Tech & Counsel

Learn/Applied Data Privacy and Policy Drafting

DPIAs and Checking a Risky Feature

About 15 minutes

Tech & Counsel provides education only. Nothing on this site is legal advice, and nothing here creates a solicitor–client relationship.

A data protection impact assessment is the structured pause before a risky feature ships. The Nigeria Data Protection Commission’s forms and portals change. This lesson teaches the questions. It does not teach a filing ritual. Confirm the current instrument before anyone treats these steps as a submission.

When to insist on the pause

Ask for the assessment when the feature does any of these:

  • Collects a new category, especially location, messages, biometrics, or financial data.
  • Uses a new SDK or sends data to a new processor.
  • Stores data in a new country or a new region.
  • Makes an automated decision about a person.
  • Keeps data longer, or for a new purpose such as training a model.
  • Is hard to undo once it is in the stores.

A small wording change on an existing screen usually does not need one. A feature that reads bank SMS to move money does.

What you actually produce

A short record, written with the product manager, not a novel:

  1. Describe the feature in one paragraph a user would recognise.
  2. List the fields, from the data map, including fields the SDK collects on its own.
  3. Say why each field is necessary. If identity can be checked another way, write that down.
  4. Name the risks: breach, unwanted disclosure to the SDK, a dark pattern in the consent, indefinite retention.
  5. Name the mitigations already in the design: hashing, a retention job, a banner that blocks the SDK, a region choice.
  6. Record the decision: ship, ship with changes, or do not ship. Name the person who accepted the residual risk.

If the team cannot answer step 2, they are not ready for step 6. Send them back to the dictionary.

Create a free account to mark this lesson complete.