C.A.C Data Breach: ASF France Calls for Accountability
Summarized and contextualized by DistantNews.
TLDR
- Avocats Sans Frontières France (ASF France) has voiced strong concerns over a data breach at Nigeria's Corporate Affairs Commission (CAC).
- The breach allegedly exposed sensitive personal data of Nigerian entrepreneurs, including signatures and identity documents, violating privacy rights.
- ASF France criticizes the CAC's response, calling for greater transparency, accountability, and improved data protection measures.
Avocats Sans Frontières France (ASF France) has sounded the alarm regarding a significant data breach at the Corporate Affairs Commission (CAC), highlighting the profound implications for the privacy rights of Nigerian entrepreneurs and the integrity of the nation's digital governance. The organization's Country Director, Angela Uwandu Uzoma-Iwuchukwu, stated that the breach, reportedly executed by a threat actor known as “ByteToBreach,” compromised highly sensitive information such as handwritten signatures, national identity documents, and passport photographs.
ASF France criticised the Commission’s handling of public communication, noting that the absence of clear disclosure on the number of affected individuals has left millions of business owners uncertain.
ASF France unequivocally condemned the incident as a severe infringement upon the constitutional right to privacy and the stipulations of the Nigeria Data Protection Act (NDPA). The group specifically took issue with the CAC's handling of public communication following the breach. The lack of clear disclosure regarding the number of individuals affected has left millions of business owners in a state of uncertainty. Furthermore, the characterization of the disruption as mere “scheduled maintenance” is seen as a tactic that could erode public confidence and undermine transparency.
The organization argued that the CAC's response falls short of legal mandates, particularly concerning the notification of victims. Under the NDPA, data controllers are obligated to directly inform affected individuals about high-risk breaches. ASF France deemed general advisories for users to monitor their records as insufficient. While acknowledging the involvement of the Nigeria Data Protection Commission and the National Information Technology Development Agency, ASF France urged a transition from reactive measures to a framework of restorative justice. The group pointed to the absence of clear mechanisms for victims to seek compensation or secure their compromised identities, especially given reported vulnerabilities linked to third-party systems.
It stressed that under the NDPA, data controllers must directly inform affected individuals in cases of high-risk breaches, adding that general advisories urging users to monitor their records are inadequate.
To address these systemic failures, ASF France proposed a suite of reforms. These include an independent forensic audit of CAC systems, the implementation of stronger regulatory enforcement, and the introduction of identity protection measures, such as free processes for flagging compromised data. The organization stressed that this breach must serve as a critical juncture for Nigeria to cultivate a more accountable and resilient data protection regime, emphasizing the need for legislative oversight and the adoption of data minimization practices.
It highlighted the absence of clear mechanisms for victims to seek compensation or secure compromised identities, especially in light of reported vulnerabilities linked to third-party systems.
Originally published by ThisDay. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.