DD
MM
YYYY

PAGES

DD
MM
YYYY

spot_img

PAGES

Home Blog Page 6242

Securing Personal Data: The Data Subject’s Responsibilities and Rights

2

When we walk on sand, lands and in the air, we leave footprints that don’t last long before they are wiped away. The walk on the internet leaves footprints that are hard to clear. These footprints are not just ordinary things but expensive information. 

These footprints are called Personal Data. According to the extant Data protection regulations in the different jurisdictions of the world, Personal data includes all information that identifies and is peculiar to a person. 

Personal data include but not limited to the following :

  • Names, Date of birth, gender, relationship status, nationality, ID number and location data 
  • Online Identifiers such as email,social media posts, IP address, Mac addresses, SIM etc
  • Bank Information such as pin, cvv, card number etc. 
  • Personal Pictures and videos 
  • All information specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. These may consists of walking style, religious beliefs, voice, style of doing things, patterns, habits etc 

In addition to the above are data that relates to the personal data i.e. information that indirectly relate to a person.

All these are expected to be protected by the Data Controllers (Any Organization that collects these data from Persons). This is the aim of the different Data Protection regulations. 

However, we data subjects have roles to play. We can decide in whose hands our data goes. I mean guarding and watching our steps online. (whether we like it or not our personal data will still be processed online for one important reason or the other).

Should we now share data anyhow because we know there’s GDPR, NDPR and others? Of course no. 

Data Subjects Responsibilities/ Cybersecurity Tips 

  1. Never share personal data on unsecured sites. Sites without the padlock sign or site with HTTP without S behind it
  2. Don’t insert important data on sites you personally don’t trust. Trust your instincts. 
  3. Don’t be too open on social media platforms. I mean practice a little bit of privacy. You don’t need to talk about everything in your life. 
  4. Secure your passwords, don’t just write it on paper and don’t use weak passwords. Check out my pinned tweet for more on that.
  5. Browse on incognito mode while using external Wi-Fi or use a trusted VPN to stay secure.
  6. Stay away from Apps from untrusted sources. 
  7. Don’t just click on every link you see. Read my thread on demystifying fraudulent URL
  8. Update your Apps and use genuine antivirus 
  9. I know this is hard, don’t allow a flash drive into your PC. 
  10. Don’t leave your mobile devices in untrusted hands locked or unlocked. 
  11. If you discover your device is operating itself. Talk to the IT guys as fast as possible. 
  12. Just like 2 above, never put your data on a site that your browser has warned you of its insecurity. You should not even go there as such may expose you to attack.
  13. Control your cookies settings in your browser. Don’t just agree to any user policy of apps or sites.

I always like to say that you should use your common sense online.  Before you post your personal life issues, ask yourself if this is necessary. All those personal stories carry your data which can be used against you later.

 Note that this post is not to be taken as a professional advice. Also it is not in any way reducing the responsibilities of Data processors and controllers in securing personal data. 

Personal Data Rights

Since we are well aware of our personal data, it is necessary we know what rights the data protection regulations provide us. I will look at the major rights provided by the GDPR, NDPR and CCPA. 

If you are giving out your data to a company, agencies or even NGOs, the data protection regulations recognize the fact that your data is just you and as you have certain inalienable rights so also your personal data. In essence your data is you going where you can’t go.

Let’s look at these rights in seriatim

  1. Right to be informed 

Most data protection regulations (I know of GDPR, CCPA & NDPR) provide that the data subject has a right to be informed of what data is collected, what it is used for and how such will be processed. The data controllers cannot collect or process data contrary to the information given to the data subject. 

Also, if a third party will have access to the personal data, the data subject must be informed. In essence you must know how your data is being processed. 

  1. Right to Erasure 

This is also called the right to be forgotten. It means you can request that your data in the hands of  the data controllers, processors and third parties be pulled away from the internet and deleted.

There are exemptions to this right

Exemptions to right to erasure includes:

  • Where such erasure infringes Freedom of expression 
  • Research purposes e.g. health research 
  • In compliance with legal obligation
  • Establishment and defense of legal claims 
  1. Right to object / opt-out

Data subjects can oppose the use of their data partially or totally. This can come in withdrawal of consent or objecting to use of data for direct marketing .

In fact the CCPA provides that business must provide a link caption “Do not sell my personal information “. In essence consumers have the right to opt-out from the selling of their personal information. 

GDPR only provides that data subjects can oppose the processing of data unless data controllers can demonstrate that such is legitimate. It is silent on restriction of selling of data.

  1. Right to Access

Data subjects can request to have access to all personal data the data controllers hold about them. Whether such was freely given, obtained or generated in the course of transactions or modified version of the one freely given. 

In answering, data controllers must state the categories of data, the purposes of the processing, recipients of such data(third parties)  and sources from which those data were generated.

  1. Right to Rectification

Data Subjects can request that errors in their personal data be rectified by the data controllers. Requests can be made orally or in writing.

Available in both GDPR & NDPR. 

Not provided by CCPA

  1. Right to Data portability 

Both GDPR and NDPR provide explicitly that data subjects can request that their data be given to them in a written or electronic format. It allows them to copy or move such data to be used in other services.

CCPA groups this under Right to access.

  1. Right to Restrict Data Processing

Data subjects can decide to restrict the way their data is being processed or used. It is not absolute but applicable in certain situations. Data controllers can still keep the data. 

GDPR & NDPR provide for such. Not applicable in CCPA

  1. Rights related to automated related decision making and profiling 

Both GDPR & NDPR implicitly provide for data subjects to know and restrict automated decision being made through their data. 

CCPA is silent on this.

Note that all the personal data rights are applicable to data collected on hard copy forms as well as online. So data collected during medical consultation, financial analysis etc are covered. It is easy to assume that data rights only covered data submitted online, this is a wrong assumption. Data protection also covers orally delivered data also. 

Now, that you know your personal data rights, you can take action for any breach of your data. Remember, only give out data when important. Data protection cannot enforce your right where you give it to a Con Artist.

Keep staying safe online! 

(This article was collated from two different threads by the author on Twitter on June 12 and 26, 2020. The author does a bi-weekly thread on cyber security and data protection issues on twitter.) 

GTBank’s Segun Agbaje Joins PepsiCo Board

0

Nigerian banking prodigy Segun Agbaje has joined the board of PepsiCo. The Guaranty Trust Bank managing director was announced on Wednesday as the newest member of the PepsiCo board in a statement issued by the company through Nasdaq website.

“I am delighted to welcome Segun to the PepsiCo Board,” said PepsiCo Chairman and CEO, Ramon Laguarta. “Segun is a well-respected and proven business leader with a deep understanding of complex businesses and fast-growing markets, particularly Sub-Saharan Africa where we recently acquired Pioneer Foods as part of our strategy to expand in the region.

“His experience in business transformation and passion for delivering consumer value will serve PepsiCo well as we continue our journey to be the global leader in convenient foods and beverages by winning with purpose.”

Prior to becoming Managing Director and Chief Executive Officer of Guaranty Trust Bank plc in 2011, Agbaje held several positions at the bank after joining in 1991, including Executive Director and most recently Deputy Managing Director from 2002 to 2011. Previously, Agbaje served as an auditor for Ernst & Young LLP in the United States from 1988 to 1990.

“We look forward to Segun joining the PepsiCo Board and to the valued global perspective he will add to our team,” said Daniel Vasella, chair of the Board’s Nominating and Corporate Governance Committee. “His knowledge and experience of embracing and scaling new technologies and critical capabilities will be valuable as we continue to invest in opportunities that create shareholder value and deliver long-term sustainable growth.”

Agbaje also currently serves as a director of MasterCard Advisory Board Middle East and Africa. He holds a Bachelor of Science in Accounting and a Masters in Business Administration from the University of San Francisco.

Under his leadership, the Guaranty Trust Bank has become one of the biggest financial institutions in the world, having over N4.057 trillion asset base. The bank has grown to have branches in Cote d’ivoire, Kenya, Liberia, Gambia, Ghana, Rwanda, Tanzania, Uganda, the United States and the United Kingdom.

About PepsiCo

PepsiCo products are enjoyed by consumers more than one billion times a day in more than 200 countries and territories around the world. PepsiCo generated more than $67 billion in net revenue in 2019, driven by a complementary food and beverage portfolio that includes Frito-Lay, Gatorade, Pepsi-Cola, Quaker and Tropicana. PepsiCo’s product portfolio includes a wide range of enjoyable foods and beverages, including 23 brands that generate more than $1 billion each in estimated annual retail sales.

INNOVATE. LEAD. ADVANCE. Register for Tekedia Mini-MBA

0

Invent, innovate and drive organizational transformation, performance, and growth. Capture emerging opportunities in changing markets while optimizing innovation and profitability. Digitally evolve your business or functional area, turning digital disruption into a competitive capability and advantage. Master the concepts of building category-king companies, and thrive.

INNOVATE. LEAD. ADVANCE. You will emerge transformed with tools and capabilities that engineer confidence, performance and growth. Accelerate your leadership ascent with us and have access to speak with me on your career and professional development!

Register for Tekedia Mini-MBA edition 3 (Aug 10 – Dec 3) today (early bird ends soon). Click and join us

https://www.tekedia.com/mini-mba-3/

The Need for Morality Checks in Leadership Selection

0

On May 20, 2020, a young South African woman lost her chance of being the 2020 Miss South Africa. Miss Bianca Schoombee from Pretoria was dropped out of the list of contestants as a result of her past posts on Twitter. These posts were dug out by Twitter users, who wanted to show that Miss Schoombee was not who she claimed to be. The posts that were dug out were her careless racial and derogatory comments, which she posted when she was a teenager. Even though she apologised for her youthful mistakes and claimed to have changed, South Africans will have none of her. They wanted her out, and she was thrown out.

One may wonder why South Africans did not let go of her past mistakes. Well, one of the reasons why they succeeded in removing her was because the rules for participation in the pageant states that those that have been involved in disrepute, unsavoury or unethical conducts such as racism, bribery, sexism, slander and libel, will be disqualified. Unfortunately for Schoombee, she was found guilty of some of these offences.

Now, you may ask yourself why South Africa bothers itself so much with all these rules for something “as trivial as” choosing a beauty queen. I am not a South African, but I can tell that the major reason for postulating all these is to ensure that whoever takes up the mantle of leadership has no past that might compromise her position as a leader. They want to make sure that whoever wears that crown will be worthy of emulation. In fact, those rules will give room for real and honest leaders to take up that position.

Now, let’s bring this discussion to Nigeria.

The moment I read about this young lady’s disqualification, I told myself that her “crimes” will not even be considered offensive in Nigeria. As disheartening as it may sound, Nigerians, or rather, many Nigerians celebrate crime and mediocrity. We have this issue of “lesser evil” or “the devil you know” ideologies. We tell ourselves, “let’s manage him” and thereby wave off red alerts that glaringly show corruptions, poor leadership and mismanagement.

If you look around the leadership of Nigeria today, you will agree with me that almost all of our public office holders have one scandalous past or another that is shouting at the top of its voice to notify us of what we will face if the person assumes office. But we ignore that voice with the statement, “who better pass” or “all of them are the same”. By the end of the day, we will sit down in one corner and wonder what we got ourselves into.

I tried to find out why Nigeria constitution allows people with questionable characters to be elected into office. I realised that anyone who, within the past ten years, has not been convicted of a crime of dishonesty or that which contravenes the code of conduct, is free to contest. I also found out that if there is no proof that you belong to a secret society, you can carry on with contesting for a position. These are just among the many requirements for contesting elections that needed review.

If you consider these two mentioned requirements, you will notice that they may not prevent the wrong persons from assuming offices. For instance, it is inappropriate for someone that has been convicted of corruption in the past to assume public office because the conviction happened more than ten year ago. What evidence do we have to show that the person has changed? What about his or her past associates? How do we know that they are no longer in contacts?

Of course, all these things were overlooked by Nigerians and that is why corruption will never leave this country, no matter how hard we try. Believe me, if Nigerian constitutional requirements for contesting elections could be a little bit modified to resemble closely that of Miss South Africa Beauty Pageant, we will have hope in Nigeria. All I am trying to say here is that the constitution should stipulate that anyone that has a shady past, whether convicted or not, should be disqualified immediately. Maybe by doing so, contestants that were cultists while in university and those that have been indicted for misappropriation of funds will be removed. Only then, will Nigeria have hope.

OPEN LETTER: How Eduwalt Concierge, an agency facilitating Students’ movement to Canada, collected N200,000 without providing agreed Service

2

When getting the needed education at secondary and tertiary levels becomes difficult, parents and guardians and individuals consider countries where the expected education could be provided. However, most admission seekers and their parents usually consider educational consultants. As news reports indicate in the last few years, many people have been duped by agents or consultants. For instance, in 2018, a news report has it that a travel consultant issues fake Canadian admission letters to 22 students.

The story of Adetula Segun Augustine is not quite different from the 22 students. In 2019, in his efforts of seeking further education in Canada, he approached Eduwalt Concierge at its Ibadan branch for the facilitation of his movement to Canada. The company collected N200,000 as professional fees, which was paid immediately into the company’s account details. For more than four months, the company repeatedly notified him that his admission has not been successful.

“I got to know about the company in March, 2019 through their communication materials and I went into a transaction with them on June 26, 2019. After the engagement at their office located at 12th Floor, Cocoa House, Ibadan, I was told that the visa processing would be concluded within two months. But, to my surprise nothing was forthcoming and this made me to get worried. I started asking for what exactly was the issue.”

Segun informed that it was later clear that the company relocated to another place after efforts to get them at Cocoa House. “I went to their office sometimes in October, 2019 and was told they have left to another location without informing their clients. I later tried to locate them to Opposite First Bank Polytechnic Road, Eleyele, Ibadan, through one of their staff. When I got there, I met them with another name (SNOWFOX). They apologized to me about the sudden change of office location and promised my admission and visa would be ready by the end of November, 2019. When nothing was forthcoming, on January 27, 2020, I sought for refund of N200,000 I paid into their Zenith Bank Account (Eduwalt Concierge Limited; 10151725216). Till this day (9/7/2020), I am yet to get my refund. All entreaties to get the refund has proved abortive. The known employees of the company keep referring me to the Head Office in Lagos, located at Lekki.”

Segun wants the Federal Complaint and Consumer Protection Commission and relevant anti-crime agencies to help locate the underlisted employees and intervene in the matter.

  1. Mr Fred Ojemaye, Managing Director, Lagos (08143746550)
  2. Mr Spencer, Branch Manager, Ibadan (08036315905)
  3. Francis, General Manager, Lagos (08165209698)
  4. Office Mobile Number (+2347002225222)

Supporting Evidence