Amecron Nigeria Limited — Port Harcourt, Rivers State, Nigeria
Data Protection Policy Framework — prepared in compliance with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Commission (NDPC) General Application and Implementation Directive (GAID).
Effective Date: 6 July 2026 | Version 1.0 | Next review: within 12 months of the effective date.
This policy sets out how Amecron Nigeria Limited collects, uses, stores, shares, and disposes of personal data in the course of its operations, including personal data processed on behalf of clients under its Manpower Supply, HR Consultancy, and Background Verification service lines. It exists to protect the rights of data subjects — including employees, job candidates, contractors, and client personnel — and to ensure Amecron's processing activities remain lawful, fair, and transparent at all times.
Amecron processes personal data in line with the following principles, consistent with Section 24 of the NDPA:
Amecron relies on one or more of the following lawful bases depending on the processing activity: the consent of the data subject; performance of a contract to which the data subject is party (e.g. an employment or engagement contract); a legitimate interest pursued by Amecron or a client (e.g. workforce screening and risk management), balanced against the rights of the data subject; and compliance with a legal obligation, where applicable.
Amecron recognises and facilitates the rights of data subjects under the NDPA, including the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, and the right to object to processing. Detailed procedures for handling these rights are set out in Section 4.
This policy is reviewed at least annually, or sooner where changes in law, NDPC guidance, or Amecron's business operations require it.
This policy establishes how long Amecron retains different categories of personal data, and the process for secure disposal once retention periods expire, in line with the storage limitation principle under the NDPA.
| Data Category | Retention Period | Basis |
|---|---|---|
| Background verification reports (unsuccessful candidates) | 6 months from completion | Legitimate interest / dispute defence |
| Background verification reports (successful / engaged candidates) | Duration of engagement + 3 years | Contract performance |
| Employee personnel files | Duration of employment + 6 years | Statutory / labour law obligations |
| Criminal record check data | 6 months post-decision, unless a longer period is agreed with the client in writing | Data minimisation; sensitive data |
| Client contracts and correspondence | 7 years from contract end | Statutory / tax obligations |
| Consent records | Duration of processing + 2 years | Accountability / evidence of consent |
Where a specific timeline has been agreed with an individual client, that contractual period may override these defaults.
On expiry of the applicable retention period, personal data is securely deleted from electronic systems and, where held in physical form, cross-shredded or incinerated. Disposal is logged — recording the data category, disposal date, and method — to maintain an auditable record.
Amecron provides engineering, procurement, project management, and human-resource consultancy services delivered under written engagement contracts. This policy explains how requests relating to fees and refunds are handled, so that clients understand their position before, during, and after an engagement.
Fees for professional services are set out in the applicable proposal, contract, or purchase order. Unless a specific engagement contract states otherwise:
Refund requests should be made in writing to Amecron's Finance team, quoting the relevant contract or invoice reference, within 30 days of the event giving rise to the request. Each request is reviewed against the terms of the applicable engagement contract, which takes precedence where its terms differ from this general policy.
Approved refunds are processed to the original payment source within 30 business days of approval. Amecron will confirm the outcome of every request in writing, including the reasons where a request is declined.
This policy explains how Amecron publicises data subject rights and provides an accessible, active mechanism for individuals to raise requests or complaints about how their personal data is processed.
Amecron makes data subjects aware of their rights at the point personal data is collected — through candidate consent forms, employment documentation, and, where applicable, a privacy notice made available on request. In plain language, you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object.
This policy sets out how Amecron identifies, contains, investigates, and reports personal data breaches, in line with NDPA breach notification requirements and NDPC guidance.
A personal data breach includes any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This covers incidents such as a lost or stolen device containing candidate data, an email sent to the wrong recipient, unauthorised access to verification records, or a compromised system.
This policy governs how Amecron selects, contracts with, and monitors third parties involved in the delivery of its services — including institutions and agencies contacted in the course of background verification (e.g. educational institutions, credit bureaux, and law enforcement authorities) — to ensure personal data shared with or processed by them is adequately protected.
Before engaging a third party that will process personal data, Amecron assesses the party's data protection practices, including their security measures and, where applicable, their own NDPA compliance status.
Where a third party processes personal data on Amecron's behalf, a written data processing agreement is put in place, setting out the scope and purpose of processing, confidentiality obligations, security requirements, breach notification obligations to Amecron, and data return or deletion obligations on termination.
Amecron periodically reviews third-party compliance with agreed data protection terms and reserves the right to suspend data sharing with any party found to be in breach of its obligations.
This policy sets out when and how Amecron conducts a Data Privacy Impact Assessment (DPIA) to identify and mitigate data protection risks before new processing activities begin.
This policy sets out the technical safeguards Amecron applies to protect personal data against unauthorised access, loss, alteration, or destruction, in support of the integrity and confidentiality principle under the NDPA.
This policy ensures staff understand their data protection obligations and are equipped to identify and respond appropriately to data protection risks.
This policy governs the use of cookies and similar tracking technologies on Amecron's website, ensuring visitors are informed and, where required, give consent before non-essential cookies are set.
You can review or change your cookie choice at any time using the button below.
In accordance with the Nigeria Data Protection Act 2023 and NDPC guidance, Amecron Nigeria Limited designates the following individual as its Data Protection Officer:
| Name | Oludotun Taiwo |
|---|---|
| Title | General Manager, HR & Operations / Data Protection Officer |
| Responsibilities | Oversight of data protection compliance; primary contact for the NDPC; management of data subject requests and breach response. |
| amecron@yahoo.co.uk | |
| Phone | +234 8178 374 675 |
| Address | 3rd floor, Pneuma Place, KM 1 Woji-Akpajo new link road, by Elelewon Bridge, Port Harcourt. |
© Amecron. All Rights Reserved.