Privacy & Data Protection Policy
How DNA Labs Nigeria collects, uses, retains, protects and disposes of your personal and genetic data β in accordance with the Nigeria Data Protection Act (NDPA).
Last updated: 28 September 2026
1. Who we are & scope
DNA Labs Nigeria is a genetic diagnostic laboratory operating in Nigeria, with laboratories and sample collection centres in Abuja, Lagos and Kaduna. For the purposes of the Nigeria Data Protection Act (NDPA) 2023, we act as the data controller of the personal data described in this policy.
This policy applies to patients, test participants (including minors whose data is provided by a parent or guardian), website visitors, enquirers, research subsidy applicants, institutional partners and healthcare professionals who interact with us. It covers data collected through our website, at our centres, through home collection kits, and through communications with our team.
2. Lawful basis for processing sensitive genetic data
Genetic and health data is sensitive personal data under the NDPA. We process it only where a lawful basis applies and, where required, with your explicit consent:
- Consent β your explicit, informed consent to perform the requested test and deliver its results (the primary basis for most testing).
- Contract β processing necessary to deliver the diagnostic service you have booked, including sample accessioning, analysis and reporting.
- Legal obligation β record-keeping and regulatory duties under Nigerian health and laboratory regulation, and compliance with lawful orders of courts or competent authorities.
- Vital interests β rare circumstances where processing is necessary to protect someone's life.
- Legitimate interests β for non-sensitive data only, such as service improvement, fraud prevention and website security, balanced against your rights.
Where processing relies on consent, you may withdraw that consent at any time; withdrawal does not affect processing already lawfully carried out, and it may mean we can no longer provide the requested service.
3. Categories of data we collect
- Identity data β full legal name, date of birth, gender, and details of government-issued identification for chain-of-custody testing.
- Contact data β phone number, email address, postal address and WhatsApp number.
- Health & genetic data β biological samples (buccal swabs, blood and other specimens), genetic and molecular test results, clinical indications you or your physician provide, and family relationship information.
- Chain-of-custody records β photographs captured at collection, witness signatures and custody documentation for legal testing.
- Case documentation β for research subsidy applicants: university identification, supervisor recommendation letters and project abstracts.
- Transaction data β booking records, payment confirmations and invoices.
- Technical & usage data β website analytics, device and browser information and IP address, used to secure and improve the website.
- Correspondence β messages you send us through forms, email, phone or WhatsApp.
4. Purpose limitation
We collect and use personal data only for specified, explicit and legitimate purposes:
- To provide the diagnostic service you request β sample processing, laboratory analysis, medical review and result reporting.
- To verify identity and maintain chain-of-custody records where testing is legal or evidential in nature.
- To communicate with you about bookings, results, password procedures and follow-up support.
- To provide pre- and post-test genetic counseling.
- To meet regulatory, laboratory accreditation, quality assurance and record-keeping obligations.
- To process research subsidy applications and academic collaborations.
- To respond to enquiries and partnership requests.
- To secure our systems, prevent misuse and improve our services.
We do not sell personal data, do not use genetic data for marketing, and do not share identifiable results with family members, employers, insurers or any third party without your explicit instruction or a lawful basis requiring it.
5. Consent
Before testing, we obtain informed consent that explains what will be done, what the results may reveal, who will receive them and how they will be protected. Special care applies to:
- Minors β consent must be given by a parent or legal guardian, who may be asked to evidence guardianship.
- Legal testing β each tested party (or their authorised representative) signs custody consent documents at collection.
- Family implications β genetic results can reveal information about relatives; counseling is available before and after testing.
6. Data retention periods
We keep personal data only as long as necessary for the purposes described above, and in line with Nigerian laboratory record-keeping requirements and limitation periods. When retention expires, data is securely disposed of under section 10. Typical retention periods are summarised below:
| Data category | Retention period | Disposal method |
|---|---|---|
| Biological samples (post-analysis) | Retained only as long as required for quality assurance and repeat testing β typically up to 90 days after the report is released, unless you instruct otherwise or law requires longer | Incineration or certified biological waste disposal |
| Laboratory reports & result data | Minimum of 7 years from release (longer for tests involving minors or legal proceedings, as required) | Secure deletion of digital records; certified destruction of physical copies |
| Chain-of-custody & ID records | For the duration of the test record, aligned to the retention period of the related report | Secure deletion and shredding |
| Photographs taken at collection | Aligned to the related test record | Secure deletion |
| Subsidy application documents | Up to 24 months from the application decision | Secure deletion of uploaded files |
| General enquiries & correspondence | Up to 24 months from resolution | Secure deletion |
| Website analytics & logs | Up to 12 months | Automated rotation and deletion |
| Transaction & payment records | As required by Nigerian tax and financial record-keeping law (typically 7 years) | Secure archival then deletion |
If you wish to request early destruction of samples already analysed, contact our Data Protection Officer β see section 11.
7. Security measures
We apply technical and organisational measures appropriate to the sensitivity of genetic data:
- Encrypted reporting β every report leaves our pipeline as a password-protected PDF; reports are never sent unprotected.
- Access control β personal and genetic data is accessible only to authorised staff on a need-to-know basis, under confidentiality obligations.
- Sample pseudonymisation β samples are tracked by barcode identifier within the laboratory, not by name.
- Secure storage β electronic records are stored on protected systems with backups; physical records are held in controlled areas.
- Transport security β samples move in sealed, tamper-evident packaging with documented custody where applicable.
- Staff training β personnel are trained on confidentiality, data protection and incident handling.
- Incident response β suspected breaches are investigated promptly and notified to the Nigeria Data Protection Commission and affected individuals where the law requires.
8. Your data subject rights
Under the NDPA, you have the right to:
- Access β request confirmation of whether we process your data and obtain a copy of it.
- Rectification β have inaccurate or incomplete personal data corrected.
- Erasure β request deletion of your data where there is no lawful basis for continued retention (subject to mandatory record-keeping periods).
- Portability β receive your data in a structured, commonly used, machine-readable format where technically feasible.
- Restriction β request that processing be limited in certain circumstances.
- Objection β object to processing based on legitimate interests.
- Withdraw consent β withdraw consent at any time where processing is consent-based.
- Complain β lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights have been infringed.
To exercise any right, contact our Data Protection Officer (section 11). We may need to verify your identity before acting on a request β a protective step for genetic data, which can never be re-issued if disclosed incorrectly.
9. Cross-border data transfers
We process and store personal data primarily within Nigeria. Where a transfer outside Nigeria is required β for example, where a specialist assay is performed through an external reporting pipeline or laboratory partner β we ensure an adequate level of protection is maintained, in line with the NDPA's requirements for cross-border transfer of personal data, including appropriate contractual and security safeguards with the receiving party.
Your data is never sold to, or shared with, foreign advertisers, insurers or immigration authorities other than in response to lawful process.
10. Data disposal & destruction
At the end of the retention period, data is destroyed securely and irreversibly:
- Digital records β secure deletion from live systems and backups according to our destruction schedule.
- Physical records β shredding or certified destruction by an approved provider.
- Biological samples β incineration or disposal as certified biological waste; retained samples are never used for secondary purposes without consent.
- Uploaded documents (subsidy applications) β deleted from storage after the retention window.
Destruction is logged, and evidence of disposal can be provided on reasonable request to our Data Protection Officer.
11. Data Protection Officer & contact
For questions, requests or complaints about how we handle your personal data, contact our Data Protection Officer:
- By email: info@dnalabsnigeria.com β with the subject line βData Protection Officerβ.
- By phone or WhatsApp: +234 800 000 0000
- Through our contact page.
We aim to respond to verified data subject requests within the timelines prescribed by the NDPA. If you are unsatisfied with our response, you may escalate to the Nigeria Data Protection Commission (NDPC).