The African Association of Compliance Professionals in Financial Services (AACPFS) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store and share personal data when you visit https://aacpfs.org, apply for membership, make a payment, attend an event or use any of our services.

1. About AACPFS

The data controller responsible for your personal data is:

African Association of Compliance Professionals in Financial Services (AACPFS)

This Policy is governed by the Nigeria Data Protection Act 2023, the NDP Act General Application and Implementation Directive 2025 and other applicable data-protection laws.

2. Personal Data We Collect

Depending on how you interact with AACPFS, we may collect:

  • Your name, title, date of birth, nationality, country and contact details;
  • Employment, professional, educational and membership information;
  • Information submitted in membership, student or corporate applications;
  • Identification or supporting documents required to verify eligibility;
  • Account details, login information and membership number;
  • Payment amounts, transaction references, invoices and refund records;
  • Seminar, training, webinar and event registration or attendance records;
  • Messages, enquiries, complaints, survey responses and feedback;
  • Profile photographs and information you choose to publish in a member directory;
  • Website usage information, including IP address, browser, device and cookie data; and
  • Any other information you voluntarily provide.

We will only collect sensitive personal data where it is necessary, lawful and appropriately protected.

3. How We Collect Personal Data

We may collect personal data:

  • Directly from you through forms, applications, payments and communications;
  • Automatically when you use our website;
  • From your employer, institution or authorised representative;
  • From payment processors and other service providers; and
  • From publicly available or lawful professional sources where verification is necessary.

4. How We Use Personal Data

We may use your personal data to:

  • Review, approve or reject membership applications;
  • Verify eligibility and supporting documents;
  • Create and manage accounts, profiles and membership numbers;
  • Administer subscriptions, renewals, payments, invoices and refunds;
  • Register you for seminars, training programmes, webinars and events;
  • Provide member benefits, resources and professional services;
  • Send service notices, renewal reminders and important Association updates;
  • Respond to enquiries, complaints and support requests;
  • Maintain the security of our website and prevent fraud or misuse;
  • Conduct surveys, analyse website performance and improve our services;
  • Send marketing communications where you have consented or where otherwise permitted by law;
  • Maintain financial, membership and regulatory records; and
  • Comply with legal, regulatory and contractual obligations.

Membership applications are reviewed by authorised personnel and are not intended to be decided solely through automated processing.

5. Lawful Bases for Processing

AACPFS processes personal data where:

  • You have given consent;
  • Processing is necessary to provide a membership, event, training or other service you requested;
  • Processing is necessary to comply with a legal obligation;
  • Processing is necessary to protect a person’s vital interests;
  • Processing is necessary for a legitimate interest of AACPFS or another party, provided that your rights do not override that interest; or
  • Another lawful basis applies under applicable law.

You may withdraw consent at any time. Withdrawal will not affect processing lawfully carried out before consent was withdrawn.

6. Payments

Online payments may be processed by Flutterwave or another authorised payment provider.

Payment-card information entered through the payment provider’s interface is processed in accordance with that provider’s privacy and security practices. AACPFS does not ordinarily receive or store complete card numbers or card security codes.

We may retain payment confirmations, transaction references, invoice details and refund records for accounting, membership administration, fraud prevention and legal compliance.

7. Sharing Personal Data

We may share personal data, where necessary, with:

  • Payment processors, including Flutterwave;
  • Website hosting, information technology and cybersecurity providers;
  • Email, communication and membership-management service providers;
  • Webinar, training, event and learning-platform providers;
  • Professional advisers, auditors and insurers;
  • Regulators, courts, law-enforcement authorities or public bodies where legally required;
  • Partner institutions where necessary to deliver a programme or service; and
  • Other parties where you have authorised the disclosure.

Our service providers are expected to use personal data only for authorised purposes and to apply appropriate confidentiality and security safeguards.

AACPFS does not sell personal data.

Where you voluntarily agree to appear in a public member directory, participate as a speaker or authorise publication, selected profile information may be displayed publicly.

8. International Data Transfers

Because AACPFS is a pan-African association and may use international technology providers, personal data may be processed outside Nigeria.

Where this occurs, we will take reasonable steps to ensure that the transfer is lawful and that appropriate safeguards are in place, including adequate data-protection laws, contractual protections or another legally permitted transfer mechanism.

9. Data Retention

We retain personal data only for as long as reasonably necessary to fulfil the purposes for which it was collected.

The retention period will depend on:

  • The duration of your membership or relationship with AACPFS;
  • Legal, accounting and regulatory requirements;
  • The need to resolve complaints or disputes;
  • Fraud-prevention and security requirements; and
  • The nature and sensitivity of the data.

When personal data is no longer required, it will be securely deleted, anonymised or otherwise disposed of, unless continued retention is required by law.

10. Data Security

AACPFS uses reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure.

These measures may include access controls, encryption, secure hosting, backups, security monitoring and restrictions on the persons authorised to process personal data.

Where a personal-data breach occurs, AACPFS will investigate and notify the Nigeria Data Protection Commission and affected individuals where required by law.

11. Cookies

Our website uses cookies and similar technologies to:

  • Enable essential website and account functions;
  • Remember preferences and language settings;
  • Maintain security;
  • Understand website usage; and
  • Improve website performance and services.

Non-essential cookies will be used only with your consent where required.

Manage Your Cookies

For more information about the cookies we use, please read our Cookie Policy.

12. Marketing Communications

Where permitted, AACPFS may send information about membership, events, training, publications and related programmes.

You may unsubscribe at any time by:

  • Clicking the unsubscribe link in an email;
  • Changing your communication preferences where available; or
  • Contacting info@aacpfs.org.

You may continue to receive essential membership, payment, security and administrative communications after opting out of marketing.

13. Children’s Personal Data

AACPFS services are generally intended for adults and eligible students.

Where personal data relating to a person who cannot legally provide valid consent is collected, AACPFS may require consent or authorisation from a parent or legal guardian.

A parent or guardian who believes that a child’s personal data has been submitted without proper authorisation should contact us.

14. Your Data-Protection Rights

Subject to applicable law, you may have the right to:

  • Request access to your personal data;
  • Obtain a copy of your personal data;
  • Correct inaccurate or incomplete data;
  • Request deletion of personal data;
  • Restrict certain processing;
  • Object to processing, including direct marketing;
  • Withdraw consent;
  • Request transfer of your data in an appropriate electronic format;
  • Challenge significant decisions made solely through automated processing; and
  • Lodge a complaint with the Nigeria Data Protection Commission.

These rights may be subject to lawful limitations, including legal record-keeping obligations.

To exercise a right, contact info@aacpfs.org. We may request information necessary to verify your identity before acting on the request.

15. External Links

Our website may contain links to websites operated by third parties. AACPFS is not responsible for the privacy practices of those websites. You should review their privacy policies before providing personal data.

16. Changes to This Policy

AACPFS may update this Privacy Policy to reflect changes in its services, technology or legal obligations.

The revised Policy will be published on this page with an updated date. Material changes may also be communicated by email or through the member portal.

17. Language Versions

This Privacy Policy may be provided in English, French and Portuguese.

Where there is an inconsistency between translated versions, the English version will prevail, except where applicable law requires otherwise.

18. Contact and Complaints

For privacy questions, complaints or requests, contact:

African Association of Compliance Professionals in Financial Services (AACPFS)
Email: info@aacpfs.org
Website: https://aacpfs.org

You may also lodge a complaint with the Nigeria Data Protection Commission where you believe your personal data has been processed unlawfully.