Data Compliance
Last updated: 1 July 2026
OceanX Ltd is committed to full compliance with the Nigeria Data Protection Act 2023 (NDPA) and all applicable data protection regulations. This page explains our compliance framework and your rights as a data subject.
1. Overview
OceanX Ltd is a Nigerian technology company operating in the maritime sector. We take our data protection obligations seriously and are committed to full compliance with applicable Nigerian and international data protection frameworks.
This page describes the regulatory frameworks we comply with, how we implement those requirements, and how you can exercise your rights as a data subject. For full details of how we collect and use personal data, please read our Privacy Policy.
2. Applicable Regulations
OceanX Ltd operates under the following data protection frameworks:
Nigeria Data Protection Act 2023 (NDPA) The primary data protection law in Nigeria. The NDPA governs how organisations collect, process, store, and transfer personal data of Nigerian residents. It is administered by the Nigeria Data Protection Commission (NDPC).
Nigeria Data Protection Regulation 2019 (NDPR) The predecessor regulation to the NDPA, issued by the National Information Technology Development Agency (NITDA). We continue to align with NDPR principles as required.
General Data Protection Regulation (GDPR) Where we process data of individuals located in the European Economic Area (EEA), we comply with the GDPR as applicable.
IMO Maritime Data Standards We align our vessel and certificate data handling with guidelines issued by the International Maritime Organization (IMO) relating to maritime data governance.
3. Lawful Basis for Processing
Under the NDPA 2023, we process personal data only where we have a lawful basis to do so. The lawful bases we rely on include:
- •Contract: Processing necessary to provide services you have requested or to fulfil a contract with you
- •Legitimate Interests: Processing necessary for our legitimate business interests, where these do not override your rights and freedoms
- •Legal Obligation: Processing required to comply with Nigerian law or maritime regulatory requirements (NIMASA, NPA, IMO)
- •Consent: Where we rely on consent, we obtain it clearly and you may withdraw it at any time by contacting legal@oceanx-ltd.com
4. Data Subject Rights
Under the NDPA 2023, you have the following rights in respect of your personal data:
- •Right of Access: Request a copy of the personal data we hold about you
- •Right to Rectification: Request correction of inaccurate or incomplete data
- •Right to Erasure: Request deletion of your personal data where there is no compelling legal basis for continued processing
- •Right to Restrict Processing: Request that we limit how we use your data in certain circumstances
- •Right to Data Portability: Request your data in a structured, machine-readable format
- •Right to Object: Object to processing based on legitimate interests, including direct marketing
- •Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time
- •Right to Lodge a Complaint: Complain to the Nigeria Data Protection Commission if you believe your rights have been violated
To exercise any of these rights, contact us at legal@oceanx-ltd.com. We will respond within 30 days.
5. Data Transfers
OceanX Ltd stores data on cloud infrastructure provided by Supabase (hosted on AWS). Data may be processed in data centres outside Nigeria. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
- •Standard contractual clauses with data processors
- •Transfers only to jurisdictions with adequate data protection standards
- •Contractual obligations on processors to maintain security and confidentiality
We do not sell or transfer personal data to third parties for their own commercial purposes.
6. Data Protection by Design
OceanX Ltd implements data protection by design and by default across all our platforms:
- •Minimisation: We collect only the data necessary for the specific purpose
- •Access Controls: Role-based access ensures only authorised personnel can access personal data
- •Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- •Pseudonymisation: Where feasible, we separate identifying information from operational data
- •Audit Logs: All access to personal data is logged for accountability
- •Retention Limits: Data is deleted or anonymised as soon as it is no longer needed for its stated purpose
7. Data Breach Response
In the event of a personal data breach, OceanX Ltd will:
- •Contain the breach and assess the risk to data subjects as quickly as possible
- •Notify the Nigeria Data Protection Commission within 72 hours of becoming aware of the breach, where required under the NDPA 2023
- •Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- •Document the breach, its effects, and the remedial actions taken
- •Review and update our security measures to prevent recurrence
To report a suspected breach or security vulnerability, contact: legal@oceanx-ltd.com
8. Data Protection Officer
OceanX Ltd has designated a point of contact for all data protection matters. If you have any questions, concerns, or requests relating to how we handle your personal data, please contact:
Data Protection Contact Email: legal@oceanx-ltd.com Organisation: OceanX Ltd, Lagos, Nigeria
We take all data protection enquiries seriously and will respond within 30 business days.
9. Third-Party Processors
We engage the following categories of third-party data processors, all of whom are contractually bound to process data only on our instructions and to maintain appropriate security:
- •Cloud Infrastructure: Supabase (database and storage), hosted on AWS
- •Email Delivery: Resend (transactional emails and notifications)
- •Analytics: Where used, analytics providers process usage data in aggregated or pseudonymised form only
We conduct due diligence on all processors before engagement and review these relationships periodically.
10. Regulatory Authority
The supervisory authority for data protection in Nigeria is the Nigeria Data Protection Commission (NDPC). If you are unsatisfied with how we have handled your personal data, you have the right to lodge a complaint with the NDPC:
Nigeria Data Protection Commission Tel: +234 (0) 916 061 5551 Email: info@ndpc.gov.ng Website: https://ndpc.gov.ng
Where you remain dissatisfied after raising a concern with the NDPC, you reserve the right to pursue other legal remedies available under Nigerian law.
11. Updates to This Page
We review and update our data compliance documentation regularly to reflect changes in applicable law, our business practices, and regulatory guidance. Material changes will be communicated via our website and, where appropriate, by email.
Last updated: 1 July 2026
Data protection enquiries
Contact our data protection team for any questions about how we handle your personal data.