Plateau State data breach? Here’s what Nigerian entrepreneurs actually need to do
💡 律咖编者按:
本文由律咖网社群读者 Tianjiexing 投稿分享。
为了方便大家阅读,律咖网编辑 JingJing(微信:lvga2015)对原文进行了细致的逻辑润色与合规性整理。希望能给正在 尼日利亚 创业路上的你带来真实的参考。
I’m 59. From Jinan. Studied e-commerce in Harbin. Sold portal cranes in Shandong for 30 years. Then I came to Nigeria.
I didn’t come for the sun. I came because the market here doesn’t care if you’re old, Chinese, or speak broken Pidgin. It only cares if you show up with paperwork that doesn’t look like a child’s doodle.
Last month, I was in Plateau State — not for tourism, not for the cool weather — I was chasing a contract with a state-owned logistics firm. While waiting for the finance director to finish his tea and his “nobody touches my files” speech, I saw his assistant copy a client’s ID onto a USB stick… and plug it into a Windows XP machine in the corner.
No password. No encryption. No firewall. Just a dusty CRT monitor blinking “Welcome back, Admin.”
I didn’t say a word. But inside? I wanted to scream.
Because this isn’t just bad practice.
This is how data breaches start.
And in Nigeria, when data leaks, it doesn’t just cost you customers.
It costs you your life.
The Real Risk Isn’t Hacking — It’s Human Laziness
I’ve seen it everywhere: Lagos, Kano, Jos, Port Harcourt.
A Nigerian SME owner hands his client’s passport scan to his nephew who “knows computers.” The nephew saves it in a folder called “clients 2026” on his phone, then uploads it to a free Google Drive account because “it’s easier.”
No NDPR compliance. No data retention policy. No staff training.
And yet, when the ICPC released its list of 30 wanted persons last week — names, photos, even home addresses — I didn’t see headlines screaming “Data exposed!” I saw headlines screaming “Criminals caught!”
Funny, isn’t it?
The same people who complain about corruption don’t realize they’re feeding it.
In Plateau State, I talked to a local accountant who told me his firm keeps 12 years of client tax records in a single Excel sheet — with names, bank account numbers, BVNs, and even copies of marriage certificates — on a laptop that’s been used in three different markets since 2018.
I asked him: “What if that laptop gets stolen?”
He shrugged. “Then I’ll make another copy.”
That’s not negligence.
That’s suicide with paperwork.
And here’s the truth nobody wants to admit: Nigeria’s data protection law (NDPR) is not the problem.
The problem is the belief that “it won’t happen to me.”
It already has.
In 2025, a Lagos fintech startup lost 87,000 client records after an intern used the same password for his Gmail, WhatsApp, and company database. The hacker sold the data on Telegram. One client lost ₦2.3 million in 48 hours.
No one filed a police report.
Why?
Because they were too ashamed.
What You Actually Need to Do — Not the Theory, the Steps
I’m not a lawyer. I’m not a tech guy. I’m a crane salesman who learned the hard way that if your paperwork looks like a Nigerian government form from 2003, you won’t get paid.
Here’s what I did after seeing that XP machine in Plateau State:
1. Stop using phones or USBs to store client data
- Use encrypted cloud storage only: Proton Drive or Tresorit (not Google Drive, not Dropbox).
- Enable two-factor authentication on every account.
- Never email PDFs of IDs or bank statements. Use a secure portal like DocuSign or SignNow — even if the client says “Just send it by WhatsApp.”
2. Create a “Data Handling Policy” — one page, in English and Pidgin
- Example:
“All client documents must be stored in encrypted folder ‘CLIENTS_2026’ on company laptop. No copies on phones. No sharing via WhatsApp. All access logged. Violation = immediate suspension.”
- Print it. Put it on the wall. Make every staff member sign it.
3. Train your staff — even the cleaner
- In Nigeria, your cleaner might be the one who finds your laptop left on the table after a meeting.
- I paid a local IT guy ₦15,000 to do a 30-minute session:
- “Don’t plug in unknown USBs.”
- “If someone asks for your password, say ‘I don’t know it.’”
- “If you see a stranger taking photos of your screen, call the police — not your cousin.”
4. Keep a physical logbook — yes, paper
- In Plateau State, power cuts are daily. Internet? Sometimes.
- I keep a bound notebook:
- Date | Client Name | Document Type | Who Accessed | Time | Signature
- If someone steals your laptop, this logbook is your proof you were responsible.
5. Know your legal exit route
- If you suspect a breach:
→ Contact the National Information Technology Development Agency (NITDA) via their portal: https://www.nitda.gov.ng
→ File a report using Form NDPR-01 (available on their site)
→ Notify affected clients within 72 hours — even if you’re not sure what was leaked
→ Do NOT wait for the police. They won’t help.
This isn’t about being “tech-savvy.”
This is about being responsible.
I’m 59. I didn’t learn this from a webinar. I learned it because I almost lost a $400,000 contract because the state government thought my company didn’t take data seriously.
I fixed it. I got the contract.
Now I tell every Chinese trader I meet:
“If you can’t protect data, you can’t do business here.”
❓ FAQ: What Should I Do Right Now?
Q1: I store client data on my phone. What’s the first step to fix this?
A:
- Install Proton Drive (free version) on your phone.
- Transfer all client documents from your phone gallery to Proton Drive.
- Delete the originals from your phone.
- Set a 6-digit passcode + biometric lock on your phone.
- Send each client a secure link via Proton Mail — not WhatsApp.
Q2: My Nigerian partner says “We don’t need this stuff.” What do I do?
A:
- Print your Data Handling Policy in English and Pidgin.
- Put it on the table during your next meeting.
- Say: “This is what my Chinese bank requires before they release funds to your account.”
- If they still refuse — find another partner.
- In Nigeria, trust is earned. But compliance? That’s non-negotiable.
Q3: Where do I report a data leak if I’m in Plateau State?
A:
- Go to NITDA’s official reporting portal: https://www.nitda.gov.ng/report-a-breach
- Fill out Form NDPR-01 — include:
- Date of breach
- Type of data exposed (e.g., names, BVNs, bank details)
- Number of affected clients
- Steps taken to contain it
- Email a copy to compliance@nitda.gov.ng
- Keep the confirmation number.
- Do not wait for “official response.” Your report is your shield.
Final Advice — From a 59-Year-Old Who’s Seen Too Much
I used to think Nigeria was about big contracts and big machines.
Now I know it’s about small habits.
The way you store a client’s ID.
The way you answer a phone call from someone claiming to be from “the tax office.”
The way you say “no” when someone asks to borrow your laptop.
Data isn’t just information.
In Nigeria, data is power.
And if you don’t protect it, someone else will use it to steal from you.
I didn’t come here to be a tech guru.
I came to sell cranes.
But if I can’t trust that your documents aren’t sitting on a USB stick in a dusty office — then I won’t sign your contract.
And you won’t get paid.
Simple.
🔸 延伸阅读
🔹 ICPC lists 30 wanted persons in Nigeria, releases names and photos 🗞️ 来源: Legit – 📅 2026-06-05
🔗 阅读原文
🔹 Nigeria Cholera Outbreak: Situation Report #2 (June 4, 2026) 🗞️ 来源: ReliefWeb – 📅 2026-06-04
🔗 阅读原文
🔹 Gunmen kidnap seven students from school in northwestern Nigeria 🗞️ 来源: The Hindu – 📅 2026-06-05
🔗 阅读原文
请知悉:律咖网(Lvga.com)是跨境创业公开信息与内容分享平台,不提供法律、税务、会计或合规服务。
本文内容基于公开资料,并由人工编辑与 AI 工具协助整理,仅供信息参考之用,不构成任何法律、投资、移民或商业决策建议。
政策可能随时间变化,请以官方渠道与当地持牌专业人士意见为准。
如内容有需要修订之处,欢迎随时与我联系。
如果你也在尼日利亚,正为数据安全、合同签署、员工管理头疼 ——
JingJing 在律咖网帮过几百个像我一样的老外。
她不卖服务,不承诺结果,只分享真实经验。
加她微信:lvga2015
备注:“Plateau 数据” —— 她会拉你进我们的跨境创业群。
我们聊的不是暴富,是活下来。
