1. POLICY OVERVIEW

Ultraviolet Microfinance Bank Limited (hereinafter “UVMFB”), as a data collector/controller, is committed toconducting its business in accordance with the Nigeria Data Protection Regulation (NDPA) 2019,  and other material guidelines relating to the protection of personal data and privacy of individuals to ensure compliance with the Data Protection requirements. Non- compliance may expose Ultraviolet MFB to complaints, regulatory actions, fines or/and reputational damage.

2. PURPOSE
3. DEFINITION OF TERMS
TERMSMEANING 
Personal Data A name, identification number, location data, and/or online identifier, including one or more specific factors such as physical, physiological, genetic, mental, economic, cultural or social identifiers relating to a natural person directly or indirectly. 
DatabaseA collection of data organized in a manner that allows access, retrieval, deletion and processing of that data; it includes but not limited to structured, unstructured, cached and file system type Databases
TERMSMEANING 
Data SubjectAny living individual or natural person from whom personaldata is collected 
ConsentAny specific, informed, and unambiguous indication of the data subject’s wishes that is freely given by a statement or by a clear affirmative action, which signifies agreement to the processing of his/her personal data. 
Third Party A natural or legal person, public authority, agency, vendor, contractor, or entity other than the data subject, who, under UVMFB’s authority, is authorised to process personal data. 
Data AdministratorAny persons or organisation that processes data. 
Data ControllerAny person who either alone, jointly with other persons or incommon with other persons or as a statutory body, determines the purposes for and the manner in which personal data is processed or is to be processed 
ProcessingAny operation or set of operations which is performed onpersonal data or on sets of personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. 
Data Protection Impact AssessmentA tool and process for assessing the protection impacts on data subjects in processing their personal data and for identifying remedial actions as necessary in order to avoid or minimize such 
Data Protection Officer An authorized staff of UVMFB who supervises, monitors and reports matters related to data protection and privacy in compliance with this Policy 
Data Encryption The process of converting data or information into a code to prevent unauthorised access by human and/or computer systems. Data encryption can be used during data storage or transmission and is typically used in conjunction withauthentication services to ensure that keys are only provided to, or used by, authorized users.
TERMSMEANING 
Personal Data BreachA breach of data security leading to the accidental orunlawful/illegitimate access, destruction, loss, alteration,unauthorized disclosure of personal data that is beingtransferred, stored or otherwise processed 
GDPRGeneral Data Protection Regulation It is a European Union (EU) that governs the way in which we can use, process, and store personal data (information about an identifiable, living person) 
NDPRNigerian Data Protection Regulation, 2019 
UVMFBUltraviolet Microfinance Bank Limited
4. POLICY STATEMENT
5. DATA PROTECTION PRINCIPLES

Ultraviolet Microfinance Bank Limited is committed to processing data in accordance with its responsibilities under the Nigeria Data Protection Regulation (2019). 

Article 5 of the General Data Protection Regulation requires that personal data shall be:

6. GENERAL PROVISIONS

7. LAWFUL PURPOSES

8. DATA MINIMIZATION

Ultraviolet Microfinance Bank Limited shall ensure that personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. 

9. ACCURACY
10. ARCHIVING/REMOVAL
  1. To ensure that personal data is kept for no longer than necessary, Ultraviolet     Microfinance Bank Limited shall put in place an archiving policy for each   area in which personal data is processed and review this process annually.
  2. The archiving policy shall consider what data should/must be retained, for how long, and why. 
11. SECURITY
  1. Ultraviolet Microfinance Bank Limited shall ensure that personal data is stored securely using modern software that is kept-up-to-date.  
  2. Access to personal data shall be limited to personnel who need access and appropriate security should be in place to avoid unauthorised sharing of information. 
  3. When personal data is deleted this should be done safely such that the data is irrecoverable. 
  4. Appropriate back-up and disaster recovery solutions shall be in place. 
12. BREACH

In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, Ultraviolet  Microfinance Bank Limited  shall promptly assess the risk to people’s rights and freedoms and if appropriate report this breach to the Nigeria Data Protection Bureau via info@ultravioletmfb.com  

For more details, please address any questions, comments and requests regarding our data processing practices to our Data Protection Officer via info@ultravioletmfb.com

UV Account Opening Form