EDLUM Data Protection Policy Summary
Document Purpose: This policy outlines the principles, responsibilities, and standards Edlum adheres to regarding the processing, storage, and protection of personal data belonging to schools, teachers, parents, and students. This document applies to all Edlum employees, contractors, and processors handling platform data.
Compliance Frameworks: Primarily the Nigeria Data Protection Act (NDPA) 2023 and Nigeria Data Protection Regulation (NDPR) 2019, aligned with international best practices (GDPR principles).
1. Key Data Protection Principles
Edlum is committed to processing personal data in accordance with the following principles:
| Principle | Policy Standard |
| Lawfulness & Fairness | Data is processed only with a clear, specific legal basis (e.g., performance of the educational service contract). All processing is transparently communicated in the Privacy Policy. |
| Purpose Limitation | Personal data, especially student results, is collected strictly for Creating Clarity in Education—specifically for result management, progress tracking, and secure communication. Data will never be used for unrelated commercial advertising. |
| Data Minimization | We only collect the minimum amount of Personal Data necessary to achieve the stated purpose. Data collection is limited to names, contact details, and academic scores. |
| Accuracy | Edlum provides systems for the prompt identification and correction of inaccurate data by authorized school staff to ensure the integrity of the Personal Academic Record. |
| Storage Limitation | Personal data is stored only for the duration required by the educational purpose or as mandated by Nigerian legal/retention requirements. Data deletion is securely managed post-retention period. |
| Integrity & Confidentiality | We employ appropriate technical and organizational measures to ensure data security, including encryption, access controls, and logging of data access activities. |
| Accountability | Edlum maintains full documentation of its processing activities and conducts regular reviews to ensure ongoing compliance with data protection laws. |
2. Roles and Responsibilities
| Role | Responsibility under this Policy |
| Edlum (Data Controller) | Determines the purpose and means of processing personal data. Responsible for system-wide security, policy setting, and compliance. |
| School (Data Controller) | Responsible for the lawfulness of the data submitted to Edlum. Responsible for managing user accounts, granting access rights, and ensuring staff compliance with data entry accuracy. |
| Teacher | Responsible for the accurate, timely, and secure input of results, adhering to the principle of Simplified Workflows and maintaining the confidentiality of login details. |
| Edlum Staff | All staff are required to undergo training on this policy and only access data strictly necessary for their job function (e.g., technical support). |
3. Data Subject Rights Implementation
The platform is designed to facilitate the exercise of user rights:
| User Right | Edlum System Feature |
| Right to be Informed | Transparent Privacy Policy and Terms of Service. |
| Right of Access | Parent/student login dashboard provides real-time access to all their data (results, charts). |
| Right to Rectification | Tools are provided for schools/teachers to correct erroneous records easily. |
| Right to Erasure | Procedures are established for the secure and permanent deletion of a user’s personal data upon legal request, subject to mandatory school data retention laws. |
| Right to Data Portability | We can provide a copy of a student’s academic record in a commonly used format (e.g., downloadable PDF report cards). |
4. Security and Breach Management
- Technical Measures: Data is protected with secure logins and stored with industry-standard encryption protocols.
- Incident Response: Edlum has an internal Data Breach Response Plan to ensure that any security incident involving personal data is investigated immediately.
- Notification: In the event of a high-risk data breach, Edlum commits to notifying the relevant supervisory authority (Nigeria Data Protection Commission) and affected Schools/Data Subjects as required by law.
5. Review and Training
This policy will be reviewed annually. All Edlum personnel involved in data processing will receive mandatory and regular data protection training to ensure continued awareness and compliance.
Note for Partners/Users: This is a summary. The full internal Data Protection Policy and any related procedures are available to authorized parties upon request.