Data Privacy & NDPR Compliance Architecture
1. Executive Summary & Legal Framework
Debelu operates under the jurisdiction of the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR), while maintaining architectural parity with the European Union General Data Protection Regulation (GDPR).
Because Debelu processes personal data belonging to university students, academic staff, and merchants—including National Identification Numbers (NIN), Bank Verification Numbers (BVN), delivery coordinates, and residential dormitories—the platform incorporates a Privacy-by-Design and Privacy-by-Default engineering architecture.
graph TD
subgraph Data Subject Rights (Clients)
DS[Data Subject / User] -->|Request Data Export (DSAR)| EXPORT_API[SubjectPrivacyExportService]
DS -->|Request Account Erasure (RTBF)| PLAN_API[PrivacyErasurePlanService]
end
subgraph Security & Verification Perimeter
MFA{AAL2 Multi-Factor Enforced}
VERIFY[SHA-256 Digest & Nonce Handshake]
end
subgraph Internal Privacy Engines
EXPORT_API --> MFA --> ARTIFACT[PrivacyExportArtifactService]
PLAN_API --> MAKER_CHECKER[PrivacyErasureExecutionService]
end
subgraph Storage & Database Layer
ARTIFACT --> S3[(Encrypted Export Artifact)]
MAKER_CHECKER --> DB_DEL[(7 Erasable Collections)]
MAKER_CHECKER --> STORAGE_DEL[(Version-Pinned Storage Deletion)]
MAKER_CHECKER -.->|Statutory Exemption| RETAIN[(7 Retained Audit & Ledger Sources)]
end2. Personal Identifiable Information (PII) Data Catalog
Debelu maintains a strict data classification matrix mapping all user data attributes to their storage mechanisms, encryption states, and retention schedules:
| PII Category | Fields | Storage Location | Encryption & Protection | Retention Schedule |
|---|---|---|---|---|
| Identity & KYC | Full Name, Student ID / Matriculation No, NIN, BVN Hash | public.profiles, public.vendor_profiles | AES-256 at rest; BVN/NIN never stored raw (cryptographic hash only) | Active Account + 7 Years (Financial Law) |
| Contact Data | Phone Number, Email, Delivery Addresses, Hostel/Room | public.addresses, public.orders | TLS 1.3 in transit; Scoped access via RLS | Erased on approved RTBF request |
| Financial & Payout | NUBAN Bank Account Number, Bank Code, Recipient Code | public.vendor_bank_details, public.payout_requests | Masked in logs (last 4 digits only); TLS 1.3 | Statutory 7 Years (CBN / Tax Regulations) |
| Behavioral & Logs | Search queries, cart items, favorites, session tokens | public.carts, public.favorites, public.search_history | Scoped strictly to User ID via RLS | Purged on RTBF request |
| Media & Avatars | Profile pictures, KYC ID card scans, product images | Supabase Storage (avatars, verification) | Private bucket; signed URLs with 15-minute TTL | Version-pinned deletion on RTBF |
3. Data Subject Access Requests (DSAR) Engine
Under Section 34 of the NDPA 2023, data subjects possess the right to obtain an immutable, machine-readable export of all personal data held by Debelu within 30 calendar days. Debelu automates this via SubjectPrivacyExportService ([debelu-backend/src/services/SubjectPrivacyExportService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/SubjectPrivacyExportService.ts)).
sequenceDiagram
autonumber
actor User as Data Subject
participant API as SubjectPrivacyExportService
participant DB as Postgres Security Definer
participant Client as Storefront Web / Mobile
User->>Client: 1. Request Personal Data Export
Client->>API: 2. GET /api/privacy/exports (requires AAL2)
Note over API: Enforces AAL2 MFA; rejects AAL1 with 403 Forbidden
API->>DB: 3. subject_privacy_exports(subjectId)
DB-->>API: 4. Returns metadata (byteCount, checksumSha256, expiresAt)
User->>Client: 5. Click Download Export
Client->>API: 6. GET /api/privacy/exports/:id/download
API->>DB: 7. download_subject_privacy_export(id)
DB-->>API: 8. Returns payload (JSON/ZIP) + unique nonce
API->>API: 9. Verify Buffer.byteLength === byteCount AND SHA-256 digest
API-->>Client: 10. Deliver artifact stream + nonce
Client->>API: 11. POST /api/privacy/exports/:id/acknowledge (nonce, checksum, bytes)
API->>DB: 12. acknowledge_subject_privacy_export()
DB-->>API: 13. Returns verified_client_download_acknowledgment receipt3.1 Security & Cryptographic Invariants
- Mandatory Step-Up Authentication (AAL2): Export generation and download strictly require
aal === 'aal2'. Sessions authenticated via password only are rejected with403 Forbidden(42501), preventing session hijackers from exfiltrating personal dossiers. - Payload Size Bound: Exports are capped at 10 MB ($10,485,760$ bytes).
- Cryptographic Checksum Verification: Every artifact payload must satisfy: $$\text{crypto.createHash('sha256').update(payload).digest('hex')} === \text{metadata.checksumSha256}$$
- Client Nonce Handshake: Download completion is confirmed only when the client echoes the server-generated UUIDv4
nonceback to the server, generating an immutable audit receipt.
4. Right to Erasure / "Right to be Forgotten" (RTBF) Engine
Under Section 34 of the NDPA 2023, data subjects may demand the permanent erasure of their personal information. Debelu implements a formal Maker-Checker erasure execution pipeline via PrivacyErasureExecutionService ([debelu-backend/src/services/PrivacyErasureExecutionService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/PrivacyErasureExecutionService.ts)).
4.1 The 7 Erasable Collections
When an erasure plan executes under the owned_low_retention_execution_v1 scope, the system completely deletes records across exactly 7 collections:
addresses: Saved physical delivery locations and room numbers.carts: Abandoned and active shopping carts.favorites: Wishlisted products.search_history: Search queries and behavioral tracking.chat_sessions: Private direct message session metadata.chat_messages: Private message body text and attachments.user_sessions: Active refresh tokens and device logins.
4.2 The 7 Statutory Retained Sources
Under Nigerian financial, commercial, and criminal laws, certain records are statutorily exempt from deletion. The erasure manifest explicitly documents and preserves:
financial_orders_payments_ledger_payouts: 7-year statutory retention under CBN financial regulations. Historical order buyer identities are pseudonymized ("Deleted User #<ID>").immutable_audit_approvals_and_privacy_receipts: Proof of legal and regulatory compliance.shared_support_disputes_messages_and_moderation: Historical evidence required for ongoing or future litigation.profiles_auth_and_provider_identities: Retained in deactivated state to prevent ban evasion.notification_workers_and_external_delivery: Transactional notification receipts.backups_and_external_systems: Encrypted disaster recovery snapshots (expiring via automated 30-day lifecycle policies).storage_bytes_deletion_and_unclassified_objects: System audit files.
5. Version-Pinned Storage Deletion Protocol
When a user's uploaded avatar or media is deleted, issuing a naive path deletion (DELETE /avatars/user_123.jpg) introduces a race condition: if the user concurrently re-uploads a new photo, the deletion worker could inadvertently destroy the newly uploaded image.
Debelu prevents this via Version-Pinned Storage Deletion:
// DELETE payload pinned to exact object version ID
const endpoint = new URL(process.env.SUPABASE_URL + '/storage/v1/object/avatars');
const response = await fetch(endpoint, {
method: 'DELETE',
headers: {
Authorization: 'Bearer ' + process.env.SUPABASE_SERVICE_ROLE_KEY,
'Content-Type': 'application/json'
},
body: JSON.stringify({
prefixes: [{ path: claim.path, versionId: claim.version }]
})
});Deletion Verification States
Every storage item tracks five deterministic lifecycle states:
pending: Scheduled for deletion.uncertain: Network timeout occurred; deletion unconfirmed.verifiedAbsent: Storage provider confirmed deletion of the exact object version.unavailable: Storage bucket unreachable.- Scope Erasure Invariant: State
scope_erasedis ONLY granted when $\text{verifiedAbsent} === \text{total}$.
6. Data Breach Response & Notification SLA
In compliance with NDPA Section 40, Debelu maintains an emergency breach containment protocol:
stateDiagram-v2
[*] --> Detection : Breach Detected (SEV-1 Security Incident)
Detection --> Containment : Revoke Compromised Keys & Isolate Subnets (T < 2h)
Containment --> RiskAssessment : Classify Impact & PII Scope (T < 12h)
state RiskAssessment {
[*] --> HighRisk : Financial / Auth Credentials Exposed
[*] --> LowRisk : Pseudonymized Telemetry Only
}
HighRisk --> RegulatorNotice : Formal Notice to NDPC (T < 72h)
RegulatorNotice --> UserNotice : Mandatory Public / User Notification (T < 72h)
LowRisk --> InternalReport : Logged to Internal Compliance Ledger
UserNotice --> PostMortem : Blameless RCA & Corrective Actions
InternalReport --> PostMortem
PostMortem --> [*]Statutory Notification Rules
- Regulator Notification: The Data Protection Officer (DPO) must submit a formal incident report to the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of a confirmed personal data breach.
- User Notification: If the breach is likely to result in high risk to the rights and freedoms of individuals (e.g., exposed passwords, payment credentials, identity documents), affected users must be notified without undue delay via direct email and in-app alerts.