Insights

Automated Decision-Making Under the NDPA: Navigating the Line Between Automation and Regulation

5 min read

The rapid integration of artificial intelligence, algorithms, and automated workflows across corporate operations raises a critical compliance question under the Nigeria Data Protection Act 2023 (NDPA): When does standard corporate automation trigger Section 37 regulation?

Legal Context

Section 37 guarantees data subjects the right not to be subjected to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. However, not every operational script, algorithm, or execution tool falls under this statutory restriction. To avoid regulatory overreach and operational paralysis, organisations must distinguish between regulated individual determinations and non-regulated automated executions.

1. The Statutory Threshold: A Three-Part Cumulative Test

To determine whether an automated process falls under Section 37, organisations must evaluate three cumulative statutory elements:

(a)    A Decision: A definitive outcome or determination regarding a data subject.

(b)   Solely Automated Basis: Processing conducted without meaningful human oversight or evaluation of personal data (including profiling).

(c)    Legal or Similarly Significant Effects: An impact that alters an individual's legal status, rights, or materially impacts their financial, contractual, or personal position.

Where any element is absent, Section 37 is not engaged.

2. Statutory Exceptions & Operational Flexibility

The NDPA does not impose an absolute prohibition on solely automated decision-making. Section 37(2) recognises circumstances in which a data subject may be subjected to such a decision, including where the decision is necessary for entering into or performing a contract between the data subject and the data controller, where the decision is authorised by written law applicable to the controller or processor and that law provides appropriate safeguards for the data subject’s rights and interests, or where the decision is based on the data subject’s explicit consent. These exceptions are important because they demonstrate that the NDPA’s objective is not to prevent businesses from using automated systems, but to regulate the circumstances in which automation is used to produce significant effects for individuals and to ensure that appropriate safeguards accompany such processing.

3. Corporate Business Strategy vs Individual Determinations

We take the view that a genuine business decision is different from an automated individual decision. For instance, if a technology company decides to withdraw operations from a country, this is a corporate/business decision. The decision is made by the company’s directors, management or other authorised decision-makers based on commercial considerations such as, profitability, regulatory environment; market conditions, strategic priorities; capital allocation; risk; competition; or corporate restructuring.

Additionally, even though a company may subsequently use software to implement the decision, the fact that the final administrative action is performed automatically does not, by itself, transform the underlying corporate decision into a Section 37 automated decision. The critical distinction is that the system is implementing a decision that has already been made at the organisational level as opposed to evaluating users on an individual level and deciding which user should lose access based on that user’s personal data.

4. Decoupling Execution from Automated Decision-making

We take the view that automation of execution is not necessarily automation of decision making within the context of section 37 of the NDPA. This distinction is particularly important in technology businesses. A company may make a valid human decision and then automate its implementation. For example, management approves termination of a product and then implements software to disable the product for all users. In our view, these processes should not automatically be characterised as Section 37 decisions merely because the execution is automated. The relevant question should be whether or not the automated system itself determines the individual’s legal or similarly significant outcome based on personal data? If the answer is no, Section 37 may not be engaged.

5. Profiling vs. Section 37 Decisions 

The NDPA expressly refers to decisions based on automated processing, including profiling. But profiling and automated decision-making should not be treated as synonymous. A company can profile customers without necessarily making a Section 37 decision. For example, an e-commerce platform might analyse a customer’s browsing history to determine which products to display. That is automated processing and may involve profiling. But if the resulting recommendation does not produce a legal or similarly significant effect, it is not necessarily the type of automated decision contemplated by Section 37.

Strategic Takeaways for Business Leaders & Data Protection Officers

The NDPA does not prohibit automation. Rather, it regulates certain consequential automated determinations about people. A company should not have to put a human in the loop merely because a computer is executing a decision. In our view, the key legal threshold to test is: Did the computer decide something significant about this particular person using that person’s personal data? If the answer is no, the company may simply be automating a business or administrative process. If the answer is yes, the company should carefully assess Section 37, the applicable exceptions and the safeguards required by the NDPA. This distinction is important because modern businesses routinely use automated systems for administration, logistics, fraud monitoring, pricing, communications, customer service and account management. The mere fact that software executes an action does not necessarily mean that an automated decision has been made within Section 37.

 


This publication is provided Balogun Harold for general informational purposes only and does not constitute legal advice. Specific circumstances may require tailored legal analysis. For consultation requests, please reach out to your usual Balogun Harold contact or via support@balogunharold.com

Olu A.

Olu A.

LL.B. (UNILAG), B.L. (Nigeria), LL.M. (UNILAG), LL.M. (Reading, U.K.)

Olu is a Partner in the Firm’s Transactions & Policy Practice. Admitted as a Barrister & Solicitor of the Supreme Court of Nigeria in 2009, he has spent over a decade advising clients on high-value transactions and policy matters at some of Nigeria’s leading law firms.

olu@balogunharold.com
Esther O.

Esther O.

LL.B. (OOU), B.L. (Nigeria)

Esther is a Legal Analyst at Balogun Harold.