Skip to content

Data Privacy & NDPR Compliance Architecture ​


Debelu operates under the jurisdiction of the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR), while maintaining architectural parity with the European Union General Data Protection Regulation (GDPR).

Because Debelu processes personal data belonging to university students, academic staff, and merchants—including National Identification Numbers (NIN), Bank Verification Numbers (BVN), delivery coordinates, and residential dormitories—the platform incorporates a Privacy-by-Design and Privacy-by-Default engineering architecture.

mermaid
graph TD
    subgraph Data Subject Rights (Clients)
        DS[Data Subject / User] -->|Request Data Export (DSAR)| EXPORT_API[SubjectPrivacyExportService]
        DS -->|Request Account Erasure (RTBF)| PLAN_API[PrivacyErasurePlanService]
    end

    subgraph Security & Verification Perimeter
        MFA{AAL2 Multi-Factor Enforced}
        VERIFY[SHA-256 Digest & Nonce Handshake]
    end

    subgraph Internal Privacy Engines
        EXPORT_API --> MFA --> ARTIFACT[PrivacyExportArtifactService]
        PLAN_API --> MAKER_CHECKER[PrivacyErasureExecutionService]
    end

    subgraph Storage & Database Layer
        ARTIFACT --> S3[(Encrypted Export Artifact)]
        MAKER_CHECKER --> DB_DEL[(7 Erasable Collections)]
        MAKER_CHECKER --> STORAGE_DEL[(Version-Pinned Storage Deletion)]
        MAKER_CHECKER -.->|Statutory Exemption| RETAIN[(7 Retained Audit & Ledger Sources)]
    end

2. Personal Identifiable Information (PII) Data Catalog ​

Debelu maintains a strict data classification matrix mapping all user data attributes to their storage mechanisms, encryption states, and retention schedules:

PII CategoryFieldsStorage LocationEncryption & ProtectionRetention Schedule
Identity & KYCFull Name, Student ID / Matriculation No, NIN, BVN Hashpublic.profiles, public.vendor_profilesAES-256 at rest; BVN/NIN never stored raw (cryptographic hash only)Active Account + 7 Years (Financial Law)
Contact DataPhone Number, Email, Delivery Addresses, Hostel/Roompublic.addresses, public.ordersTLS 1.3 in transit; Scoped access via RLSErased on approved RTBF request
Financial & PayoutNUBAN Bank Account Number, Bank Code, Recipient Codepublic.vendor_bank_details, public.payout_requestsMasked in logs (last 4 digits only); TLS 1.3Statutory 7 Years (CBN / Tax Regulations)
Behavioral & LogsSearch queries, cart items, favorites, session tokenspublic.carts, public.favorites, public.search_historyScoped strictly to User ID via RLSPurged on RTBF request
Media & AvatarsProfile pictures, KYC ID card scans, product imagesSupabase Storage (avatars, verification)Private bucket; signed URLs with 15-minute TTLVersion-pinned deletion on RTBF

3. Data Subject Access Requests (DSAR) Engine ​

Under Section 34 of the NDPA 2023, data subjects possess the right to obtain an immutable, machine-readable export of all personal data held by Debelu within 30 calendar days. Debelu automates this via SubjectPrivacyExportService ([debelu-backend/src/services/SubjectPrivacyExportService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/SubjectPrivacyExportService.ts)).

mermaid
sequenceDiagram
    autonumber
    actor User as Data Subject
    participant API as SubjectPrivacyExportService
    participant DB as Postgres Security Definer
    participant Client as Storefront Web / Mobile

    User->>Client: 1. Request Personal Data Export
    Client->>API: 2. GET /api/privacy/exports (requires AAL2)
    Note over API: Enforces AAL2 MFA; rejects AAL1 with 403 Forbidden
    API->>DB: 3. subject_privacy_exports(subjectId)
    DB-->>API: 4. Returns metadata (byteCount, checksumSha256, expiresAt)
    User->>Client: 5. Click Download Export
    Client->>API: 6. GET /api/privacy/exports/:id/download
    API->>DB: 7. download_subject_privacy_export(id)
    DB-->>API: 8. Returns payload (JSON/ZIP) + unique nonce
    API->>API: 9. Verify Buffer.byteLength === byteCount AND SHA-256 digest
    API-->>Client: 10. Deliver artifact stream + nonce
    Client->>API: 11. POST /api/privacy/exports/:id/acknowledge (nonce, checksum, bytes)
    API->>DB: 12. acknowledge_subject_privacy_export()
    DB-->>API: 13. Returns verified_client_download_acknowledgment receipt

3.1 Security & Cryptographic Invariants ​

  1. Mandatory Step-Up Authentication (AAL2): Export generation and download strictly require aal === 'aal2'. Sessions authenticated via password only are rejected with 403 Forbidden (42501), preventing session hijackers from exfiltrating personal dossiers.
  2. Payload Size Bound: Exports are capped at 10 MB ($10,485,760$ bytes).
  3. Cryptographic Checksum Verification: Every artifact payload must satisfy: $$\text{crypto.createHash('sha256').update(payload).digest('hex')} === \text{metadata.checksumSha256}$$
  4. Client Nonce Handshake: Download completion is confirmed only when the client echoes the server-generated UUIDv4 nonce back to the server, generating an immutable audit receipt.

4. Right to Erasure / "Right to be Forgotten" (RTBF) Engine ​

Under Section 34 of the NDPA 2023, data subjects may demand the permanent erasure of their personal information. Debelu implements a formal Maker-Checker erasure execution pipeline via PrivacyErasureExecutionService ([debelu-backend/src/services/PrivacyErasureExecutionService.ts](file:///c:/Users/frank/OneDrive/Desktop/Chisom/Debelu/New%20Debelu%20Marketplace/debelu-backend/src/services/PrivacyErasureExecutionService.ts)).

4.1 The 7 Erasable Collections ​

When an erasure plan executes under the owned_low_retention_execution_v1 scope, the system completely deletes records across exactly 7 collections:

  1. addresses: Saved physical delivery locations and room numbers.
  2. carts: Abandoned and active shopping carts.
  3. favorites: Wishlisted products.
  4. search_history: Search queries and behavioral tracking.
  5. chat_sessions: Private direct message session metadata.
  6. chat_messages: Private message body text and attachments.
  7. user_sessions: Active refresh tokens and device logins.

4.2 The 7 Statutory Retained Sources ​

Under Nigerian financial, commercial, and criminal laws, certain records are statutorily exempt from deletion. The erasure manifest explicitly documents and preserves:

  1. financial_orders_payments_ledger_payouts: 7-year statutory retention under CBN financial regulations. Historical order buyer identities are pseudonymized ("Deleted User #<ID>").
  2. immutable_audit_approvals_and_privacy_receipts: Proof of legal and regulatory compliance.
  3. shared_support_disputes_messages_and_moderation: Historical evidence required for ongoing or future litigation.
  4. profiles_auth_and_provider_identities: Retained in deactivated state to prevent ban evasion.
  5. notification_workers_and_external_delivery: Transactional notification receipts.
  6. backups_and_external_systems: Encrypted disaster recovery snapshots (expiring via automated 30-day lifecycle policies).
  7. storage_bytes_deletion_and_unclassified_objects: System audit files.

5. Version-Pinned Storage Deletion Protocol ​

When a user's uploaded avatar or media is deleted, issuing a naive path deletion (DELETE /avatars/user_123.jpg) introduces a race condition: if the user concurrently re-uploads a new photo, the deletion worker could inadvertently destroy the newly uploaded image.

Debelu prevents this via Version-Pinned Storage Deletion:

typescript
// DELETE payload pinned to exact object version ID
const endpoint = new URL(process.env.SUPABASE_URL + '/storage/v1/object/avatars');
const response = await fetch(endpoint, {
  method: 'DELETE',
  headers: {
    Authorization: 'Bearer ' + process.env.SUPABASE_SERVICE_ROLE_KEY,
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    prefixes: [{ path: claim.path, versionId: claim.version }]
  })
});

Deletion Verification States ​

Every storage item tracks five deterministic lifecycle states:

  • pending: Scheduled for deletion.
  • uncertain: Network timeout occurred; deletion unconfirmed.
  • verifiedAbsent: Storage provider confirmed deletion of the exact object version.
  • unavailable: Storage bucket unreachable.
  • Scope Erasure Invariant: State scope_erased is ONLY granted when $\text{verifiedAbsent} === \text{total}$.

6. Data Breach Response & Notification SLA ​

In compliance with NDPA Section 40, Debelu maintains an emergency breach containment protocol:

mermaid
stateDiagram-v2
    [*] --> Detection : Breach Detected (SEV-1 Security Incident)
    Detection --> Containment : Revoke Compromised Keys & Isolate Subnets (T < 2h)
    Containment --> RiskAssessment : Classify Impact & PII Scope (T < 12h)
    
    state RiskAssessment {
        [*] --> HighRisk : Financial / Auth Credentials Exposed
        [*] --> LowRisk : Pseudonymized Telemetry Only
    }

    HighRisk --> RegulatorNotice : Formal Notice to NDPC (T < 72h)
    RegulatorNotice --> UserNotice : Mandatory Public / User Notification (T < 72h)
    LowRisk --> InternalReport : Logged to Internal Compliance Ledger
    
    UserNotice --> PostMortem : Blameless RCA & Corrective Actions
    InternalReport --> PostMortem
    PostMortem --> [*]

Statutory Notification Rules ​

  1. Regulator Notification: The Data Protection Officer (DPO) must submit a formal incident report to the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of a confirmed personal data breach.
  2. User Notification: If the breach is likely to result in high risk to the rights and freedoms of individuals (e.g., exposed passwords, payment credentials, identity documents), affected users must be notified without undue delay via direct email and in-app alerts.

Released under Proprietary Enterprise License.