Miva Open University, Data Privacy and Protection Policy

Effective Date: Sept. 23, 2024

1. Introduction

In the digital age, safeguarding personal information has become a critical priority for organizations across the globe. As an institution of higher learning, Miva Open University is committed to ensuring the privacy and protection of the personal data of all individuals who interact with the University, including students, faculty, staff, contractors, and visitors. This policy is aligned with the Nigeria Data Protection Act 2023 (NDPA 2023), which mandates that organizations implement strict measures to protect personal data and uphold the privacy rights of individuals.

Miva Open University collects and processes personal data to provide high-quality education and support services, ensure operational efficiency, and maintain academic integrity. The personal data collected may include names, contact information, academic records, employment history, health information, and other sensitive data necessary for academic and administrative purposes. Ensuring the privacy, confidentiality, and security of this information is a top priority, and the University is committed to handling data responsibly and ethically.

This Data Privacy and Protection Policy outlines the procedures and safeguards Miva Open University employs to protect personal data. It defines how data is collected, used, stored, and shared, ensuring compliance with applicable data protection laws and regulations. The policy also informs individuals of their rights concerning their data and provides guidance on how the University manages data breaches and other privacy concerns.

By adhering to this policy, Miva Open University demonstrates its commitment to building trust and maintaining the highest standards of data protection, contributing to a secure and reliable educational environment for all members of the University community.

2. Scope

This policy applies to all aspects of data collection, processing, storage, and transmission within Miva Open University. It governs how personal data is handled by all individuals and entities associated with the University, including but not limited to full-time and part-time staff, faculty, students, contractors, vendors, and third-party service providers. The policy ensures that any person or organization that interacts with the University's data systems adheres to the highest standards of data privacy and protection, as mandated by the Nigeria Data Protection Regulation (NDPR).

The scope of this policy covers all types of personal data, whether collected in digital or physical formats, including but not limited to names, contact information, financial data, academic records, health information, and sensitive personal identifiers. This policy also extends to any third-party partners or service providers who process personal data on behalf of the University, ensuring that they comply with the same standards of security and confidentiality.

Furthermore, this policy applies to all systems, devices, and platforms used to store, process, or transmit personal data, whether hosted on-site, in the cloud, or via external services. It ensures that data protection measures are implemented across all levels of interaction, from data collection through online forms, email communications, physical records, and academic or administrative systems, to the secure disposal of data that is no longer needed.

By establishing clear guidelines for every participant within the University's data ecosystem, this policy helps safeguard personal data from unauthorized access, breaches, or misuse, thus fostering a secure academic environment for both individuals and the University as a whole.

3. General Principles for Data Processing

At Miva Open University, the processing of personal data is guided by a set of core principles that ensure compliance with the Nigeria Data Protection Act 2023 (NDPA 2023) and reflect the University's commitment to protecting individual privacy. These principles are fundamental to the responsible and ethical handling of personal data, ensuring that it is processed lawfully, fairly, and transparently, while minimizing risks to data subjects.

3.1 Lawfulness, Fairness, and Transparency

Personal data must be processed in a lawful, fair, and transparent manner at all times. This means that the University collects and uses personal data based on legitimate and clearly defined purposes, which are communicated to the data subjects in an understandable and accessible manner.

3.2 Data Accuracy

Ensuring the accuracy of personal data is critical to maintaining the integrity of the University's records and preventing harm to data subjects.

3.3 Purpose Limitation

Personal data collected by the University is used only for the specific, explicit, and legitimate purposes for which it was originally collected. Data is not processed further in a way that is incompatible with these purposes, unless the data subject has provided consent or there is a lawful basis for additional processing.

3.4 Data Minimization

The University collects only the personal data that is necessary, adequate, and relevant to the specific purpose for which it is being processed. Excessive or irrelevant data is not collected, and the volume of data retained is limited to what is required for academic, administrative, or legal needs.

3.5 Storage Limitation

Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Once data is no longer needed, it is securely deleted, anonymised, or archived in line with the University's Data Retention Policy.

3.6 Integrity and Confidentiality

Personal data is processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through appropriate technical and organizational measures.

3.7 Accountability

The University is responsible for, and able to demonstrate compliance with, all of the principles above. Roles, responsibilities, and processes are documented; staff are trained; and records of processing activities are maintained.

4. Rights of Data Subjects

Miva Open University respects the rights of data subjects under the NDPA 2023 and applicable international standards. These include:

4.1 Right to Be Informed

Data subjects have the right to be informed about:

4.2 Right of Access

Data subjects may request confirmation of whether their personal data is being processed and obtain a copy of that data.

4.3 Right to Rectification

Data subjects have the right to request correction of inaccurate or incomplete personal data held about them.

4.4 Right to Erasure

Data subjects may request deletion of their personal data where, for example:

4.5 Right to Data Portability

Where technically feasible, data subjects may request that their personal data be transferred to another controller in a structured, commonly used, machine-readable format.

4.6 Right to Object

Data subjects may object to the processing of their personal data in certain circumstances, including direct marketing and processing based on legitimate interests.

5. Procedure for Exercising Data Subject Rights

To exercise any of the rights above, data subjects should submit a written request to the Data Protection Officer using the contact details in Section 9. Requests should include:

5.1 Acknowledgement of Requests

The University will acknowledge receipt of valid requests promptly and respond within the timelines required by applicable law.

5.2 Verification of Identity

Before disclosing any personal data, the University will take reasonable steps to verify the identity of the person making the request to ensure data is not released to unauthorized parties.

6. Legal Grounds for Processing Personal Data

Personal data is processed only where at least one lawful basis applies, including:

Processing of Sensitive Personal Data

The processing of sensitive personal data is restricted and only permitted where one of the following applies:

  1. Explicit Consent: The Data Subject has given explicit consent for processing their sensitive data.
  2. Legal or Employment Obligations: Processing is necessary to comply with legal obligations in areas such as employment law, social security, or health and safety.

7. Consent

7.1 Obtaining Consent

Consent is defined as a freely given, specific, informed, and unambiguous indication of the Data Subject's agreement to the processing of their personal data. The University ensures that Data Subjects provide their consent voluntarily, without coercion, and are fully aware of what they are consenting to.

7.2 Clarity of Consent Requests

Consent requests are presented in clear, plain language and are kept separate from other matters so that data subjects can easily understand what they are agreeing to.

7.3 Granularity

Where multiple processing activities are involved, consent is sought separately for each, so that data subjects can choose to consent to some activities and not others.

7.4 Records of Consent

The University keeps records of consents obtained, including when and how consent was given and the information provided to the data subject at the time.

7.5 Children and Vulnerable Persons

Where personal data of children or other vulnerable persons is processed, additional safeguards are applied, including obtaining consent from a parent or guardian where required by law.

7.6 Withdrawal of Consent

Data Subjects may withdraw consent at any time without penalty. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.

8. Data Breach Management

8.1 Types of Data Breaches

  1. Confidentiality Breaches: Unauthorized or accidental disclosure of, or access to, personal data.
  2. Integrity Breaches: Unauthorized or accidental alteration of personal data.
  3. Availability Breaches: Accidental or unauthorized loss of access to, or destruction of, personal data.
  4. System Breaches: Compromise of systems that store or process personal data, including via malware or hacking.
  5. Physical Security Breaches: When personal data stored in physical formats (e.g., paper records) is improperly accessed or mishandled.

8.2 Breach Detection and Identification

The University maintains monitoring, logging, and reporting mechanisms to detect potential data breaches as early as possible. Staff and students are required to report any suspected breach to the Data Protection Officer without undue delay.

8.3 Containment

On detection of a breach, immediate steps are taken to contain it, prevent further loss or damage, and preserve evidence for investigation.

8.4 Investigation and Corrective Actions

The University investigates each reported breach to determine its cause, scope, and impact.

  1. Corrective Actions: Based on the findings of the investigation, the University implements corrective measures to prevent a recurrence of the breach. This could include updating security protocols, patching system vulnerabilities, retraining staff, or strengthening access controls.

8.5 Notification of Data Breaches

Where a breach is likely to result in a risk to the rights and freedoms of data subjects, the University will notify the relevant supervisory authority and, where required, affected data subjects. Notifications include:

8.6 Mitigation and Recovery

Following a breach, the University takes appropriate steps to mitigate harm to affected individuals and to restore the integrity, availability, and confidentiality of affected systems and data.

9. Data Protection Officer (DPO)

9.1 Contact Information of DPO

The Data Protection Officer
Miva Open University
dpo@miva.university

10. Data Transfers

Where personal data is transferred outside Nigeria, the University ensures that appropriate safeguards are in place to provide a level of protection essentially equivalent to that required under Nigerian law, including appropriate contractual clauses and assessments of the recipient jurisdiction.

← Back to home