Naijagistonline Privacy Policy
Effective Date: August 1, 2025 | Last Updated: August 1, 2025
This policy complies with Nigeria's Nigeria Data Protection Act (NDPA) 2023 and global standards including GDPR and CCPA.
1. Data We Collect
When you use Naijagistonline.com, we may collect:
Data Category | Examples | Legal Basis |
---|---|---|
Personal Data | Name, email, phone number (for newsletter subscribers) | Explicit consent (Article 7 NDPA) |
Behavioral Data | Click patterns, reading duration, preferred categories | Legitimate interest (Article 19 NDPA) |
Technical Data | IP address, browser type, device fingerprints | Contractual necessity |
Special Note for Nigerian Users: We implement data localization for all .ng domain visitors as required by NCC regulations.
2. Cookie Policy
We use these cookie categories:
Essential Cookies
- Session Cookies: Maintain login state
- Security Cookies: CSRF protection
Analytics Cookies
- Google Analytics 4: Anonymized tracking (IP masking enabled)
- Hotjar: Behavior analytics (opt-out available)
Advertising Cookies
- Google AdSense: Interest-based ads
- Facebook Pixel: Conversion tracking
Cookie Consent Management: |
4. Data Retention Periods
We adhere to Nigeria's NDPB Retention Guidelines (2024):
Data Type | Retention Period | Deletion Process |
---|---|---|
User Account Data | 3 years post-account closure | Automated erasure via GDPR-compliant tools |
Newsletter Subscriptions | 2 years of inactivity | Quarterly database cleansing |
Comment Data | 5 years (Legal Defense Archive) | Manual review before deletion |
Backup Protocols
- Encrypted AWS S3 backups (Lagos region) retained for 90 days
- Anonymized analytics data kept indefinitely
5. Third-Party Data Processors
We engage these compliant processors under NDPA Article 25:
A. Advertising Partners
- Google Ad Manager: DPA | US-EU Privacy Shield
- Taboola Africa: Data localization in South Africa
B. Analytics Providers
- Google Analytics 4: IP anonymization enabled
- Hotjar: Opt-out instructions
C. Infrastructure Partners
- Amazon Web Services (AWS): Lagos data center
- Cloudflare: Global CDN with edge caching
Processor Audits: We conduct annual security assessments of all vendors.
6. Data Breach Response
In compliance with NDPA Section 43, our escalation matrix:
Response Timeline
- 0-24 Hours: Internal security team containment
- 48 Hours: Preliminary notice to NDPB
- 72 Hours: User notifications if high-risk impact
User Notification Content
All breach notices will include:
- Nature of compromised data
- Recommended protective actions
- Dedicated support contacts
Example Notification: View 2023 Incident Report
7. Cross-Border Data Transfers
Under Nigeria Data Protection Regulation (NDPR) Implementation Framework 2023:
Approved Transfer Mechanisms
- EU Standard Contractual Clauses (SCCs)
- Binding Corporate Rules for intra-group transfers
- NDPB White-listed Countries (Ghana, Kenya, Rwanda)
Explicit Consent Requirement
For transfers outside approved jurisdictions, we obtain:
- Two-factor authentication for consent confirmation
- Clear disclosure of destination countries
- Right to withdraw via Consent Dashboard
9. Contact Our Data Protection Officer
By Email: dpo@naijagistonline.comBy Post: Data Protection Office, Naija Gist Online.
Abuja, Nigeria.
Response Time: Within 72 hours for NDPA-related requests
By continuing to use Naijagistonline.com, you acknowledge you've read and understood this Privacy Policy.
We use cookies in compliance with NDPA 2023. Learn more