Data Compliance Framework
NDPA 2023 · NDPC GAID 2025 · ISO/IEC 27001 Alignment · Last Updated: October 2026
1. Statutory Authority & Governance Scope
ESERIA Systems Ltd. operates under strict compliance with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Commission (NDPC) General Application and Implementation Directive (GAID) 2025. This framework governs every digital jurisdiction across our global infrastructure:
- eseria.org (Enterprise Systems Architecture & Sovereign Infrastructure)
- citadel.eseria.org (Citadel Vanguard Flight Simulator & 21-Day Incident Gauntlet)
- uncaved.eseria.org (UNCAVED Verified Talent Ledger & Proof-of-Work Portfolios)
- institute.eseria.org (The Institute Executive Advisory & Corporate Training)
2. Dual-Role Classification: Controller vs. Processor
In compliance with NDPA Section 24, ESERIA strictly partitions its legal duties based on systemic context:
Citadel Vanguard & Fellow Accounts
ESERIA determines processing purposes for Fellow identity, authentication tokens, ƩC token transactions, and Proof-of-Work verifications published onto UNCAVED profiles.
Enterprise Client Pipelines
When institutions use ESERIA data engines or private cohort sandboxes to evaluate proprietary datasets, the client retains full Controllership. ESERIA acts strictly as a Processor under binding Data Protection Agreements (DPAs).
3. Data Subject Access Request (DSAR) Protocol
Every individual whose personal data is processed within the ESERIA network possesses unambiguous statutory rights under NDPA Part VI:
- Right to Confirmation & Access: Fellows may request full disclosure of all processed personal records, telemetry logs, and simulation scores.
- Right to Rectification: Inaccuracies in profile metadata or account details can be updated via the terminal profile or upon written notice.
- Right to Erasure ("Right to be Forgotten"): Account holders may request irreversible deletion of their personal identity, terminating access and expunging records, except where statutory financial records require retention.
- Right to Data Portability: Users may request a structured, machine-readable JSON archive of their UNCAVED deliverables, Git commits, and historical performance metrics.
4. Cryptographic Proof of Work & Talent Anonymization
A core pillar of the ESERIA ecosystem is the verification of technical competence without compromising privacy:
- Cryptographic Hashes: Node solutions, code commits, and simulation timestamps are validated using SHA-256 hashes to guarantee provenance without exposing raw personal identifiers to unauthorized third parties.
- Public Talent Ledger Discretion: Fellows maintain total sovereignty over what appears on UNCAVED. Public visibility can be toggled between Public, Anonymized Stealth (skill metrics visible to vetted enterprise recruiters with identity hidden), or Private.
5. Cross-Border Transfers & Sub-Processor Architecture
ESERIA Systems Ltd. leverages high-availability Tier-1 global infrastructure to deliver millisecond-latency WASM sandboxes and multi-agent coordination. All international transfers are compliant with NDPA Section 41–43 and protected under Standard Contractual Clauses (SCCs):
| Sub-Processor | Jurisdiction | Function | Safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | EU / US | Primary DB Hosting, S3 Vaults | AES-256 Encryption at rest, ISO 27001 |
| Google Cloud / Firebase | Global Edge | Edge CDN, Identity State | SOC 2 Type II, TLS 1.3 in transit |
| Paystack / Licensed Gateways | Nigeria / Global | Fiat Billing & Subscriptions | PCI-DSS Level 1, CBN Licensed |
6. Annual Compliance Audit Returns (CAR)
In alignment with NDPC directives, ESERIA engages certified Data Protection Compliance Organizations (DPCO) to perform annual external audits. These audits verify:
- End-to-end data minimization across Next.js and Django REST frameworks.
- Zero exposure of student code or enterprise data to external foundational AI training loops.
- Rigorous backup integrity and 72-hour incident response readiness.
7. Data Protection Officer (DPO) Contact
For compliance verifications, institutional DPAs, or regulatory inquiries, contact our Data Protection Officer:
Office: Office of the Data Protection Officer
Entity: ESERIA Systems Ltd.
Direct Dispatch: dpo@eseria.org
Physical Architecture: Kubwa, Federal Capital Territory, Nigeria