1. Background Statement

BEEZENDS GLOBAL PAY SERVICES LTD (the “Company”) in the course of its business operations, collects, processes, stores, and transmits personal data belonging to customers, employees, partners, and other stakeholders. This includes but is not limited to names, contact information, financial details, identification numbers, and other Personally Identifiable Information (PII).

Protecting this data is critical to maintaining individual privacy rights, complying with applicable data protection laws, and upholding BEEZENDS GLOBAL PAY SERVICES LTD reputation for trust and transparency. This Data Protection Policy sets out the principles, roles, and responsibilities for ensuring the lawful, fair, and secure handling of personal data across all business functions and processes.

2. Purpose, Scope and Applicability

The purpose of this document is to define the foundational principles and objectives of BEEZENDS GLOBAL PAY SERVICES LTD data protection framework, and to establish a cohesive structure for the development, implementation, and governance of all related policies and procedures. This Data Protection Policy acts as a central reference point that identifies the core policies required to ensure the lawful, secure, and accountable processing of personal data throughout the organization.

This policy applies to all employees, contractors, consultants, interns, and third-party service providers who process or have access to personal data on behalf of BEEZENDS GLOBAL PAY SERVICES LTD. It covers all business units and functions with this policy and its supporting components are mandatory for ensuring that BEEZENDS GLOBAL PAY SERVICES LTD meets its legal obligations and builds a privacy-respectful culture across the organization.

3. Applicable Laws and References

This policy shall be implemented and interpreted in accordance with applicable laws, regulations, and recognized standards, including but not limited to:

  • Nigeria Data Protection Act (NDPA), 2023
  • Nigeria Data Protection Act General Application and Implementation Directive (GAID), 2025
  • Risk-Based Cybersecurity Framework and Guidelines
  • Nigeria Cybercrimes (Prohibition, Prevention, etc.) Act, 2015
  • ISO/IEC 27001:2022 (Information Security Management Systems)
  • PCI-DSS (Payment Card Industry Data Security Standard)

4. Objectives of the Data Protection Policy

The objectives of this Data Protection Policy are to:

  • Establish a unified framework for developing, implementing, and maintaining supporting data protection policies across the organization.
  • Ensure compliance with applicable data protection laws and regulations, including the Nigeria Data Protection Act (NDPA) 2023, and the General Application and Implementation Directive (GAID) 2025.
  • Safeguard the rights, freedoms, and privacy of individuals by promoting lawful, fair, and transparent processing of personal data.
  • Promote responsible data handling practices, including data minimization, data integrity, availability, and confidentiality.
  • Define and assign clear roles and responsibilities to internal stakeholders for the protection of personal and sensitive information.
  • Integrate data protection into risk management and incident response procedures to proactively manage and mitigate data breaches.
  • Foster a culture of data protection awareness and compliance through continuous training and stakeholder engagement.

5. Governance and Roles

Effective data protection requires clear accountability and defined roles across the organization. BEEZENDS GLOBAL PAY SERVICES LTD adopts a governance model that supports oversight, implementation, and continuous improvement of data protection practices across all business units.

5.1 Board of Directors / Executive Management

  • Provides strategic direction and oversight on data protection risks.
  • Approves the Data Protection Policy and ensures alignment with organizational objectives and regulatory obligations.

5.2 Data Protection Officer (DPO)

  • Oversees the implementation of the data protection framework.
  • Serves as the primary contact for data subjects and regulatory authorities.
  • Monitors compliance with applicable laws and internal policies.
  • Coordinates privacy impact assessments and training initiatives.

5.3 Data Protection Unit / Legal & Compliance Team

  • Supports the DPO in ensuring operational adherence to data protection standards.
  • Reviews contracts and vendor engagements to ensure appropriate data protection clauses.
  • Manages incident response and breach reporting procedures.

5.4 Information Security Team

  • Ensures the confidentiality, integrity, and availability of personal and sensitive data.
  • Implements appropriate technical and organizational measures in collaboration with the DPO.

5.5 Departmental Heads / Line Managers

  • Ensure that team members understand and comply with data protection responsibilities.
  • Escalate privacy-related risks or incidents to the DPO.

5.6 All Employees, Contractors, and Partners

  • Must comply with this policy and related procedures.
  • Complete mandatory data protection training.
  • Report suspected data breaches or privacy concerns in a timely manner.

6. General Principles for Processing Data Protection

BEEZENDS GLOBAL PAY SERVICES LTD is committed to processing personal data in accordance with the core principles set out under the Nigeria Data Protection Act (NDPA) 2023, General Application and Implementation Directive (GAID) 2025 and other applicable regulations. These principles guide all personal data handling activities, both internally and externally:

7. Legal Grounds for Processing of Personal Data

BEEZENDS GLOBAL PAY SERVICES LTD is committed to processing personal data strictly in accordance with the legal bases provided under applicable data protection laws and regulations. All processing activities must be lawful, fair, and transparent, and shall only occur where at least one of the following grounds applies:

8. Supporting Policies and Procedures

To ensure the effectiveness of this Data Protection Policy, the following supporting policies and procedures should be developed to provide operational guidance and compliance safeguards across the organization:

8.1 Privacy Policy

BEEZENDS GLOBAL PAY SERVICES LTD Privacy Policy defines how the organisation collects, uses, stores, shares, and protects personal data in compliance with applicable data protection laws and regulations. Specifically, the Privacy Policy must cover:

  • Categories of Personal Data Collected: types of personal information gathered from customers, employees, and partners.
  • The legal bases for processing personal data.
  • The purpose and specific reasons for which personal data is collected and processed.
  • Data Sharing Practices: The third parties’ data is shared with, including regulators and service providers, and the circumstances under which data may be disclosed to those third parties.
  • Grievance Resolution – SNAG Process: mechanisms for individuals to exercise their rights to issue a Standard Notice to Address Grievance and how the company addresses complaints or disputes.
  • Data Subject Rights: rights of individuals, including access, rectification, erasure, restriction, objection, and portability and the mechanism to exercise these rights.
  • Storage and Security Measures: technical and organizational safeguards to protect personal data.
  • International Data Transfers: conditions under which personal data may be transferred outside Nigeria.

The Privacy Policy also serves as a public-facing commitment to accountability, fairness, and transparency, ensuring that individuals understand how their personal data is handled and the safeguards in place to protect it. It must be periodically reviewed and updated to reflect legal, regulatory, technological, or operational changes.

8.2 Cookie Policy

BEEZENDS GLOBAL PAY SERVICES LTD Cookie Policy outlines the organisation’s approach to the use of cookies and other tracking technologies across its digital platforms, including websites, applications, and online services. Specifically, the Cookie Policy covers:

  • Types of Cookies Used: categories such as strictly necessary cookies, performance/analytical cookies, functionality cookies, and targeting/advertising cookies.
  • The Duration of the Cookies: The notice will indicate the duration of the cookies.
  • The details of the third-party administrators of the cookies and links to their privacy notice (where applicable).
  • How cookies support user experience (i.e., remembering preferences, enhancing navigation) and business operations (e.g., analytics, security, personalization).
  • The legal bases for deploying cookies, including consent and legitimate interests.
  • User Consent and Preferences: how BEEZENDS GLOBAL PAY SERVICES LTD obtains user consent, provides options to accept or decline cookies, and allows users to manage their cookie settings at any time.
  • Transparency and Updates: commitment to review the policy periodically to reflect evolving legal requirements, technological changes, and user expectations.

The policy ensures compliance with data protection and privacy laws by establishing rules for obtaining consent, providing transparency on cookie practices, and enabling users to manage their cookie preferences. It must be reviewed periodically to reflect evolving legal requirements, technological practices, and user expectations.

8.3 Cookie Banner

The Cookie Banner is the user-facing statement displayed on the organisation’s digital platforms that informs visitors about the use of cookies and tracking technologies. It provides clear and concise information on the categories of cookies in use, their purposes, and options available to users for managing consent and preferences.

The Cookie Banner complements the Cookie Policy by acting as an immediate transparency tool at the point of interaction, ensuring that users are fully aware of and can control how their data is processed through cookies.

  • It must be easily accessible;
  • written in plain language;
  • Must allow users to set their cookies preference;
  • Include the link to the cookies and other tracking technologies policy; and
  • updated in line with changes to the Cookie Policy or applicable legal requirements.

8.4 Data Classification and Confidentiality Policy

BEEZENDS GLOBAL PAY SERVICES LTD Data Classification and Confidentiality Policy establishes how data is categorized based on sensitivity and the obligations of employees, contractors, and third parties to maintain the confidentiality of sensitive and personal data. This policy ensures consistent identification, labelling, and handling of data while safeguarding against unauthorized disclosure, misuse, or loss. Specifically, the policy covers:

  • Data Categories: classification levels such as Public, Internal Use, Restricted, and Confidential.
  • Criteria for Classification: factors used to determine classification, including legal/regulatory requirements, business impact, and sensitivity of the data.
  • Handling Procedures: rules for accessing, storing, transmitting, and disposing of data in each category.
  • Confidentiality Obligations: responsibilities of employees, contractors, and third parties to protect sensitive and personal data both during and after their engagement with BEEZENDS GLOBAL PAY SERVICES LTD.
  • Non-Disclosure Requirements: prohibition against unauthorized sharing or disclosure of confidential information, including intellectual property, trade secrets, customer data, and operational records.
  • Access Control: measures to ensure that only authorized individuals can access data based on its classification and confidentiality requirements.

This policy promotes accountability, consistent handling of data, and compliance with data protection requirements, ensuring that appropriate safeguards and confidentiality obligations are upheld throughout the data lifecycle.

Establishes the obligations of employees, contractors, and third parties to maintain the confidentiality of sensitive and personal data they may access during business operations, both during and after their engagement with BEEZENDS GLOBAL PAY SERVICES LTD.

8.5 Data Subject Rights Policy

BEEZENDS GLOBAL PAY SERVICES LTD Data Subject Rights Policy defines the rights of individuals under applicable data protection laws and establishes the processes by which those rights can be exercised and fulfilled. The policy ensures that data subjects are empowered to understand, control, and protect their personal information while BEEZENDS GLOBAL PAY SERVICES LTD remains accountable for responding in a fair, lawful, and timely manner. Specifically, the policy covers:

  • Access Rights: the right of individuals to obtain confirmation of whether their data is being processed and to receive a copy of their personal data.
  • Rectification: the right to correct inaccurate or incomplete personal data.
  • Erasure (“Right to be Forgotten”): the right to request deletion of personal data, subject to legal or operational limitations.
  • Restriction of Processing: the right to limit the way personal data is processed under certain circumstances.
  • Objection: the right to object to processing activities, including direct marketing.
  • Data Portability: the right to request and receive personal data in a structured, commonly used, and machine-readable format, and to transfer it to another controller.
  • Right to not be subject to decisions made solely based on automated decision-making.
  • Grievance Resolution – SNAG Process: mechanisms for handling complaints, disputes, and requests, ensuring fair consideration and resolution.
  • Timelines for Response: commitment to acknowledging and fulfilling data subject requests within statutory deadlines.
  • Verification and Security Measures: processes for validating the identity of data subjects before acting on their requests to protect against unauthorized disclosures.
  • Awareness and Communication: ensuring that individuals are informed about their rights through accessible privacy notices and communication channels.

This policy reinforces BEEZENDS GLOBAL PAY SERVICES LTD commitment to fairness, transparency, and accountability by ensuring individuals can effectively exercise their rights and by maintaining robust procedures for compliance.

8.6 Data Retention and Disposal Policy

BEEZENDS GLOBAL PAY SERVICES LTD Data Retention and Disposal Policy establishes the rules and standards for how long personal and business data must be stored and the methods for its secure disposal once it is no longer required. The policy ensures compliance with legal, regulatory, contractual, and business requirements, while also minimizing risks associated with over-retention, unauthorized access, or improper destruction of data. Specifically, the policy covers:

  • Categories of Data Covered: types of data subject to retention, including customer records, employee information, financial data, contractual documents, and operational records.
  • Retention Periods: defined timelines for maintaining data based on statutory obligations, regulatory requirements, and business needs.
  • The legal and operational grounds on which data is retained (e.g., tax laws, employment laws, dispute resolution, regulatory investigations).
  • Data Disposal Practices: secure methods for deleting or destroying data (e.g., shredding, secure deletion, anonymization) when retention periods expire.
  • Data Subject Rights: the ability of individuals to request deletion or erasure of their data, subject to lawful retention obligations.
  • Storage and Security Measures: technical and organizational controls to ensure retained data remains secure and confidential throughout its lifecycle.
  • International Data Transfers: conditions under which retained data may be transferred outside Nigeria and safeguards to ensure compliance.

This policy reinforces BEEZENDS GLOBAL PAY SERVICES LTD commitment to accountability, transparency, and responsible data stewardship by ensuring data is retained only for as long as necessary and disposed of securely when no longer required.

8.7 Third-Party and Vendor Management Policy

BEEZENDS GLOBAL PAY SERVICES LTD Third-Party and Vendor Management Policy establishes the framework for selecting, onboarding, monitoring, and managing third parties, vendors, and service providers who process data or provide critical services on behalf of the organization. The policy ensures that third-party engagements comply with applicable legal, regulatory, and contractual obligations while upholding BEEZENDS GLOBAL PAY SERVICES LTD standards for security, privacy, and ethical conduct. Specifically, the policy covers:

  • Categories of Data Shared: types of personal and business data that may be accessed or processed by third parties, including customer, employee, financial, and operational information.
  • Legal Bases for Sharing: the legal grounds for disclosing data to vendors and partners (e.g., contractual necessity, regulatory requirements, or consent).
  • Data Sharing Practices: requirements and controls for when and how data may be shared with third parties, including confidentiality obligations, contractual safeguards, and compliance with data protection laws.
  • Vendor Risk Assessments: due diligence processes for assessing the security, privacy, financial, and operational risks of third parties before engagement and on a recurring basis.
  • Data Subject Rights: assurances that vendors and partners respect the rights of individuals in line with BEEZENDS GLOBAL PAY SERVICES LTD obligations.
  • Monitoring and Audits: ongoing oversight mechanisms such as periodic reviews, audits, and performance evaluations to ensure compliance with policy requirements.

Provides a framework for managing data protection risks associated with outsourcing and partnerships.

8.8 Breach Management and Incident Response Policy

BEEZENDS GLOBAL PAY SERVICES LTD Breach Management and Incident Response Policy defines the framework for identifying, reporting, managing, and resolving actual or suspected data breaches, security incidents, or policy violations in compliance with applicable data protection and cybersecurity regulations. The policy ensures timely containment, investigation, communication, and remediation of incidents to minimize risk and safeguard data subjects. Specifically, the policy covers:

  • Categories of Incidents Covered: data breaches (unauthorized access, loss, disclosure, or destruction of personal data), cybersecurity incidents (malware, ransomware, denial of service), insider threats, and other privacy or security violations.
  • The legal obligations require incident reporting and remediation, including NDPA, NDPR, GAID, and regulatory directives from the Nigeria Data Protection Commission (NDPC) or other relevant authorities.
  • Incident Reporting and Escalation: procedures for employees, contractors, and third parties to promptly report incidents; defined escalation paths; and roles/responsibilities of the incident response team.
  • Containment and Investigation: steps for immediate containment of breaches, forensic analysis, root-cause investigation, and impact assessment.
  • Notification Obligations: requirements for notifying affected individuals, regulators, and other stakeholders within legally mandated timelines and in a transparent manner.
  • Data Subject Rights: assurance that breach response activities respect individual rights (e.g., right to be informed, access, rectification, and erasure).
  • Storage and Security Measures: documentation and secure retention of incident logs, investigation reports, and lessons learned for audit and accountability purposes.
  • Third-Party Involvement: procedures for coordinating with vendors, regulators, and law enforcement agencies when breaches involve external parties.
  • Continuous Improvement: post-incident reviews, policy updates, staff training, and simulation exercises to strengthen incident preparedness and resilience.

This policy outlines BEEZENDS GLOBAL PAY SERVICES LTD proactive commitment to detecting, reporting, managing, and mitigating personal data breaches. It includes internal escalation procedures, external notification timelines, and documentation requirements in line with legal obligations.

8.9 Training and Awareness Policy

BEEZENDS GLOBAL PAY SERVICES LTD Data Protection Training and Awareness Policy establishes a framework for equipping employees, contractors, and third parties with the knowledge and skills necessary to comply with data protection, privacy, security, and confidentiality obligations. The policy ensures that all personnel understand their roles and responsibilities in safeguarding personal and sensitive data, thereby fostering a culture of accountability and compliance. Specifically, the policy covers:

  • Categories of Training Provided: data protection and privacy rights, information security, confidentiality and non-disclosure, acceptable use of systems, breach response, vendor management, and emerging regulatory updates.
  • Compliance with obligations under the Nigeria Data Protection Act (NDPA), General Application and Implementation Directive (GAID), and other applicable laws requiring organizations to demonstrate accountability and staff awareness.
  • Mandatory training for employees; role-specific and enhanced training for high-risk functions (e.g., IT, Legal, Compliance, Operations, and Customer Service).
  • Training Delivery Methods: onboarding sessions, periodic refresher courses, workshops, e-learning modules, newsletters, and awareness campaigns tailored to roles and business functions.
  • Monitoring and Evaluation: assessments, tests, and feedback mechanisms to evaluate training effectiveness and measure staff knowledge retention.
  • Storage and Security Measures: secure maintenance of training records, attendance logs, test results, and evidence of compliance for audit purposes.

This policy ensures that every individual handling personal data on behalf of BEEZENDS GLOBAL PAY SERVICES LTD is consistently educated, aware, and accountable for compliance with data protection standards.

8.10 Data Protection Impact Assessments (DPIAs) Policy

BEEZENDS GLOBAL PAY SERVICES LTD Data Protection Impact Assessments (DPIAs) Policy establishes a structured process for identifying, assessing, and mitigating privacy and data protection risks associated with high-risk processing activities. The policy ensures compliance with the Nigeria Data Protection Act (NDPA), the General Application and Implementation Directive (GAID), and other applicable laws by embedding DPIAs into the organization’s project lifecycle, product development, and operational decision-making. Specifically, the policy covers:

  • Categories of Processing Subject to DPIAs: activities likely to result in high risks to the rights and freedoms of individuals, including large-scale processing of sensitive data, cross-border transfers, use of emerging technologies (AI, biometrics), and systematic monitoring of data subjects.
  • Compliance with legal and regulatory obligations, demonstration of accountability under NDPA/GAID, and alignment with BEEZENDS GLOBAL PAY SERVICES LTD governance framework.
  • DPIA Procedure: screening of processing activities, risk assessment, stakeholder engagement, documentation of risks and safeguards, and management approval.
  • Monitoring and Evaluation: ongoing review of processing activities post-DPIA to ensure that safeguards remain effective and aligned with legal and operational requirements.

This policy reinforces BEEZENDS GLOBAL PAY SERVICES LTD commitment to embedding risk-based privacy safeguards into its operations, thereby protecting individuals’ rights while enabling responsible innovation.

9. Data Protection Audit

BEEZENDS GLOBAL PAY SERVICES LTD shall conduct an annual data protection audit through a licensed Data Protection Compliance Organization (DPCO) to verify BEEZENDS GLOBAL PAY SERVICES LTD compliance with the provisions of the Nigeria Data Protection Act (NDPA) 2023, the General Application and Implementation Directive (GAID) 2025, and other applicable data protection laws and regulations.

The audit report shall be certified and filed with the Nigeria Data Protection Commission (NDPC) or any other competent authority in line with regulatory obligations.

10. Policy Monitoring and Renewal

This policy shall be reviewed every two (2) years or as needed, particularly when there are material changes to applicable laws, regulatory guidance, organisational structure, or operational practices that affect the processing and protection of personal data.

When evaluating the effectiveness and adequacy of this policy, the following criteria shall be considered:

  • Frequency and nature of data protection incidents, including breaches or non-compliance;
  • Level of compliance with the policy by internal teams;
  • Feedback from users, departments, and stakeholders on the clarity and practicality of the policy;
  • Results from internal audits, regulatory inspections, or external assessments related to data privacy practices;
  • Relevance and alignment of policy requirements with emerging data protection risks and legal obligations;
  • Adequacy of current technical and organisational safeguards and supporting procedures in ensuring lawful and secure data processing across the data lifecycle.

Schedule A: Definition and Acronyms

For the purposes of this Policy, the following terms shall have the meanings stated below: