PERCEPTIONS OF DATA PROTECTION COMPLIANCE AMONG SOFTWARE ENGINEERS IN NIGERIA FINANCIAL TECH
Keywords:
Data Protection, Fintech, Software Engineers, Nigeria Data Protection Regulation (NDPR), ComplianceAbstract
Data protection compliance has emerged as a central issue in Nigeria’s growing financial technology (FinTech) ecosystem, where vast amounts of sensitive personal data are processed daily. However, concerns remain regarding how well software engineers who create and manage FinTech systems understand and implement regulatory frameworks such as the Nigerian Data Protection Regulation (NDPR) and the European Union’s General Data Protection Regulation (GDPR). The study therefore, examined the perceptions of data protection compliance among software engineers in Nigerian FinTech companies. Specifically, the objectives of the study were to examine the level of familiarity of software engineers in Nigerian FinTech companies with data protection laws; assess how software engineers perceive their role in protecting user data and the extent to which they implement data protection practices; and identify the challenges software engineers face in complying with data protection regulations. The study adopted a mixed-methods design comprising a quantitative survey of 113 engineers and qualitative Key Informant Interviews with compliance managers across leading Lagos-based FinTech firms. The analysis revealed a significant positive correlation between awareness of data protection laws and responsible compliance behaviour (r = .582, p < .01). However, practical compliance remains constrained by inadequate training, limited managerial support, and the absence of localized compliance tools. The study concludes that awareness alone is insufficient to ensure compliance unless it is supported by strong institutional frameworks and the integration of privacy-by-design principles into software development processes. It recommends, among other measures, the provision of hands-on data protection training for engineers, the integration of privacy considerations into all stages of software development, and investment in modern security tools.
References
Amaral, A., Bastos, J., & Dias, A. (2022). Information security compliance and employee behaviour: A systematic literature review. Computers & Security, 113, 102546. https://doi.org/10.1016/j.cose.2021.102546
CBN. (2020). Financial Stability Report – December 2020. Central Bank of Nigeria. https://www.cbn.gov.ng
ComplexDiscovery. (2024). LockBit 3.0 ransomware attacks and trends report. https://complexdiscovery.com
Cyber Management Alliance. (2024). Evolve Bank ransomware breach: Timeline and analysis. https://www.cm-alliance.com
Diyoke, M. C., & Edeh, S. T. (2020). An analysis of data protection and compliance in Nigeria. International Journal of Research and Innovation in Social Science (IJRISS), 4(5), 377–382. https://www.rsisinternational.org/journals/ijriss/Digital-Library/volume-4-issue-5/377-382.pdf
EFInA. (2023). Access to Financial Services in Nigeria Survey 2023. Enhancing Financial Innovation & Access. https://www.efina.org.ng
Elahidoost, P., Méndez Fernández, D., Seyff, N., & Christmann, P. (2024). Practices, challenges, and opportunities when inferring requirements from regulations in the FinTech sector. arXiv. https://arxiv.org/abs/2405.02867
Eleweke, C. B., & Oseni, K. (2025). Applying software engineering to legal technology solutions in Nigeria. African Journal of Information Systems, 12(1), 54–66.
Fausto, J. (2018). Understanding GDPR and its implications for global data protection. European Journal of Law and Technology, 9(2), 1–15.
Franke, L., Liang, H., Brantly, A., & Davis, J. C. (2024a). An exploratory mixed-methods study on GDPR compliance in open-source software. arXiv. https://arxiv.org/abs/2406.14724
Franke, L., Davis, J. C., Liang, H., & Brantly, A. (2024b). A first look at the GDPR in open-source software ecosystems. arXiv. https://arxiv.org/abs/2401.14629
McMillan LLP. (2024). Data privacy law and anonymization risk update. McMillan Law. https://mcmillan.ca
Mordi, C. (2021). Digital savings platforms and financial inclusion in Nigeria: The PiggyVest example. Journal of African Financial Technology, 5(1), 35–48.
NITDA. (2019). Nigeria Data Protection Regulation (NDPR). National Information Technology Development Agency. https://nitda.gov.ng
NITDA. (2021). NDPR Performance Report 2021. National Information Technology Development Agency. https://nitda.gov.ng
Ohm, P. (2010). Broken promises of privacy: Responding to the surprising failure of anonymization. UCLA Law Review, 57(6), 1701–1777.
Oladokun, L. (2025). GITEX debuts in Nigeria: Lagos attracts $6 billion tech fund – Sanwo-Olu; Digital economy’s contribution to GDP to reach 21 percent by 2027 – Bosun Tijani; Nigeria is ready to lead the future economy – DG NITDA. National Information Technology Development Agency (NITDA). https://nitda.gov.ng
Sabo, S. B., & Utulu, S. C. A. (2023). Institutional propositions in the Nigerian Data Protection Regulation (NDPR) implementation. arXiv. https://arxiv.org/abs/2309.12893
TechCrunch. (2020, October 15). Stripe acquires Paystack in a $200M+ deal to expand in Africa. TechCrunch. https://techcrunch.com
Torre, D., Méndez Fernández, D., & Vogelsang, A. (2020). Bridging legal requirements and model-based engineering for GDPR compliance. Requirements Engineering, 25(2), 203–229. https://doi.org/10.1007/s00766-020-00334-5
Wang, H., Luo, S., & Li, Y. (2023). Automating compliance checking in FinTech platforms using regulatory knowledge graphs. Journal of Financial Innovation Systems, 8(2), 77–91.