Data Protection (JSS 2)
Introduction:
Think about this for a moment. You open your phone and all your photos are gone. Someone has accessed your school login and changed your details. Your parents' bank account information has been stolen because a family member clicked a suspicious link. These situations may sound like something from a movie, but they happen to real people every day — including families right here in Nigeria.
We now live in a world where almost everything we do leaves a digital trace. When you register on a website, fill a school form online, or even use a social media app, you are sharing data about yourself. That data — your name, age, address, phone number, photos — is valuable. And just like you protect your physical belongings from theft, you also need to protect your data from misuse.
Learning Objectives
By the end of this lesson, students should be able to:
- Define data protection in clear and simple terms
- Explain why data protection is important in our digital world
- Identify examples of personal data and sensitive data
- Describe the legal responsibilities involved in data protection in Nigeria
- Explain the ethical responsibilities of individuals and organisations when handling data
- Demonstrate safe practices for protecting personal data online and offline
What Is Data Protection?
Data protection refers to the process of safeguarding important information from loss, corruption, unauthorised access, or misuse. In simpler terms, it means keeping data safe and making sure only the right people can access it.
Data in this context means any information that can be used to identify a person or describe an event. This includes names, phone numbers, home addresses, email addresses, passwords, bank account details, photographs, medical records, and even school results.
When we talk about data protection, we are really asking two important questions:
First — how do we keep data safe from people who should not have access to it?
Second — how do we make sure that data is used in a fair, responsible, and honest way?
These two questions form the heart of data protection.
Types of Data That Need Protection
Not all data carries the same level of risk, but all personal data deserves some level of care. Here are the main types:
Personal Data This is any information that can identify a specific person. Examples include your full name, date of birth, home address, phone number, and email address. In a Nigerian school setting, your admission number, class, and parent's contact information are all personal data.
Sensitive Data This is a special category of personal data that requires extra protection because its exposure could cause serious harm. Examples include medical records, financial information, religious beliefs, political opinions, and biometric data such as fingerprints.
Organisational Data This includes records held by schools, hospitals, government agencies, banks, and businesses. For example, a school keeps the academic records of all its students. This is organisational data that must be protected.
Why Is Data Protection Important?
This is one of the most practical questions any student can ask. The truth is, when data is not properly protected, the consequences can be serious and sometimes irreversible. Let us look at why data protection matters so much.
It Prevents Identity Theft Identity theft happens when someone uses your personal information without your permission, usually to commit fraud or access your money. In Nigeria, many people have lost money to fraudsters who obtained their bank verification number (BVN), account details, or SIM card information through phishing scams or data breaches.
It Builds Trust When schools, hospitals, or companies protect your data well, you can trust them with your information. For example, if a hospital in Lagos stores patient records securely, patients will feel comfortable sharing sensitive health information that is necessary for proper treatment.
It Protects Children and Young People Young people are especially vulnerable online. A stranger who gains access to a child's name, school, and location could use that information in harmful ways. Data protection helps keep children safe by limiting who can access their personal information.
It Ensures Privacy Everyone has a right to privacy. This means you have the right to control who knows what about you. Data protection laws and practices help enforce this right. You should be able to decide who sees your phone number, your photographs, or your medical history.
It Supports Business and Economic Growth For businesses to grow in the digital age, customers must trust them. When companies in Nigeria protect customer data properly, people are more willing to shop online, use mobile banking apps, and engage with digital services. A single data breach can destroy a company's reputation and cause customers to leave.
It Prevents Cybercrime Cybercrime costs Nigeria billions of naira every year. Many of these crimes begin with stolen or poorly protected data. When individuals and organisations take data protection seriously, it becomes harder for cybercriminals to succeed.
Legal Responsibilities in Data Protection
Laws exist to make data protection mandatory, not just optional. In Nigeria, the most important legal framework for data protection is the Nigeria Data Protection Act (NDPA), which was signed into law in 2023. This law replaced the earlier Nigeria Data Protection Regulation (NDPR) of 2019 and strengthened the rights of Nigerians over their personal data.
Here are some key legal responsibilities under Nigerian data protection law:
Organisations Must Have a Lawful Reason to Collect Data No school, company, or government agency is allowed to collect your personal data without a valid reason. They must explain why they need it and get your consent where required. For example, if an online learning platform asks for your home address, they must explain why that information is needed.
Data Must Be Collected Only for a Specific Purpose This is called the principle of purpose limitation. If a hospital collects your phone number to send appointment reminders, they cannot then sell that number to advertisers. The data must only be used for the purpose it was collected.
Data Must Be Kept Accurate and Up to Date Organisations are legally required to ensure that the data they hold about people is correct. If you have moved to a new address, for example, a school or bank must update its records if you inform them.
Data Must Not Be Kept Longer Than Necessary Once the purpose for collecting data has been fulfilled, the data should be deleted or anonymised. Keeping data longer than needed increases the risk of a breach.
Individuals Have the Right to Access Their Data Under Nigerian data protection law, you have the right to ask any organisation what data they hold about you and why. This is known as the right of access. If you believe your data is being misused, you can report it to the Nigeria Data Protection Commission (NDPC).
Organisations Must Secure Data Against Breaches Any organisation that holds personal data has a legal duty to put security measures in place. This includes using passwords, encryption, firewalls, and regular security audits. If a data breach occurs, the affected individuals must be notified.
Ethical Responsibilities in Data Protection
While laws tell us what we must do, ethics tell us what we ought to do — the difference between what is legally required and what is simply the right thing to do.
Ethical responsibilities in data protection go beyond following the law. They are about treating people's information with honesty, fairness, and respect.
Respect for Privacy Even if no law prevents you from sharing someone's information, you should ask yourself: would this person want their information shared? If the answer is no, then sharing it is unethical. For example, taking a screenshot of a classmate's private message and posting it online may not always be illegal, but it is definitely unethical.
Transparency and Honesty If you collect data from people — whether for a school project, a community survey, or an online form — you have an ethical duty to tell them exactly what you will do with the information. Hiding the true purpose of data collection is dishonest and wrong.
Informed Consent Before collecting personal information from anyone, you should ask for their permission and make sure they understand what they are agreeing to. This is especially important when the person involved is a child. Children should not be asked to provide personal information without the knowledge of their parents or guardians.
Do Not Use Data to Harm Others Using someone's personal data to embarrass, blackmail, bully, or defraud them is both unethical and illegal. Unfortunately, cases of cyberbullying using stolen or misused personal data are becoming increasingly common among young people in Nigerian secondary schools and social media platforms.
Handle Data With Care Even when you have legitimate access to someone else's data — such as a teacher who has access to student records — you have an ethical responsibility to handle it carefully. Do not leave files open on a shared computer. Do not discuss confidential information in public places. Do not share data with people who do not need it.
Practical Applications in Nigerian Everyday Life
Let us look at how data protection applies to real situations that Nigerian students and families face regularly.
Online School Registration Many Nigerian secondary schools now use online portals for registration and result checking. When you enter your name, phone number, and parent's contact details into these portals, you are sharing personal data. Schools have a responsibility to protect this data, and students should be careful not to share their login details with others.
Mobile Banking and Fintech Apps Apps like Opay, Palmpay, Kuda, and traditional bank apps all store sensitive financial data. Nigerians are advised never to share OTPs (One-Time Passwords), PINs, or BVN details with anyone, even someone claiming to be a bank official.
WhatsApp and Social Media Many Nigerian students use WhatsApp, Facebook, Instagram, and TikTok. When you post photos of yourself, share your school name, or reveal your location, you are making personal data publicly available. This can be used by strangers in ways you did not intend.
Government Services (NIN Registration) The National Identification Number (NIN) is a unique identifier assigned to every Nigerian citizen. When you register for NIN, you provide biometric data including fingerprints and facial photographs. The government has a legal and ethical responsibility to protect this data securely.
Advantages of Good Data Protection Practices
Personal safety is maintained because private information does not fall into the wrong hands.
Trust between individuals and organisations is strengthened, making people more comfortable using digital services.
Cybercrime and fraud are reduced because criminals have less access to usable personal information.
It gives individuals control and power over their own information, respecting their dignity and privacy.
Businesses and institutions that protect data well tend to have stronger reputations and attract more users.
Consequences of Poor Data Protection
Financial loss through fraud, scams, and identity theft can cause devastating hardship to families.
Emotional harm such as embarrassment, shame, or fear can result from the exposure of private information.
Loss of trust in institutions — when banks, hospitals, or schools fail to protect data, people stop trusting them.
Legal penalties — organisations that fail to comply with Nigerian data protection laws can face heavy fines and sanctions.
Digital Safety and Ethical Considerations
Before sharing any personal information online, ask yourself: Is this platform trustworthy? Do I know who will see this? Is there a privacy policy?
Always use strong, unique passwords for your accounts and change them regularly.
Never share your passwords, PINs, or OTPs with anyone — not even a close friend.
Be careful about clicking links in messages or emails from unknown senders. These could be phishing attempts designed to steal your data.
If you manage data for a school project, club, or community activity, treat that data the same way you would want your own data to be treated — with care, honesty, and respect.
Classroom and Home Activities
Activity 1 — Data Audit Make a list of all the apps and websites you have accounts on. Next to each one, write down what personal information you think they hold about you. Discuss with your class which ones you think are safe and which ones might need a second look.
Activity 2 — Privacy Policy Review Visit any Nigerian website or app (such as a school portal, a bank app, or an online store) and find its privacy policy. Try to answer these questions: What data do they collect? Why do they collect it? Do they share it with anyone?
Activity 3 — Role Play In groups of three, act out a scenario where one person is a student, one is a cybercriminal trying to get personal data, and one is a data protection officer. Show how the student should respond to suspicious requests and how the data protection officer handles a breach.
Activity 4 — Design a Data Protection Poster Create a simple poster or digital design that shows five tips for protecting personal data. Use Nigerian examples and language that your fellow students will understand. Display it in your classroom or share it on a school notice board.
Assessment Questions
Objective Questions
-
What does the term "data protection" mean? a) Deleting all digital files b) Safeguarding personal information from unauthorised access or misuse c) Storing files on a USB drive d) Using the internet safely
-
Which of the following is an example of sensitive data? a) A person's favourite colour b) A school's timetable c) A patient's medical record d) A public holiday announcement
-
The Nigeria Data Protection Act was signed into law in which year? a) 2015 b) 2019 c) 2021 d) 2023
-
Which principle states that data should only be used for the purpose it was collected? a) Data minimisation b) Purpose limitation c) Data accuracy d) Storage limitation
-
What is identity theft? a) Losing your national ID card b) Forgetting your password c) Someone using your personal information without permission to commit fraud d) Changing your username on social media
Theory Questions
-
Explain three reasons why data protection is important for students in Nigeria today. Use specific examples in your answer.
-
Describe two legal responsibilities that an organisation in Nigeria has when collecting personal data from members of the public.
-
What is the difference between legal responsibility and ethical responsibility in data protection? Give one example of each.
Summary
In this lesson, we have learned that data protection is the process of keeping personal and sensitive information safe from unauthorised access, misuse, or loss. We identified the types of data that need protection, including personal data, sensitive data, and organisational data. We explored the importance of data protection in preventing identity theft, protecting privacy, building trust, and reducing cybercrime. We also looked at Nigerian laws governing data protection, especially the Nigeria Data Protection Act of 2023, and the role of the Nigeria Data Protection Commission. Finally, we discussed the ethical responsibilities that individuals and organisations have when handling data — going beyond the law to treat people's information with honesty, care, and respect.
Conclusion
Data is often described as the new oil — it is valuable, powerful, and in high demand. But just like oil can cause harm if not handled properly, data can also destroy lives and livelihoods when it falls into the wrong hands or is misused.
As a JSS 2 student in Nigeria today, you are already a participant in the digital world. Every time you log in, register, or share information online, you are interacting with data. Understanding data protection gives you the knowledge and the tools to stay safe, to respect the privacy of others, and to make responsible decisions in a world where information is everywhere.
The responsibility of data protection does not rest with governments and big companies alone. It begins with you — in how you manage your own accounts, how you treat information shared with you in confidence, and in the choices you make every day online and offline.
Frequently Asked Questions (FAQ)
What is data protection in simple terms for a JSS 2 student? Data protection means keeping personal information — like your name, phone number, photos, and passwords — safe from people who should not have access to it. It also means making sure information is used in a fair and honest way.
Why is data protection important in Nigeria? Nigeria has millions of internet users, mobile banking customers, and social media users. Without data protection, people's financial details, health records, and personal information can be stolen and used for fraud or other crimes. Good data protection practices help keep Nigerians safe in the digital space.
What law protects data in Nigeria? The Nigeria Data Protection Act (NDPA) of 2023 is the main law that governs how personal data is collected, stored, and used in Nigeria. It is enforced by the Nigeria Data Protection Commission (NDPC).
What is the difference between personal data and sensitive data? Personal data is any information that can identify a person, such as a name or phone number. Sensitive data is a special type of personal data that could cause serious harm if exposed — for example, medical records, financial details, or biometric information like fingerprints.
What should I do if I think my data has been misused? If you believe your personal data has been collected or used without your permission, you or your parent or guardian can report it to the Nigeria Data Protection Commission (NDPC). You can also contact the organisation directly and ask them to delete or correct your information.
Can a student be responsible for a data breach? Yes. If a student shares another person's private information without permission — such as posting someone's home address or phone number online without their consent — they can be held responsible for a data breach. This is both an ethical violation and, depending on the circumstances, a legal one.

Join the conversation