lawyer6-logo
✕
  • HOME
  • ABOUT
  • OUR TEAM
  • PRACTICE AREAS
  • AGREEMENTS
  • CONTACT
MLD brown logo
  • HOME
  • ABOUT
  • OUR TEAM
  • PRACTICE AREAS
  • AGREEMENTS
  • CONTACT
+234 (0) 8033982694
lawyer6-header-icon1
✕
  • HOME
  • ABOUT
  • OUR TEAM
  • PRACTICE AREAS
  • AGREEMENTS
  • CONTACT
Published by @myMLD on October 1, 2026
Categories
  • Data Protection & AI Governance
Tags

For technology startups and growing digital enterprises, a cybersecurity breach is no longer merely an operational problem for the information technology department. It is a board-level legal, regulatory and corporate-governance risk.

The period when businesses could dismiss cyberattacks as unforeseeable acts of digital vandalism is rapidly receding. Regulators, courts, investors and corporate clients increasingly examine data security through the lenses of statutory compliance, organizational accountability, contractual responsibility and directors’ oversight.

When a startup suffers a personal-data breach, the consequences may extend well beyond the immediate technical disruption. Depending on the circumstances and jurisdictions involved, the incident may trigger regulatory investigations, statutory notification obligations, contractual claims, litigation by affected individuals, loss of commercial partnerships and serious reputational damage.

Frameworks such as the European Union’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the Nigeria Data Protection Act 2023 (NDPA) impose substantial obligations concerning the collection, use, security and disclosure of personal information.

Under the GDPR, the gravest infringements may attract administrative fines of up to €20 million or 4 per cent of the undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher. The NDPA similarly empowers the Nigeria Data Protection Commission (NDPC) to investigate non-compliance, issue enforcement orders and impose significant statutory penalties.

Personal data may be borderless, but the organizations processing it are not beyond regulatory accountability.

From Cyber Incident to Legal Exposure

A data breach does not automatically establish legal liability. The outcome will ordinarily depend on several factors, including:

  • the nature and sensitivity of the affected personal data;
  • the likelihood and severity of harm to data subjects;
  •  the technical and organizational safeguards implemented before the incident;
  • the organization’s response after discovering the breach;
  • compliance with statutory notification requirements;
  • representations made to consumers and commercial partners;
  • contractual allocation of cybersecurity responsibilities; and
  •  whether the organization can demonstrate accountability and reasonable risk management.

The modern legal question is therefore not simply whether a cyberattack occurred. It is whether the organization anticipated reasonably foreseeable risks, adopted proportionate safeguards, monitored the effectiveness of those safeguards and responded appropriately when the incident occurred.

A sophisticated attacker may still penetrate a well-secured system. Nevertheless, an organization that cannot demonstrate basic access control, risk assessment, incident-response planning, staff training and data-governance measures may find it difficult to establish that it exercised the standard of care expected of a responsible data controller or processor.

The Multi-Jurisdictional Regulatory Maze

Digital enterprises frequently operate across borders long before they establish physical offices outside their home countries. A Nigerian startup may use overseas cloud infrastructure, serve customers in Europe, engage contractors in several jurisdictions and process information belonging to individuals in multiple countries.

Consequently, regulatory exposure must be determined by examining the territorial scope and qualifying conditions of each applicable law—not merely the country in which the company was incorporated.

The Nigeria Data Protection Act 2023

The NDPA establishes Nigeria’s principal statutory framework for the processing and protection of personal data. It applies to processing conducted by data controllers and processors within its territorial scope and protects the rights and interests of covered data subjects.

Section 24 establishes fundamental principles of personal-data processing. Among other requirements, personal data must be processed fairly, lawfully and transparently; collected for specified, explicit and legitimate purposes; limited to what is adequate, relevant and necessary; retained only for as long as required; and kept accurate, complete and up to date.

The same provision requires appropriate security safeguards and imposes duties of care and accountability upon data controllers and processors.

The NDPA is now supplemented by the General Application and Implementation Directive issued by the NDPC in 2025. Together, these instruments provide the central framework within which Nigerian organisations must address lawful processing, data-subject rights, governance, cybersecurity safeguards, breach response and regulatory accountability.

Section 40 governs personal-data breach notification. Where a breach is likely to result in a risk to the rights and freedoms of individuals, the data controller must notify the NDPC within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, affected data subjects must also be informed promptly in clear and plain language.

The 72-hour requirement is therefore not an indiscriminate rule applying identically to every technical incident. It requires a prompt and properly documented risk assessment.

The General Data Protection Regulation

The GDPR applies directly to processing conducted in the context of an establishment in the European Union. In defined circumstances, it also applies to organisations established outside the EU where they offer goods or services to individuals in the EU or monitor their behaviour within the Union.

Its obligations include lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability. It also recognises qualified rights relating to access, rectification, erasure, restriction, objection and certain forms of automated decision-making.

The frequently referenced “right to be forgotten” is not absolute. It operates as a qualified right to erasure, subject to statutory grounds and exceptions.

For startups seeking European customers, investors or commercial partners, GDPR compliance cannot safely be treated as a concern to be addressed only after international expansion. Privacy governance should be considered during product design, vendor selection, contracting and market-entry planning.

The CCPA and CPRA

The CCPA/CPRA gives California consumers substantial rights concerning personal information collected by covered businesses. These include rights to know, delete and correct certain information, as well as rights to opt out of the sale or sharing of personal information, subject to statutory qualifications and exceptions.

The legislation does not apply to every startup merely because it processes information connected with California. Its application depends on the statutory definition of a covered business, including relevant commercial and threshold requirements.

For qualifying enterprises, however, the CCPA/CPRA creates important transparency, data-governance and consumer-response obligations. A startup entering the Californian market must therefore determine whether it falls within the legislation rather than assuming that its small size or foreign incorporation automatically excludes it.

Hypothetical Scenario: Pre-Marriage AI Profiling and Algorithmic Defamation

Consider an artificial-intelligence application marketed as a pre-marriage background-check service. The platform claims to cross-reference an individual’s personal, commercial and legal history and generate a risk assessment for prospective partners.

Rather than obtaining information solely from verified or authorised sources, the application uses automated open-source intelligence tools to collect material from websites, social-media accounts, public records, archived pages and third-party databases. Its AI system then aggregates the information, attempts to identify relationships among the data points and produces a consolidated personal profile.

The process may be represented as follows:

AI profiling application → collection of fragmented or unverified data → algorithmic matching and inference → consolidated profile or risk score → possible reputational harm

The legal danger becomes acute when the system creates an incorrect association. Information originating from an undisclosed corporate breach, outdated website, inaccurate public entry or unrelated person may be linked to an innocent individual who shares a similar name, telephone number, address or other identifier.

The resulting profile may falsely attribute litigation, debt, criminal allegations, marital history or other sensitive information to the wrong person. Because algorithmic outputs are often presented with an appearance of technical objectivity, a user may accept the profile as verified fact even where the underlying data is incomplete, outdated or fundamentally incorrect.

Data-protection implications

Section 24 of the NDPA requires covered personal data to be accurate, complete, not misleading and kept up to date, having regard to the purposes for which it is processed.

Accordingly, an operator cannot necessarily avoid responsibility by asserting that the underlying information was publicly accessible. Public availability does not, by itself, resolve questions concerning lawful basis, transparency, purpose limitation, accuracy, fairness, data minimisation or the rights of the affected individual.

Once a company collects, aggregates, analyses and republishes personal data, it becomes responsible for its own processing activities. Where the processing presents a high risk to individuals, additional governance measures—including an appropriate data-protection impact assessment—may be required.

The organisation should also provide accessible procedures through which individuals can challenge false information, request correction and obtain meaningful human review of consequential automated outputs.

Defamation and related liability

“Inaccurate data processing” and “defamation” are not interchangeable legal concepts. Nevertheless, the same factual circumstances may create exposure under both data-protection and defamation principles.

An AI-generated statement may raise defamation concerns where it is published to a third party, refers to an identifiable person, conveys a defamatory meaning and is not protected by an applicable defence. Additional claims may arise, depending on the facts and governing law, through negligence, breach of confidence, consumer-protection rules or other civil remedies.

The term “algorithmic defamation” is useful in describing reputational injury produced or amplified by automated systems. It should not, however, be understood as a separately codified cause of action. The existing elements of defamation and other applicable legal rules must still be established.

The central lesson is that automation does not extinguish legal responsibility. A company that designs, deploys and commercially benefits from an AI-profiling system cannot automatically transfer responsibility to the algorithm or to the websites from which the original information was obtained.

Zero Trust as Evidence of Risk-Based Security

Traditional “castle-and-moat” cybersecurity assumes that users or devices operating within an organisation’s network perimeter may be trusted. That assumption has become increasingly unsuitable for enterprises operating through cloud services, remote workforces, mobile devices and interconnected vendors.

Zero Trust Architecture offers a different approach: no user, device or connection is granted implicit trust merely because of its location or previous access. Authentication, authorisation and risk evaluation are applied to each request for protected resources.

The framework is commonly associated with several operational principles:

· Explicit identity and device verification: Access decisions are based on authenticated identity, device status and other relevant risk information.

· Least-privilege access: Users receive only the level of access reasonably required to perform authorised functions, thereby limiting unnecessary internal exposure.

· Continuous monitoring: Systems observe access patterns and data flows to identify unusual behaviour and respond to potential compromise.

· Assume-breach planning: Security controls are designed on the understanding that no perimeter is impenetrable and that rapid detection, containment and recovery are essential.

Zero Trust is not expressly mandated as the universal or definitive security standard under the NDPA, GDPR or CCPA/CPRA. Nor does its implementation create automatic immunity from regulatory action or civil claims.

It is, however, an increasingly influential cybersecurity framework. When proportionately and effectively implemented, it may help an organisation demonstrate that it adopted risk-based technical and organisational measures to protect personal data.

Its legal value lies not in the label attached to the architecture, but in the effectiveness of its controls and the organisation’s ability to document, test and improve them.

Moreover, Zero Trust addresses only part of the compliance problem. It may reduce unauthorised access and data exfiltration, but it cannot independently cure unlawful collection, excessive retention, inaccurate profiling, inadequate transparency or the absence of a lawful basis for processing. Effective privacy governance must therefore combine cybersecurity architecture with policies governing the entire lifecycle of personal data.

The Boardroom Dimension

Cybersecurity and data protection can no longer be delegated entirely to technical personnel. Directors and senior executives must ensure that appropriate governance structures exist to identify risks, allocate responsibility, supervise compliance and respond to incidents.

This does not mean that every data breach automatically creates personal liability for directors or removes the protection of separate corporate personality. Personal exposure will depend on the applicable legal framework, the director’s responsibilities, the nature of the alleged conduct and the evidence available.

Nevertheless, sustained inattention to known cybersecurity risks may raise serious questions concerning oversight, corporate governance and the proper discharge of managerial responsibilities.

Boards should therefore require periodic reporting on:

  •  categories of personal and sensitive data processed;
  • applicable jurisdictions and regulatory obligations;
  • cybersecurity and privacy risk assessments;
  •  contracts with cloud providers and other processors;
  •  access controls and data-retention arrangements;
  •  incident-response and business-continuity plans;
  • staff training and internal accountability;
  • data-protection impact assessments;
  •  regulatory notifications and complaints; and
  •  remediation of identified vulnerabilities.

For investors and commercial partners, evidence of mature data governance increasingly serves as an indicator of institutional credibility. Compliance is therefore not merely a defensive obligation; it can also become a source of commercial trust and competitive advantage.

Conclusion: Innovation and Accountable Governance

As the digital economy advances through 2026, the relationship among technology, data protection, cybersecurity and corporate governance has become inseparable.

Startups must navigate overlapping regulatory regimes, evolving AI systems, complex supply chains and rapidly changing expectations of organisational accountability. The legal question after a data breach will rarely be limited to how the attacker entered the system. Regulators, courts, clients and investors may also ask what the company knew, what safeguards it implemented, how it supervised its processors, how quickly it responded and whether it respected the rights of affected individuals.

Zero Trust Architecture can form an important part of that response, but technology alone is insufficient. Effective compliance requires an integrated framework combining lawful data processing, responsible product design, contractual safeguards, accurate recordkeeping, human oversight, incident preparedness and board-level accountability.

The essential principle is clear: innovation without accountable data governance can quickly become institutionalised risk.

The future of the digital economy will belong not merely to enterprises that innovate quickly, but to those that recognise that sustainable innovation, public trust and legal compliance are mutually reinforcing foundations of long-term success.

Selected Legal and Technical Authorities

1. Nigeria Data Protection Act 2023.

2. Nigeria Data Protection Commission, General Application and Implementation Directive 2025.

3. Regulation (EU) 2016/679, General Data Protection Regulation.

4. California Consumer Privacy Act, as amended by the California Privacy Rights Act.

5. National Institute of Standards and Technology, Zero Trust Architecture, NIST Special Publication 800-207.

About the Author

Mary Lawrence-Dokpesi, LL.B., B.L., LL.M., is an international legal, governance and regulatory consultant with over 20 years of executive advisory experience spanning corporate law, regulatory compliance, media and telecommunications, capital markets, cross-border transactions, dispute resolution and institutional advisory. She is Principal Partner at Mary Lawrence-Dokpesi & Associates. Her legal-technology practice focuses on data protection, artificial-intelligence governance, cybersecurity liability and the regulatory implications of emerging technologies.

Share
0
@myMLD
@myMLD

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

PRY LOGO 1

MLD offers high quality legal services and support that you can afford any day any time.

ADDRESS

SHELL COOPE EAST – GARDEN ESTATE,
GADUWA, ABUJA,
NIGERIA.

CONTACT

info@marydokpesi.com

mary@marydokpesi.com

+234 (0) 8033982694

© 2026 Mary Lawrence Dokpesi & Associates. | All Rights Reserved.
✕

Login

Lost your password?

  • Consent
  • Details
  • About Cookies

This website uses cookies

We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.

Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Analytics & Performance

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission. This means that cookies which are categorized as necessary, are processed based on GDPR Art. 6 (1) (f). All other cookies, meaning those from the categories preferences and marketing, are processed based on GDPR Art. 6 (1) (a) GDPR.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.

Deny Customize Allow selected Allow all