Type to search

News

NDPC Investigates Temu for Possible Data Protection Violations

Share
NDPC Investigates Temu for Possible Data Protection Violations

In a significant move for data protection enforcement, Nigeria’s data regulator — the Nigeria Data Protection Commission (NDPC) — has opened a formal investigation into Chinese‑owned e‑commerce platform Temu over potential violations of the Nigeria Data Protection Act (NDPA). The probe centers on the platform’s handling of personal data, including online surveillance, transparency, data minimisation, and cross‑border transfers.

This development places Nigeria among the growing list of jurisdictions scrutinising Temu’s data practices and reinforces the importance of robust privacy governance as digital commerce expands rapidly.

What Triggered the Investigation?

The NDPC’s investigation was ordered by its Chief Executive Officer, Vincent Olatunji, after preliminary findings suggested that Temu might be violating core principles of Nigeria’s data protection regime, such as:

  • Online surveillance and tracking of users
  • Lack of transparency in data collection
  • Possible failure to limit data to what is necessary
  • Cross‑border transfer of personal data without adequate safeguards

These concerns align with obligations set out in the Nigeria Data Protection Act, 2023, which requires organisations to ensure personal data is processed lawfully, transparently, and with respect for the rights of data subjects.

According to the regulator, Temu processes personal data for approximately 12.7 million Nigerian users, with around 70 million daily active users globally — underscoring the scale of potential data protection implications.

NDPC partners with Civil Society Organisations

Why the Probe Matters for Nigerians and Digital Consumers

This investigation is especially significant for several reasons:

1. Data Sovereignty and Local Regulation

Nigeria’s NDPC is asserting its authority under the NDPA to demand compliance from digital platforms operating within its jurisdiction. This upholds data sovereignty — the principle that personal data of Nigerian citizens must be governed by local law rather than foreign systems alone.

In the past, the Commission fined Multichoice Nigeria ₦766 million for breaches of data protection rules, including unlawful cross‑border transfers, demonstrating that enforcement has real consequences.

2. Transparency and Accountability

Consumers increasingly demand clear information about how their data is used. When an international platform like Temu operates at scale without clear transparency, regulators step in to protect privacy rights.

3. Precedent for Digital Market Oversight

Global regulators have begun scrutinising Temu in other jurisdictions too. For example, the Personal Information Protection Commission (PIPC) of South Korea previously sanctioned Temu for unlawful cross‑border data transfers and other violations, reflecting a broader pattern of regulatory concern.

What the NDPC Is Focusing On

The NDPC’s probe is looking into specific areas where Temu may be non‑compliant:

Focus AreaWhat It MeansWhy It Matters
Online SurveillanceMonitoring user behaviour beyond what is necessaryThreatens user privacy and may be unlawful
TransparencyClear communication of data practicesUsers must know what is collected and why
Data MinimisationRestricting collection to only necessary dataReduces risk of misuse or breach
Cross‑border TransfersMoving data outside Nigeria without adequate protectionRaises concerns over data security and foreign access

Temu’s Response and Cooperation

So far, Temu has emphasised that it is committed to complying with applicable laws and has expressed willingness to cooperate with the NDPC during the ongoing investigation. However, precise details about how the company plans to address the regulator’s concerns have not been publicly disclosed.

This cooperation reflects a pragmatic approach many global platforms take when engaging with privacy regulators — balancing compliance with operational needs.

Broader Implications for Digital Platforms

Nigeria’s move to probe Temu is part of wider trends in data protection enforcement:

  • Regulators globally are increasingly holding tech and e‑commerce companies accountable under local privacy laws.
  • Cross‑border data transfers are a focal point for multiple data protection authorities due to concerns over jurisdictional controls and access.
  • Platforms that command large user bases are now expected to go beyond minimal compliance to adopt privacy‑by‑design principles.

For organisations seeking to understand data protection best practices, the International Association of Privacy Professionals (IAPP) provides an authoritative resource on emerging privacy trends and regulatory expectations.

What This Means for Nigerian Consumers

If you are a Nigerian user of Temu or similar digital platforms:

  • Be aware that your personal information may be subject to more rigorous scrutiny and protection under Nigerian law.
  • Monitor updates from the NDPC, which will likely publish outcomes once the investigation concludes.
  • Understand that data protection laws are designed to protect your rights, including consent, transparency, and control over how your data is used.

Frequently Asked Questions

What is the Nigeria Data Protection Commission (NDPC)?

The NDPC is Nigeria’s regulatory authority responsible for enforcing the Nigeria Data Protection Act, ensuring organisations comply with data privacy laws.

Does the investigation mean Temu has already broken the law?

Not necessarily. An investigation is a formal assessment to determine whether violations have occurred. If breaches are confirmed, the NDPC may take enforcement actions.

What laws govern this investigation?

The probe is conducted under the Nigeria Data Protection Act (NDPA), 2023, which sets standards for lawful collection, processing, storage, and transfer of personal data.

Could Temu face fines or sanctions?

Yes. If the NDPC finds Temu non‑compliant, penalties could include fines, restrictions on data activities, or other enforcement measures under the NDPA.

How long will the investigation take?

The NDPC has not specified a timeline. Complex data investigations involving international platforms can take several weeks to months.

Conclusion

Nigeria’s investigation into Temu’s data handling practices marks a pivotal moment in data protection enforcement in Africa. This case highlights the increasing expectations placed on global digital platforms to respect local data protection laws, uphold transparency, and safeguard user privacy.

For consumers, this is a reminder of the evolving digital rights landscape. For businesses, it signals that robust data governance isn’t optional — it’s central to legal compliance and trust in the digital economy.

Staying informed and proactive about data protection obligations will be key as regulators like the NDPC continue to reinforce privacy standards in a fast‑digitising world.

Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.