Learning Objectives:

  • Understand the key data protection and privacy laws affecting financial institutions.

  • Apply data protection requirements to cybersecurity programs.

  • Recognise the implications of cross-border data flows for cyber risk management.

  • Understand the relationship between data protection and cybersecurity.

5.1 Data Protection and Privacy Laws

Financial institutions must comply with data protection and privacy laws that impose requirements for the protection of personal data. The Central Bank of Nigeria’s Framework considers the requirements of the Nigerian Data Protection Act (NDPA) 2023, which aligns with global standards for data protection.

Key Data Protection Requirements:

Lawful Basis for Processing: Financial institutions must have a lawful basis for collecting and processing personal data.

Data Subject Rights: Individuals have the right to access, rectify, and delete their personal data.

Data Protection by Design: Data protection must be integrated into the design of systems and processes.

Breach Notification: Data breaches must be reported to regulators and affected individuals.

Data Retention: Personal data must be retained only for as long as necessary.

5.2 Data Protection and Cybersecurity

Cybersecurity and data protection are closely linked. The Regulation on Information Systems and Cyber Risk Management requires that the risk management process addresses the confidentiality, integrity, and availability of information. The EBA’s Guidelines on ICT and security risk management set out requirements for the protection of information assets.

Key Interconnections:

Data Confidentiality: Ensuring that data is accessible only to authorised individuals.

Data Integrity: Ensuring that data is accurate and complete.

Data Availability: Ensuring that data is accessible when needed.

5.3 Cross-Border Data Flows

Cross-border data flows are subject to increasing regulation. The People’s Bank of China’s Administrative Measures for the Reporting of Cybersecurity Incidents requires financial institutions to report cybersecurity incidents that occur within the territory of the People’s Republic of China . The Measures also address data protection requirements for the PBC’s business domain .

Key Considerations:

Data Localization: Requirements to keep data within specific geographic boundaries.

Data Transfer Mechanisms: Legal mechanisms for transferring data across borders.

Regulatory Notification: Notification requirements for cross-border data transfers.

5.4 Data Security and Breach Notification

The Central Bank of the UAE requires the API Hub to immediately notify the Central Bank of any significant breaches of User Data and notify the User of such breaches without undue delay . The API Hub must also immediately report major security and operational incidents, including downtimes, to the Central Bank .

Breach Notification Requirements:

  • Immediate Notification: Notify the regulator and affected individuals without undue delay.

  • Investigation: Conduct a thorough investigation of the breach.

  • Remediation: Take steps to remediate the breach and prevent recurrence.