contractors and service providers must promptly report suspected Personal Data breaches or significant security incidents affecting NDAPS through designated security or data-protection channels.
17. Cookies and similar technologies
NDAPS may use cookies and similar technologies for essential website operation, authentication, security, functionality, analytics, service improvement, and marketing where applicable. Where consent is required for non-essential cookies, Users receive appropriate information and an opportunity to accept or decline, and may withdraw consent at any time. See the Cookie Policy for details.
18. Data subject rights
Subject to applicable law and relevant exemptions, Data Subjects may have rights including:
- Access to Personal Data;
- Rectification of inaccurate or incomplete Personal Data;
- Erasure where applicable;
- Restriction of processing where applicable;
- Data portability where applicable;
- Objection to certain processing;
- Withdrawal of consent where processing is based on consent; and
- The right to lodge a complaint with the relevant data protection authority.
Requests should be submitted to the Data Protection Officer at dpo@nipost.gov.ng. NIPOST may request information reasonably necessary to verify the identity of the requester and will respond to valid requests within the period required by applicable law.
19. Automated processing and decision-making
NIPOST may use automated tools to support functions such as address standardization, duplicate detection, data-quality assessment, security monitoring, fraud detection and service optimization. Where automated processing can produce a legal or similarly significant effect on a Data Subject, NIPOST applies the safeguards required by applicable law, including appropriate human oversight where required.
20. Children's privacy
NDAPS is not primarily directed at children. NIPOST processes Personal Data relating to children only where permitted by applicable law and where the relevant safeguards and, where required, parental or guardian authorization are in place.
21. Third-party websites and services
NDAPS may contain links to or integrations with third-party websites, applications or services. This Privacy Policy does not govern third-party services; Users should review the applicable third-party privacy notices and terms before providing Personal Data to such third parties.
22. Data quality and address corrections
NIPOST seeks to maintain accurate and reliable postcode and address-reference information through applicable data-quality, validation and maintenance processes. Users may submit address corrections or other data-quality reports through authorized NDAPS channels; submitted corrections may be subject to verification before being incorporated into the NDAPS Database, and submission of a correction does not guarantee that the requested change will be accepted.
23. Changes to this Privacy Policy
NIPOST may update this Privacy Policy from time to time. Where changes materially affect the way NIPOST processes Personal Data, NIPOST will provide appropriate notice before, or where legally permissible and reasonably necessary, promptly following the effective date of the change.
24. Contact and privacy complaints
Nigerian Postal Service (NIPOST)
Address: No 1 Nkwere Street, Off Mohammadu Buhari Way, Garki II, Abuja
Privacy Email: privacy@nipost.gov.ng
DPO Email: dpo@nipost.gov.ng
Complaints may also be submitted to the Nigeria Data Protection Commission through its officially designated channels:
Email: info@ndpc.gov.ng
Website: ndpc.gov.ng
25. Governing law
This Privacy Policy shall be interpreted in accordance with applicable laws of the Federal Republic of Nigeria, including applicable Nigerian data protection legislation and regulatory requirements.
