Recitals
THIS DATA PROCESSING AGREEMENT (this “Agreement”) between the Registered School and Access Bank PLC (Access Bank).
“The Registered School” and Access Bank shall individually be referred to as a “Party” and collectively as “Parties”.
WHEREAS:
Being the “Registered School for the Access Bank Spot the Scam Financial Crime Awareness Initiative” (Spot the Scam Initiative), We (the registered school) acknowledge that our participation in the Initiative involves the collection and processing of Personal Data relating to students, parents/guardians, teachers and other participants (“Data Subjects”).
For purposes of Personal Data collected directly by or on behalf of Access Bank Plc (“Access Bank”) in connection with the administration and delivery of the Spot the Scam Financial Crime Awareness Initiative, Access Bank shall be the Data Controller and shall determine the purposes and means of processing such Personal Data.
The Registered School shall act as a Data Processor only where it processes Personal Data strictly on behalf of Access Bank and in accordance with Access Bank’s registration / participation requirements for the Spot the Scam Initiative.
Where the Registered School independently determines the purposes and means of processing Personal Data within its own school operations, the Registered School shall be responsible for such processing in its capacity as an independent Data Controller.
Given that the Initiative involves students aged 12–16 years, the parties shall apply heightened safeguards in relation to children’s Personal Data, including appropriate parental/guardian consent and age-appropriate privacy information where required by applicable law.
The Parties enter into this Agreement to ensure the protection and security of any Data transferred from the Processor (Registered School) to the Controller (Access Bank) in accordance with Data Protection Laws.
1. Definitions and Interpretation
1.1Definitions
In this Agreement, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
“Data Controller” Access Bank shall be the Data Controller, having received from the Data Processor — Personal Data relating to students, parents/guardians, teachers and other participants (“Data Subjects”). Access Bank shall determine the purposes and means of processing such Personal Data;
“Data Processor” means the Registered School — where it processes Personal Data strictly on behalf of Access Bank and in accordance with Access Bank’s registration / participation requirements for the Spot the Scam Initiative. This definition also covers any approved technology provider by Access Bank; Where applicable, Access Bank may engage third-party service providers or implementation partners to process Personal Data on its behalf. Such parties shall be required to comply with applicable Data Protection Laws and Access Bank’s instructions and data protection requirements.
“Independent Data Controller” Where the Registered School independently determines the purposes and means of processing Personal Data within its own school operations, the Registered School shall be responsible for such processing in its capacity as an independent Data Controller.;
“Business Days” means a day (other than a Saturday, Sunday or public holiday declared by the Federal Government of Nigeria) on which banks and offices are open for general business in Nigeria;
“Company Data” means any Data belonging to the Controller herein processed by the Processor on behalf of the Controller pursuant to or in connection with this Agreement and the Spot the Scam Initiative;
“Contracted Processor” means the Processor or its contracted Sub-Processors;
“Data” means information in whatever form or howsoever stored as may be defined in any applicable Data Protection Laws, including Company Data and Personal Data;
“Data Protection Laws” means all data protection laws and regulations applicable to a Party’s processing of Data under this Agreement, including: (a) Nigeria Data Protection Act 2023 (NDPA), (b) any other applicable law relating to the Processing, privacy and/or use of Personal Data, (c) any laws which implement or supplement any such laws and (d) any laws that replace, extend, re-enact, consolidate or amend any of the foregoing;
“Data Subject” means a natural person who can be identified directly or indirectly by reference to the Personal Data collected by the Controller and the Processor; For this agreement on the Spot the Scam initiative, data subjects include students, parents/guardians, teachers and other participants;
“Data Transfer” means:
- a transfer of Company Data and/or Personal Data from the Controller to the Processor; or
- an onward transfer of Company Data and/or Personal Data from the Processor to a Subcontracted Processor,
in each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);
“Intellectual Property” means all patents, rights to inventions, copyrights and any related rights, design rights, performer’s rights, trade marks, business names and domain names, rights in get up, goodwill and right to sue for passing off, database rights, rights to use, and protect the confidentiality of, confidential information, and all other intellectual property rights, whether registered or unregistered, including all applications and rights to apply for and be granted, renewals or extensions of, and rights to claim property from, such rights and all similar or equivalent rights or forms of protection which subsist or will subsist now or in the future exercisable in any part of the world, which subsist or will subsist now or in the future;
“Personal Data” means any information relating to a Data Subject and containing an identifier such as a name, photo, email address, phone number, physical address, state, signed parental consent form, team assignment, leaderboard display name. For this agreement on the Spot the Scam initiative, data subjects include students, parents/guardians, teachers and other participants;
“Processing” or “Process” either mean any activity that involves the use of Company Data/Personal Data or as the Data Protection Laws may otherwise define processing or process. It includes any operation or set of operations which is performed on Company Data or Personal Data or sets of Company Data and Personal Data, whether or not by automated means, such as collection, recording, organising, structuring, storing, adapting or altering, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, Processing also includes transferring Company Data and/or Personal Data to third parties;
“Security Incident” means any unauthorised or unlawful breach of security that leads to the accidental or unlawful destruction, loss, or alteration of, or unauthorised disclosure of or access to, Company Data and/or Personal Data transmitted, stored or otherwise processed;
“Security Measures” means processes adopted by the Controller and the Processor to protect its Data or other Data in its possession. Such measures include but not limited to protecting systems from hackers, cyberattacks, viral attack, data theft, damage by rain, fire or exposure to other natural elements. These measures also include setting up firewalls, storing data securely with access to specific authorised individuals, employing data encryption technologies, developing organizational policy for handling personal data (and other sensitive or confidential data), protection of email systems and continuous capacity building for staff;
“Sensitive Data” means identifiers and Personal Information such as name, photo, email address, date of birth, phone number, physical address, state, signed parental consent form, team assignment, leaderboard display name (of students, schools, school coordinator and all participants) and any other information that falls within the definition of “special categories of data” under applicable Data Protection Laws;
“Services” means the collection by the Processor for the Controller of students’ data, parent/guardian consent, designation of school coordinator and any other activity in connection with the administration and delivery of the Spot the Scam Financial Crime Awareness Initiative;
“Sub-Processor” means any processor or authorized technology provider engaged by the Processor to assist in fulfilling its obligations with respect to the Spot the Scam Initiative or this Agreement. Sub-Processors may include third parties or Affiliates of the Processor but shall exclude the Processor’s employees or consultants
“The Registered School” means the legal person (the registered school) accepting the terms of this Agreement and may qualify as the Processor or Independent Data Controller
1.2Interpretations
In addition to the terms above, the terms, “Commission”, “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach” and “Supervisory Authority” shall have the same meaning as in the applicable Data Protection Laws, and their cognate terms shall be construed accordingly.
The word “include” shall be construed to mean include without limitation, and cognate terms shall be construed accordingly.
2. Business Purpose
The Processor shall Process Personal Data solely for the purpose of administration and delivery of the Spot the Scam Financial Crime Awareness Initiative. Such Processing shall relate to the following business purpose(s):
Nature of Processing / Business Activity: Collection of personal information of the following participants as identified below to enable the Data Controller and/or its approved technology provider to identify and process participants data in connection with the Spot the Scam initiative
- Schools: Name, email address, phone number, physical address, and state.
- Coordinators: Name and contact phone number.
- Students (Minors): Full name, age, avatar/photo, signed parental consent form, team assignment, and leaderboard display name.
Duration of Processing: Processing shall take place between September and December 2026 for the duration of the Spot the Scam Initiative or for such fixed term as may be expressly agreed by the parties in writing and shall cease upon the expiration or termination of the applicable Spot the Scam Terms and Conditions, subject to any retention obligations required under the applicable law and the data deletion provisions of this Agreement.
3. Roles and Responsibilities
3.1Lawful Basis for Processing
Controller Responsibility for Lawful Basis: The Bank, acting as Data Controller, shall ensure that all Processing of Personal Data under this Agreement is supported by a valid lawful basis in accordance with applicable Data Protection Laws. Such lawful bases may include, but are not limited to, performance of a contract, compliance with a legal obligation, legitimate interests, or consent of the Data Subject, as applicable.
Processor Obligations: The Registered School and any authorized Technology provider, acting as Data Processor, shall Process Personal Data solely in connection with the administration and delivery of the Spot the Scam Financial Crime Awareness Initiative and shall not Process Personal Data for its own purposes, except where the school is acting in its capacity as Independent Data Controller.
The Registered School and any authorized Technology provider shall not be responsible for determining the lawful basis for Processing but shall promptly inform the Bank if, in its opinion, any instruction infringes applicable Data Protection Laws. Assistance and Cooperation.
The Registered School and any authorized Technology provider shall provide reasonable assistance to the Bank, upon request, to enable the Bank to demonstrate compliance with its obligations regarding lawful basis, including providing relevant information about Processing activities and implementing appropriate technical and organizational measures.
3.2The Parties
The Controller and the Processor shall implement and maintain effective Security Measures that are designed to preserve the security and confidentiality of each Party’s Data and protect its Data from Security Incidents. For Personal Data, such effective Security Measures include pseudonymisation and encryption of Personal Data.
Each Party shall ensure it implements a process for regularly testing, assessing and evaluating the effectiveness of its Security Measures.
3.3The Controller
The Controller shall comply with applicable Data Protection Laws in providing (or causing to be provided) Personal Data, including any Sensitive Data, to the Processor for Processing under this Agreement. The Parties acknowledge that the Processing may involve the following categories, as applicable:
- Categories of Personal Data: [Name, email address, phone number, physical address, date of birth, state, age, avatar/photo, signed parental consent form, team assignment, and leaderboard display name, etc.
- Categories of Data Subjects: [e.g. students of the registered school, designated school coordinator, parents / guardians, etc]
Given that the Initiative involves students aged 12–16 years, the parties shall apply heightened safeguards in relation to children’s Personal Data, including appropriate parental/guardian consent and age-appropriate privacy information where required by applicable law.
The Parties acknowledge that such data merits specific and heightened protection, as its Processing may pose significant risks to the fundamental rights and freedoms of Data Subjects. Accordingly, the Processor shall apply appropriate technical and organisational measures in accordance with this Agreement and applicable Data Protection Laws.
NB: Where the Registered School independently determines the purposes and means of processing Personal Data within its own school operations, the Registered School shall be responsible for such processing in its capacity as an independent Data Controller.
The Controller represents and warrants that:
- it has complied, and will continue to comply, with all applicable laws, including Data Protection Laws, in respect of its processing of Personal Data and any processing instructions it issues to the Processor; and
- it has obtained, and will continue to obtain, all consents and rights necessary under Data Protection Laws for the Processor to process Personal Data for the purposes described in the Spot the Scam Terms & Conditions or this Agreement.
The Controller shall have sole responsibility for the legality of Company Data and/or Personal Data and the means by which the Controller acquired such Company Data and/or Personal Data.
3.4The Processor
The Registered School shall ensure that all Personal Data disclosed to Access Bank or its authorised processors in connection with the Initiative has been collected and disclosed lawfully and in accordance with applicable Data Protection Laws, including the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), to the extent applicable, and applicable guidance issued by the Nigeria Data Protection Commission (NDPC).
The parties shall process Personal Data only for specified, explicit and legitimate purposes connected with the Initiative and shall apply appropriate measures to ensure confidentiality, security, accuracy and protection of the Personal Data of participating students and other Data Subjects.
Given that the Initiative involves students aged 12–16 years, the parties shall apply heightened safeguards in relation to children’s Personal Data, including appropriate parental/guardian consent and age-appropriate privacy information where required by applicable law.
The following shall apply:
3.4.1The Processor (Registered School) shall authorize a school coordinator who will be responsible for obtaining the required sign-up information (school name, teacher/coordinator’s name, school email address, teacher’s e-mail address, school phone number, teacher phone number, physical address, state, signed parental consent form, team assignment, leaderboard display name, etc) from the Data subjects.
3.4.2The authorization from the school shall be documented and signed by the school’s authorized signatory and uploaded as a pre-requisite for school registration on the spot the scam platform.
3.4.3The school coordinator will register on the spot the scam website providing relevant details (school name, teacher/coordinator’s name, school email address, teacher’s e-mail address, school phone number, teacher phone number, physical address, state, signed parental consent form, team assignment, leaderboard display name, etc) and create a profile for a team of 4 students. A signed Parent/Guardian Consent form is a pre-requisite for onboarding of each student on the website.
3.4.4Upon satisfactory completion of the 3.4.1 – 3.4.3, the student will gain access to training materials, educational quizzes and can feature on the competition leaderboard which celebrates the top performers.
3.4.5The school coordinator is required to upload a 3-minutes debate video submission featuring its team of 4 students on a selected financial crimes related topic.
The Processor shall adopt such measures to ensure a level of security appropriate to the sensitivity of the Data being collected and processed in connection with the Spot the Scam Initiative. This includes the use of encryption and/or anonymization, where applicable.
The Processor shall notify the Controller in writing within forty-eight (48) hours, unless prohibited from doing so under Data Protection Laws, if it becomes aware or believes that any data processing instruction from the Controller violates any Data Protection Law.
The Processor (approved technology provider) shall ensure it can restore the availability and access to Data promptly in the event of a Security Incident.
Where applicable, Access Bank may engage third-party service providers or implementation partners to process Personal Data on its behalf. Such parties shall be required to comply with applicable Data Protection Laws and Access Bank’s instructions and data protection requirements.
The Processor shall ensure that any person who is authorised by the Processor to process Data (including its staff, agents and subcontractors) shall be under a contractual or statutory obligation of confidentiality.
The Processor shall, in updating or modifying its Security Measures, ensure that such updates and modifications do not result in the degradation of the the Processor’s Security Measures.
Upon becoming aware of a Security Incident, the Processor shall:
- notify the Controller without undue delay, and where feasible, in any event no later than forty eight (48) hours from becoming aware of the Security Incident;
- provide timely information relating to the Security Incident as it becomes known or as is reasonably requested by the Controller; and
- promptly take reasonable steps to contain and investigate any Security Incident.
The Processor’s notification of or response to a Security Incident under Clause 2.3.6 shall not be construed as an acknowledgement by the Processor of any fault or liability concerning the Security Incident until proven otherwise.
Notwithstanding the above, the Controller agrees that except as provided in this Agreement, the Controller is responsible for protecting the security of Personal Data when in transit to the Processor while the Processor is responsible for protecting the security of Personal Data it receives and transfers to any party including any Sub-Processor.
4. Privacy Notice
The registered school is bound by the Access Bank privacy notice and is required to bring this to the attention of the Data Subjects. Both Parties acknowledge Access Bank’s privacy notice (which is accessible on the spot the scam website) that informs data subjects of the processing of their personal data in accordance with applicable data protection laws and regulations and shall maintain the following minimum standards:
- Accessibility. The privacy notice shall be easily accessible to the data subjects, such as through a website or appropriate means.
- Up to date. Each Party shall update its privacy notice as necessary to reflect any changes in the processing of personal data or in applicable data protection laws and regulations.
- Confirmation of Privacy Notices. Each Party shall, upon data request and collection, inform the Data Subjects of the Access Bank privacy notice in place.
- Compliance. Each Party shall ensure that its privacy notice complies with all applicable data protection laws and regulations.
5. Processing of Data
The Processor (or its other Contracted sub-processors) shall:
- Comply with Data Protection Laws in the Processing of Data.
- Not Process Data other than on the Controller’s documented instructions unless Processing is required by Data Protection Laws to which the Processor is subject, in which case the Processor shall, to the extent permitted by Data Protection Laws, inform the Controller of that legal requirement before the relevant Processing of that Data.
The Controller:
Instructs the Processor (and authorises the Processor to instruct each Sub-Processor) to:
- Process Data; and
- in particular, transfer Data to any country or territory, must be expressly instructed or approved by the Controller, and only where such transfer complies with applicable Data Protection Laws, including the existence of an adequacy decision or appropriate safeguards. The Processor shall document the applicable data transfer mechanism and safeguards and make such records available to the Controller upon request.
Warrants and represents that it is and will at all relevant times remain duly and legitimately authorised by the Data Subject to give the instruction set out in Clause 4.2.1.
6. Processor Personnel
The Processor shall take reasonable steps to ensure the reliability of any employee, agent or any contractor of the Processor who may have access to the Data provided by The Controller, ensuring in each case that access is strictly limited to those individuals who need to know/access the relevant Company Data and/or Personal Data, as strictly necessary for the purposes of the Spot the Scam Initiative and/or this Agreement, and to comply with Data Protection Laws in the context of that individual’s duties to the Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
7. Security
7.1Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall in relation to Data implement appropriate technical and organizational measures such, as encryption, access control, audit log & monitoring etc., to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Data Protection Laws.
7.2In assessing the appropriate level of security, the Processor shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
7.3The Controller shall have the right at any time to verify compliance with the obligations and warranties under this Clause 6. If any breach is discovered, it shall be cured by the Processor without undue delay.
7.4The Processor will, and, as applicable, will cause Sub-Processors to, at all times maintain ISO 27001 certification and/or industry-standard successor report accepted by the Controller, for security availability, confidentiality, and privacy-related controls of the information processing management systems (including procedures, people, software, data, and infrastructure) used by the Processor and Sub-Processors or the Processor Personnel in processing Company Data and/or Personal Data.
7.5The Processor shall, upon request, promptly provide the controller with a copy of its ISO 27001 certification and/or the ISO Statement of Applicability (SoA) or its SOC 2 report. Where such certifications are not applicable having regard to the nature, scale, or risk profile of the Processor’s business or services, the Processor shall provide alternative relevant certifications or independent assurance evidence, acceptable to the Controller, upon request.
8. Crossborder and International Data Transfers
8.1The Processor shall not transfer, access, store, or otherwise Process Personal Data outside Nigeria except on the prior documented instruction or authorization of the Controller and in full compliance with applicable Data Protection Laws.
8.2Where any crossborder or international transfer of Personal Data is approved by the Controller, such transfer shall only take place where:
- the receiving country or territory is subject to an adequacy decision under applicable Data Protection Laws; or
- appropriate safeguards are implemented to ensure an adequate level of protection for the Personal Data, including contractual, technical, or organizational measures as required by law.
8.3Accordingly, Personal Data shall not be transferred to any jurisdiction that has not been assessed as adequate or is not protected by approved safeguards.
8.4The Processor shall document the applicable data transfer mechanism and safeguards relied upon for each approved crossborder transfer and shall make such documentation available to the Controller upon request.
9. Sub-Processing
9.1The Controller agrees that the Processor may engage Sub-Processors to process Company Data and Personal Data on the Controller’s behalf.
9.2The Processor may continue to use those Sub-Processors already engaged by the Processor as at the date of this Agreement, subject to the Processor in each case as soon as practicable meeting the obligations set out in Clause 7.4.
9.3The Processor shall give the Controller prior written notice of the appointment of any new Sub-Processor, including full details of the Processing to be undertaken by the Sub-Processor. If, within ten (10) business days of receipt of that notice, the Controller notifies the Processor in writing of any objections (on reasonable grounds) to the proposed appointment:
- The Processor shall work with the Controller in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Sub-Processor.
- Where such a change cannot be made within thirty (30) calendar days from the Processor’s receipt of the Controller’s notice, the Controller may by written notice to the Processor with immediate effect terminate the Service in connection to the Spot the Scam Initiative to the extent that it relates to the Services which require the use of the proposed Sub-Processor.
9.4With respect to each Sub-Processor, the Processor shall:
- Before the Sub-Processor first Processes the Controller’s Data (or, where relevant, in accordance with Clause 7.2), carry out adequate due diligence to ensure that the Sub-processor is capable of providing the level of protection for the Controller Data required by this Agreement.
- Ensure that the arrangement between the Processor and the Sub-processor is governed by a written contract including terms which offer at least the same level of protection for the Controller Data as those set out in this Agreement and meet the requirements of Data Protection Laws.
- Provide to the Controller for review such copies of the Processors’ agreements with Sub-Processors (which may be redacted to remove confidential commercial information not relevant to the requirements of this Agreement) as the Controller may request from time to time.
- Remain responsible for the Sub-processor’s compliance with the obligations of this Agreement and for the acts or omissions of such Sub-Processor that cause the Processor to breach any of its obligations under this Agreement.
9.5The Processor shall ensure that each Sub-Processor performs the obligations under Clauses 4.1, 5, 6, 8.1, 9, 10, and 12.1 of this Agreement, as they apply to Processing of the Controller Data carried out by that Sub-Processor, as if it were party to this Agreement in place of the Processor.
9.6The Controller may, acting reasonably, object to the further use of a Sub-Processor at any time in the event that the Controller has reasonable grounds to suspect that the relevant Sub-Processor is in breach of Data Protection Laws applicable to the Sub-Processor or of the written contract with the Sub-Processor under Clause 7.4.2, by providing written notice to the Controller specifying the grounds to suspect such breach. If consent is revoked, the Processor shall without undue delay stop using the Sub-processor for data processing work and shall have the right to terminate any agreement(s) for which the Processor would have used the relevant Sub-Processor.
9.7The processing or transfer of Data by or to a Sub-Processor is permitted only if (and as long as) the Processor can show that the requirements defined in Clauses 7.4 and 7.5 are satisfied.
10. Data Subject Rights
10.1Taking into account the nature of the Processing, the Processor shall assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligations, as reasonably understood by the Controller, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
10.2The Processor shall:
- Promptly notify the Controller if the Processor or any of its Contractor receives a request from a Data Subject under any Data Protection Laws in respect of the Controller Data.
- Notify the Controller, and in any case in not less than three (3) days of becoming aware, if the Processor receives a request from a Data Subject under any Data Protection Law in respect of the Controller Data and, if required by the Controller, permit the Controller to handle such request and at all times at the Controller’s reasonable expense, cooperate with and assist the Controller to ensure its compliance with its obligations under the Data Protection Laws in relation to such Data Subject requests, including requests where Data Subjects exercise their rights to (i) access, rectify or erase Personal Data; (ii) restrict or object to the processing of Personal Data; or (iii) Personal Data portability; and
- Ensure that the Processor does not respond to that request except on the documented instructions of the Controller or as required by Data Protection Laws to which the Processor is subject, in which case the Processor shall to the extent permitted by Data Protection Laws inform the Controller of that legal requirement before the response is given to the Data Subject.
10.3If a law enforcement agency sends the Processor a demand for Personal Data (for example, through a subpoena or court order), the Processor shall attempt to redirect the law enforcement agency to request that Data directly from the Controller. As part of this effort, the Processor may provide the Controller’s contact information to the law enforcement agency. If compelled to disclose Personal Data to a law enforcement agency, then Processor shall give the Controller reasonable notice of the demand to allow the Controller to seek a protective order or other appropriate remedies, unless the Processor is legally prohibited from doing so.
11. Personal Data Breach
11.1The Processor shall notify the Controller no later than forty eight (48) hours upon the Processor or any Sub-Processor becoming aware of a Personal Data Breach affecting the Controller Personal Data, providing the Controller with sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects of the Personal Data Breach under Data Protection Laws.
11.2Such notification shall as a minimum:
- describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;
- communicate the name and contact details of the Processor’s data protection officer (if any) or other relevant contact from whom more information may be obtained;
- describe the likely consequences of the Personal Data Breach; and
- describe the measures taken or proposed to be taken to address the Personal Data Breach.
11.3The Processor shall cooperate with the Controller and take such reasonable commercial steps as are directed by the Controller to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
12. Data Protection Impact Assessment and Prior Consultation
The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments, and prior consultations with supervising authorities or other competent data privacy authorities, which the Controller reasonably considers to be required by Data Protection Laws, in each case solely in relation to Processing of the Controller Data by, and taking into account the nature of the Processing and information available to the Processor.
13. Deletion or Return of Access Bank Data by Authorized Technology Provider
13.1Subject to Clauses 13.2 to 13.4, the Processor (approved technology provider) shall promptly and in any event within thirty (30) calendar days of the date of cessation of any Services involving the Processing of the Controller Data (the “Cessation Date”), delete, return and procure the deletion of all copies of the Controller Data.
13.2Personal information collected in connection with the Initiative will be securely retained for 1 year from September 21st, 2026 and processed for purposes relating to registration, administration, communication, participation, certification, and publicity connected with the Initiative. All personal data will be deleted after 1 year.
13.3Subject to Clause 13.4, the Controller may in its absolute discretion by written notice to the Processor within ten (10) business days of the Cessation Date require the Processor to (a) return a complete copy of all the Controller Data to the Controller by secure file transfer in such format as is reasonably notified by the Controller to the Processor; and (b) delete and procure the deletion of all other copies of the Controller Data Processed by the Processor or any of its contracted sub-processors. The Processor shall comply with any such written request within twenty (20) business days of the Cessation Date.
13.4The Processor may retain the Controller Data to the extent required by Data Protection Laws and other applicable laws binding such Processor only to the extent and for such period as required by Data Protection Laws and always provided that the Processor shall ensure the confidentiality of all such the Controller Data and shall ensure that such the Controller Personal Data is only Processed as necessary for the purpose(s) specified in the Data Protection Laws requiring its storage and for no other purpose.
13.5The Processor shall provide written certification to the Controller that it has fully complied with this Clause 13.1 to 13.4 within twenty (20) business days of the Cessation Date.
14. Audit Rights
14.1Subject to Clauses 14.2 and 14.3, the Processor shall make available to the Controller on request all information necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by the Controller in relation to the Processing of the Controller Data by the Processor and its Contracted sub-Processors.
14.2Information and audit rights of the Controller only arise under Clause 14.1 to the extent that the Principal Agreement does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Laws.
14.3The Controller shall give the Processor reasonable notice of any audit or inspection to be conducted under Clause 13.1 and shall make (and ensure that each of its mandated auditors makes) reasonable endeavors to avoid causing (or, if it cannot avoid, to minimise) any damage, injury or disruption to the Processor’s premises, equipment, personnel and business while its personnel are on those premises in the course of such an audit or inspection.
14.4The Processor shall at regular intervals audit the performance of data processing services for conformity with the terms of this Agreement. If an audit reveals errors or irregularities, the Controller shall be informed, and the Processor shall take all reasonable steps for mitigation and remediation of each such errors or irregularities.
15. Confidentiality
15.1Neither Party shall without written authorisation from the other Party disclose to any third party the terms and conditions of this Agreement except as may be necessary to establish or assert rights hereunder or required by law; provided, however that either Party may, on a confidential basis, disclose this Agreement to its accountants, attorneys or other individuals within each other’s organizations with a “need to know”.
15.2Each of the Parties hereto undertakes to the other to keep confidential all information (written or oral) concerning the business and affairs of the other that it shall have obtained or received as a result of the discussions leading up to or the entering into this Agreement save that which is (a) or already in its possession other than as a result of a breach of this clause; or (b) in the public domain other than as a result of a breach of this clause, each of the Parties undertakes to the other to take all such steps as shall from time to time be necessary to ensure compliance with the provisions of this clause by its employees, agents and sub-contractors.
16. Indemnity
Each Party herein shall be responsible for and keep the other Party indemnified against all claims, demands, actions, proceedings, losses or expenses whatsoever which may be made, brought, commenced, suffered and/or sustained by or against one Party arising from the other Party’s acts or omissions in respect of this Agreement.
17. Force Majeure
17.1Neither Party shall be liable for any failure in performance of this Agreement if such failure arises out of a Force Majeure Event.
17.2On the occurrence of a Force Majeure Event:
- the affected Party will give notice to the other Party specifying the nature and extent of the Force Majeure Event promptly on becoming aware of the Force Majeure Event;
- the affected Party shall, wherever possible, promptly take the necessary reasonable and appropriate steps to bring the Force Majeure Event to an end. The affected Party shall also find a solution by which its obligations under the Rulebook may be performed, despite the continuance of the Force Majeure Event or to mitigate the severity of the Force Majeure Event;
- without prejudice to the generality of Clause 15.2(a) above, the affected Party shall implement the relevant elements of the business continuity and/or disaster recovery procedures maintained by the affected Party in accordance with its obligations under Applicable Law or otherwise; and
- the affected Party shall keep the other Party informed of the circumstances relating to the Force Majeure Event and its progress in resolving the issues affecting its performance of its obligations under this Agreement.
17.3The Parties shall, to the extent permissible under this Agreement, be relieved of their obligations during the period of such events and its consequences, but only to the extent the performance of their obligations were so prevented and shall not be liable for any delay or failure in the performance of any obligations hereunder or loss or damage which the other Party may suffer due to or resulting from such delay or failure. No Party shall be entitled to relief under this Clause if it fails to notify the other Party in writing of the occurrence of a Force Majeure Event in accordance with this clause.
18. Notice
18.1Any notice or other communication or correspondence to be given under this Agreement must be in writing and shall be delivered personally or sent by prepaid post or courier or by facsimile transmission or by electronic mail and shall be deemed to have been served if by personal delivery when receipt is acknowledged by the addressee’s authorized representative, and if by facsimile transmission when receipt is confirmed.
18.2A notice or other communication received on a day other than a business day or after business hours in the place of receipt shall be deemed to be given on the next following business day in such place.
19. Intellectual Property Rights
19.1Each Party shall, unless otherwise specifically agreed in writing, retain all Intellectual Property rights including trademarks, trade names, copyright, patents, designs and other rights used and/or embodied in, or in connection with its products, software, equipment, etc., which rights it owned prior to the Effective Date of this Agreement, during the term of this Agreement and after the duration and/or termination of the Agreement.
19.2Nothing herein shall be construed as conferring, transferring or in any other manner creating for either Party any right of ownership or license over the other Party’s Intellectual Property, assets, property and confidential/proprietary information or any other right beyond those expressly agreed by that Party in writing.
19.3Unless otherwise agreed in writing, inventions, documentation, know-how, designs or work-results developed by either Party within the framework of the Spot the Scam Initiative shall be the property of that Party. This Agreement does not allow a Party to use any such rights belonging to the other Party whether or not created by virtue of the Agreement, without the written consent of that Party.
19.4It is agreed that all Intellectual Property rights of either Party whatsoever, whether capable of registration or not, or not yet registered, including their names, logos, images and other intellectual property matters relating to them, shall remain their exclusive and sole property.
19.5Neither Party shall copy, reproduce, republish, upload, post, transmit or distribute material that forms part of the other Party’s Intellectual Property rights or any information to which it becomes privy in connection with this Agreement, in any manner, including by email or other electronic means and whether directly or indirectly, for marketing, advertising, promotional, or publicity purposes or otherwise, without obtaining the prior written consent of that Party.
19.6Neither Party shall directly or indirectly, or through or in connection with any third party or person, copy, modify, create, decompile, disassemble, re-program, reverse-engineer or otherwise deal with the other Party’s Confidential Information or Intellectual Property, or in whole or in part, write or develop any derivative software or any other software program based on that Party’s Confidential and Proprietary Information and/or Intellectual Property, or related information or permit use of the Party’s Confidential and Proprietary Information by any third party or entity without that Party’s prior written consent.
20. Representations and Warranties
Each Party warrants and undertakes to the other that:
- it has full authority to enter into this Agreement and is not bound by any Agreement with any third Party that adversely affects this Agreement;
- it has and will maintain throughout the term of this Agreement, all necessary powers, authority and consents to enter into and fully perform its obligations under this Agreement; and
- it has obtained all the relevant licenses, permits and authorizations required for the performance of its obligations under this Agreement.
21. Term and Termination
21.1This Agreement shall commence from the Effective Date and remain in effect for as long as the Processor Processes Data on behalf of the Controller or until termination of the Spot the Scam Financial Crimes Awareness Initiative (and all the Controller Data has been deleted per Clause 11 above).
21.2Either Party may by written notice served on the other Party terminate this Agreement immediately if the other Party is in material or persistent breach of this Agreement other than as a consequence of an event of Force Majeure and fails to remedy such breach within thirty (30) calendar days following the service of a written notice from the Party not in breach, specifying the breach and requesting for its remediation.
21.3The termination of this Agreement or any part thereof shall operate without prejudice to the Parties’ accrued rights and obligations under this Agreement.
22. General
22.1Nothing in this Agreement reduces the Processor’s obligations under any Service Agreement in relation to the protection of Personal Data or permits the Processor to Process (or permit the Processing of) Personal Data in a manner which is prohibited by the Spot the Scam Terms & Conditions or this Agreement.
22.2Subject to Clause 22.1, with regard to the subject matter of this Agreement, in the event of inconsistencies between the provisions of this Agreement and any other agreements between the Parties, including the Spot the Scam Terms & Conditions and including (except where explicitly agreed otherwise in writing, signed on behalf of the Parties) agreements entered into or purported to be entered into after the date of this Agreement, the provisions of this Agreement shall prevail.
22.3The Controller may propose any other variations to this Agreement which the Controller reasonably considers to be necessary to address the requirements of any Data Protection Laws.
22.4If the Controller gives notice under Clause 22.3:
- The Parties shall promptly discuss the proposed variations and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements identified in the Controller’s notice as soon as is reasonably practicable.
- The Processor shall promptly co-operate (and ensure that any affected Sub-Processors promptly co-operate) to ensure that equivalent variations are made to any agreement put in place thereto.
- The Controller shall not unreasonably withhold or delay agreement to any consequential variations to this Agreement proposed by the Processor to protect the Processor against additional risks associated with the variations.
22.5Should any provision of this Agreement be invalid or unenforceable, then the remainder of this Agreement shall remain valid and in force. The invalid or unenforceable provision shall be either (i) amended as necessary to ensure its validity and enforceability, while preserving the Parties’ intentions as closely as possible or, if this is not possible, (ii) construed in a manner as if the invalid or unenforceable part had never been contained therein.
22.6The Parties agree that this Agreement shall replace any existing data processing agreement or similar document that the Parties may have previously entered into in connection with the Services.
22.7In the event of any conflict or inconsistency between this Agreement and the Spot the Scam Financial Crimes Awareness Terms & Conditions this Agreement shall prevail.
22.8Except for any changes made by this Agreement, the Spot the Scam Financial Crimes Awareness Terms & Conditions remains unchanged and in full force and effect.
22.9No one other than a party to this Agreement, its successors and permitted assignees shall have any right to enforce any of its terms.
22.10The Parties agree that this Agreement, any Addendum thereto or any other document necessary for the consummation of the transaction contemplated by this Agreement may be accepted, executed or agreed to through the use of an electronic or digital signature in accordance with the applicable laws and will be binding on the Parties the same as if it were physically or manually signed.
22.11This Agreement shall be binding upon the Parties hereto and their lawful successors or assigns; provided this Agreement shall not be assigned by either Party without the written consent of the other Party.
22.12Any waiver or modification of, or addition to this Agreement or any of its provisions shall not be binding upon the parties unless the same shall be in writing and signed by the Parties.
22.13No failure to exercise and no delay in exercising any right, power, or privilege herein contained by either Party hereto shall operate as a waiver thereof and no partial exercise of any right, power and/or privilege shall preclude any or further exercise thereof or of any other right, power and/or privilege.
22.14If any provision of this Agreement is held to be illegal, invalid or unenforceable in whole or in part, the legality, validity and enforceability of the remaining provisions shall not in any way be affected or impaired thereby. Notwithstanding any other provision of this Agreement, any term or provision found by a court of competent jurisdiction to be invalid, illegal or otherwise unenforceable shall thereafter be deemed modified to the extent necessary to render such term or provision enforceable, and the rights and obligations of the Parties shall be construed and enforced accordingly, preserving to the fullest permissible extent, the rights and obligations of the Parties.
23. Governing Law
23.1This Agreement shall be governed by and construed in accordance with the laws of Nigeria.
23.2Any dispute between the Parties in connection with the interpretation, implementation or operation of this Agreement or the validity of any document furnished by the Parties shall be resolved in accordance with the dispute resolution provision in the relevant Service Agreement(s) between the Parties.
23.3In the absence of any such dispute resolution provisions in the Service Agreement referred to in 23.2, such dispute shall be resolved by negotiation between the Parties.