- Introduction
Templars is committed to protecting the privacy of confidential and “Personal Data” (information that directly or indirectly identifies individuals who may be clients, staff, agents, lawyers, law students, job applicants or others inside or outside the Firm).
This Privacy Policy (the “Policy”) sets out Templars’ commitment to ensuring that any Personal Data as defined in paragraph 19 of this Policy, which Templars processes, is handled in compliance with laws which regulate data protection in Nigeria as well as all other applicable international data protection laws and policies (Applicable Data Protection Laws). Templars is committed to ensuring that the processing of Personal Data is carried out in accordance with these laws.
- Purpose of this Policy
This Policy is based on the privacy and data protection principles applicable locally and in other jurisdictions where our clients operate. It is applied in view of our overarching desire to comply with the provisions of the Applicable Data Protection Laws, to preserve client confidentiality and to represent our clients as effectively as possible within the bounds of the law.
This Policy applies to all Personal Data processed by Templars and is part of Templars’ approach towards full compliance with Applicable Data Protection Laws and principles. This Policy is applicable to all Templars services accessed by you and all Templars staff are required to comply.
- Who We Are and What We Do
Templars is a Nigerian registered partnership of lawyers, whose registered office is at 13a A.J Marinho Drive, Victoria Island, Lagos, Nigeria.
Our website and services are operated by Templars (“we”, “us” or “our”). The data controller responsible for your Personal Data processed via the website or in relation to our services is Templars.
- Data Protection Principles
Templars complies with the data protection principles set out below. When processing Personal Data, it ensures that:
- it is processed lawfully, fairly and in a transparent manner.
- it is collected for specified, explicit and legitimate purposes.
- it is at all times adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
- it is all times accurate and, where necessary, kept up to date and that reasonable steps are taken to ensure that Personal Data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay.
- it is kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the Personal Data is processed.
- it is processed in a manner that ensures appropriate security of the Personal Data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
- Information We Collect as You Use Our Services
1. At Templars, we collect and process certain information about you through the services you use, such as our websites, when you submit recruitment applications, and through social media sites. The specific categories of Personal Data we may collect include, but are not limited to:
- Contact Information: This includes your name, email address, phone number, professional details, and employment details.
- Communication Data: Information related to your interactions with us, including emails, support inquiries, and any feedback you provide.
- Usage Data: We collect data about how you use our websites, such as device information and browsing history.
- Device and Log Information: We gather information about the devices you use to access our services, including device type, operating system, and unique device identifiers. Additionally, we collect log information, such as IP addresses, browser type, and access times, to improve our websites.
- Other Information: Any additional information you provide to us voluntarily or that we collect, such as public information from publicly available sources, including open postings on social media.
2. We will always strive to minimize the collection of Personal Data to what is necessary for the intended purpose. Where applicable and required by law, we will obtain your consent before collecting certain categories of data. Our Personal Data collection is always conducted in accordance with Applicable Data Protection Laws and best practices.
3. It is important to note that certain Personal Data may be necessary to provide you with our services, and refusal to provide such data may impact our ability to serve you effectively. We are committed to ensuring the security and confidentiality of your Personal Data, and our data processing activities are conducted in accordance with this Policy and Applicable Data Protection Laws.
- How Data is Collected
As a law firm operating primarily in Nigeria, Templars collects data from clients, staff, vendors, lawyers, law students, job applicants or others inside or outside the Firm in the following circumstances:
- When our website is assessed;
- When legal advice is sought from us;
- In relation to our recruitment process;
- When services are provided to us by external or third-party organisations or vendors; and
- From contact made via email, social media platforms or subscription to any of our products and services.
- Purpose of Processing and Lawful Basis
| Purpose | Lawful Basis |
|
Processing your Personal Data to provide you with legal and professional services. |
Where we have your consent to do so.
For the performance of our contract with you. Where it is in our legitimate interests to manage and run our business efficiently. Where it is in your vital interest. |
| Processing your Personal Data in order to provide you with access to our website. | Where it is in our legitimate interests to manage and run our business efficiently.
Where we have your consent to do so. |
| Processing your Personal Data in order to respond to your inquiries via our support services. | Where we have your consent to do so.
Where it is in our legitimate interests to manage and run our business efficiently. |
| To utilize cookies and to share your information with third parties for marketing purposes. | Where we have your consent to do so.
|
| To personalize your experience, improve the Services, and develop new features | Where it is in our legitimate interests to manage and run our business efficiently and consider future strategy.
Where we have your consent to do so. |
Where processing is based on consent, we shall obtain explicit consent directly from you at the time of collection of your Personal Data or through a third-party processor. In this regard, we will ensure that the consent is freely given by you and obtained without fraud, coercion or undue influence.
By clicking the ‘Send’ button on the ‘Get in Touch’ page of the website, you consent to the collection, retention, and use of your information as set forth in this Privacy Policy. If you do not agree to the Privacy Policy, you may exit and discontinue use of the website.
You can withdraw your consent at any time, but such withdrawal shall not affect the lawfulness of processing based on consent given prior to the withdrawal.
- Process/ Procedures/ Guidance
Templars will:
- ensure that all processing complies with the law;
- not do anything with your Personal Data that you would not expect given the content of this Policy and the fair processing or privacy notice;
- only collect and process the Personal Data that it needs for purposes it has identified in advance;
- ensure that, as far as possible, the Personal Data it holds is accurate, or a system is in place for ensuring that it is kept up to date as far as possible;
- ensure that appropriate security measures are in place to ensure that Personal Data can only be accessed by those who need to access it and that it is held and transferred securely.
Templars will ensure that all staff who handle Personal Data on its behalf are aware of their responsibilities under this Policy and other relevant data protection and information security policies, and that they are adequately trained and supervised.
Breaching this policy may result in disciplinary action for misconduct, including dismissal. Obtaining (including accessing) or disclosing Personal Data in breach of Templars data protection policies may also be a criminal offence.
- How We Use Cookies on Our Website
What is a cookie? Cookies are text files containing small amounts of information which are downloaded to your device when you visit a website. Cookies are then sent back to the originating website on each subsequent visit, or to another website that recognises that cookie. Cookies are useful because they allow a website to recognise a user’s device, preferences and generally help to improve your online experience.
By using our website, you agree that we can place these types of cookies on your device. If you want to restrict or block any of the above cookies, you should do this through the web browser settings for each browser you use and on each device you use to access the internet. Please be aware that some of the areas of our website may not function properly if your web browser does not accept cookies. However, you can allow cookies from specific websites by making them “trusted websites” in your web browser. The “Help” function within your web browser should tell you how to make these changes. To learn more about our Cookie Policy, please visit [here].
- Responsibility for the Security of Processed Personal Data
The Partners and staff of Templars take ultimate responsibility for data protection. Consistent with our professional obligations, it has always been the policy of the Firm to exercise the utmost discretion regarding the information our clients entrust to us.
We maintain reasonable and appropriate, albeit not infallible, physical, electronic and procedural safeguards intended to maintain the confidentiality of Personal Data, including that provided by a visitor to our website.
We require consultants, suppliers and vendors to maintain data protection practices consistent with Applicable Data Protection Laws.
Templars is dedicated to safeguarding your Personal Data and maintaining its confidentiality and integrity. We implement robust security measures and follow industry best practices to protect your information from unauthorized access, disclosure, alteration, and destruction. Our security measures include:
- Encryption: We use encryption techniques to protect the transmission of data between your device and our servers. This ensures that your Personal Data remains confidential during transit.
- Access Control: We restrict access to your Personal Data to authorized personnel only, and access is granted on a need-to-know basis. Our employees and third-party service providers are subject to strict confidentiality obligations.
- Regular Security Audits: We conduct regular security audits and assessments of our systems and infrastructure to identify and address potential vulnerabilities.
- Data Backup: We regularly back up your data to prevent data loss and ensure business continuity in the event of unforeseen circumstances.
- Incident Response Plan: We have established an incident response plan to promptly address any data breaches or security incidents and to notify the appropriate authorities and affected individuals, as required by law.
- User Authentication: We implement strong user authentication methods to ensure that only authorized users have access to your account and Personal Data.
While we take every reasonable precaution to protect your Personal Data, it’s important to acknowledge that no system can be entirely immune to security risks. We encourage you to take steps to safeguard your Personal Data, such as using strong and unique passwords, keeping your login credentials confidential, and promptly reporting any suspicious activity.
In the event of a data breach that could result in a high risk to your rights and freedoms, we will notify you and the appropriate regulatory authorities in accordance with legal requirements. Our commitment is to continuously enhance our security practices to ensure the safety of your Personal Data.
- Disclosure and Transfer of Personal Data
We operate systems that may make data related to your matters accessible from our various offices around the world and often transfer client data which may include Personal Data between our offices. Where we share or transfer your Personal Data, we will do this in accordance with Applicable Data Protection Laws and always take appropriate safeguards to ensure its protection. These include ensuring that:
- All recipients of Personal Data transferred to countries outside of Nigeria are subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism that affords an adequate level of protection with respect to the Personal Data in accordance with Applicable Data Protection Laws; or
- In the absence of the above, we only transfer Personal Data to other jurisdictions if:
- you have granted and not withdrawn consent to such transfer after having been informed of the possible risks of such transfers for the Data Subject due to the absence of adequate protections;
- transfer is necessary for the performance of a contract to which you are a party or in order to take steps at your request, prior to entering into a contract;
- transfer is for your sole benefit and (i) it is not reasonably practicable to obtain your consent to that transfer, and (ii) if it were reasonably practicable to obtain such consent, you would likely give it;
- transfer is necessary for important reasons of public interest;
- transfer is necessary for the establishment, exercise, or defense of legal claims; or transfer is necessary to protect your vital interests or of other persons, where you are physically or legally incapable of giving consent.
- We may also use such data transfer mechanisms which are available to us under the Applicable Data Protection Laws, and which is adequate to ensure appropriate safeguards for your Personal Data or other data transfer mechanisms stipulated by the law.
- Retaining your Personal Data
We will only retain your Personal Data in accordance with Applicable Data Protection Laws, for no longer than is necessary to achieve the purpose for which it was collected. We will also retain some Personal Data after your relationship with us has ended. The retention period will be determined by various criteria, including:
- the purpose for why we keep your Personal Data, e.g. to defend or take legal action;
- if we have a legal obligation to retain Personal Data for a defined period, e.g. example, some laws and regulations mandate that some Personal Data must be retained for a specific period (e.g., tax requirements);
- if we have to evidence compliance with our legal and regulatory obligations; and/or
- if we have to withhold destruction because of ongoing litigation, a court order or an investigation by law enforcement agencies or our regulators.
When your Personal Data is no longer necessary for the above purposes, we will securely destroy such information or permanently de-identify it. For more information about our data retention practices, please see our contact details in paragraph 15 below.
- Data Subject Rights
Templars has processes in place to ensure that it can facilitate any request made by an individual to exercise their rights under data protection law. All staff have received training and are aware of the rights of Data Subjects. Staff can identify such a request and know who to send it to. All requests will be considered without undue delay and within one month of receipt as far as possible.
As a Data Subject, you have the following rights:
- Your right of access – You have the right to ask us for copies of your Personal Data.
- Your right to rectification – You have the right to ask us to rectify Personal Data you think is inaccurate, incomplete or misleading.
- Your right to erasure – You have the right to ask us to erase your Personal Data held with us, and such request will oblige your request without any undue delay.
- Your right to restrict the processing of your Personal Data.
- Your right to object to processing – You have the right to object to the processing of your Personal Data on grounds relating to your particular situation, when the applicable legal basis is legitimate interests, for scientific or historical research, or statistical purposes, or for direct marketing purposes.
- Right to request the transfer of your Personal Data to yourself or a third-party – We will provide to you, or (where technically feasible) a third-party you have chosen, your Personal Data in a structured, commonly used, and machine-readable format.
- Right to withdraw your consent – You may withdraw your consent by contacting us using the details set out below. If you withdraw your consent, we may not be able to provide and/or perform the associated
- Right to lodge a complaint with the Nigeria Data Protection Commission, where you are of the opinion that your Personal Data rights have been violated.
- Right to be informed of the existence of automated decision-making, including profiling, its significance and potential impact on the Data Subject and the right to object to or challenge such processing.
- Our Policy Towards Children
If you become aware that your child or minor has provided us with Personal Data without your consent, please send us an email via Contact Us details below. We do not knowingly collect Personal Data from children under the age of 18 years. If we become aware that a child under the age of 18 has provided us with Personal Data, we take steps to remove such information and discontinue processing.
- Contact Us
If you have any questions, concerns, or requests regarding your Personal Data or this Privacy Policy, please contact us via:
Address: 5th Floor, The Octagon Building, 13A, A.J. Marinho Drive, Victoria Island Lagos.
Email: [email protected]; [email protected]
Phone: +234 811 570 8339
- Right to Lodge a Complaint
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Nigeria Data Protection Commission at:
Address: No. 12, Dr. Clement Isong Street, Asokoro, Abuja, Nigeria.
Email: [email protected]
Telephone: +234 (0) 916 061 5551
- Third-Party Links
Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share Personal Data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
- Changes, Monitoring and Review of this Policy
We reserve the right to update or modify this Privacy Policy to reflect changes in our data processing practices or legal requirements. We will notify you of any material changes by posting the updated Policy on our platform or by other means of communication, where appropriate. We encourage you to review this Policy periodically to stay informed about how we are protecting your Personal Data.
- Glossary
|
TERMS |
DEFINITIONS |
| Data Subject | means an individual to whom Personal Data relates.
|
| Applicable Data Protection Laws | means the Nigeria Data Protection Act 2023 (NDPA); General Application and Implementation Directive 2025 (GAID), and other applicable data protection laws.
|
| Personal Data |
means any information relating to an individual, who can be identified or is identifiable, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, psychological, cultural, social, or economic identity of that individual.
|
Last Updated : 19 March 2026