Beyond Compliance: Why Organisational Accountability is Critical for Consumer Protection

The announcement of a two-year data protection initiative between the Nigeria Data Protection Commission (NDPC) and Meta has sparked important conversations about accountability, consumer protection, and the role organisations play in building trust within the digital economy.
While data protection is often discussed as a regulatory or compliance issue, its impact is much broader. At its core, effective data protection is about safeguarding people. It helps protect consumers from fraud, identity theft, scams, manipulation, and the misuse of personal information.
As organisations increasingly collect, process, and store large amounts of personal data, accountability becomes more than a legal obligation. It becomes a business responsibility and a societal expectation.
Why Accountability Matters
Modern scams and cyber-enabled fraud often rely on access to personal information. Criminals exploit leaked, poorly protected, or improperly shared data to conduct phishing attacks, impersonation scams, account takeovers, and financial fraud.
When organisations implement strong privacy and security practices, they reduce opportunities for cybercriminals to exploit consumers.
Accountability means organisations:
- Understand what data they collect and why.
- Minimise unnecessary collection of personal information.
- Protect data through appropriate security controls.
- Respond quickly to incidents and breaches.
- Educate users on digital safety risks.
- Continuously assess and improve their privacy practices.
- Training programmes can develop lasting expertise.
- Public awareness campaigns can reach millions of users.
- Research initiatives can inform future policy decisions.
- Capacity-building efforts can strengthen institutions and organisations.
- Establish clear performance indicators and success metrics.
- Publish periodic progress reports.
- Measure actual improvements in consumer awareness and protection.
- Maintain consistent enforcement standards across the ecosystem.
- Treat privacy as a business responsibility, not merely a compliance exercise.
- Integrate cybersecurity and data protection programmes.
- Conduct regular risk assessments.
- Invest in employee awareness and training.
- Adopt privacy-by-design principles in products and services.
- Understand personal data rights.
- Verify requests for sensitive information.
- Enable multi-factor authentication where available.
- Remain cautious of unsolicited messages and offers.
- Report suspected scams promptly.
These actions create safer digital environments and help build public trust.
The Link Between Data Protection and Scam Prevention
Consumer protection and cybersecurity are increasingly interconnected.
Many scams begin with information that has been exposed, mismanaged, or obtained through weak security controls. Personal data can be used to create convincing fraudulent messages that appear legitimate and trustworthy.
Strong data governance reduces this risk by limiting the amount of information available to malicious actors.
Initiatives focused on public awareness are equally important. Technology alone cannot eliminate scams. Consumers who understand how to identify phishing attempts, fake investment schemes, impersonation attacks, and social engineering tactics are better equipped to protect themselves.
This is why capacity building, public education, and ecosystem-wide awareness programmes are often among the most effective long-term investments in consumer protection.
Positive Outcomes of the NDPC-Meta Initiative
Several aspects of the initiative have the potential to deliver meaningful benefits.
1. Increased Public Awareness
One of the most effective defences against scams is an informed public. Educational campaigns can help individuals understand how their data is used, how to exercise their privacy rights, and how to recognise online threats.
Greater awareness often leads to safer online behaviour and reduced susceptibility to fraud.
2. Improved Professional Capacity
The initiative includes training and capacity-building programmes for data protection professionals and compliance organisations.
A stronger community of privacy practitioners contributes to better implementation of data protection requirements across industries. Over time, this can improve overall cybersecurity maturity and organisational resilience.
3. Better Governance and Research
Investments in research and governance frameworks help organisations make evidence-based decisions regarding privacy and security risks.
Research can identify emerging threats, consumer concerns, and gaps in existing protections, allowing regulators and organisations to respond more effectively.
4. Stronger Digital Trust
Trust is a foundational element of digital transformation.
Consumers are more likely to engage with digital services when they believe their personal information is being handled responsibly. Increased trust can support innovation, financial inclusion, and growth within the digital economy.
5. Ecosystem-Wide Benefits
Data protection is not solely the responsibility of regulators or technology companies.
By encouraging collaboration among regulators, industry participants, compliance professionals, educators, and consumers, initiatives like this can contribute to a more secure and resilient digital ecosystem.
The Policy Question: Settlement Versus Financial Penalties
An important discussion arising from this initiative concerns the decision to pursue a programme of activities rather than relying solely on financial penalties.
This issue deserves careful consideration because both approaches have strengths and limitations.
Potential Advantages of the Settlement Approach
A structured programme can create long-term benefits that extend beyond a one-time financial payment.
For example:
From a public interest perspective, these outcomes may provide ongoing value over several years rather than a single financial transfer.
The approach also encourages constructive engagement and may lead to sustained improvements in privacy practices.
Potential Drawbacks and Concerns
At the same time, some observers may question whether the absence of a direct financial penalty could weaken perceptions of accountability.
Several concerns are worth considering:
1. Perception of Reduced Deterrence
Financial penalties often serve as a visible reminder that compliance failures carry consequences.
When organisations are allowed to resolve matters through alternative arrangements, stakeholders may wonder whether the deterrent effect is reduced.
2. Difficulty Measuring Impact
A financial penalty is relatively straightforward to quantify.
By contrast, educational campaigns and capacity-building programmes can be more difficult to evaluate. Their success depends on effective implementation, transparency, and measurable outcomes.
3. Public Expectations
Consumers may expect enforcement actions to result in clear consequences when regulatory concerns arise.
Maintaining public confidence requires clear communication about why a particular approach was chosen and how it delivers value to society.
4. Risk of Precedent
Regulators must carefully ensure that alternative settlements do not create expectations that similar outcomes will be available in all future cases.
Each regulatory matter should be assessed based on its specific facts, risks, and public interest considerations.
The Bigger Picture
The most important question is not whether a financial penalty or a development programme is inherently better.
The real question is whether the chosen approach produces measurable improvements in consumer protection, privacy outcomes, and digital safety.
If the initiative successfully increases awareness, improves organisational practices, strengthens professional capacity, and reduces consumer exposure to scams and cyber risks, it could represent a meaningful contribution to Nigeria's evolving digital ecosystem.
However, achieving these outcomes will require transparency, measurable objectives, independent evaluation, and regular reporting on progress.
Case Study: How Industry Action Can Reduce Consumer Harm
A useful example comes from the GSMA's anti-scam use case library, which documents how organisations are using technology, governance, and collaboration to protect consumers from fraud.
In one case study, South Korean mobile operator LG Uplus implemented an on-device artificial intelligence solution designed to detect voice phishing (vishing) scams and synthetic voice impersonation during live phone calls. The system was trained using anonymised fraud data obtained through collaboration with relevant authorities and was designed to provide real-time warnings to users when suspicious activity was detected. According to the GSMA, the solution achieved a reported detection accuracy of approximately 95 per cent and generated thousands of scam detections each month.
The significance of this example is not the technology alone. Rather, it demonstrates how organisations can move beyond compliance and take proactive responsibility for protecting consumers. Instead of waiting for fraud to occur and then responding, the organisation invested in prevention, awareness, and user protection at the point where consumers were most vulnerable.
The broader lesson is that when organisations treat consumer protection as a shared responsibility, they can significantly reduce the success rate of scams. Strong governance, privacy safeguards, threat intelligence, and consumer education work best when combined into a coordinated approach rather than being treated as separate initiatives.
The GSMA has highlighted similar examples globally, including network-based anti-scam systems, SIM-swap fraud prevention measures, and cross-industry fraud intelligence sharing programmes that help identify and disrupt criminal activity before consumers suffer financial loss.
Recommendations
To maximise the value of initiatives like this, several principles should guide implementation.
For Regulators
- Establish clear performance indicators and success metrics.
- Publish periodic progress reports.
- Measure actual improvements in consumer awareness and protection.
- Maintain consistent enforcement standards across the ecosystem.
- Treat privacy as a business responsibility, not merely a compliance exercise.
- Integrate cybersecurity and data protection programmes.
- Conduct regular risk assessments.
- Invest in employee awareness and training.
- Adopt privacy-by-design principles in products and services.
- Understand personal data rights.
- Verify requests for sensitive information.
- Enable multi-factor authentication where available.
- Remain cautious of unsolicited messages and offers.
- Report suspected scams promptly.
For Organisations
- Treat privacy as a business responsibility, not merely a compliance exercise.
- Integrate cybersecurity and data protection programmes.
- Conduct regular risk assessments.
- Invest in employee awareness and training.
- Adopt privacy-by-design principles in products and services.
For Consumers
- Understand personal data rights.
- Verify requests for sensitive information.
- Enable multi-factor authentication where available.
- Remain cautious of unsolicited messages and offers.
- Report suspected scams promptly.
Conclusion
Data protection is ultimately about protecting people.
Effective accountability frameworks help create environments where organisations manage personal information responsibly, consumers are better protected from scams and fraud, and trust in digital services can grow.
The NDPC-Meta initiative presents an opportunity to demonstrate how collaboration, education, governance, and accountability can work together to strengthen consumer protection. Its long-term success will depend on measurable outcomes that improve privacy, security, and trust for the individuals it is intended to serve.
About the Author
Patricia Eromosele is Director of the Africa Chapter at the Global Anti-Scam Alliance. She has more than 18 years of experience across IT, project management and software engineering, including a decade specialising in cybersecurity, information security, governance, risk and compliance.
Latest blogs & research
Beyond Compliance: Why Organisational Accountability is Critical for Consumer Protection
How the NDPC-Meta initiative could strengthen data protection, organisational accountability, scam prevention and consumer trust across Nigeria’s digital economy.
Policy Blind Spots in Cyber-Enabled Investment | GASA Africa
GASA Africa Chapter explores cyber risks, investor protection, and policy gaps in digital investment ecosystems.
League of Protectors: Women Fighting Against Scams
Explore key insights from our International Women’s Month webinar on combating scams. Discover how women leaders are driving cross-border collaboration, digital literacy, and collective action to protect communities from fraud.
GASA Launches Africa Chapter to Strengthen Regional Scam Prevention
GASA is launching its Africa Chapter, creating a dedicated platform for public and private sector collaboration across the continent.
Nigeria’s EU High-Risk Delisting and the Importance of Sustained AML Enforcement
Nigeria has been removed from the EU’s high-risk AML list following its exit from the FATF grey list, changing how EU-regulated entities assess Nigeria-linked transactions.