Miva Open University, Data Privacy and Protection Policy
Effective Date: Sept. 23, 2024
1. Introduction
In the digital age, safeguarding personal information has become a critical priority for organizations across the globe. As an institution of higher learning, Miva Open University is committed to ensuring the privacy and protection of the personal data of all individuals who interact with the University, including students, faculty, staff, contractors, and visitors. This policy is aligned with the Nigeria Data Protection Act 2023 (NDPA 2023), which mandates that organizations implement strict measures to protect personal data and uphold the privacy rights of individuals.
Miva Open University collects and processes personal data to provide high-quality education and support services, ensure operational efficiency, and maintain academic integrity. The personal data collected may include names, contact information, academic records, employment history, health information, and other sensitive data necessary for academic and administrative purposes. Ensuring the privacy, confidentiality, and security of this information is a top priority, and the University is committed to handling data responsibly and ethically.
This Data Privacy and Protection Policy outlines the procedures and safeguards Miva Open University employs to protect personal data. It defines how data is collected, used, stored, and shared, ensuring compliance with applicable data protection laws and regulations. The policy also informs individuals of their rights concerning their data and provides guidance on how the University manages data breaches and other privacy concerns.
By adhering to this policy, Miva Open University demonstrates its commitment to building trust and maintaining the highest standards of data protection, contributing to a secure and reliable educational environment for all members of the University community.
2. Scope
This policy applies to all aspects of data collection, processing, storage, and transmission within Miva Open University. It governs how personal data is handled by all individuals and entities associated with the University, including but not limited to full-time and part-time staff, faculty, students, contractors, vendors, and third-party service providers. The policy ensures that any person or organization that interacts with the University's data systems adheres to the highest standards of data privacy and protection, as mandated by the Nigeria Data Protection Regulation (NDPR).
The scope of this policy covers all types of personal data, whether collected in digital or physical formats, including but not limited to names, contact information, financial data, academic records, health information, and sensitive personal identifiers. This policy also extends to any third-party partners or service providers who process personal data on behalf of the University, ensuring that they comply with the same standards of security and confidentiality.
Furthermore, this policy applies to all systems, devices, and platforms used to store, process, or transmit personal data, whether hosted on-site, in the cloud, or via external services. It ensures that data protection measures are implemented across all levels of interaction, from data collection through online forms, email communications, physical records, and academic or administrative systems, to the secure disposal of data that is no longer needed.
By establishing clear guidelines for every participant within the University's data ecosystem, this policy helps safeguard personal data from unauthorized access, breaches, or misuse, thus fostering a secure academic environment for both individuals and the University as a whole.
3. General Principles for Data Processing
At Miva Open University, the processing of personal data is guided by a set of core principles that ensure compliance with the Nigeria Data Protection Act 2023 (NDPA 2023) and reflect the University's commitment to protecting individual privacy. These principles are fundamental to the responsible and ethical handling of personal data, ensuring that it is processed lawfully, fairly, and transparently, while minimizing risks to data subjects.
3.1 Lawfulness, Fairness, and Transparency
Personal data must be processed in a lawful, fair, and transparent manner at all times. This means that the University collects and uses personal data based on legitimate and clearly defined purposes, which are communicated to the data subjects in an understandable and accessible manner.
- Lawfulness: All data processing activities must be grounded in one of the legal bases outlined in the NDPR, such as obtaining the data subject's consent, fulfilling contractual obligations, complying with legal requirements, or safeguarding vital interests.
- Fairness: The University ensures that data subjects are treated fairly, meaning that data is not collected or used in ways that could deceive or harm individuals. Data subjects are informed of their rights and how their personal data will be used.
- Transparency: The University is committed to transparency by providing clear, concise, and easily accessible information about data collection practices, data subjects' rights, and the purposes for which their data will be used. Privacy notices and consent forms are presented in clear and understandable language.
3.2 Data Accuracy
Ensuring the accuracy of personal data is critical to maintaining the integrity of the University's records and preventing harm to data subjects.
- Accurate Data Collection: Miva Open University takes measures to ensure that the data it collects is accurate, complete, and up-to-date at the time of collection. Inaccurate data may lead to incorrect decisions or negative outcomes for the data subject, particularly in academic, financial, or employment-related contexts.
- Ongoing Data Review: The University has established processes to review and update personal data regularly, ensuring that outdated or incorrect data is corrected or erased in a timely manner. Data subjects are also encouraged to review and update their information through accessible platforms provided by the University.
3.3 Purpose Limitation
Personal data collected by the University is used only for the specific, explicit, and legitimate purposes for which it was originally collected. Data is not processed further in a way that is incompatible with these purposes, unless the data subject has provided consent or there is a lawful basis for additional processing.
3.4 Data Minimization
The University collects only the personal data that is necessary, adequate, and relevant to the specific purpose for which it is being processed. Excessive or irrelevant data is not collected, and the volume of data retained is limited to what is required for academic, administrative, or legal needs.
3.5 Storage Limitation
Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Once data is no longer needed, it is securely deleted, anonymised, or archived in line with the University's Data Retention Policy.
3.6 Integrity and Confidentiality
Personal data is processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through appropriate technical and organizational measures.
- Archival for Public Interest or Research: In cases where personal data is retained for historical research, statistical analysis, or archiving in the public interest, appropriate safeguards are in place to ensure that data privacy is maintained, and the data is securely stored.
3.7 Accountability
The University is responsible for, and able to demonstrate compliance with, all of the principles above. Roles, responsibilities, and processes are documented; staff are trained; and records of processing activities are maintained.
4. Rights of Data Subjects
Miva Open University respects the rights of data subjects under the NDPA 2023 and applicable international standards. These include:
4.1 Right to Be Informed
Data subjects have the right to be informed about:
- The purpose of processing their data.
- The categories of personal data being processed.
- The third parties or recipients with whom the data may be shared.
4.2 Right of Access
Data subjects may request confirmation of whether their personal data is being processed and obtain a copy of that data.
4.3 Right to Rectification
Data subjects have the right to request correction of inaccurate or incomplete personal data held about them.
4.4 Right to Erasure
Data subjects may request deletion of their personal data where, for example:
- The data has been unlawfully processed.
- The data must be erased to comply with a legal obligation under Nigerian law or any applicable regulation.
4.5 Right to Data Portability
Where technically feasible, data subjects may request that their personal data be transferred to another controller in a structured, commonly used, machine-readable format.
- Format of Data: The University will ensure that the personal data provided in response to such requests is delivered in a standardized format that is compatible with widely used systems.
4.6 Right to Object
Data subjects may object to the processing of their personal data in certain circumstances, including direct marketing and processing based on legitimate interests.
5. Procedure for Exercising Data Subject Rights
To exercise any of the rights above, data subjects should submit a written request to the Data Protection Officer using the contact details in Section 9. Requests should include:
- The data subject's full name and contact details.
- A clear description of the data or processing activities the request relates to, to enable efficient retrieval.
5.1 Acknowledgement of Requests
The University will acknowledge receipt of valid requests promptly and respond within the timelines required by applicable law.
5.2 Verification of Identity
Before disclosing any personal data, the University will take reasonable steps to verify the identity of the person making the request to ensure data is not released to unauthorized parties.
6. Legal Grounds for Processing Personal Data
Personal data is processed only where at least one lawful basis applies, including:
- Consent of the data subject.
- Performance of a contract with the data subject, or steps taken at their request prior to entering into a contract.
- Compliance with a legal obligation to which the University is subject.
- Protection of vital interests of the data subject or another natural person.
- Public interest or exercise of official authority vested in the University.
- Legitimate interests pursued by the University or a third party, except where overridden by the data subject's rights.
Processing of Sensitive Personal Data
The processing of sensitive personal data is restricted and only permitted where one of the following applies:
- Explicit Consent: The Data Subject has given explicit consent for processing their sensitive data.
- Legal or Employment Obligations: Processing is necessary to comply with legal obligations in areas such as employment law, social security, or health and safety.
7. Consent
7.1 Obtaining Consent
Consent is defined as a freely given, specific, informed, and unambiguous indication of the Data Subject's agreement to the processing of their personal data. The University ensures that Data Subjects provide their consent voluntarily, without coercion, and are fully aware of what they are consenting to.
7.2 Clarity of Consent Requests
Consent requests are presented in clear, plain language and are kept separate from other matters so that data subjects can easily understand what they are agreeing to.
7.3 Granularity
Where multiple processing activities are involved, consent is sought separately for each, so that data subjects can choose to consent to some activities and not others.
7.4 Records of Consent
The University keeps records of consents obtained, including when and how consent was given and the information provided to the data subject at the time.
7.5 Children and Vulnerable Persons
Where personal data of children or other vulnerable persons is processed, additional safeguards are applied, including obtaining consent from a parent or guardian where required by law.
7.6 Withdrawal of Consent
Data Subjects may withdraw consent at any time without penalty. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
8. Data Breach Management
8.1 Types of Data Breaches
- Confidentiality Breaches: Unauthorized or accidental disclosure of, or access to, personal data.
- Integrity Breaches: Unauthorized or accidental alteration of personal data.
- Availability Breaches: Accidental or unauthorized loss of access to, or destruction of, personal data.
- System Breaches: Compromise of systems that store or process personal data, including via malware or hacking.
- Physical Security Breaches: When personal data stored in physical formats (e.g., paper records) is improperly accessed or mishandled.
8.2 Breach Detection and Identification
The University maintains monitoring, logging, and reporting mechanisms to detect potential data breaches as early as possible. Staff and students are required to report any suspected breach to the Data Protection Officer without undue delay.
8.3 Containment
On detection of a breach, immediate steps are taken to contain it, prevent further loss or damage, and preserve evidence for investigation.
8.4 Investigation and Corrective Actions
The University investigates each reported breach to determine its cause, scope, and impact.
- Corrective Actions: Based on the findings of the investigation, the University implements corrective measures to prevent a recurrence of the breach. This could include updating security protocols, patching system vulnerabilities, retraining staff, or strengthening access controls.
8.5 Notification of Data Breaches
Where a breach is likely to result in a risk to the rights and freedoms of data subjects, the University will notify the relevant supervisory authority and, where required, affected data subjects. Notifications include:
- The University's response to the breach and what actions it is taking to mitigate the impact.
- Contact information for further assistance and support.
8.6 Mitigation and Recovery
Following a breach, the University takes appropriate steps to mitigate harm to affected individuals and to restore the integrity, availability, and confidentiality of affected systems and data.
9. Data Protection Officer (DPO)
9.1 Contact Information of DPO
The Data Protection Officer
Miva Open University
dpo@miva.university
10. Data Transfers
Where personal data is transferred outside Nigeria, the University ensures that appropriate safeguards are in place to provide a level of protection essentially equivalent to that required under Nigerian law, including appropriate contractual clauses and assessments of the recipient jurisdiction.