📖 ABSTRACT/OVERVIEW
Data breaches affecting Nigerian e-commerce platforms expose customer financial and personal data, yet most platforms lack professionally designed response protocols that enable rapid containment, regulatory reporting, and customer notification in compliance with Nigerian data protection law. This study developed a data breach response protocol for Nigerian e-commerce platforms operating under the Nigeria Data Protection Regulation 2019 and Nigeria Data Protection Act 2023 regulatory regime. A professional protocol design methodology was applied, drawing on a breach incident survey of 20 Nigerian e-commerce platform operators, review of NITDA NDPA guidance, European GDPR breach notification standards, and structured consultations with 10 data protection lawyers and 8 platform security engineers. Incident survey results showed that detection-to-containment time averaged 72 hours, NITDA breach notification within the required 72-hour window was not achieved in any documented incident reviewed, and customer notification was absent in 80.0 percent of breach cases. The protocol developed covers six phases: breach detection and preliminary assessment, immediate containment, forensic investigation, regulatory notification, customer communication, and post-breach review. Specific provisions for each NDPA notification requirement and customer rights restoration obligations are included. Expert review by eight data protection and e-commerce security specialists confirmed the protocol's regulatory alignment. The study recommends the protocol be published by NITDA as a sectoral data breach response guidance document for Nigerian e-commerce operators.
Keywords: data breach response, e-commerce, NDPA, Nigeria Data Protection, breach notification
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬