Data protection

Privacy compliance that matches what your systems actually do.

Fintechs collect identity documents, transaction histories, and device data. We build the privacy programme each market's data protection authority expects, and keep it current.

By market

Law and authority in each market

Nigeria

the Nigeria Data Protection Act

the NDPC

Ghana

the Ghana Data Protection Act 2012

the Data Protection Commission

Kenya

the Kenya Data Protection Act 2019

the ODPC

Uganda

the Uganda Data Protection and Privacy Act 2019

the Personal Data Protection Office

South Africa

POPIA

the Information Regulator

What we implement

The working parts of a privacy programme

  • 01

    Data mapping

    An inventory of what you collect, where it lives, who touches it, and why.

  • 02

    Lawful basis and notices

    A lawful basis register and notices written for your actual product flows.

  • 03

    Rights handling

    A procedure for access, correction, and deletion requests inside statutory timelines.

  • 04

    Processors and transfers

    Contract clauses for vendors and cross-border transfers.

  • 05

    DPIA

    Impact assessments for high-risk processing such as biometrics and credit scoring.

  • 06

    Breach response

    A tested plan for notification to the authority and affected customers.

Legum provides regulatory and compliance advisory services. Where a matter requires licensed legal representation, we will say so clearly before work begins.