Legal
Privacy Policy
Table of Contents
- 1.About This Policy and Our Company
- 2.Who This Policy Applies To
- 3.Types of Personal Data We Collect
- 4.How We Collect Your Personal Data
- 5.Lawful Basis for Processing Your Personal Data
- 6.Purposes for Which We Use Your Personal Data
- 7.Disclosure of Your Personal Data
- 8.International Transfers of Personal Data
- 9.How Long We Keep Your Personal Data
- 10.Your Rights as a Data Subject
- 11.Automated Decision-Making and Profiling
- 12.Cookies and Tracking Technologies
- 13.Data Security Measures
- 14.Data Breach Notification
- 15.Children's Privacy
- 16.Third-Party Links and External Websites
- 17.Updates to This Privacy Policy
- 18.Complaints and Supervisory Authority
- 19.Our Compliance Commitment
- 20.How to Contact Us
Section 1: About This Policy and Our Company
1.1 Who We Are
The Energy Consulting Practice LLP (“TECP”, “the Company”, “we”, “us”, or “our”) is a company duly incorporated under the Companies and Allied Matters Act (CAMA) 2020 and registered to carry out oil and gas operations in Nigeria in accordance with applicable laws, including the Petroleum Industry Act (PIA) 2021 and other relevant sector-specific regulations.
Registered Office Address:
Block 5, No 11, Philip Aduda Street, Wuye District, Abuja,
Federal Republic of Nigeria.
We operate as the Data Controller in respect of personal data processed through this website and in connection with our business operations, meaning we determine the purposes for which and the means by which your personal data is processed.
Where we engage third-party service providers to process personal data on our behalf, such parties act as Data Processors and are bound by contractual obligations to process your data only in accordance with our instructions and in compliance with applicable Nigerian data protection laws.
Where applicable, we may operate as a Joint Controller with affiliated entities, joint venture partners, or co-owners of operational assets. In such cases, we will inform you of the identity of the joint controller(s) and the nature of the joint arrangement at the point of data collection.
1.2 About This Privacy Policy
This Privacy Policy explains:
- What personal data we collect from visitors to our website energyconsultingpractice.com, job applicants, contractors, vendors, investors, customers, regulators, and other individuals who interact with us;
- Why we collect and process that data;
- The lawful basis on which we process it;
- How long we retain it;
- With whom we share it;
- What rights you have in relation to your data; and
- How to exercise those rights or make a complaint.
This policy applies in conjunction with any other notices or policies we may provide on specific occasions when we collect or process personal data about you, so that you are fully aware of how and why we are using your data.
1.3 Our Legal Framework
We are committed to processing personal data in accordance with:
- Nigeria Data Protection Act (NDPA) 2023
- NDPC General Application and Implementation Directive (GAID) 2025
- Petroleum Industry Act (PIA) 2021
- Nigerian Upstream Petroleum Regulatory Commission (NUPRC) Regulations
- Nigerian Midstream and Downstream Petroleum Regulatory Authority (NMDPRA) Regulations
- Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (as amended)
- Consumer Protection Council Act (CPC Act)
- Companies and Allied Matters Act (CAMA) 2020
- Federal Competition and Consumer Protection Act (FCCPA) 2018
- Any other applicable Nigerian legislation and subsidiary regulations
Section 2: Who This Policy Applies To
This Privacy Policy applies to all individuals whose personal data we collect, receive, or process, including but not limited to:
| Stakeholder Category | Description |
|---|---|
| Website Visitors | Any person who visits, browses, or interacts with our website |
| Customers and Clients | Entities or individuals purchasing our products or services |
| Job Applicants | Individuals who apply for employment opportunities with us |
| Employees and Contractors | Personnel working with or for us, subject also to separate internal policies |
| Vendors and Suppliers | Third parties supplying goods or services to the Company |
| Investors and Shareholders | Individuals and entities with ownership or financial interests in the Company |
| Regulators and Government Agencies | Regulatory bodies and government representatives with whom we interact |
| Joint Venture Partners | Companies participating in joint operational arrangements with us |
| Professional Advisers | Legal counsel, auditors, consultants, and financial advisers |
| Members of the Public | Any other person who contacts us or is affected by our operations |
If you are providing personal data about other individuals, for example as an emergency contact or next of kin, you confirm that you have obtained the consent of or have the lawful authority to share their information with us.
Section 3: Types of Personal Data We Collect
We collect and process the following categories of personal data, depending on the nature of your interaction with us:
3.1 Identity Data
- Full legal name
- Title (Mr., Mrs., Dr., etc.)
- Date of birth
- Gender
- Nationality
- Government-issued identification numbers, including National Identification Number (NIN), International Passport number, Driver's Licence number, etc.
- Taxpayer Identification Number (TIN)
- Corporate identification data, including RC numbers and directorship details
- Photographs or profile images, where applicable
3.2 Contact Data
- Email address(es)
- Phone number(s), personal and business
- Postal address, residential and business
- Social media handles or professional profile links, where voluntarily shared
3.3 Technical Data
- Internet Protocol (IP) address
- Browser type and version
- Device identifiers and device type
- Operating system and platform
- Screen resolution and language settings
- Time zone settings
- Cookie identifiers and session data
- Login credentials, where accounts are maintained
3.4 Usage Data
- Pages visited on our website and time spent
- Links clicked and navigation paths
- Search terms used on the website
- Referring website addresses (URLs)
- Frequency and duration of site visits
- Downloads initiated
- Interaction with online forms and features
3.5 Transactional Data
- Payment information, including bank account details, invoicing details, and transaction references. We do not store full credit/debit card data.
- Service request records
- Purchase or procurement history
- Contract terms and commercial correspondence
- Delivery or service performance records
3.6 Recruitment and Employment Data
- Curriculum vitae (CV) and résumé information
- Academic qualifications and professional certifications
- Employment history and references
- Skills assessments and interview records
- Background check results, where lawfully obtained
- Health and safety fitness records relevant to oil and gas operational roles
- Emergency contact details
- Pre-employment screening data
3.7 Regulatory, Compliance, and KYC Data
- Know Your Customer (KYC) documentation
- Anti-money laundering (AML) screening records
- Politically Exposed Persons (PEP) status
- Sanctions screening records
- Due diligence records for vendors, contractors, and partners
- Regulatory filings and correspondence
- HSE (Health, Safety, and Environment) compliance records
- Licences, permits, and certifications
3.8 Oil and Gas Sector-Specific Data
- Vendor pre-qualification and onboarding records
- HSE training records and competency assessments
- Site access records and field personnel data
- Environmental compliance documentation
- Operational data relating to contract performance
- Community and host community representative data
- Project-specific personnel data
- Insurance and indemnity documentation
3.9 Marketing and Communication Data
- Communication preferences
- Subscription choices for newsletters or updates
- Records of marketing communications sent and responses received
- Event attendance or conference participation records
- Feedback and survey responses
3.10 Special Categories of Data
In limited and specific circumstances, particularly in the context of employment, HSE requirements, and occupational health, we may need to process special categories of personal data, as recognised under the NDPA 2023. These may include:
- Health data, such as medical fitness for duty and occupational health assessments
- Biometric data, such as fingerprint access for secure site entry where applicable
Where we process special categories of data, we will ensure that an additional and specific lawful basis under the NDPA 2023 applies, such as explicit consent, compliance with employment law obligations, or vital interest, and we will inform you separately at the point of collection.
Section 4: How We Collect Your Personal Data
We collect personal data through the following means:
4.1 Direct Collection
You provide personal data directly to us when you:
- Visit and interact with our website
- Complete contact, enquiry, or feedback forms
- Submit a job application or CV
- Register for events, conferences, or webinars
- Subscribe to our newsletters or mailing lists
- Enter into a contract or commercial agreement with us
- Communicate with us by email, phone, post, or in person
- Participate in surveys or market research
- Attend site visits or meetings at our facilities
- Engage with our investor relations communications
4.2 Automated Collection
When you visit our website, we automatically collect certain technical and usage data through:
- Cookies and similar tracking technologies, see Section 12
- Web analytics tools, such as Google Analytics or similar platforms
- Server logs
- Session monitoring tools
4.3 Third-Party Sources
We may receive your personal data from third parties, including:
- Background check service providers, for recruitment and compliance purposes
- Regulatory authorities, such as NUPRC, NMDPRA, or NDPC
- Credit reference agencies and financial institutions
- Professional referees provided by job applicants
- Joint venture partners and affiliated entities
- Publicly available sources, including company registries, regulatory databases, and professional directories
- Recruitment agencies or headhunters
- Anti-fraud and sanctions screening databases
Whenever we receive your data from third parties, we take steps to ensure that those parties had the lawful right to share your data with us.
Section 5: Lawful Basis for Processing Your Personal Data
The Nigeria Data Protection Act (NDPA) 2023 requires that every act of processing personal data must be grounded in a recognised lawful basis. We rely on the following lawful bases, depending on the specific processing activity:
5.1 Consent (Section 25(1)(a) NDPA 2023)
We rely on your freely given, specific, informed, and unambiguous consent where:
- We send you direct marketing communications or newsletters;
- We use non-essential cookies and tracking technologies on our website;
- We process special categories of data in circumstances requiring explicit consent;
- We process data of children through parental or guardian consent.
Your right to withdraw consent: Where we rely on consent, you have the right to withdraw it at any time without penalty. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us using the details in Section 20.
5.2 Contractual Necessity (Section 25(1)(b) NDPA 2023)
We process your personal data where it is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This applies to:
- Processing vendor, contractor, or supplier data to onboard and manage commercial relationships;
- Managing service delivery, procurement, and payment obligations;
- Processing job applicant data in relation to a prospective employment contract;
- Administering client or customer accounts and service agreements.
5.3 Legal and Regulatory Obligation (Section 25(1)(c) NDPA 2023)
We process personal data where this is necessary for compliance with a legal obligation to which we are subject. This includes:
- Compliance with petroleum industry regulations under the PIA 2021 and NUPRC/NMDPRA requirements;
- Anti-money laundering (AML) and Know Your Customer (KYC) obligations;
- Tax reporting obligations to the Federal Inland Revenue Service (FIRS);
- Occupational health and safety obligations under Nigerian law;
- Regulatory filings with the Securities and Exchange Commission (SEC), the Nigerian Exchange Group (NGX), or other authorities;
- Compliance with court orders, government directives, or law enforcement requests;
- Statutory record-keeping obligations.
5.4 Legitimate Interests (Section 25(1)(f) NDPA 2023)
Where we cannot rely on consent, contract, or legal obligation, we may process your data on the basis of our legitimate interests or those of a third party, provided that those interests are not overridden by your fundamental rights and freedoms. We carry out a Legitimate Interests Assessment (LIA) before relying on this basis.
Our legitimate interests include:
- Operating and improving our website and digital services;
- Fraud prevention and cybersecurity monitoring;
- Protecting our physical assets, employees, and operations, including CCTV at facilities;
- Internal administrative and operational management;
- Managing legal claims and disputes;
- Conducting background checks on contractors and vendors for operational safety;
- Analytics and business intelligence to improve service delivery;
- Investor relations and corporate communications.
5.5 Public Interest (Section 25(1)(e) NDPA 2023)
Given the nature of our operations in a strategic national sector, we may occasionally process personal data where necessary for the performance of tasks carried out in the public interest, including:
- Environmental monitoring and reporting;
- Community and host community engagement programmes;
- Regulatory cooperation with governmental authorities on matters of national energy policy or security;
- Emergency response coordination with governmental bodies.
5.6 Vital Interests (Section 25(1)(d) NDPA 2023)
In emergency situations, particularly those arising in the context of oil and gas field operations, we may process personal data, including health data, where this is necessary to protect the vital interests of a data subject or another natural person, for example in a medical emergency or HSE incident response.
Section 6: Purposes for Which We Use Your Personal Data
The table below sets out the purposes for which we process personal data and the lawful basis on which each activity rests:
| Purpose of Processing | Data Categories Used | Lawful Basis |
|---|---|---|
| Operating and maintaining our website | Technical data, usage data | Legitimate interests |
| Responding to enquiries and communications | Identity data, contact data | Legitimate interests; Contract (pre-contractual) |
| Providing oil and gas services and managing service contracts | Identity, contact, transactional, regulatory data | Contractual necessity; Legal obligation |
| Vendor and contractor onboarding and management | Identity, contact, regulatory/KYC, HSE data | Contractual necessity; Legal obligation |
| Investor relations and corporate communications | Identity, contact, transactional data | Legitimate interests; Legal obligation |
| Recruitment and HR processing | Recruitment data, identity, contact, health data | Contract (pre-contractual); Legal obligation; Consent where applicable |
| Regulatory compliance (petroleum sector) | Identity, regulatory/KYC, HSE data | Legal obligation; Public interest |
| Anti-money laundering and KYC compliance | Identity, regulatory/compliance data | Legal obligation |
| Security monitoring and fraud prevention | Technical data, identity data | Legitimate interests; Legal obligation |
| Physical site security and access control | Identity data, biometric data where applicable | Legitimate interests; Legal obligation |
| HSE compliance and occupational health | Health data, HSE compliance data | Legal obligation; Vital interests |
| Website analytics and improvement | Technical data, usage data | Legitimate interests; Consent for non-essential cookies |
| Marketing and stakeholder engagement | Identity, contact, communication preference data | Consent; Legitimate interests |
| Managing legal claims and disputes | All relevant data categories | Legitimate interests; Legal obligation |
| Tax and financial reporting obligations | Identity, transactional data | Legal obligation |
| Environmental and community reporting | Identity, sector-specific data | Legal obligation; Public interest |
| Emergency response coordination | Identity, health data, contact data | Vital interests; Legal obligation |
Section 7: Disclosure of Your Personal Data
We treat your personal data with the strictest confidence. We do not sell your personal data to third parties. We may, however, share your data with carefully selected categories of recipients where this is necessary and lawful.
7.1 Categories of Recipients
Regulatory and Government Authorities:
- Nigeria Data Protection Commission (NDPC)
- Nigerian Upstream Petroleum Regulatory Commission (NUPRC)
- Nigerian Midstream and Downstream Petroleum Regulatory Authority (NMDPRA)
- Federal Inland Revenue Service (FIRS)
- Securities and Exchange Commission (SEC Nigeria)
- Nigerian Exchange Group (NGX)
- Corporate Affairs Commission (CAC)
- Department of Petroleum Resources, archived functions now under NUPRC/NMDPRA
- Nigerian Financial Intelligence Unit (NFIU)
- Economic and Financial Crimes Commission (EFCC)
- Other competent Nigerian law enforcement or regulatory authorities, where legally required
- Courts of competent jurisdiction
Service Providers and Data Processors:
- IT infrastructure, hosting, and cloud computing service providers
- Website development and maintenance vendors
- Data analytics and business intelligence providers
- Cybersecurity and network security service providers
- Payment processing and banking institutions
- Printing and document management service providers
- Communication and correspondence service providers
Professional Advisers:
- Legal counsel and law firms
- External auditors and accountants
- Tax advisers and consultants
- Management consultants
- Insurance brokers and underwriters
Oil and Gas Sector Partners:
- Joint venture partners and co-owners of petroleum licences
- Upstream, midstream, and downstream operational partners
- Oilfield service companies
- Drilling and engineering contractors
- Environmental consultants and HSE advisers
Recruitment and Employment-Related:
- Background screening agencies
- Occupational health service providers
- Pension fund administrators (PFAs)
- Health Management Organisations (HMOs)
- Professional referees, where consent has been given
Affiliates and Group Companies:
7.2 Safeguards for Third-Party Disclosures
Before disclosing your personal data to any third party, we take the following steps:
- We enter into Data Processing Agreements (DPAs) or equivalent contractual arrangements with all Data Processors, ensuring they process data only on our documented instructions;
- We conduct due diligence on third-party processors to confirm their data protection standards;
- We only share the minimum data necessary for the purpose of the disclosure;
- We include confidentiality obligations in all relevant commercial contracts;
- Where required by law, we seek or confirm the existence of an appropriate legal basis for the disclosure;
- We do not disclose data to third parties for their own independent marketing or commercial purposes without your explicit consent.
Section 8: International Transfers of Personal Data
8.1 Cross-Border Transfers
Our operations may involve the transfer of personal data outside Nigeria, including to our affiliates, cloud service providers, or technical support teams located in other jurisdictions.
The NDPA 2023 restricts the transfer of personal data to foreign countries unless adequate protections are in place. We comply fully with these restrictions.
8.2 Safeguards for International Transfers
Whenever we transfer personal data outside Nigeria, we ensure that at least one of the following safeguards is in place:
a) Adequacy Decision:
Where the NDPC has determined that the recipient country provides an adequate level of data protection comparable to Nigeria, we may transfer data to that country on this basis.
b) Standard Contractual Clauses (SCCs):
Where no adequacy decision exists, we execute Standard Contractual Clauses (SCCs) approved or recognised by the NDPC, which contractually require the recipient to protect your personal data to standards equivalent to those required under Nigerian law.
c) Binding Corporate Rules (BCRs):
For transfers within our corporate group or affiliated entities, we may rely on Binding Corporate Rules approved in accordance with NDPC guidelines.
d) Explicit Consent:
In limited circumstances, we may transfer your data internationally on the basis of your freely given, informed, and explicit consent, after explaining the risks of such transfer to you.
e) Contractual Necessity:
Transfers may be made where necessary for the performance of a contract between you and us, or for the implementation of pre-contractual measures taken at your request.
8.3 Transfer Impact Assessments
Before implementing any cross-border data transfer mechanism, we conduct a Transfer Impact Assessment (TIA) to evaluate whether the legal framework of the destination country ensures adequate protection and whether supplementary safeguards may be required.
You may request information about the specific safeguards applicable to any international transfer of your data by contacting our Data Protection Officer. See Section 20.
Section 9: How Long We Keep Your Personal Data
9.1 Our Retention Principles
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, contractual, or reporting obligations. This is in accordance with the storage limitation principle under the NDPA 2023.
We do not retain data indefinitely or beyond the period reasonably required. Once the relevant retention period expires, we securely delete, destroy, or anonymise personal data in a manner that prevents reconstruction.
9.2 Retention Periods by Data Category
The following retention schedule reflects our general practices. Specific retention periods may vary based on regulatory requirements, contractual obligations, or the nature of particular processing activities:
| Data Category | Retention Period | Basis for Retention Period |
|---|---|---|
| Website visitor and technical data | 12 months from date of collection | Operational needs and analytics |
| Cookie data (consent-based) | As specified in Cookie Policy, typically 12 to 24 months | Consent duration and operational purpose |
| Enquiry and contact form data | 12 months from last interaction | Operational needs and follow-up |
| Marketing and communication data | Until consent is withdrawn or 3 years from last engagement | Consent and legitimate interests |
| Job applicant data (unsuccessful candidates) | 6 months from notification of outcome | Legitimate interests for future vacancies; consent where extended retention is sought |
| Job applicant data (successful candidates) | Duration of employment plus 7 years post-termination | Employment law, legal obligation |
| Employee and contractor records | Duration of engagement plus 7 years | Nigerian labour and tax law requirements |
| Vendor and supplier data | Duration of contract plus 7 years | Contractual and legal obligation |
| KYC and AML compliance records | 5 years from end of business relationship | Money Laundering (Prevention and Prohibition) Act 2022 |
| Transactional and financial records | 7 years from date of transaction | FIRS tax obligations; CAMA requirements |
| Regulatory and petroleum industry records | As specified by NUPRC/NMDPRA regulations, typically 7 to 10 years or longer | PIA 2021; sector regulatory requirements |
| Legal claims and dispute records | Duration of legal proceedings plus 6 years | Limitation laws; legal obligation |
| HSE and occupational health records | Duration of employment plus 10 years, or as required by law | Occupational health legislation; PIA 2021 HSE requirements |
| Investor relations data | 6 years from end of relationship | SEC/NGX regulations; CAMA |
| Incident and breach records | 5 years from date of incident | NDPA 2023; Cybercrimes Act 2015 |
9.3 Criteria for Determining Retention Periods
Where no specific period is listed above, we determine appropriate retention periods by considering:
- The nature and sensitivity of the personal data;
- The purpose for which it was collected and whether that purpose has been fulfilled;
- Statutory and regulatory requirements specifying minimum or maximum retention periods;
- Contractual obligations requiring records to be maintained for specified periods;
- The potential risk of harm to data subjects if data is retained unnecessarily;
- Limitation periods under Nigerian law within which legal claims may arise;
- Guidance issued by the NDPC, NUPRC, NMDPRA, or other relevant regulators.
9.4 Secure Disposal
At the end of the applicable retention period, personal data is:
- Securely deleted from electronic systems using industry-standard deletion protocols;
- Physically destroyed, for paper records, using cross-cut shredding or incineration;
- Anonymised where ongoing use of the data in non-identifiable form serves a legitimate purpose, such as aggregated statistical analysis.
We maintain a Records Management and Retention Schedule that is reviewed and updated periodically.
Section 10: Your Rights as a Data Subject
10.1 Overview of Your Rights
Under the NDPA 2023, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to certain conditions, limitations, and exemptions provided by Nigerian law. We will respond to valid requests within 30 days, although complex or multiple requests may require up to 60 days, with prior notification to you.
10.2 Right of Access (Section 34 NDPA 2023)
You have the right to request confirmation of whether we process personal data about you, and if so, to receive:
- A copy of the personal data we hold about you;
- Information about the purposes for which it is processed;
- Categories of data and recipients;
- Retention periods applicable;
- Your other rights in relation to the data.
How to exercise this right: Submit a written Data Subject Access Request (DSAR) to our DPO using the contact details in Section 20.
10.3 Right to Rectification (Section 34 NDPA 2023)
You have the right to request the correction of inaccurate or incomplete personal data that we hold about you. We will take reasonable steps to verify the accuracy of your information before making corrections.
10.4 Right to Erasure (Right to Be Forgotten) (Section 34 NDPA 2023)
You may request the deletion of your personal data where:
- The data is no longer necessary for the purposes for which it was collected;
- You withdraw consent and there is no other lawful basis for processing;
- You have successfully objected to the processing;
- The data has been unlawfully processed;
- Erasure is required for compliance with a legal obligation.
Please note: This right is not absolute. We may be legally obligated to retain certain data, for example for regulatory or tax compliance purposes, in which case we will inform you of our inability to comply with your erasure request and the reasons therefor.
10.5 Right to Data Portability (Section 34 NDPA 2023)
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller where technically feasible.
10.6 Right to Object to Processing (Section 34 NDPA 2023)
You have the right to object to:
- Processing based on legitimate interests, on grounds relating to your particular situation;
- Processing for direct marketing purposes, which is an unconditional right and we will stop immediately upon receipt of your objection;
- Processing for research, statistical, or public interest purposes, on grounds relating to your particular situation.
10.7 Right to Restrict Processing (Section 34 NDPA 2023)
You may request that we suspend or restrict the processing of your personal data in circumstances where:
- You contest the accuracy of the data, pending verification;
- Processing is unlawful but you prefer restriction over erasure;
- We no longer need the data but you require it for a legal claim;
- You have objected to processing pending our verification of legitimate grounds.
During a restriction, we will store your data but not otherwise process it, except with your consent or for legal claims.
10.8 Right to Withdraw Consent (Section 25 NDPA 2023)
Where we process your personal data on the basis of consent, you have the right to withdraw your consent at any time, without penalty or detriment, and without affecting the lawfulness of processing prior to withdrawal. To withdraw consent, contact our DPO or use the opt-out mechanisms provided within our communications, such as unsubscribe links in marketing emails.
10.9 Rights Relating to Automated Decision-Making and Profiling
Where we use automated decision-making that produces legal or similarly significant effects on you, you have the right to:
- Request human intervention in the decision-making process;
- Express your point of view;
- Contest the decision made solely by automated means.
See Section 11 for full details on our use of automated processing.
10.10 How to Exercise Your Rights
To exercise any of the rights described above:
- Submit a written request to our Data Protection Officer at the contact details set out in Section 20;
- Clearly identify yourself and describe the right you wish to exercise;
- Provide sufficient information to enable us to locate your personal data and verify your identity. This is for your protection;
- We will acknowledge receipt of your request within 5 business days and provide a substantive response within 30 days, extendable by a further 30 days for complex requests.
We will not charge a fee for responding to valid requests. However, where requests are manifestly unfounded, excessive, or repetitive, we reserve the right to charge a reasonable administrative fee or decline to respond, in line with NDPA provisions.
Section 11: Automated Decision-Making and Profiling
11.1 Our Current Use of Automated Processing
We use limited forms of automated processing on our website and in our operations, including:
- Website analytics and user behaviour tracking: To understand how visitors interact with our website and to improve user experience. This does not produce legal or similarly significant effects on individuals.
- Fraud and security screening tools: Automated systems may flag unusual website activity or access attempts as potential security risks. These systems support human review and do not make final decisions autonomously.
- Vendor and supplier screening tools: We may use automated sanctions and AML screening tools to check individuals and entities against regulatory databases. Where an automated match is identified, the result is always reviewed by a qualified human analyst before any decision is made.
11.2 No Fully Automated Decisions with Legal Effects
At present, we do not make fully automated decisions that produce legal or similarly significant effects on individuals without human review and oversight. Where our practices change in this regard, we will update this policy, notify affected data subjects where required, and implement appropriate safeguards including the right to request human intervention.
11.3 Profiling
We may use limited profiling for the following purposes:
- Customising website content and communications based on interests or engagement patterns;
- Segmenting stakeholder communications for relevance.
Such profiling does not produce legally significant effects and does not result in discriminatory outcomes. You may object to profiling at any time by contacting our DPO.
Section 12: Cookies and Tracking Technologies
12.1 What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They enable websites to recognise your device, store preferences, and collect usage information. We also use similar technologies such as web beacons, pixel tags, and local storage objects.
12.2 Types of Cookies We Use
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary Cookies | Essential for the website to function correctly, such as session management, security, and load balancing. Without these, the website cannot operate. | No. Applied automatically as essential to service provision. |
| Functional Cookies | Remember your preferences and settings, such as language selection and display preferences, to enhance your experience. | Yes. Applied with your consent. |
| Analytics and Performance Cookies | Collect aggregated, anonymised data about how visitors use our website, such as pages visited, time on site, and error messages. Used to improve website performance. | Yes. Applied with your consent. |
| Marketing and Targeting Cookies | Track your browsing behaviour to deliver relevant advertising and assess the effectiveness of marketing campaigns. | Yes. Applied with your consent. |
12.3 Third-Party Cookies
Our website may include cookies set by third-party service providers, including analytics providers such as Google Analytics, social media platforms such as LinkedIn, and advertising networks. These third parties have their own privacy policies governing their use of cookies, and we encourage you to review them.
12.4 Your Cookie Choices and Controls
When you first visit our website, a Cookie Consent Banner will appear, allowing you to:
- Accept all cookies, including non-essential cookies;
- Reject non-essential cookies, so only strictly necessary cookies will be applied;
- Customise your preferences by toggling specific cookie categories on or off.
You may change or withdraw your cookie consent at any time by:
- Accessing the Cookie Preference Centre on our website, usually accessible via a link in the footer;
- Adjusting your browser settings to refuse or delete cookies, please note this may affect website functionality;
- Using browser extensions designed for privacy management.
Please be aware that withdrawing consent for certain cookies may impact your experience on our website.
12.5 Cookie Retention Periods
Session cookies are deleted when you close your browser. Persistent cookies remain on your device for a defined period as set out in our detailed Cookie Policy.
Section 13: Data Security Measures
We take the security of your personal data extremely seriously. As an oil and gas company operating critical national infrastructure, we apply robust technical and organisational security measures to protect personal data from unauthorised access, loss, alteration, disclosure, or destruction.
13.1 Technical Safeguards
- Encryption: Personal data is encrypted both in transit using TLS/SSL protocols and at rest using AES-256 or equivalent encryption standards;
- Access Controls: Strict role-based access control (RBAC) systems ensure that only authorised personnel can access personal data, on a need-to-know basis;
- Multi-Factor Authentication (MFA): Required for access to systems containing sensitive personal or operational data;
- Firewalls and Intrusion Detection Systems: Network perimeter security measures actively monitor for and block unauthorised access attempts;
- Data Loss Prevention (DLP) Tools: Systems designed to detect and prevent the unauthorised transmission of sensitive data;
- Secure Development Practices: Our website and internal systems are developed and maintained in accordance with established cybersecurity frameworks and regularly tested for vulnerabilities;
- Regular Security Audits and Penetration Testing: We conduct periodic security assessments, vulnerability scans, and penetration tests;
- Backup and Disaster Recovery: Regular encrypted data backups are maintained, with tested recovery procedures to ensure business continuity.
13.2 Organisational Safeguards
- Data Protection Policies: Comprehensive internal data protection, information security, and acceptable use policies govern all staff;
- Staff Training and Awareness: All employees receive mandatory data protection and cybersecurity training, with specialised training for staff handling sensitive data;
- Confidentiality Obligations: All personnel, contractors, and third-party processors handling personal data are bound by legally enforceable confidentiality obligations;
- Data Protection Officer (DPO): A qualified DPO oversees our data protection compliance programme. See Section 20;
- Vendor and Processor Vetting: We conduct security due diligence on all third-party service providers before granting them access to personal data;
- Physical Security: Our offices and operational facilities are secured with appropriate physical access controls and surveillance measures;
- Clean Desk and Clear Screen Policies: To prevent unauthorised viewing of personal data in physical or on-screen formats.
13.3 Important Limitation
While we implement all reasonably practicable security measures, no method of data transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security; however, we are committed to maintaining and improving our security posture in line with evolving threats and best practices.
If you believe your interaction with our website may have resulted in a security concern, please contact us immediately using the details in Section 20.
Section 14: Data Breach Notification
14.1 Our Breach Response Obligations
We maintain a formal Data Breach Response and Incident Management Plan in accordance with the NDPA 2023, the NDPC GAID 2025, and the Cybercrimes (Prohibition, Prevention, etc.) Act 2015.
14.2 Internal Incident Response
Upon detecting or becoming aware of a potential personal data breach:
- Immediate Containment: Our IT Security and Data Protection teams will take immediate steps to contain the breach and prevent further compromise;
- Assessment: A rapid assessment will be carried out to determine the nature, scope, and potential impact of the breach;
- Escalation: All suspected or confirmed breaches are escalated to the DPO and relevant senior management within 24 hours of detection;
- Documentation: All incidents are documented in our Breach Register, including the nature of the breach, data affected, remedial action taken, and any notifications made;
- Remediation: Appropriate remedial and corrective actions are implemented to prevent recurrence.
14.3 Notification to NDPC
Where a personal data breach is likely to result in a risk to the rights and freedoms of data subjects, we will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, in accordance with the NDPA 2023. Where it is not possible to provide full details within 72 hours, an initial notification will be submitted with subsequent supplementary information to follow as it becomes available.
14.4 Notification to Data Subjects
Where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will notify the affected data subjects directly and without undue delay, in clear and plain language, providing:
- A description of the nature of the breach;
- Contact details of our DPO;
- Likely consequences of the breach;
- Measures taken or proposed to address the breach and mitigate its effects;
- Recommended steps that individuals can take to protect themselves.
Notification to individuals may be delayed in exceptional circumstances if required by a competent authority, for example where notification may compromise a criminal investigation.
14.5 Compliance with Cybercrimes Act
Where a data breach involves a cybercrime or unauthorised computer access, we will also comply with our obligations under the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (as amended) and will cooperate fully with the relevant law enforcement authorities, including reporting obligations to appropriate agencies.
Section 15: Children's Privacy
15.1 Age Restriction
Our website is not directed at children and is intended solely for use by adults, specifically corporate stakeholders, professionals, and members of the public aged 18 years and above. We do not knowingly or intentionally collect personal data from persons under the age of 18 years through this website.
15.2 Incidental Collection
If we become aware that personal data has been collected from a person under 18 without verifiable parental or guardian consent, we will:
- Take immediate steps to delete such data from our records; and
- Where appropriate, notify the parent or guardian and the NDPC.
15.3 Parental Consent in Employment and Community Contexts
In specific contexts such as community engagement programmes, apprenticeship schemes, or youth development initiatives permitted under Nigerian law where we may engage with persons under 18, we will:
- Obtain verifiable parental or guardian consent prior to collecting any personal data;
- Collect only the minimum data necessary for the lawful purpose;
- Apply heightened security and access restrictions to any data relating to minors;
- Retain such data only for the minimum period required.
15.4 Parental or Guardian Contact
If you are a parent or guardian and believe that your child has submitted personal data to us without your consent, please contact our DPO immediately at the details provided in Section 20, and we will promptly investigate and address the matter.
Section 16: Third-Party Links and External Websites
16.1 External Links
Our website may contain hyperlinks to external websites, platforms, or resources operated by third parties, including regulatory bodies, industry associations, news platforms, and partner organisations. These links are provided for information and convenience only. They do not constitute our endorsement of, or responsibility for, the content, privacy practices, or data handling of those external websites or their operators.
16.2 No Responsibility for Third-Party Privacy Practices
We have no control over third-party websites and are not responsible for their content, privacy policies, or practices. Each external website operates under its own terms and privacy framework. We strongly encourage you to review the privacy policy of every third-party website you visit before providing any personal information to that website.
16.3 Social Media Plugins and Integrations
Our website may include social media sharing buttons or embedded content, for example LinkedIn, Twitter/X, or YouTube. Your interaction with these features may result in data being collected by those third-party platforms, governed by their respective privacy policies. We are not responsible for such collection.
Section 17: Updates to This Privacy Policy
17.1 Our Right to Update
We reserve the right to update, amend, or modify this Privacy Policy at any time to reflect:
- Changes in applicable laws or regulatory requirements, including NDPC guidance and directives;
- Changes to our data processing activities, services, or business operations;
- Technological developments affecting how we collect or process data;
- Best practice developments in data protection.
17.2 Effective Date
The current version of this Privacy Policy is identified by the “Effective Date” shown at the top of this document. The effective date will be updated each time this policy is amended.
17.3 Notification of Material Changes
Where we make material changes to this Privacy Policy that significantly affect your rights or how we process your personal data, we will:
- Post the updated policy prominently on our website with a “Last Updated” notice;
- Where practicable, notify you by email, if we hold your email address and the change affects you directly;
- For consent-based processing that changes materially, we will seek fresh consent where required by law.
We encourage you to review this Privacy Policy periodically to stay informed of how we protect your data. Your continued use of our website following the posting of changes constitutes your acknowledgement of the revised policy.
Section 18: Complaints and Supervisory Authority
18.1 Internal Complaint Resolution
If you have a concern, complaint, or query about how we handle your personal data, we encourage you to contact us in the first instance so that we may attempt to resolve the matter promptly and effectively.
- Submit your complaint in writing to our Data Protection Officer, using the contact details in Section 20, clearly describing the nature of your concern, the personal data affected, and the outcome you are seeking.
- We will acknowledge receipt of your complaint within 5 business days and provide a substantive response within 30 days, or notify you if a longer period is required.
- If you are dissatisfied with our response, or if we are unable to resolve your complaint to your satisfaction, you have the right to escalate the matter to the NDPC.
18.2 Nigeria Data Protection Commission (NDPC)
You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC), the competent supervisory authority for data protection in Nigeria, at any time.
Contact Details of the NDPC:
Nigeria Data Protection Commission (NDPC)
No. 5 Donau Crescent, Off Amazon Street,
Maitama, Abuja, FCT,
Federal Republic of Nigeria.
Website: www.ndpc.gov.ng
Email: info@ndpc.gov.ng
You may also use the NDPC's online complaint submission portal available on their official website.
Lodging a complaint with the NDPC does not affect your right to pursue any available civil remedy under Nigerian law.
Section 19: Our Compliance Commitment
19.1 Statement of Commitment
The Energy Consulting Practice LLP is fully committed to maintaining the highest standards of personal data protection in compliance with the Nigeria Data Protection Act (NDPA) 2023 and the NDPC General Application and Implementation Directive (GAID) 2025. We recognise that responsible data stewardship is not only a legal obligation but a fundamental aspect of our corporate integrity, stakeholder trust, and social licence to operate.
19.2 Awareness of Regulatory Penalties
We acknowledge that non-compliance with the NDPA 2023 may expose the Company to significant regulatory sanctions, including:
- For Data Controllers and Processors classified as Major: A fine not exceeding 2% of annual gross revenue of the preceding financial year, or ₦10,000,000 (Ten Million Naira), whichever is greater.
- For Data Controllers and Processors not classified as Major: A fine not exceeding 2% of annual gross revenue of the preceding financial year, or ₦2,000,000 (Two Million Naira), whichever is greater.
In addition, we are aware that breaches of the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 and other applicable laws may attract further civil and criminal sanctions. Our compliance programme is designed to ensure that such penalties are avoided through proactive, systematic, and organisation-wide adherence to applicable data protection obligations.
19.3 Data Protection Compliance Programme
Our data protection compliance programme includes:
- Appointment of a qualified Data Protection Officer (DPO);
- Registration with the NDPC as required under the NDPA 2023 and GAID 2025;
- Maintenance of a Record of Processing Activities (RoPA) as required by law;
- Conduct of Data Protection Impact Assessments (DPIAs) for high-risk processing activities;
- Regular staff training and awareness on data protection obligations;
- Periodic audit and review of data protection practices;
- Maintenance and periodic testing of our Data Breach Response Plan;
- Annual compliance reporting to the NDPC where required.
19.4 NDPC Filing Status
The Energy Consulting Practice LLP is registered / has filed its annual data protection compliance report with the Nigeria Data Protection Commission in accordance with the NDPA 2023 and GAID 2025.
Section 20: How to Contact Us
For any questions, concerns, or requests relating to this Privacy Policy, your personal data, or your data subject rights, please contact us through the following:
Data Protection Officer (DPO)
Title: Data Protection Officer
Email: compliance@energyconsultingpractice.com
General Privacy Inquiries
Email: compliance@energyconsultingpractice.com
Attention: Data Protection Officer
Website: energyconsultingpractice.com
Office Hours: Monday to Friday, 9:00am to 5:00pm (WAT), excluding Nigerian public holidays.
We aim to acknowledge all privacy-related communications within 2 business days.
Schedule: Glossary of Key Terms
For ease of understanding, the following definitions apply throughout this Privacy Policy:
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person |
| Data Controller | The entity that determines the purposes and means of processing personal data |
| Data Processor | A party that processes personal data on behalf of and under the instructions of the Data Controller |
| Data Subject | The individual to whom the personal data relates |
| Processing | Any operation performed on personal data, including collection, storage, use, disclosure, or deletion |
| Special Categories of Data | Sensitive categories of personal data requiring heightened protection, such as health data and biometric data |
| NDPA | Nigeria Data Protection Act 2023 |
| NDPC | Nigeria Data Protection Commission |
| GAID | General Application and Implementation Directive 2025 issued by the NDPC |
| NUPRC | Nigerian Upstream Petroleum Regulatory Commission |
| NMDPRA | Nigerian Midstream and Downstream Petroleum Regulatory Authority |
| PIA | Petroleum Industry Act 2021 |
| DPO | Data Protection Officer |
| DPIA | Data Protection Impact Assessment |
| RoPA | Record of Processing Activities |
| KYC | Know Your Customer identity verification and due diligence procedures |
| AML | Anti-Money Laundering regulatory framework preventing money laundering |
| HSE | Health, Safety, and Environment |
| SCC | Standard Contractual Clauses, contractual safeguards for international data transfers |
| TIA | Transfer Impact Assessment, assessment of protections available in destination country for data transfers |
| Cookies | Small data files stored on a user's device by a website |
| Consent | Freely given, specific, informed, and unambiguous indication of agreement to processing |