
INTRODUCTION TO CHURCHES AS DATA CONTROLLERS IN NIGERIA
Can I lift up holy hands without being captured by a camera lens? Can I worship freely without my emotional posture broadcast live on YouTube?
These questions capture a profound modern tension, the intersection between religious devotion and digital exposure. In contemporary Nigerian society, religious assemblies are no longer just places of cloistered fellowship, they are aslo multimedia production hubs. Sunday services are livestreamed to global audiences, first-timers submit personal information on physical forms or mobile apps, and CCTV cameras quietly record congregants.
While these technologies facilitate evangelism and church administration, they transform the church from a mere sanctuary into a Data Controller and Data Processor operating within the regulatory framework of the Nigeria Data Protection Act (NDPA) 2023 and Section 37 of the 1999 Constitution of the Federal Republic of Nigeria (CFRN, as amended).
CONCEPTUAL CLARIFICATION BETWEEN CONSTITUTIONAL PRIVACY AND STATUTORY DATA PROTECTION
To appreciate the obligations of churches, a distinction must be drawn between the general right to privacy and the specific regime of data protection,
Section 37 of the 1999 CFRN establishes privacy as a fundamental right, declaring that:
“The privacy of citizens, their homes, correspondence, telephone conversations and telegraphic communications is hereby guaranteed and protected.”
Historically, the debate persisted as to whether this section directly accommodated digital and informational privacy. Nigerian courts, however, have increasingly read Section 37 of the Constitution purposively to obligate churches as data controllers and data processors pursuant to the Nigeria Data Protection Act 2023 protect informational self-determination, affirming that unauthorised meddling with an individual’s personal data strikes at the core of their constitutional dignity as seen in the case of Incorporated Trustees of Digital Rights Lawyers Initiative & Ors v. National Identity Management Commission[1].
The NDPA 2023[2], by contrast, establishes a specialised statutory mechanism governing how personal data is collected, stored, processed, and disseminated. While privacy protects an individual’s physical and mental space from external intrusion, data protection confers operational rights upon the Data Subject to govern the lifecycle of their identifiable information.
CHURCHES AS DATA CONTROLLER AND PROCESSOR
Under Section 65 of the NDPA 2023, a Data Controller is defined as an individual, private entity, or public body that determines the purposes and means of processing personal data. A Data Processor is an entity that processes personal data on behalf of, or under the direction of, a data controller.
Churches routinely satisfy both definitions,as data controllers by deciding to record church service, collect new member forms or maintain registers. And as data processors when media teams or technical crews edit footage, upload media streams online, or manage church administration software.
Crucially, personal data handled within a church context often falls under the category of Sensitive Personal Data under Section 30 of the NDPA 2023, which explicitly encompasses information revealing an individual’s religious beliefs or philosophical affiliations. The law subjects sensitive personal data to a far more stringent processing thresholds than ordinary commercial data.
THE FICTION OF THE PUBLIC SPACE AND THE DOCTRINE OF REASONABLE EXPECTATION
It is often erroneously assumed that because a church service is open to the public, attendees forfeit all privacy and data protection rights.
While the degree of privacy in a public auditorium naturally differs from that within a private home, the legal inquiry hinges on the reasonable expectation of privacy. An individual attending an open service may expect to sit in the congregation without their tearful prayer during a sermon being published on social media as promotional material.
Public presence does not equal an open waiver of statutory rights. Under the NDPA, collection of personal data which in this instance includes the recognisable facial images and live footage must always rest on a recognised lawful base.
THE CONCEPT OF CONSENT FOR CHURCHES AS DATA CONTROLLERS
Pursuant to Section 25 of the NDPA 2023, processing of personal data must be founded on at least one lawful basis. For churches, the most relevant base is
Consent (Section 26 NDPA)
Consent cannot be inferred from mere passive acquiescence. Section 26(3) of the NDPA provides that silence or inactivity does not constitute valid consent. A simple billboard placed at the gate warning congregants that “You may be filmed” does not satisfy the statutory test for express, affirmative consent under the NDPA. Furthermore, under Section 26(5), a data subject retains the right to withdraw consent at any time, requiring the controller to stop processing unless an independent lawful basis persists.
OBLIGATIONS OF CHURCH LEADERSHIP
To remain compliant with both the NDPA 2023 and the spirit of Section 37 of the 1999 CFRN (as amended), religious administrations must implement practical operational compliance measures:
- Adherence to Data Processing Principles (Section 24 NDPA): Data must be collected for explicit, specified, and legitimate purposes (purpose limitation), limited strictly to what is necessary i.e. data minimization, and kept securely and in confidentiality.
- Clear Privacy Notices: Prominently placed, comprehensive privacy notices must explain that services are broadcast, how footage will be used, and where individuals can direct privacy requests or objections.
- Opt-Out & Unfilmed Zones: In line with best practices for legitimate public events, large congregations should designate specific seating areas that are outside camera angles or excluded from livestream coverage for congregants who object to being broadcast.
CONCLUSION churches as data controllers
The right to manifest one’s religion under Section 38 of the 1999 CFRN includes the collective sharing of faith, but it must coexist with the right to privacy under Section 37 and statutory rights under the NDPA 2023. Technology enhances worship and community outreach, but it cannot turn the sanctuary into an arena of unconsented surveillance. By putting structured data policies in place, respecting unfilmed zones, and treating congregants’ data with confidentiality, religious institutions fulfill not only a legal duty to data subjects, but an institutional commitment to the dignity and trust of their members.
[1] (2021) LPELR-55623 (CA)
[2] Nigeria Data Protection Act 2023
churches as data controllers,churches as data controllers
CONTRIBUTORS

Ojienoh Segun Justice, ESQ
LEAD PARTNER, EKO SOLICITORS AND ADVOCATES

Counsel EKO SOLICITORS AND ADVOCATES

Olokun Oreoluwa Joseph
INTERN, EKO SOLICITORS AND ADVOCATES
