FREE LEARNING PATH · DATA PROTECTION

Day 5: Finance, Audit and Review

A complete 30-day study path through the Nigeria Data Protection Act—practical lessons, scenarios and self-checks, open to everyone.

TrustStack Academy CDPO study badge: free 30-day data protection learning pathA study-path badge, not a professional certification
30complete study days
Freeno sign-in or payment
Practicediagnostics and model answers
Self-pacedprogress saved in this browser
LESSON 05 OF 30

Finance, Audit and Review

Read the assigned provisions, attempt the diagnostics, then compare your reasoning with the model responses.

Today’s topicFinance, Audit and Review
Estimated time90-120 minutes
Primary Act referencess.19-23
Guide referenceGuide pp.4, 7 and Assessment 1

Learning Objectives

Explain and apply funds and expenditure.

Explain and apply borrowing and gifts.

Explain and apply accounts and audit.

Explain and apply annual reports.

Explain and apply institutional accountability.

Diagnostic Assessment

Attempt these questions before reading the model responses.

1. What is the principal compliance issue addressed by ss.19-23?

Show model response

Model response: It is finance, audit and review. The analysis should focus on funds and expenditure and the connected statutory conditions.

2. Identify two concepts that must be considered when analysing finance, audit and review.

Show model response

Model response: Any two of the following are relevant: funds and expenditure, borrowing and gifts, accounts and audit, annual reports.

3. Why should a DPO cite the exact section instead of relying only on a general privacy principle?

Show model response

Model response: The section contains the controlling conditions, limits and exceptions. A general principle may guide analysis but cannot replace the specific statutory test.

4. What evidence should an organisation retain when applying ss.19-23?

Show model response

Model response: It should retain the facts considered, the statutory test, the decision, supporting records, responsible approval and any review or corrective action.

5. How should the organisation respond when the uploaded sources do not resolve a material detail?

Show model response

Model response: It should record the limitation and avoid inventing a requirement. The DPO should return to the full statutory wording and seek current authoritative material when permitted.

Structured Lesson

LEGAL RULE: The controlling statutory material for this lesson is ss.19-23. Apply its precise language, conditions and exceptions to the facts.

1. Funds And Expenditure

Funds and expenditure is a central issue for this study day. The DPO should locate the exact statutory conditions in ss.19-23, apply them to the particular processing activity and retain evidence supporting the conclusion.

2. Borrowing And Gifts

Borrowing and gifts is a central issue for this study day. The DPO should locate the exact statutory conditions in ss.19-23, apply them to the particular processing activity and retain evidence supporting the conclusion.

3. Accounts And Audit

Accounts and audit is a central issue for this study day. The DPO should locate the exact statutory conditions in ss.19-23, apply them to the particular processing activity and retain evidence supporting the conclusion.

4. Annual Reports

Annual reports is a central issue for this study day. The DPO should locate the exact statutory conditions in ss.19-23, apply them to the particular processing activity and retain evidence supporting the conclusion.

5. Institutional Accountability

Institutional accountability is a central issue for this study day. The DPO should locate the exact statutory conditions in ss.19-23, apply them to the particular processing activity and retain evidence supporting the conclusion.

GUIDE GUIDANCE: The Guide assigns Day 5 to finance, audit and review and requires study of ss.19-23. Its practical emphasis is funds and expenditure, borrowing and gifts, accounts and audit.
TUTOR EXPLANATION: Use a five-step analysis: identify the processing facts, confirm the actor and role, locate the controlling section, test every condition and exception, then document the decision and evidence.

Nigerian Scenario and Model Analysis

A telecommunications company begins a project involving staff or customer personal data. The project raises questions about funds and expenditure and borrowing and gifts. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under ss.19-23, key risks and the compliance evidence that should be retained.

Show model response

Model analysis: The organisation determining why and how the project operates is normally the controller. A vendor acting only on documented instructions is normally a processor. Staff or customers are the data subjects. The DPO should inventory the data, apply ss.19-23 to the stated purpose, document the decision, assign controls and retain evidence. The final conclusion depends on the precise facts and statutory conditions.

Lesson Summary

Day 5 establishes how a DPO should understand and apply finance, audit and review. The legal starting point is ss.19-23. The main operational lesson is to connect funds and expenditure, borrowing and gifts, accounts and audit to documented facts and evidence.

Ten Key Terms

TermWorking definition
ControllerA person or body that determines the purposes and means of processing personal data.
ProcessorA person or body that processes personal data on behalf of a controller.
Data SubjectThe identified or identifiable individual to whom personal data relate.
Personal DataInformation relating to an identified or identifiable individual.
ProcessingAn operation performed on personal data, including collection, use, storage, disclosure or deletion.
Lawful BasisA statutory justification that permits processing under section 25.
AccountabilityResponsibility for compliance and the ability to demonstrate it with evidence.
SecurityRisk-appropriate technical and organisational protection for personal data.
RecipientA person or body to whom personal data are disclosed.
DpoA Data Protection Officer who advises, monitors compliance and acts as a regulatory contact under section 32.

Definitions are paraphrased for study. Check section 65 and the relevant operative provision for controlling wording.

Five Revision Questions and Responses

1. What provisions govern this lesson?

Show model response

Response: ss.19-23

2. What are the principal concepts?

Show model response

Response: funds and expenditure, borrowing and gifts, accounts and audit, annual reports, institutional accountability.

3. What is the correct source hierarchy?

Show model response

Response: The Act is primary authority. The Guide supports learning and professional application. Tutor explanation assists interpretation without creating new law.

4. What is the central evidence requirement?

Show model response

Response: Record the facts, applicable test, conclusion, approval, controls and review trigger.

5. What common error should be avoided?

Show model response

Response: Do not assume a broad principle answers the issue. Test the exact conditions and exceptions in the assigned section.

Five Multiple-Choice Questions

1. Which source provides the primary statutory rule for Day 5?

A. The Guide

B. The Act

C. A workplace policy

D. A vendor contract

2. Which provision set should be consulted first?

A. Section 1 only

B. ss.19-23

C. Section 65 only

D. No statutory provision

3. What should follow identification of the relevant section?

A. Assume compliance

B. Test conditions and exceptions

C. Ignore evidence

D. Use consent automatically

4. Which record best supports accountability?

A. An undocumented opinion

B. A reasoned decision record

C. A verbal assurance

D. A marketing brochure

5. If the sources do not resolve a detail, what should the learner do?

A. Invent a rule

B. State the limitation

C. Cite an unrelated law

D. Ignore the uncertainty

Show model response

Answer key: 1-B, 2-B, 3-B, 4-B, 5-B. Review the lesson citations before marking.

Practical Workplace Task

Prepare a one-page compliance record for a Nigerian organisation applying ss.19-23. Include the processing purpose, actors, data subjects, personal data, statutory test, risks, decision, controls, owner, evidence and review date.

Show model response

Expected deliverable: A dated, approved record that links factual evidence to each applicable statutory condition and records any unresolved issue.

Three Flashcards

Front: Act reference for Day 5? | Back: ss.19-23

Front: Central topic? | Back: Finance, Audit and Review

Front: Best analysis habit? | Back: Facts → role → section → conditions → evidence.

Reread and Progress Record

Reread: ss.19-23; Guide pp.4, 7 and Assessment 1.

Date completed________________Score______%
Strong areas________________Weak areas________________
Recommended revision________________ReadinessDeveloping / Competent / Ready

Cumulative Assessment 1

This checkpoint covers Days 1-5. Answer without consulting the model responses.

Explain and apply one central rule from Day 1, with its section citation and a Nigerian workplace example.

Explain and apply one central rule from Day 2, with its section citation and a Nigerian workplace example.

Explain and apply one central rule from Day 3, with its section citation and a Nigerian workplace example.

Explain and apply one central rule from Day 4, with its section citation and a Nigerian workplace example.

Explain and apply one central rule from Day 5, with its section citation and a Nigerian workplace example.

Show model response

Marking guide: 20 marks per response, allocated to correct section, accurate rule, application, evidence and clear conclusion.