1. Introduction
Amstel Tech Compliance and Consulting Limited d/b/a Amstel Consulting (“we”, “us”, “our” or the “Company”) is a professional consulting firm providing data protection, privacy, governance, compliance and related advisory services to private-sector organisations, public-sector institutions, and other clients, in Nigeria and other countries.
We are committed to protecting the privacy, confidentiality and security of personal data entrusted to us and to processing personal data in accordance with applicable data protection and privacy laws.
This Privacy Statement (“Privacy Statement”) explains how we collect, use, store, disclose, transfer, secure and otherwise process personal data in the course of our business activities.
Our processing activities are governed principally by:
- the Constitution of the Federal Republic of Nigeria 1999 (as amended), including the constitutional right to privacy;
- the Nigeria Data Protection Act 2023 (“NDPA”);
- applicable regulations, directives, guidance notices, codes and other regulatory instruments issued by the Nigeria Data Protection Commission (“NDPC”); and
- other applicable Nigerian laws and regulations relating to privacy, cybersecurity, confidentiality, records management and information governance.
Where we process personal data relating to persons and clients outside Nigeria or provide services involving other jurisdictions, other applicable data protection laws may also apply.
2. About Us
Organisation: Amstel Tech Compliance and Consulting Limited (d/b/a Amstel Consulting)
Registered Address: Leisure Court Estate, Karshijikwoyi 2, Jikwoyi, Abuja. FCT
Email: dpo@amstelconsulting.ng
Website: amstelconsulting.ng
Amstel Consulting provides services including:
- Data Protection Compliance Organisation (“DPCO”) services;
- Data Protection Officer (“DPO”) services;
- data protection and privacy compliance audits;
- privacy and data protection advisory services;
- data protection gap assessments;
- data mapping and records of processing activities;
- Data Protection Impact Assessments (“DPIAs”);
- privacy risk assessments;
- development and review of privacy policies and notices;
- review and preparation of data processing agreements and contractual privacy provisions;
- data subject rights management;
- personal data breach response and remediation support;
- data governance and information-management advisory services;
- privacy-by-design and privacy-by-default advisory services;
- employee and management training and awareness;
- vendor and third-party privacy assessments;
- cross-border data transfer assessments;
- regulatory and corporate compliance support;
- liaison and engagement with the NDPC where authorised by a client; and
- other related data protection, information governance, risk and compliance services.
Amstel Consulting operates as a DPCO licensed by the Nigeria Data Protection Commission.
3. Our Role When Processing Personal Data
Our role in relation to personal data depends on the circumstances in which the data is processed.
3.1 Where We Act as a Data Controller
We act as a data controller where we determine the purposes and means of processing personal data.
This generally includes personal data relating to:
- our employees, consultants and contractors;
- prospective employees and job applicants;
- our clients and prospective clients;
- representatives and employees of our clients;
- suppliers and service providers;
- professional advisers;
- regulators and government officials;
- individuals attending our meetings, training programmes, seminars and events;
- visitors to our offices;
- users of our website and digital platforms; and
- persons who otherwise communicate or engage directly with us.
In these circumstances, we are responsible for determining why and how the relevant personal data is processed.
3.2 Where We Act on Behalf of a Client
In providing DPCO, DPO, audit, consulting, investigation, compliance or advisory services, we may obtain access to personal data controlled by one of our clients.
Depending on the particular engagement and processing activity, we may act as a data processor or otherwise process information strictly within the scope of our client's documented instructions and the applicable engagement terms.
For example, we may review samples of:
- employee records;
- customer or citizen records;
- complaint records;
- data subject access requests;
- vendor records;
- incident or data breach records;
- processing registers;
- consent records;
- CCTV governance documentation;
- marketing databases;
- application or system records;
- correspondence; and
- other information required to evaluate our client's compliance with applicable data protection requirements.
Where a client is the relevant data controller, the client remains responsible for determining the lawful purpose and basis for processing personal data. We process such data only to the extent necessary to perform the agreed services, subject to applicable law and our contractual obligations.
Individuals wishing to exercise rights concerning personal data controlled by one of our clients should ordinarily direct their request to the relevant client. Where required by applicable law, we may assist the client in responding to such requests.
3.3 Independent Professional and Regulatory Obligations
In limited circumstances, we may be required to process certain information independently in order to comply with legal, regulatory, professional, audit, security or record-keeping obligations.
Where this occurs, our role and responsibilities will be determined by the nature of the processing and applicable law.
4. Our Data Protection Principles
We are committed to processing personal data in accordance with the principles established under the NDPA.
Accordingly, personal data under our control will be:
- processed fairly, lawfully and transparently;
- collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes;
- adequate, relevant and limited to what is necessary for the relevant purpose;
- accurate, complete and, where necessary, kept up to date;
- retained only for as long as is necessary for the relevant lawful purpose or as required by law; and
- processed using appropriate technical and organisational measures designed to ensure its security, confidentiality, integrity and availability.
We recognise accountability as a fundamental component of responsible data processing and endeavour to demonstrate compliance through appropriate policies, procedures, controls, records, assessments and governance arrangements.
5. Personal Data We May Collect
Depending on your relationship with us, we may collect and process the following categories of personal data.
5.1 Identity Information
This may include:
- full name;
- title;
- date of birth;
- gender, where relevant;
- photograph;
- signature;
- employee or personnel number;
- professional identification; and
- other information required to verify identity.
5.2 Contact Information
This may include:
- business or residential address;
- email address;
- telephone number;
- organisation;
- job title;
- department; and
- other professional contact details.
5.3 Client and Professional Information
This may include:
- employer or organisation;
- position and responsibilities;
- correspondence;
- meeting records;
- contracts;
- instructions;
- project information;
- compliance records;
- training attendance;
- certifications; and
- other information relating to our professional relationship.
5.4 Financial and Transaction Information
Where relevant, we may process:
- bank account information;
- payment details;
- invoices;
- transaction records;
- tax-related information; and
- other information necessary for billing, accounting and financial administration.
We do not ordinarily retain payment-card information unless specifically necessary and appropriately secured.
5.5 Recruitment and Employment Information
For employees, consultants and job applicants, we may process information including:
- curriculum vitae;
- educational history;
- employment history;
- qualifications;
- references;
- interview records;
- identification documentation;
- remuneration information;
- performance information;
- training records;
- leave information;
- emergency contact information; and
- other information required for employment or engagement purposes.
5.6 Technical and Digital Information
When you use our website, email systems or other digital services, we may collect:
- IP address;
- device and browser information;
- operating system;
- access logs;
- website usage information;
- security logs;
- cookie information; and
- other technical information necessary for security, administration and service improvement.
5.7 Information Obtained During DPCO and DPO Engagements
Our professional services may require us to review or otherwise process personal data contained in our clients' systems, records and documentation.
The precise categories will depend on the client's activities and the scope of our engagement.
We seek to apply data minimisation when performing such work and, where practicable, request anonymised, pseudonymised, redacted, aggregated or sample data rather than unrestricted access to identifiable personal data.
6. Sensitive Personal Data
In the course of our business, we may occasionally process sensitive personal data as defined under applicable law.
This may include information concerning an individual's:
- genetic or biometric data used for identification;
- race or ethnic origin;
- religious or similar beliefs;
- health status;
- sex life;
- political opinions or affiliations;
- trade union membership; or
- other categories recognised as sensitive personal data under applicable Nigerian law.
We do not intentionally collect sensitive personal data unless it is reasonably necessary and there is a lawful basis for doing so.
Where sensitive personal data is processed, we apply enhanced safeguards appropriate to the nature, volume, context and risks associated with the processing.
When sensitive personal data is accessed in connection with DPCO, DPO or consulting services, we seek to limit access to what is strictly necessary for the engagement.
7. How We Obtain Personal Data
We may obtain personal data:
- directly from you;
- from your employer or organisation;
- from our clients;
- from suppliers and business partners;
- through contracts and procurement processes;
- through meetings, telephone calls and correspondence;
- through our website;
- through training and event registrations;
- during compliance audits and assessments;
- during DPO and DPCO engagements;
- through publicly accessible professional or corporate sources;
- from regulators and public authorities where legally permitted;
- from professional advisers; and
- from other lawful sources.
Where personal data has not been obtained directly from you, we will handle it in accordance with applicable transparency requirements and any relevant exemptions under law.
8. Why We Process Personal Data
We may process personal data for purposes including:
- providing DPCO and DPO services;
- conducting data protection audits and compliance assessments;
- performing client engagements;
- providing privacy, governance, legal-compliance and risk advisory services;
- preparing reports, assessments and recommendations;
- conducting DPIAs and risk assessments;
- responding to privacy incidents and personal data breaches;
- supporting clients with data subject rights requests;
- delivering training and awareness programmes;
- communicating with clients and stakeholders;
- managing contracts and engagements;
- responding to enquiries;
- preparing proposals and tenders;
- managing our suppliers and professional advisers;
- recruitment and employment administration;
- invoicing and payment administration;
- complying with tax, accounting and corporate requirements;
- maintaining appropriate business and professional records;
- protecting our systems, premises, personnel and information;
- preventing and investigating fraud, misuse and security incidents;
- establishing, exercising or defending legal claims;
- complying with lawful requests from regulators, courts and public authorities;
- meeting our professional and regulatory obligations;
- improving our services and internal processes; and
- carrying out other purposes that are compatible with the circumstances in which the personal data was collected.
We will not ordinarily use personal data for a materially incompatible purpose without first identifying an appropriate lawful basis and, where required, informing the affected data subject.
9. Lawful Bases for Processing
We only process personal data where there is an appropriate lawful basis under applicable law.
Depending on the circumstances, we may rely upon:
Consent
We may process personal data where you have freely given specific, informed and unambiguous consent to the processing.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Performance of a Contract
We may process personal data where necessary to perform a contract to which you are a party or to take steps at your request before entering into a contract.
Legal Obligation
We may process personal data where necessary to comply with an obligation imposed on us by law.
Vital Interests
In exceptional circumstances, we may process personal data where necessary to protect the vital interests of an individual or another person.
Public Interest
Where permitted by applicable law, personal data may be processed where necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
This basis may be particularly relevant to certain engagements involving public-sector organisations, although the appropriate lawful basis remains dependent upon the particular processing activity.
Legitimate Interests
We may process personal data where necessary for legitimate interests pursued by us or by a third party, provided that those interests are not overridden by the rights, freedoms and legitimate interests of the affected data subject.
Where appropriate, we conduct and document an assessment before relying upon legitimate interests.
10. Public-Sector Engagements
We provide services to Ministries, Departments and Agencies (“MDAs”), public institutions and other public-sector organisations.
Public-sector engagements may involve personal data processed in connection with statutory functions, public administration, regulatory activities and public services.
When working with a public-sector organisation, we:
- seek to clearly establish our respective data protection roles and responsibilities;
- process personal data only for authorised purposes;
- maintain confidentiality obligations;
- limit access to authorised personnel;
- apply appropriate technical and organisational safeguards;
- support the public institution in meeting its data protection obligations where this falls within our engagement;
- avoid using information obtained through the engagement for unrelated commercial purposes; and
- comply with applicable legal, contractual and regulatory restrictions relating to government information.
Where our role is that of a processor or service provider, the relevant public institution remains responsible for determining the purposes and lawful basis for its processing unless applicable law provides otherwise.
11. DPO Services and Professional Independence
Where Amstel Consulting or one of its personnel is appointed to provide Data Protection Officer services to a client, we recognise the importance of independence, confidentiality, professional competence and avoidance of conflicts of interest. Our DPO services may include:
- advising management on data protection obligations;
- monitoring compliance;
- reviewing policies and procedures;
- supporting privacy governance programmes;
- monitoring staff awareness and training;
- advising on DPIAs;
- supporting personal data breach management;
- monitoring data subject rights procedures;
- advising on processor and vendor arrangements;
- maintaining appropriate compliance records;
- reporting privacy risks to management; and
- serving as a point of contact for relevant data protection matters.
Information received in our capacity as an outsourced or consulting DPO will be handled confidentially and only used for legitimate purposes connected with the relevant engagement, professional obligations or applicable law.
12. Sharing Personal Data
We do not sell personal data. We may disclose personal data to third parties where reasonably necessary and legally permitted, including:
- our employees and authorised consultants;
- professional advisers;
- auditors;
- accountants;
- insurers;
- banks and payment providers;
- IT and cybersecurity providers;
- cloud and data-hosting providers;
- communications providers;
- training and event service providers;
- background-screening providers where lawful;
- regulators and supervisory authorities;
- law-enforcement agencies;
- courts and tribunals;
- government authorities; and
- other service providers supporting our operations.
Where third-party processors process personal data on our behalf, we take reasonable steps to ensure that appropriate contractual, confidentiality, security and data protection requirements are in place.
We expect service providers to process personal data only for authorised purposes and to implement appropriate security safeguards.
13. Disclosure to the Nigeria Data Protection Commission
As a DPCO and provider of DPO and compliance services, we may interact with the Nigeria Data Protection Commission on behalf of clients where authorised to do so.
This may include:
- submitting compliance documentation;
- supporting regulatory registrations;
- submitting or supporting audit filings;
- responding to regulatory enquiries;
- supporting breach notifications;
- seeking regulatory guidance; and
- assisting with investigations or compliance matters.
Where personal data is disclosed to the NDPC or another competent authority, we will seek to ensure that the disclosure is lawful, relevant and limited to information reasonably required for the applicable purpose.
14. International and Cross-Border Transfers
Our services and technology providers may occasionally require personal data to be transferred to or accessed from locations outside Nigeria.
We will only transfer personal data internationally where the transfer complies with the NDPA and other applicable legal requirements.
Depending upon the circumstances, this may include transfers based on:
- an applicable finding or determination concerning the adequacy of protection;
- appropriate safeguards recognised under applicable law;
- legally valid contractual arrangements;
- the data subject's valid consent where legally appropriate;
- necessity for the performance of a contract;
- important reasons of public interest;
- establishment, exercise or defence of legal claims;
- protection of vital interests; or
- another legally recognised basis for international transfer.
Where appropriate, we conduct a transfer risk assessment and maintain records concerning cross-border processing.
We also expect relevant overseas recipients to maintain appropriate confidentiality, security and data protection safeguards.
15. Data Security
We implement technical and organisational measures appropriate to the nature of the personal data we process and the risks associated with the processing.
Access to personal data is restricted to persons who reasonably require access for authorised business or professional purposes.
No information system can be guaranteed to be completely secure. We therefore maintain processes designed to identify, investigate, contain, remediate and, where necessary, report personal data breaches.
16. Personal Data Breaches
We maintain procedures for responding to actual or suspected personal data breaches.
Where a breach occurs, we will assess:
- the nature of the incident;
- categories and approximate volume of data affected;
- affected data subjects;
- likely consequences;
- risks to individuals;
- containment measures;
- remedial actions; and
- applicable notification obligations.
Where we are acting as a processor or service provider, we will notify the relevant client in accordance with our contractual and legal obligations.
Where required by applicable law, we will notify the Nigeria Data Protection Commission and/or affected data subjects within the applicable statutory or regulatory timeframe.
We document personal data breaches and the actions taken in response to them.
17. Data Protection Impact Assessments and Privacy by Design
We apply risk-based data protection practices to our own processing activities.
Where a proposed processing activity is likely to result in a high risk to the rights and freedoms of individuals, we will undertake a Data Protection Impact Assessment where required.
We also encourage and support the principles of privacy by design and privacy by default.
This means that data protection considerations should, where appropriate, be integrated into the design and implementation of:
- business processes;
- information systems;
- applications;
- digital services;
- procurement exercises;
- projects;
- products;
- contracts; and
- organisational changes.
18. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and for any additional period required by law, regulation, contract or legitimate professional record-keeping requirements.
Retention periods may depend on:
- the nature of the information;
- the purpose for which it was collected;
- contractual requirements;
- applicable limitation periods;
- tax and accounting obligations;
- professional and regulatory requirements;
- security requirements;
- ongoing disputes or investigations; and
- requirements relating to public-sector records.
At the end of the applicable retention period, personal data will be securely deleted, destroyed, anonymised or otherwise disposed of in accordance with our applicable procedures.
Where we hold personal data solely on behalf of a client, deletion or return of such data will also be governed by our contractual arrangements with that client.
19. Your Rights as a Data Subject
Subject to the NDPA, applicable exemptions and the circumstances of the processing, you may have rights concerning your personal data.
These may include the right to:
- receive information about the processing of your personal data;
- request access to personal data held about you;
- request correction of inaccurate or incomplete personal data;
- request deletion or erasure of personal data where applicable;
- request restriction of processing in applicable circumstances;
- object to certain processing;
- withdraw consent where processing is based upon consent;
- request data portability where applicable;
- object to certain forms of direct marketing;
- obtain information concerning certain automated decision-making activities;
- object to or seek safeguards concerning decisions based solely on automated processing where applicable; and
- lodge a complaint with the Nigeria Data Protection Commission.
These rights are not absolute. In certain circumstances, applicable law may permit or require us to continue processing personal data despite a request.
20. Exercising Your Rights
To exercise a data protection right concerning personal data for which Amstel Consulting is the controller, please contact our Data Protection Officer at dpo@amstelconsulting.ng. Please clearly describe your request and provide sufficient information to allow us to identify the relevant records.
We may request reasonable evidence of identity before acting on a request in order to protect personal data against unauthorised disclosure. We aim to respond within the period prescribed by applicable law.
We will not ordinarily charge a fee for exercising a data protection right. However, where permitted by law, reasonable charges may apply to requests that are manifestly unfounded, excessive or repetitive.
Where your request concerns personal data that we process solely on behalf of one of our clients, we may refer the request to the relevant client or assist the client in responding.
21. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects concerning individuals solely through automated processing.
If we introduce such processing, we will assess the applicable legal requirements and implement appropriate safeguards, including transparency and mechanisms for human intervention where required.
22. Children's Personal Data
Our professional services are primarily directed toward organisations and adult professionals and are not directed toward children.
However, in providing services to clients in sectors such as government, education, health or social services, we may encounter children's personal data contained within client-controlled systems or records.
In such circumstances, we will treat children's personal data as requiring a heightened level of protection and will process it only as necessary for the authorised engagement and in accordance with applicable law.
23. Direct Marketing
Where we send information about our professional services, events, training or publications, we will do so in accordance with applicable legal requirements.
Recipients may opt out of electronic marketing communications at any time by using the unsubscribe facility provided in the communication or by contacting us at dpo@amstelconsulting.ng.
Opting out of marketing does not prevent us from sending necessary service, contractual, regulatory or administrative communications.
24. Cookies and Website Technologies
Our website may use cookies and similar technologies to operate effectively, maintain security, remember preferences and understand how visitors use our website.
Where cookies or similar technologies are not strictly necessary, we will seek consent where required by applicable law.
Users may manage cookies through our website's cookie-management tools, where available, and through their browser settings. Additional information may be provided in our separate Cookie Notice.
25. Third-Party Websites
Our website and communications may contain links to third-party websites.
We are not responsible for the privacy, security or content of websites operated by third parties. Individuals should review the privacy statements of those organisations before providing personal data to them.
26. Confidentiality
Confidentiality is fundamental to our professional services.
Our personnel, consultants and relevant service providers are subject to appropriate confidentiality obligations.
Information obtained through a DPCO, DPO, audit, compliance or advisory engagement will not be disclosed or used for unrelated purposes except:
- as authorised by the client;
- as necessary to perform the engagement;
- where required by law;
- where required by a competent regulator or court;
- where necessary to establish, exercise or defend legal rights; or
- where another lawful justification applies.
27. Conflicts of Interest
Given our role as a professional privacy and compliance adviser, we seek to identify and appropriately manage actual or potential conflicts of interest.
Before accepting certain DPO, DPCO, audit or advisory engagements, we may undertake conflict checks and assess whether the proposed services could impair our professional independence or create incompatible responsibilities.
Where a material conflict cannot be appropriately managed, we may decline or discontinue an engagement.
28. Accountability and Governance
We maintain an internal data protection and privacy governance framework appropriate to our size, activities and risk profile.
Our privacy and security controls are periodically reviewed and updated to reflect changes in our operations, technology, risks and applicable law.
29. Complaints
If you have a concern about how we process your personal data, we encourage you to contact our Data Protection Officer first so that we can investigate and attempt to resolve the matter.
You also have the right, where applicable, to submit a complaint or petition to the Nigeria Data Protection Commission (NDPC).
30. Regulatory Cooperation
We are committed to cooperating appropriately with the Nigeria Data Protection Commission and other competent regulatory or public authorities.
Where legally required, we will provide relevant information and assistance in connection with:
- regulatory enquiries;
- investigations;
- audits;
- breach notifications;
- compliance assessments; and
- enforcement proceedings.
Any disclosure of personal data for these purposes will be limited to what is lawful, necessary and appropriate in the circumstances.
31. Changes to this Privacy Statement
We may amend this Privacy Statement periodically to reflect:
- changes in applicable law or regulatory guidance;
- changes in our business or services;
- changes in technology;
- changes in our processing activities; or
- improvements to our privacy and information-governance practices.
The current version will be published on our website with the date on which it was last updated.
Where a change materially affects the way in which we process personal data, we will take reasonable steps to provide appropriate notice.
32. Contact Us
Questions concerning this Privacy Statement or our processing of personal data should be directed to our Data Protection Officer (DPO) at dpo@amstelconsulting.ng.
33. Commitment to Data Protection
Amstel Consulting recognises that effective data protection is not merely a regulatory requirement but an essential component of trust, responsible governance and professional service delivery.
As a provider of DPCO, DPO and privacy advisory services, we seek to apply to our own operations the standards of accountability, transparency, confidentiality, security and responsible data governance that we recommend to our clients.
We are committed to continually reviewing and improving our data protection programme and to supporting organisations in Nigeria and other countries in building sustainable and accountable privacy practices.
© 2026 Amstel Tech and Compliance Consulting Ltd. All rights reserved.