Privacy Policy

Privacy Policy Information

What information do we collect?

When you interact with us, we may collect your name, address, email address(es), telephone number(s), and, where appropriate, date of birth.

How do we collect information?

We may collect information about you whenever you interact with us. For example, when you contact regarding our activities, register as a supporter, send or receive information or sign a petition, you specifically and knowingly provide us with your personal information. We may also receive information about you from third parties – but only if you have given them permission to share your information.

Confidentiality

We will not be responsible for the privacy of data collected by websites not owned or managed by Charity, including those linked through our website.

Making a complaint

If you are not satisfied with the response, please contact us at eagle-elite@email.com with the details explaining your concerns. We will review your complaint and investigate if the right procedures have been followed and respond back to you as appropriate. We aim to complete this investigation within 15 working days of receiving your complaint, however, in some cases it may take longer. If you are still unsatisfied with the response, you may contact us.

 

Executive Privacy Notice
The Chartered Institute of Directors Nigeria (“CIoD Nigeria,” “we,” “our,” or “us”) is committed to protecting the privacy and personal data of our members, visitors, trainees, event attendees, website users, and all other individuals who interact with us. This Privacy Notice explains how we collect, use, disclose, and safeguard your personal data in compliance with the Nigeria Data Protection Act, 2023 (NDP Act) and the General Application and Implementation Directive (GAID) issued by the Nigeria Data Protection Commission (NDPC).
By engaging with CIoD Nigeria—whether through our websites, events, training programmes, membership services, or other interactions—you entrust us with your personal data. We take this responsibility seriously and are dedicated to maintaining transparency, accountability, and the highest standards of data protection.
Key points of this notice:
  • We collect personal data only for specified, explicit, and legitimate purposes
  • We process your data based on lawful bases as defined by the NDP Act, 2023
  • You have rights over your personal data, including access, rectification, and erasure
  • We implement robust security measures to protect your information
  • We do not sell your personal data to third parties
We encourage you to read this full notice carefully. If you have any questions, please contact our Data Protection Officer using the details provided in Section 12.
  1. About CIoD Nigeria
The Chartered Institute of Directors Nigeria is the apex professional body representing directors in their individual capacities across all sectors of the Nigerian economy . Founded on 17 May 1983, CIoD Nigeria has been at the forefront of promoting good governance practices in Nigerian companies and the public sector .
Our mission is to strengthen the professional capacity of directors, business leaders, technocrats, and senior public servants through internationally recognised Director Development Programmes, advocacy, and the promotion of ethical leadership and corporate governance .
In carrying out our activities, we process personal data of various individuals, including:
  • Members (across our membership categories)
  • Training and event participants
  • Job applicants and potential employees
  • Stakeholders, partners, and service providers
  • Visitors to our offices
As a data controller under the NDP Act, 2023, we determine the purposes and means of processing personal data and are accountable for ensuring compliance with all applicable data protection laws.
  1. Personal Data We Collect
We collect personal data that is necessary for our legitimate activities and to fulfil our obligations to you. The categories of personal data we process include:
2.1 Identity and Contact Information
  • Full name
  • Title and professional designation
  • Date of birth
  • Gender
  • Nationality
  • Contact address (residential and business)
  • Email address
  • Telephone and mobile numbers
  • Professional affiliations and memberships
2.2 Professional and Membership Information
  • Employment history and current position
  • Organisation name and industry sector
  • Board memberships and directorships
  • Professional qualifications and certifications
  • Membership category and history with CIoD Nigeria
  • Continuing Professional Development (CPD) records
  • Performance and attendance records for training programmes
2.3 Financial and Payment Information
  • Bank account details for payments or refunds
  • Payment card information (processed securely through third-party payment processors)
  • Billing and invoicing information
  • Transaction history for memberships, events, and training programmes
2.4 Technical and Usage Data (Website and Portal)
  • Internet Protocol (IP) addresses
  • Browser type and version
  • Operating system and device information
  • Referring website URLs
  • Pages visited, time spent, and navigation patterns
  • Cookies and similar tracking technologies (see Section 9)
2.5 Communication and Interaction Data
  • Correspondence with CIoD Nigeria (emails, letters, phone calls)
  • Feedback and survey responses
  • Enquiries and complaints
  • Social media interactions with our official accounts
2.6 Event and Training Data
  • Registration details for events, conferences, and training programmes
  • Photographs and videos taken at events (with consent where required)
  • Participation records and assessment results
2.7 Sensitive Personal Data
In limited circumstances, we may process sensitive personal data (known as “special categories” of data under the NDP Act), such as:
  • Health information (e.g., dietary or accessibility requirements at events)
  • Biometric data (e.g., photographs for identification purposes)
Where we process such data, we will obtain your explicit consent or rely on another lawful basis as permitted by the NDP Act, 2023.
  1. How We Collect Personal Data
We collect personal data through various channels and interactions:
3.1 Direct Collection from You
  • When you register for membership or renew your membership
  • When you apply for or participate in training programmes, events, or conferences
  • When you make payments for our services
  • When you subscribe to our newsletters, publications, or updates
  • When you contact us for information, support, or complaints
  • When you complete surveys or provide feedback
  • When you submit job applications or expressions of interest
3.2 Automated Collection
  • Through log files and server monitoring
  • Through the use of our ERP portal
3.3 Collection from Third Parties
  • From employers or organisations nominating you for membership or training
  • From event partners or co-organisers
  • From payment service providers (e.g., Flutterwave, paystack) 
  • From publicly available sources for professional and business purposes
  • From regulatory bodies and professional associations (with your consent or as permitted by law)
3.4 Collection from Other Sources
  • Information provided by your employer or organisation for corporate membership or sponsorship arrangements
  • Information received during our advocacy, policy, and stakeholder engagement activities
  1. Purposes of Processing
CIoD Nigeria processes your personal data for the following purposes:
4.1 Membership Management
  • Processing membership applications, renewals, and resignations
  • Maintaining and updating membership records
  • Issuing membership certificates and credentials
  • Collecting membership fees and managing subscriptions
  • Communicating membership benefits, services, and updates
4.2 Training and Professional Development
  • Registering participants for Director Development Programmes and events
  • Managing attendance, assessments, and certification
  • Issuing CPD credits and certificates
  • Customising training content based on professional needs
  • Evaluating and improving training programmes
4.3 Event Management
  • Organising and managing conferences, seminars, and networking events
  • Processing event registrations and payments
  • Managing venue logistics, catering, and accessibility needs
  • Facilitating networking opportunities among participants
  • Communicating event information and updates
4.4 Communication and Public Relations
  • Sending newsletters, publications, and industry updates
  • Informing you of events, training, and other opportunities
  • Sharing information about corporate governance developments
  • Responding to your enquiries and requests
  • Managing our social media presence and engagement
4.5 Website and Portal Operations
  • Operating and maintaining our websites and ERP portal
  • Managing user accounts and access controls
  • Improving user experience and website functionality
  • Analysing website usage to optimise content and services
  • Ensuring the security of our digital platforms
4.6 Advocacy and Policy Engagement
  • Supporting our advocacy initiatives on corporate governance
  • Engaging with policymakers and stakeholders on relevant issues
  • Representing members’ interests at national and international levels
  • Contributing to research and publications on governance
4.7 Administrative and Compliance Purposes
  • Maintaining financial records and accounts
  • Auditing and compliance with legal and regulatory requirements
  • Managing risks and insurance
  • Processing complaints and disciplinary matters
  • Ensuring the security of our premises, data, and systems
4.8 Research and Development
  • Conducting research on corporate governance and director development
  • Analysing trends and needs of our membership
  • Developing new programmes and services
  • Measuring the impact and effectiveness of our activities
  1. Lawful Bases for Processing
In compliance with the Nigeria Data Protection Act, 2023, we process personal data only when we have a lawful basis to do so . The lawful bases we rely on are:
5.1 Consent
We process your personal data based on your explicit consent for specific purposes, including:
  • Sending you promotional and marketing communications
  • Processing sensitive personal data (e.g., health information)
  • Using cookies and tracking technologies (where consent is required)
  • Publishing photographs and videos from events
Article 19 of the GAID specifies that consent to cookies and other tracking tools must be obtained in a manner that is freely given, specific, informed, and unambiguous . You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5.2 Contract
We process personal data when necessary for the performance of a contract with you, including:
  • Membership contracts and agreements
  • Training and event registration contracts
  • Service agreements with partners and service providers
Article 21 of the GAID confirms that reliance on contract as a lawful basis is appropriate where processing is necessary for the performance of a contract to which you are a party .
5.3 Legal Obligation
We process personal data to comply with legal and regulatory obligations, including:
  • Tax and financial reporting requirements
  • Anti-money laundering and counter-terrorism financing obligations
  • Compliance with court orders and regulatory investigations
  • Reporting obligations to the Nigeria Data Protection Commission
Article 22 of the GAID provides that reliance on legal obligation is justified where processing is necessary for compliance with a legal obligation to which we are subject .
5.4 Legitimate Interests
We process personal data where it is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your rights and freedoms . This includes:
  • Improving our programmes, services, and membership experience
  • Promoting corporate governance and director development
  • Conducting research and analysis
  • Ensuring the security of our operations and data
  • Engaging in advocacy and policy activities
Article 26 of the GAID requires us to evaluate the legitimate interests basis carefully, ensuring that our interests are balanced against your rights and freedoms .
5.5 Public Interest
We may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us. This relates to our role in promoting corporate governance and professional standards in Nigeria.
  1. Sharing and Disclosure of Personal Data
CIoD Nigeria may share your personal data with third parties in the following circumstances:
6.1 Service Providers and Partners
We engage trusted third-party service providers to assist with our operations, including:
  • Payment processors (e.g., Flutterwave for online payments) 
  • IT service providers and website hosting
  • Event management and logistics companies
  • Training partners and facilitators
  • Marketing and communications agencies
  • Legal and accounting professionals
All service providers are contractually obligated to process personal data only on our instructions and in accordance with applicable data protection laws. We require them to implement appropriate security measures.
6.2 Professional and Regulatory Bodies
We may share personal data with:
  • The Nigeria Data Protection Commission (NDPC) for compliance purposes
  • Professional associations and regulatory bodies relevant to our activities
  • Government agencies where required by law
6.3 Event and Training Participants
In the context of events and training programmes, we may share limited participant information (such as names, titles, and organisations) with other attendees for networking purposes. You will be informed of this at the time of registration.
6.4 Legal and Compliance
We may disclose personal data where required by law, regulation, or legal process, including:
  • In response to court orders or regulatory investigations
  • To enforce our terms and conditions
  • To protect the rights, property, or safety of CIoD Nigeria, our members, or others
6.5 Business Transfers
In the event of a merger, acquisition, or reorganisation, we may transfer personal data to the successor entity, subject to compliance with applicable data protection laws.
6.6 With Your Consent
We will share your personal data with third parties when we have obtained your explicit consent for such sharing.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
  1. International Data Transfers
CIoD Nigeria is committed to ensuring that your personal data is protected when transferred outside Nigeria. In the course of our activities, we may transfer personal data to recipients in other countries for purposes such as:
  • Collaborating with international professional bodies and partners
  • Using cloud-based IT services and platforms
  • Engaging international training facilitators or consultants
Article 45 of the GAID provides guidance on cross-border data transfer . We ensure that any international transfer of personal data is carried out in compliance with the NDP Act, 2023, including by:
  1. Transferring only to countries with adequate data protection laws that provide a level of protection comparable to Nigeria’s standards
  1. Implementing appropriate safeguards, such as Standard Contractual Clauses approved by the NDPC
  1. Obtaining your explicit consent where required
  1. Conducting Data Privacy Impact Assessments for higher-risk transfers
  1. Ensuring that third parties processing data on our behalf adhere to the same data protection standards
We recognise that transfers to jurisdictions with weaker data protection may involve risks, including increased exposure to unauthorised access, limited recourse for data breaches, and inadequate security measures. We take steps to mitigate these risks through contractual safeguards and security measures.
  1. Data Security
CIoD Nigeria implements robust technical, administrative, and physical security measures to protect your personal data against unauthorised access, loss, destruction, alteration, or disclosure. These measures include:
8.1 Technical Measures
  • Encryption: Data is encrypted in transit (using TLS/SSL protocols) and at rest
  • Access Controls: Role-based access control (RBAC) ensures only authorised personnel have access to personal data
  • Authentication: Multi-factor authentication (MFA) for access to our systems
  • Firewalls and Intrusion Detection: Network security measures to prevent unauthorised access
  • Regular Security Testing: Vulnerability assessments and penetration testing
  • Audit Logging: Monitoring and logging of all access to personal data
8.2 Administrative Measures
  • Data Protection Policies: Comprehensive policies and procedures governing data handling
  • Staff Training: Regular training on data protection and privacy for all personnel
  • Data Processing Agreements: Contractual obligations on our service providers to maintain data security
  • Data Privacy Impact Assessments: Conducted for high-risk processing activities
  • Incident Response Plan: Procedures for detecting, reporting, and responding to data breaches
Article 29 of the GAID mandates the monitoring, evaluation, and maintenance of data security systems . We are committed to complying with this requirement and regularly reviewing our security practices.
8.3 Physical Security Measures
  • Secured Premises: Physical access controls at our offices
  • Document Security: Secure storage and disposal of physical records containing personal data
  • Device Security: Management of devices used for processing personal data
Article 32 of the GAID requires measures against privacy breach abetment . We ensure that our security measures protect against both internal and external threats.
8.4 Data Breach Notification
In the event of a data breach that may compromise your personal data, we will:
  • Notify the Nigeria Data Protection Commission within 72 hours of becoming aware of the breach (as required by Article 33 of the GAID
  • Communicate with affected data subjects where the breach is likely to result in a high risk to your rights and freedoms
  • Provide information about the breach, its potential consequences, and any mitigation measures taken
  1. Data Retention
CIoD Nigeria retains personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal and regulatory obligations, and to protect our legitimate interests.

9.1 Retention Periods

Our retention periods vary depending on the type of data and the purpose of processing. For example:

9.2 Retention Criteria
When determining retention periods, we consider:
  • Legal requirements (e.g., tax and financial reporting laws)
  • Regulatory obligations (e.g., professional standards and accreditation)
  • Contractual requirements (e.g., membership terms and conditions)
  • Legitimate business interests (e.g., research, analysis, and historical records)
  • Your rights and expectations (e.g., access to historical membership records)
9.3 Secure Disposal
When personal data is no longer required, we dispose of it securely through:
  • Deletion of electronic records using secure deletion methods
  • Shredding or incineration of physical records
  • Purging of backup copies where technically feasible
  1. Your Rights under the Nigeria Data Protection Act, 2023
The Nigeria Data Protection Act, 2023, grants you specific rights regarding your personal data. These rights are detailed in Sections 34 to 38 of the NDP Act and further elaborated in the GAID .
10.1 Right to Be Informed
You have the right to be informed about how we collect, use, and process your personal data. This Privacy Notice is our primary means of fulfilling this obligation.
10.2 Right to Access
You have the right to request:
  • Confirmation of whether we process your personal data
  • Access to a copy of your personal data
  • Information about the purposes of processing, categories of data, recipients, retention periods, and sources of data
Article 36 of the GAID provides guidance on the exercise of the right to rectification and access . To exercise this right, please contact our Data Protection Officer.
10.3 Right to Rectification
You have the right to request that we correct inaccurate or incomplete personal data. We will make necessary corrections promptly upon verification.
10.4 Right to Erasure (Right to be Forgotten)
You have the right to request the deletion of your personal data where:
  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw your consent and there is no other legal basis for processing
  • You object to processing based on legitimate interests and we have no overriding grounds
  • The data has been unlawfully processed
  • Erasure is required to comply with a legal obligation
Article 38 of the GAID provides guidance on the exercise of the right to be forgotten .
10.5 Right to Restrict Processing
You have the right to restrict (limit) processing of your personal data in certain circumstances, including:
  • When you contest the accuracy of the data (restriction applies during verification)
  • When the processing is unlawful but you oppose erasure
  • When we no longer need the data but you require it for legal claims
  • When you object to processing based on legitimate interests (restriction applies during assessment)
10.6 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller where:
  • The processing is based on consent or contract
  • The processing is carried out by automated means
Article 37 of the GAID provides guidance on the exercise of the right to data portability .
10.7 Right to Object
You have the right to object to processing of your personal data where the processing is based on legitimate interests or for direct marketing purposes.
10.8 Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you or significantly affect you. We do not currently engage in significant automated decision-making that affects you in this manner.
10.9 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
10.10 Right to Lodge a Complaint
You have the right to lodge a complaint with the Nigeria Data Protection Commission if you believe that your rights have been violated. The contact details of the NDPC are provided in Section 11.
Article 39 of the GAID and Article 40 provide guidance on the exercise of the right to lodge a complaint and the standard notice to address grievance .
10.11 How to Exercise Your Rights
To exercise any of these rights, please contact our Data Protection Officer using the details provided in Section 11. We will respond to your request within one month of receipt. In complex cases, we may extend this period by up to two further months, and we will inform you of the extension and reasons.
We may request specific information from you to verify your identity and confirm your right to access the information. This is to ensure that we do not disclose personal data to unauthorised individuals.
  1. Cookies and Website Analytics
Our websites (https://ciodnigeria.org/ and https://erp.ciodnigeria.org/) use cookies and similar tracking technologies to enhance your browsing experience and understand how users interact with our content.
11.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help remember your preferences, enhance functionality, and gather analytics.
Article 19 of the GAID (Data Processing Which Requires Consent) specifies the requirements for obtaining consent to cookies and other tracking tools . Article 19 of the GAID also addresses consent to cookies .
11.2 Types of Cookies We Use
We use the following categories of cookies, and we request your consent before placing non-essential cookies on your device:
  • Necessary Cookies: Essential for basic website functionality, such as secure login and preference settings. These do not store personally identifiable data and do not require consent. Article 19 of the GAID provides for consent to cookies .
  • Functional Cookies: Enhance functionality by remembering your choices, such as language preferences and social media sharing.
  • Analytical Cookies: Help us understand how visitors interact with our website, including metrics on visitor numbers, bounce rates, and traffic sources. Article 19 of the GAID requires consent for these types of cookies .
  • Performance Cookies: Analyse key performance indexes of the website to deliver a better user experience.
  • Advertisement Cookies: Provide customised advertisements based on your browsing history and analyse advertising effectiveness.
11.3 Consent Management
When you first visit our websites, you will be presented with a cookie consent banner that allows you to accept or decline different categories of cookies . You can customise your preferences at any time through our consent management tool. Article 19 of the GAID specifies that a cookie notice must be displayed in such a way that it significantly obstructs the middle, left, or right side of the homepage of a website .
11.4 Website Analytics
We use analytics tools (such as Google Analytics) to collect information about how visitors use our websites. This includes:
  • Number of visitors and page views
  • Browsing patterns and navigation paths
  • Device and browser information
  • Geographic location (country level)
  • Referring websites
This information is aggregated and does not directly identify you. We use it to improve our websites, content, and user experience. Analytics tools may use their own cookies and are governed by their respective privacy policies.
11.5 Third-Party Tracking
Our websites may include links to third-party websites (e.g., social media platforms, payment processors). These third parties may place their own cookies or track your interactions. We do not control these third-party practices, and they are governed by their own privacy policies.
  1. Contacting the Data Protection Officer
CIoD Nigeria has appointed a Data Protection Officer (DPO) to oversee compliance with the Nigeria Data Protection Act, 2023, and to serve as a point of contact for data subjects and the Nigeria Data Protection Commission .
Article 11 of the GAID requires the designation of a Data Protection Officer by data controllers . Article 12 addresses the position of the Data Protection Officer . Article 13 requires the submission of internal semi-annual data protection reports by the DPO .
If you have any questions, concerns, or requests regarding this Privacy Notice or our data processing practices, please contact our Data Protection Officer:
Data Protection Officer
Chartered Institute of Directors Nigeria
Email: admin@ciodnigeria.org
Phone: 08138565041
Address: 28 Olawale Edun Road, Ikoyi, Lagos
Website: https://ciodnigeria.org/
12.1 Submitting a Request or Complaint
When contacting our DPO, please provide sufficient information to identify you and the nature of your request or complaint. This may include:
  • Your full name and contact details
  • The nature of your request (e.g., access, rectification, erasure)
  • Details of any specific data or processing activity
  • Any supporting documentation
We will acknowledge receipt of your request and respond within the timelines specified in the NDP Act, 2023.
12.2 Right to Complain to the NDPC
If you are not satisfied with our response to your request or complaint, or if you believe we have violated your data protection rights, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) .
Contact details of the NDPC:
  • Website: https://ndpc.gov.ng/
  • Email: info@ndpc.gov.ng
  • Phone: +234 (0) 916 061 5551
  • Address: [Provide NDPC address here]
You also have the right to seek judicial remedies in accordance with Nigerian law.
  1. Changes to this Privacy Notice
CIoD Nigeria reserves the right to update or modify this Privacy Notice from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. We will notify you of significant changes through:
We encourage you to review this notice periodically to stay informed about how we are protecting your personal data. Your continued engagement with us after any changes constitutes acceptance of the updated notice.
13.1 Review and Compliance
We conduct periodic reviews of our data protection practices to ensure compliance with the NDP Act, 2023, and the GAID. This includes:
  • Data Privacy Impact Assessments (DPIAs) for new processing activities as required by Article 28 of the GAID 
  • Compliance Audit Returns as required by Article 10 of the GAID 
  • Registration with the NDPC if we qualify as a Data Controller of Major Importance under Articles 8 and 9 of the GAID 
  • Internal sensitisation and training on privacy as required by Article 30 of the GAID 
Contact Information
Chartered Institute of Directors Nigeria
Website: https://ciodnigeria.org/
ERP Portal: https://erp.ciodnigeria.org/
Email:  membership@ciodnigeria.org]
Phone:  +234 706 214 8115, +234 908 749 2985
Address: Abuja 19B, Bobo Street, Off Gana Street, Maitama-Abuja.
28, Olawale Edun Road, (Formerly Cameron Road), Ikoyi, Lagos. Ikoyi (Kings way road) Nigeria
Data Protection Officer:
Email: admin@ciodnigeria.org
Phone: 08138565041
Nigeria Data Protection Commission:
Website: https://ndpc.gov.ng/
Email: info@ndpc.gov.ng
Phone: +234 (0) 916 061 5551
This Privacy Notice is issued in compliance with the Nigeria Data Protection Act, 2023, and the General Application and Implementation Directive (GAID) issued by the Nigeria Data Protection Commission. It reflects our commitment to safeguarding your privacy and upholding the highest standards of data protection.