Effective date: 17th July 2026 · Last updated: 13 July 2026
This Privacy Policy explains how the Digital Standards Platform (DSP) collects, uses, shares, stores and protects personal data when you visit https://nnsdp.son.gov.ng/, create or use an account, subscribe to standards or services, apply for a certificate, communicate with support, use the marketplace, access training information, or otherwise interact with the platform.
The policy is designed to support the Nigeria Data Protection Act 2023 (NDPA), relevant public-sector data-protection guidance, consumer-protection expectations and internationally recognized privacy practices. The Nigeria Data Protection Commission (NDPC) identifies safeguarding the rights of natural persons to data privacy and secure processing practices as core objectives of the NDPA framework. Where another law imposes a higher or different requirement, that law will apply to the relevant processing.
Data controller: The Standards Organization of Nigeria (SON) is the data controller for the Digital Standards Platform. SON determines the purposes for which, and the means by which, personal data is processed through the Platform, and remains accountable for that processing under the Nigeria Data Protection Act 2023.
Technology and service operator: Goringo Digital Technology Infrastructure Limited (GDTIL) operates and maintains the Platform under a concession from SON. GDTIL processes personal data as SON's data processor, subject to the applicable agreement and data-protection controls. GDTIL implements the technical and organizational security measures described in section 8 and operates the user support desk. GDTIL may engage sub-processors upon the same terms.
Bureau of Public Procurement (BPP): BPP participates in the Project alongside SON. Platform compliance functions interface with BPP's e-procurement systems, and BPP receives standards-compliance and transaction information relating to procurement activity carried out through or verified by the Platform.
Regulatory oversight: The Infrastructure Concession Regulatory Commission (ICRC) receives regulatory reporting in respect of the Project and acts as an independent data controller for its own regulatory purposes.
Other government and standards institutions: Other public institutions or standards bodies may process information in connection with a particular service where they have their own statutory or operational purpose. The responsible institution will be identified in the relevant notice, form or service flow.
Privacy contact: Info@son.gov.ng, Info@goringoconsult.org.ng
General support: WhatsApp +234 911 062 3187; goringoconsult@gmail.com; info@goringoconsult.com; support page. The privacy contact should be used for data-rights requests; support may help route a request but should not require a person to disclose more data than necessary.
The Privacy Policy shall identify the relevant data controller(s), any joint-controller arrangements, the involvement of processors or sub-processors, where applicable, and the appropriate contact details for legal notices, data protection enquiries and the exercise of data subject rights.
The exact data collected depends on the service and registration category. We seek to collect only data that is reasonably necessary for the stated purpose.
| Category | Examples | Main reason for collection |
|---|---|---|
| Identity and contact data | Name, title, organization, job role, email, telephone number, business address, state or country | Account creation, verification, support, service delivery and official communications |
| Account and authentication data | Username, password hash, login records, password-reset tokens, session and "keep me logged in" preferences | Secure access, authentication, fraud prevention and account recovery |
| Organization and eligibility data | Organization type, procurement role, registration category, professional or institutional details, approval information | Determining access eligibility, plan availability, certificates and public-sector workflows |
| Transaction data | Plan, standard or service purchased, amount, currency, invoice, receipt, payment status, refund and dispute details | Processing payments, accounting, audit, service activation, refunds and support |
| Certificate and compliance data | Application details, supporting information, verification results, status, certificate number and validity information | Reviewing, issuing, verifying or administering the relevant service |
| Marketplace and user-content data | Seller profile, product or service information, images, descriptions, contact details, moderation history and reports | Publishing, moderating and administering marketplace listings |
| Support and communications data | Messages, attachments, call or WhatsApp details, complaint records and responses | Resolving enquiries, complaints, technical problems and service requests |
| Technical and usage data | IP address, device and browser information, operating system, pages viewed, time stamps, referrer, security logs and approximate location inferred from IP | Security, service operation, diagnostics, accessibility and aggregated service improvement |
| Preference and consent data | Cookie choices, marketing preferences, communication history and consent records | Respecting choices and demonstrating compliance |
Do not send passwords, full card numbers, one-time authentication codes or unrelated sensitive information through support channels. If a form requests sensitive personal data, the form should explain why it is needed, whether it is optional and the lawful basis for processing it.
We may process personal data for the following purposes, using the lawful ground that applies to the particular processing under the NDPA and other applicable law.
| Purpose | Examples of processing | Possible lawful ground, depending on context |
|---|---|---|
| Provide the DSP and requested services. | Create accounts, authenticate users, display plans, provide standards access, operate the marketplace and deliver support. | Steps requested by the data subject or performance of a service contract |
| Verify eligibility and administer public-sector services. | Confirm organization or procurement category, review approvals, administer certificates and support standards-based procurement. | Official/public functions, legal obligations, or service delivery, as applicable |
| Process payments and financial records | Confirm payment, issue receipts, reconcile transactions, investigate refunds and maintain audit records. | Service contract and legal/accounting obligations |
| Protect the platform | Detect fraud, prevent unauthorized access, investigate abuse, maintain logs and secure systems. | Legal obligations, security/public functions and legitimate interests where permitted |
| Improve services | Diagnose errors, analyse aggregated usage, test accessibility and improve content or navigation. | Consent for non-essential analytics where required, or a permitted operational interest using minimized data |
| Send service communications | Account notices, password resets, plan and certificate updates, support replies, security alerts and policy changes | Service contract, legal obligation or official function |
| Send optional marketing | News, training, product or service information | Consent or another lawful basis where permitted; every promotional message will provide an easy opt-out |
| Meet legal and governance requirements. | Respond to lawful requests, maintain records, enforce terms, manage disputes and report incidents. | Legal obligations, official/public functions or establishment/exercise/defense of legal claims |
Where processing relies on consent, you may withdraw consent at any time. Withdrawal does not invalidate processing carried out before withdrawal and may not stop processing that has another lawful ground. Where processing is necessary to provide a requested service or meet a legal obligation, refusing to provide required data may mean that the account or service cannot be created or continued; we will explain this at the point of collection where practicable.
We receive information directly from you, from your organization or authorized representative, from a public-sector or standards partner where lawful, from payment and identity-verification providers, from support channels, from your device and browser, and from publicly available or legally accessible sources. We will take reasonable steps to ensure that data received from another source is used consistently with the purpose disclosed to you or otherwise permitted by law.
We share personal data only where necessary, lawful and proportionate. Recipients fall into two groups: those acting on SON's instructions, who may use the data only for the purposes SON specifies, and those acting for their own purposes, who are responsible for their own compliance and against whom you may exercise your rights directly.
SON's own access. As data controller, SON has continuous real-time read-only access to Platform records, including transaction records, system logs and audit trails, holds a counterpart of those records, and may inspect Platform operations. This is supervision, not disclosure to a third party.
On SON's instructions. Goringo Digital Technology Infrastructure Limited (GDTIL) as processor, and the technology, hosting, security, communications and support providers it engages with SON's prior written authorisation. Each receives only the data needed for its function and is bound by confidentiality, security, sub-processing, deletion or return, and incident-reporting obligations.
For their own purposes. The Bureau of Public Procurement (BPP), which receives standards-compliance and transaction information relating to procurement activity, as [an independent controller / a joint controller with SON]; the Infrastructure Concession Regulatory Commission (ICRC), which receives regulatory reporting on the Project; other public institutions or standards bodies where a service involves them, identified in the relevant notice or service flow; payment providers and banks processing, reconciling, refunding or settling transactions; marketplace sellers and training providers, who receive what is needed to fulfil, deliver, invoice and support a purchase and whose own privacy notices apply to that use; and independent auditors and verifiers, professional advisers and insurers, for audit, advice, insurance cover or legal claims, in each case under confidentiality.
Regulators, courts and law-enforcement authorities. Where required by law or by a binding order, or necessary to protect the Platform, its users or an overriding public interest. We disclose only what is required, will tell you about a request affecting you where the law permits, and will give the other institutions involved in operating the Platform advance notice before responding to a legal demand.
If operation of the Platform changes hands. The Platform is operated under a concession from SON. At the end of the concession, it transfers to SON with its records and documentation, and the outgoing operator returns its copies. If SON takes over operation, temporarily or permanently, processing continues under this policy, and SON remains the data controller.
International transfers. Some recipients process personal data outside Nigeria. Section 6 explains the safeguards that apply and identifies the channels involved, including WhatsApp.
We do not sell personal data. We do not permit a provider to use personal data for its own unrelated marketing merely because it processes data for the DSP. Vendors should receive only the data needed for their contracted function and should be bound by confidentiality, security, deletion/return and incident-reporting obligations.
Where data is held. Platform records, backups and disaster-recovery systems are held on infrastructure contracted by GDTIL. Some of that infrastructure, and some communications, support and payment services, are located outside Nigeria. The countries or regions involved are available on request from the privacy contact in section 16.
When data may leave Nigeria. GDTIL is responsible for ensuring that any processing of personal data outside Nigeria complies with the Nigeria Data Protection Act. Before any transfer, and before any change of hosting location or engagement of a new overseas provider, the destination, recipient, purpose, security measures and legal mechanism are assessed and recorded. Transfers are reviewed periodically and whenever the arrangement changes.
Safeguards. We rely on contractual protections and approved transfer arrangements permitted under the Nigeria Data Protection Act, together with confidentiality, security and audit obligations. We do not rely on your consent, because access to the Platform is necessary for many users and consent given in those circumstances would not be freely given.
Support channels. Where you contact us through WhatsApp or another messaging channel, your message and the associated account details may be processed outside Nigeria by the provider of that channel. Please do not send sensitive information through those channels.
We retain personal data only for as long as it is reasonably necessary for the purpose collected, to provide the service, to satisfy public-sector, accounting, tax, audit, legal or dispute requirements, to protect the platform and users, or to establish, exercise or defend legal claims. When data is no longer required, it will be securely deleted, anonymized or archived with access restricted in accordance with the approved retention schedule.
| Record type | Proposed retention rule to validate before publication |
|---|---|
| Account and authentication records | While the account is active and for the approved period after closure needed for security, audit, disputes or legal obligations; insert the SON schedule. |
| Transaction, invoice and refund records | For the period required by applicable tax, accounting, audit and public-sector recordkeeping rules; insert the approved period. |
| Standards-access and certificate records | For the period required to verify access, certificate status, quality assurance, audit and disputes; insert the approved period. |
| Support and complaint records | For the period required to resolve the matter, monitor service quality and meet legal or audit obligations; insert the approved period. |
| Security and technical logs | For a limited, risk-based period necessary for security, fraud detection, troubleshooting and incident response; insert the approved period. |
| Marketing preferences and consent records | Until withdrawn or no longer needed to demonstrate the choice, subject to legal and suppression-list requirements. |
We use reasonable technical and organizational measures appropriate to the nature and risk of the data, including access controls, least-privilege permissions, encryption where appropriate, secure authentication, backups, monitoring, vendor controls, staff confidentiality obligations, vulnerability management and incident-response procedures. No service transmitted over the internet is completely risk-free. Users must protect passwords, avoid sharing credentials and notify support immediately of suspected compromise.
If we become aware of a personal-data breach, we will investigate, contain and remediate it, document the incident, and notify the NDPC, affected individuals, partners or other authorities where required by applicable law and risk. Notifications will describe the known nature of the incident, likely consequences, protective steps and a contact route where practicable. The platform will not use the absence of a public announcement to imply that no incident occurred; communications will follow the applicable legal and security assessment.
The DSP may use the following categories of cookies or similar technologies:
| Category | Purpose | Choice |
|---|---|---|
| Essential | Login sessions, security, load balancing, accessibility, language or cookie-choice storage, and core service functions | Required for the service and cannot ordinarily be disabled through the platform. |
| Preferences | Remembering non-essential choices such as display or search preferences | Used only where permitted and according to the displayed choice. |
| Analytics | Measuring traffic, diagnosing errors and improving the platform through aggregated or pseudonymous information | Optional where consent is required; the banner should provide accept/reject or equivalent choices. |
| Marketing or third-party | Advertising, embedded media or cross-site measurement | Not enabled without the required notice and choice. |
The platform should maintain a cookie inventory, disclose provider names and retention periods, and provide a settings link that allows non-essential choices to be changed. The EDPB's SME guidance illustrates the best-practice distinction between essential cookies and optional analytics cookies.
Subject to the NDPA and other applicable law, you may ask us to confirm whether we process your personal data and to provide access to it; correct inaccurate or incomplete data; request deletion or erasure where the data is no longer needed or another legal condition applies; request restriction or object to particular processing where the law permits; withdraw consent where processing relies on consent; request data portability where available; and raise a complaint about our handling of your data.
We may need to verify identity before responding. We may refuse or limit a request only where permitted by law, and we will explain the reason where legally allowed. We will not require an individual to surrender more personal data than is reasonably necessary to verify the request. Requests should be sent to Info@son.gov.ng/Info@goringoconsult.org.ng with "Data Protection Request" in the subject line.
Please contact the DSP privacy contact first so we can investigate and correct the issue. You may also contact the Nigeria Data Protection Commission (NDPC) through its official channels, including info@ndpc.gov.ng and the Commission's published contact or breach-reporting routes. You may have other rights to seek a remedy from a competent court or authority. Nothing in this policy removes those rights.
The DSP is primarily designed for professional, organizational and public-sector users. We do not knowingly require a child to provide personal data for a service that is not appropriate for that child. Where a minor may lawfully use an educational or informational feature, the required parent or guardian involvement and age-appropriate notice should be used. If we learn that personal data was collected without the required authorization, we will take reasonable steps to delete or otherwise address it.
Some Platform functions operate automatically. These include verifying registration and organisation details against official databases, checking subscription and compliance status, screening payments and account activity for fraud or misuse, and generating compliance information made available to procuring entities and to the Bureau of Public Procurement.
Where an automated result affects your access to a service, your eligibility for a certificate, or the compliance information shown about you, we will tell you the result and the main reasons for it. You may ask for the result to be reviewed by a person, provide further information, and correct any data that was wrong. Requests should be sent to the privacy contact in section 16.
An automated result from the Platform does not by itself determine a procurement decision. Procuring entities, SON and BPP take their own decisions under the applicable law and procurement rules.
We may update this Privacy Policy to reflect new services, vendors, technologies, legal requirements or security practices. The current version will be posted at this URL with a revised "Last updated" date. Material changes will be communicated through the platform, account notices or another appropriate channel. Where consent is required for a new purpose, we will request it before using data for that purpose.
Standards Organisation of Nigeria / Digital Standards Platform
Support: Info@son.gov.ng.
Info@goringoconsult.org.ng
Legal or postal address: Info@son.gov.ng, Info@goringoconsult.org.ng
General service desk: WhatsApp +234 911 062 3187; dspfeedback@son.gov.ng, contactdsp@son.gov.ng, goringoconsult@gmail.com; info@goringoconsult.com