Connect with us

E-Business

Experts Advise African Firms Processing EU Personal Data

Published

on

Kindly share this post

A piece of advice has been given to organisations in Africa processing the personal information of data subjects from within the European Union (EU).

 

At an event hosted by Baker McKenzie and Cognia Law in Johannesburg, Head of the Technology, Media and Telecommunications Practice Group at Baker McKenzie in Johannesburg, Mr Darryl Bernstein, warned organisations doing such to already have effective General Data Protection Regulation (GDPR) compliance procedures in place, including Data Breach Security Checklists, impact assessments and subject data requests procedures.

 

Mr Bernstein said this due diligence is not only required by the GDPR regulation but can significantly reduce the risks associated with security breaches, raise awareness of the GDPR and ensure that companies have appropriate technical and organisational measures in place to comply with the legislation.

Advertisement

 

He further said it was essential for organisations to have a General Data Protection Regulation (GDPR) Data Security Breach Checklist in place to assess the risks of a data security breach and to implement a plan to contain and manage any data breaches.

 

Mr Bernstein noted that the first step on any organisation’s GDPR Data Security Breach Checklist should be to assess the risks associated with a data security breach.

 

Advertisement

“It is essential to know whose data might have been disclosed, what type of data has been breached and if it contains sensitive information.

 

“Affected organisations should also asses the volume of data disclosed and if any of the data has been lost or damaged. The cause of the breach and where in the world the breach occurred must also be investigated,” he said.

 

Mr Bernstein explained that step two on the Checklist should be to contain the breach and recover the data.

Advertisement

 

“Organisations who have fallen victim to a data breach must establish who will investigate the breach, who will assist with the containment of the breach and/or the recovery of information and if action should also be taken to prevent the breach from recurring. This is also the time to inform the police, if appropriate to do so,” the data expert said.

 

During step three, organisations must notify all data subjects who have had their private information breached.

 

Advertisement

“According to the GDPR, notification must take place without undue delay and no later than 72 hours after the breach has occurred. The nature and scope of the breach, as well as its consequences and the measures taken to rectify it, must also be disclosed to affected data subjects,” he said.

 

Mr Bernstein explained that South African organisations will have to have a similar checklist in place in order to comply to the soon to be implemented Protection of Personal Information Act (POPIA).

 

POPIA stipulates that a data breach must be notified as soon as reasonably possible after the discovery of the compromise, considering the legitimate needs of law enforcement or any measures reasonably necessary to determine the scope of the compromise and to restore the integrity of the responsible party’s information system.

Advertisement

 

To assist organisations in the event of a data breach, Baker McKenzie recently launched a mobile application called “Data Breach 72”. This app, which is available in English and French, allows organisations to identify the existence of a data breach, within the scope of application of the GDPR; establish whether it is necessary to notify the competent supervisory body; and prepare an initial draft of this notification. The app forms part of Baker McKenzie’s innovation programme, which aims to rethink the way in which lawyers deal with the challenges their clients are facing.

 

The final step in Checklist includes a thorough evaluation of the breach. “Once the first three steps are complete, organisations must investigate whether employees were responsible for the breach and if disciplinary action is required. If a third party was involved, the contract should be checked for damages provisions and an impact assessment undertaken. Lastly, organisations must review their procedures and ensure their data is secure going forward,” he said.

 

Advertisement

Also, partner in Baker McKenzie’s Corporate/M&A practice and TMT specialist, Janet MacKenzie, noted that, “The GDPR further requires organisations to complete a Data Protection Impact Assessment prior to the processing of private information, where the processing is likely to result in a high risk to the rights and freedoms of natural persons.

 

MacKenzie said it is essential to conduct an Impact Assessment of third parties that process high-risk company personal data, to determine their awareness of GDPR and to ensure that they have appropriate technical and organisational measures in place to comply with the legislation.

 

For high-risk third parties, audit partners should be identified for the assessment of processes and to determine if on-site audits are required. It is worth noting that the requirements of the GDPR stipulate that data processing can only be outsourced to a third party if the processor guarantees conformity with the requirements of the GDPR.

Advertisement

 

Janet Taylor Hall, CEO of Cognia Law, explained further, “There were two operational areas where clients tend to underestimate the impact assessment efforts around GDPR –  the first being adequately preparing to deal with a data breach when it happens and the second is subject data requests, which can in themselves lead to a breach if not handled appropriately.”

 

“Right of access is a core principle of the GDPR. Individuals have the right to access their personal data and supplementary information at any time. In responding to these data requests in time (30 days), it is also important that no data is shared that belongs to another individual or that contains intellectual property or trade secrets,” she said.

 

Advertisement

“Putting a robust subject data request capability in place is an important part of the on-going GDPR compliance support we offer our clients”, highlighted Justin Ridl, Global Head of Legal Services, Cognia Law.

 

 

 

 

Advertisement

 

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

82% of Organizations Concerned about AI Risks Even as Adoption Accelerates – Survey Reveals

Published

on

Kindly share this post

At its recent Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region Kaspersky shared the results of a global study conducted by its internal research center which surveyed 1,800 IT and cybersecurity decision-makers and specialists from organisations across 18 countries and multiple industries.

The report shows that the pace of AI integration across organisations is rapid, despite associated risks. The company’s experts stressed that while AI adoption delivers clear efficiency gains, it must be accompanied by robust cybersecurity solutions, well-defined internal procedures, and comprehensive employee education programmes.

The report highlights a clear organisational preference for AI-enhanced technology: 68% of respondents said they would recommend a solution with AI features built in, while a mere 5% indicated they would prefer to avoid AI-enabled tools. This overwhelming endorsement underscores how deeply AI has embedded itself as a value driver across the modern enterprise.

AI has become a mainstream productivity tool spanning many business functions. The global survey findings confirm that employees across departments are already relying on AI tools for a wide range of everyday tasks, including: data analysis & visualisation (54%), project management (49%), search for information (47%), department-specific tasks (46%), text generation and editing (41%).

While organisations recognise the tangible benefits AI tools bring – including improved process efficiency and enhanced quality of deliverables – they also see the associated dangers. 82% of respondents voiced concerns about the risks AI poses to their organisation. These concerns are grounded in real-world experience.

Advertisement

Among the 87% of organisations worldwide that faced a cyber incident in the past year, 13% reported that they had experienced threats stemming specifically from AI-related vulnerabilities.

Notably, 74% of respondents believe that these risks can be effectively mitigated through employees’ responsible behaviour — pointing to the critical importance of security awareness and training in the AI era.

“The speed at which organisations are embracing AI is remarkable, but it must be matched with an equally strong commitment to security. We are already seeing a growing range of threats directly tied to AI adoption – whether it’s malware camouflaged as popular AI tools, vulnerabilities introduced through unsecure vibecoding, or leaked access credentials to corporate AI platforms and malicious skills by AI agents.

Managing these risks requires a holistic approach: the right technology, well-defined procedures, and a security-aware workforce,” comments Brandon Muller, senior security consultant for the META region at Kaspersky.

Advertisement

Kindly share this post
Continue Reading

E-Business

How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

Published

on

Kindly share this post

Malagasy Vanilla has transformed its decades-old wholesale business by embracing direct-to-consumer sales through Temu, enabling the family-run company to reach customers in 14 European markets while significantly reducing logistics costs.

How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

For years, premium Madagascan vanilla supplier Malagasy Vanilla sold exclusively to restaurants, bakeries and wholesalers because the cost of shipping a single pack to individual customers often equalled the value of the product itself. That changed after the company joined Temu’s Local Seller Program in November 2025.

The Belgian-based business, which sources high-quality vanilla from Madagascar, has leveraged Temu’s logistics network to cut domestic shipping costs by nearly half through a partnership with Belgian postal operator Bnode. The move has enabled the company to enter the retail market for the first time and quadruple its sales within four months.

According to Belinda Rabenandrasana, co-Chief Executive Officer of Malagasy Vanilla, Temu has opened up an entirely new customer segment for the company.

“Temu opened a new avenue for us,” she said. “We were finally able to explore selling to individuals.”

Advertisement

The platform now contributes between five and 10 per cent of the company’s overall revenue.

Expansion into 14 European Markets

Malagasy Vanilla is among businesses participating in Temu’s Local Seller Program, launched in Europe in 2024 to help local merchants expand beyond their domestic markets.

Through partnerships with more than 150 logistics providers across Europe—including Bnode in Belgium, La Poste in France and DHL Group in Germany—Temu offers sellers access to affordable shipping and delivery infrastructure without requiring major investment in logistics.

After successfully establishing direct-to-consumer sales in Belgium, Malagasy Vanilla expanded into 14 European countries, including Germany, France, Spain and Poland.

Rabenandrasana said the logistics support, competitive shipping rates and seller assistance provided by Temu made the expansion possible.

Advertisement

“Without Temu and its partnership with Bnode, it would have been very difficult for a small business like ours to start selling directly to consumers,” she said.

She added that Temu also assists sellers in managing regulatory requirements such as the European Union’s Extended Producer Responsibility (EPR) compliance, making cross-border operations easier for small businesses.

Three Generations of Vanilla Expertise

Malagasy Vanilla traces its roots to three generations of the Rabenandrasana family in Madagascar’s vanilla industry.

Belinda’s grandfather began trading vanilla locally, while her father expanded operations across Madagascar. She launched the company’s international business in 2017, supplying premium Madagascan vanilla to European restaurants, pastry shops and food wholesalers before establishing operations in Belgium in 2023.

The company partners with growers and producer associations in Madagascar, where between 20 and 40 workers oversee the six- to 10-month curing process that transforms green vanilla pods into premium black vanilla.

Advertisement

Operations in Belgium focus on packaging, quality assurance and distribution.

Customer Reviews Drive Growth

Under its Lavani brand, Malagasy Vanilla sells gourmet-grade whole vanilla pods targeted at both professional chefs and home baking enthusiasts.

Rather than relying heavily on paid advertising, the company has benefited from Temu’s product discovery tools and customer reviews, helping the niche brand gain visibility organically.

According to Rabenandrasana, strong customer feedback has played a significant role in increasing traffic and boosting sales.

The brand currently maintains a customer review rating exceeding 99 per cent on the platform.

Advertisement

Future Plans

Looking ahead, Malagasy Vanilla plans to expand its European footprint further by establishing a warehouse in France and increasing sales across the continent.

The company is also developing new products, including vanilla extract and vanilla sugar, while planning to open a physical retail and production facility in Belgium later this year.

In addition, it intends to launch a social-impact initiative aimed at supporting vanilla-growing communities in Madagascar.

Reflecting on the company’s evolution, Rabenandrasana said the business continues to build on her family’s legacy.

“My grandfather worked locally, my father expanded nationally, and now we are building internationally,” she said.

Advertisement

Kindly share this post
Continue Reading

E-Business

FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

Published

on

Kindly share this post

Stakeholders in Nigeria’s digital economy have urged the Federal Government to review its partnership with global recruitment platform Hello.cv under the 3 Million Technical Talent (3MTT) programme, citing concerns over data security, digital sovereignty and the country’s “Nigeria First” policy.

FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

3MTT

The concerns follow the Federal Ministry of Communications, Innovation and Digital Economy’s announcement on May 6 of a 10 million-dollar partnership with Hello.cv aimed at increasing the global visibility of Nigerian technology professionals.

Under the initiative, 20,000 selected 3MTT fellows will receive a global professional profile package, including an Artificial Intelligence (AI)-powered job search agent, a professional curriculum vitae (CV) writer and a personal .cv domain, valued at 500 dollars per participant.

While stakeholders acknowledged the programme’s potential to improve global employment opportunities for Nigerian tech talent, they expressed concerns about the implications of hosting participants’ digital identities and data on a foreign domain.

Chief Executive Officer of Cyberchain and Global Digital Economy Strategist, Engr. Jude Ozinegbe, said the arrangement raised important questions about data ownership and jurisdiction.

According to him, registering domains under an entity outside Nigeria gives that entity a degree of control over activities associated with the domain.

Advertisement

“When you register your domain under a different entity outside your jurisdiction, that entity will have access to whatever is happening within that domain.

“In the long run, the Nigeria Data Protection Commission (NDPC) may have to examine the agreement and assess the security implications of such domain ownership,” he said.

Ozinegbe urged the NDPC to review the security protocols employed by Hello.cv to ensure compliance with Nigeria’s data protection regulations.

Also speaking, Ugonma Egwuatu of ECAM Global Services, an information and communications technology and data protection firm, said the security of data belonging to 20,000 fellows should be of significant interest to regulators.

She noted that while the ministry had the authority to determine how the programme was implemented, there was a need for greater transparency regarding the handling of participants’ personal information.

Advertisement

“The NDPC requires its registered Data Protection Compliance Organisations (DPCOs) to subscribe to the .ng domain.

“If a government ministry permits trainees to operate on a foreign domain, then the commission should examine the arrangement because we are dealing with the data of 20,000 Nigerians,” she said.

Egwuatu also called for clarity on how data generated through the platform would be processed, stored and protected.

“There should be explanations regarding the backend. What are they doing with the data of people who visit these sites? Why use a foreign domain instead of the .ng domain? These are legitimate questions that deserve answers,” she said.

She added that government should ensure appropriate third-party agreements and safeguards were in place before implementing such initiatives.

Advertisement

On his part, Chief Executive Officer of DNS Africa, Dr. Adebunmi Adeola Akinbo, said the objectives of the programme could still have been achieved while leveraging Nigeria’s country code top-level domain.

According to him, Hello.cv could have registered a hello.cv.ng or hellocv.ng domain in collaboration with the Nigeria Internet Registration Association (NiRA).

“The .ng domain can conveniently accommodate such a platform. If Hello.cv intends to onboard millions of Nigerians, it can work with NiRA to create a local domain structure.

“That way, the investment remains within Nigeria, strengthens the digital economy and supports local internet infrastructure,” he said.

Akinbo argued that excluding the .ng domain from the initiative undermined Nigeria’s digital identity and sovereignty.

Advertisement

“As good as the programme may sound, leaving the .ng domain outside this engagement and taking Nigerian data outside the country’s digital jurisdiction is not the best approach,” he said.

Also commenting, Founder and Chief Executive Officer of Precise Financial Systems Ltd., Yele Okeremi, stressed the importance of ensuring that investments in Nigeria’s digital economy create long-term domestic value.

According to him, building a sustainable technology ecosystem requires more than developing skilled professionals.

“Investment, particularly in technology and the knowledge economy, is not just about having smart people.

“It is also about who owns the infrastructure and who ultimately benefits from the value created. Nigeria must ensure it retains as much of that value as possible,” he said.

Advertisement

Similarly, Chief Executive Officer of the Internet Exchange Point of Nigeria (IXPN), Muhammed Rudman, described the use of foreign domains for a government-sponsored initiative as inconsistent with efforts to promote Nigeria’s digital economy.

“I don’t know where this idea came from, but it is unpatriotic for Nigerian companies funded by Nigerian resources to adopt .cv domains instead of .ng.

“Global companies such as Google register country-specific domains like google.ng when operating locally. Registering 20,000 additional .ng domains would improve Nigeria’s online visibility and strengthen the local internet ecosystem,” he said.

Rudman urged the Federal Government to support indigenous digital infrastructure by encouraging the use of the .ng domain.

The 3 Million Technical Talent (3MTT) programme is a flagship initiative of the Federal Ministry of Communications, Innovation and Digital Economy aimed at equipping Nigerians with globally relevant digital skills.

Advertisement

The programme provides free training in areas including software development, artificial intelligence, cloud computing, cybersecurity, data analytics, machine learning, animation, DevOps and user interface/user experience design through a hybrid learning model.

Stakeholders maintained that while the partnership with Hello.cv could expand international employment opportunities for Nigerian technology professionals, greater attention should be paid to safeguarding the country’s digital assets, promoting local internet infrastructure and ensuring compliance with Nigeria’s data protection framework.

Kindly share this post
Continue Reading

Trending