How KYC and AML Providers Protect Customer Data: A Due Diligence Guide for Banks and Fintechs
ByVictoria okere
•5mins Read
Key Takeaways
A KYC or AML provider usually acts as a data processor for the bank or fintech, though it may be a controller for some of its own processing.
Under the Nigeria Data Protection Act 2023 (NDPA), a controller must ensure its processor meets the Act's obligations, backed by a written agreement.
Identity documents, biometrics and automated risk scoring can be high-risk processing, which may require a data privacy impact assessment (DPIA) before it starts.
Strong providers protect data through risk-based safeguards such as encryption, access controls, audit trails, data minimisation and controlled data transfers.
Certifications and attestations are useful evidence, but buyers should check their scope, period and exceptions, not just their names.
What Is Customer Data Protection?
Customer data protection is the set of legal, technical and organisational measures a business uses to keep customers' personal information secure, private and used only for lawful purposes. It covers how data is collected, stored, accessed, shared and deleted.
For KYC and AML work, the stakes are higher than in most industries. Providers handle identity documents, selfies, biometric checks, national identification numbers, addresses and screening results. A breach of that data can enable identity fraud for years.
Snippet-ready answer: Customer data protection is the set of legal, technical and organisational measures a business uses to keep customers' personal information secure and used only for lawful purposes. For KYC and AML providers, it includes encryption, access controls, audit trails, data minimisation, retention limits and compliance with data protection laws such as Nigeria's NDPA.
Data Controller vs Data Processor: Who Is Responsible?
When a bank or fintech uses a KYC provider, the usual arrangement is that the bank is the data controller and the provider is the data processor. That holds where the bank decides the purposes and essential means of processing, and the provider processes data on its behalf.
The roles are not always that simple. A provider may act as a separate or joint controller for some activities, such as its own fraud prevention, legal compliance, analytics or product improvement. Each activity should be mapped in the contract.
Where the provider is a processor, responsibility does not transfer with the data. Section 29(1) of theNDPA 2023 requires the controller to ensure the processor "complies with the principles and obligations set out in this Act." The processor must also apply appropriate security measures, help the controller respond to data subjects' rights, provide information needed to show compliance and notify the controller before engaging another processor.
Section 29(2) adds that these measures "include a written agreement between the data controllers and the data processor." The same applies between processors where one processor appoints another. In practice, this is the data processing agreement (DPA).
This is why compliance teams increasingly ask vendors how they protect data. Under the NDPA, a provider's weak security can become the bank's own compliance problem.
Snippet-ready answer: A data controller decides why and how personal data is processed. A data processor handles that data on the controller's behalf. When a bank uses a KYC provider, the bank is usually the controller and the provider the processor. Under Nigeria's NDPA, the controller must ensure its processor meets the Act's obligations.
Assess the Risk Before Processing Starts
Section 28(1) of the NDPA requires a DPIA before processing that "may likely result in high risk to the rights and freedoms of a data subject by virtue of its nature, scope, context, and purposes." The duty sits with the data controller.
Identity documents, facial matching, biometrics, automated risk scoring and large-scale onboarding may meet that threshold, depending on the exact processing. Before deploying a KYC or AML provider, the bank or fintech should assess whether section 28 applies. Where it does, the DPIA should be completed before processing begins and should record the safeguards used to reduce each risk.
Some KYC data may also count as sensitive personal data. Section 30 of the NDPA restricts processing of sensitive personal data unless a specified condition applies. Rather than assuming all KYC data is treated the same way, controllers should classify each data element and identify its lawful basis and safeguards.
How KYC and AML Providers Protect Customer Data
Section 39(1) of the NDPA requires controllers and processors to "implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data." What is appropriate depends on factors such as the amount and sensitivity of the data, the likely harm and the extent of processing. The measures below are common, risk-based safeguards rather than a fixed checklist.
Encryption
Encryption makes data unreadable to anyone without the decryption key. Strong providers encrypt data in transit, as it moves between systems, and at rest, while it is stored.
Section 39(2) of the NDPA says security measures "may include" pseudonymisation or other de-identification and "encryption of personal data." Advanced Encryption Standard (AES) with 256-bit keys, known as AES-256, is a widely used standard for data at rest.
Access Controls
Only people who need customer data for their job should be able to see it. Providers use role-based access control (RBAC), least privilege and multi-factor authentication to limit access, both inside their own team and within the client's platform.
An audit trail records who accessed or changed data, what they did and when. It allows both the provider and the client to investigate suspicious access and show compliance to a regulator.
Audit trails also protect the integrity of compliance decisions. They show who cleared an alert or approved a customer, which supportsAML case management and regulatory reviews.
Data Minimisation and Retention
Data minimisation means collecting only the data needed for a specific purpose. A provider that stores full identity document images when only a verification result is needed holds more risk than necessary.
Retention needs a clear rule. FATF Recommendation 11 generally expects transaction and customer identification records to be kept for at least five years, subject to national law. It does not set one universal period for every KYC document or AML record. In Nigeria, AML laws, Central Bank of Nigeria (CBN) and other sector rules, and contracts may set the period that applies. After that period, data should be deleted or anonymised rather than kept indefinitely.
Data Residency and Cross-Border Transfers
Where data is stored affects which laws apply to it. Section 41(1) of the NDPA prohibits transferring personal data outside Nigeria unless the recipient is subject to a law, binding corporate rules, contractual clauses, code of conduct or certification mechanism that "affords an adequate level of protection."
Section 41(2) also requires the controller or processor to "record the basis for transfer" and the adequacy of protection. Regional hosting alone does not make a transfer compliant. Businesses should know where their provider stores data, which countries it passes through and which transfer basis covers each flow.
Breach Detection and Notification
No system is immune to breaches, so response speed matters. Under section 40(1) of the NDPA, a processor must, "on becoming aware of the breach," notify "the data controller or data processor that engaged it." It must also respond to that party's information requests.
Under section 40(2), the controller must notify the Nigeria Data Protection Commission (NDPC) "within 72 hours of becoming aware of a breach which is likely to result in a risk to the rights and freedoms of individuals." Under section 40(3), where a breach is likely to result in a high risk to a data subject, the controller must "immediately communicate the personal data breach to the data subject in plain and clear language."
A contract can, and usually should, require the provider to notify the client much faster than the law requires.
Independent Certifications and Attestations
Security claims are easy to make and hard to verify. Independent certifications and attestations give buyers evidence that controls have been assessed.
ISO/IEC 27001 certification confirms that an organisation's information security management system has been assessed against the standard's requirements. It does not prove that every product or individual control is secure.
ISO/IEC 27018 provides guidance for protecting personally identifiable information in public cloud processing. ISO/IEC 42001 sets requirements for an artificial intelligence management system.
SOC 2 is an independent examination against the applicable Trust Services Criteria. A SOC 2 Type II report covers whether controls operated effectively over a defined review period. It is an attestation report, not a certification.
SOC 2 vs ISO 27001: What Is the Difference?
ISO 27001 certifies that an organisation's information security management system meets an international standard. It focuses on how the organisation identifies and manages security risk.
SOC 2 Type II is an auditor's report on whether specific controls operated effectively during a defined period. It focuses on evidence of control performance.
The two can complement each other, but neither is automatically enough. Buyers should compare scope, exclusions, systems covered, control objectives, the report period and any exceptions noted by the auditor.
Nigeria's Data Protection Rules for KYC Providers
The NDPA 2023 is Nigeria's main data protection law, enforced by the NDPC. Beyond the processor, DPIA, security, breach and transfer rules above, it sets significant penalties.
Under section 48, penalties depend on the organisation's category. A data controller or processor of major importance can face up to the "higher maximum amount," which is the greater of ₦10 million or 2% of annual gross revenue in the preceding financial year. Others can face up to the "standard maximum amount," the greater of ₦2 million or 2% of annual gross revenue.
The NDPC added detail through theGeneral Application and Implementation Directive (GAID) 2025. It was issued in March 2025 and took effect on 19 September 2025. GAID covers compliance audit returns, data protection officers, a standard DPIA template and requirements before deploying emerging technologies such as artificial intelligence.
KYC providers that use AI for document checks or face matching should be assessed under GAID's emerging-technology, privacy-risk and DPIA provisions. That does not mean every AI use triggers the same obligation. The assessment depends on the specific processing.
Vendor Due Diligence: Questions to Ask Your KYC or AML Provider
Vendor due diligence is the process of assessing a third party's risks before and during a business relationship. For KYC and AML providers, data protection should sit at the centre of that review.
Area
Question to ask
Evidence to request
Certifications
Which certifications and attestations do you hold, and what do they cover?
Current certificates with scope, issuing body and expiry; latest SOC 2 Type II report
Report scope
Does the SOC 2 report cover the product, environment and Nigerian data flows we will use?
SOC 2 system description and exceptions section
Processing instructions
What documented instructions govern how you process our data?
Data processing agreement
Encryption
How is data encrypted in transit and at rest?
Security documentation naming the standards used
Access
Who inside your company can access our customers' data, and how is it logged?
Access control policy, sample audit log
Confidentiality
What confidentiality obligations bind your staff and sub-processors?
Contract clauses, staff confidentiality terms
Data location
Where is our data stored and processed, and what transfer basis applies?
Data residency statement, transfer records
Sub-processors
Which sub-processors handle our data, and how much notice do you give before changes?
Current sub-processor list, change-notice terms
Data subject rights
Will you help us handle access, deletion, correction, portability requests and complaints?
DPA assistance clauses
Biometrics
Do you keep biometric templates, and can raw images be deleted after verification?
Biometric retention policy
AI models
How are AI models trained, tested and monitored, and is our data used for unrelated purposes?
AI governance documentation
Breach response
How quickly will you notify us of a breach?
Incident response policy with notification timelines
Resilience
What are your recovery-time and recovery-point objectives?
Business continuity and disaster recovery summary
Audit rights
What audit and inspection rights do we have?
DPA audit clauses
Exit
What happens to our data when the contract ends, including backups?
Deletion or return terms, certificate of deletion
Regulatory status
What is your registration or filing status with the NDPC and other authorities?
Evidence of registration or filing
A provider that cannot answer these questions clearly, or will not share evidence, presents a data protection risk the bank will eventually have to explain.
Snippet-ready answer: When assessing a KYC or AML provider, ask about certifications and their scope, encryption, internal access, data location and transfers, sub-processors, breach notification, retention, biometrics, AI use and exit terms. Request evidence, such as current certificates, a SOC 2 Type II report and a data processing agreement that meets NDPA requirements.
A Real-World Compliance Scenario
Consider a Nigerian fintech that onboards 50,000 customers a month through a KYC provider. A misconfigured storage server at the provider exposes identity document images.
The provider discovers the issue on a Monday but does not inform the fintech until Friday. That conflicts with section 40(1), which requires a processor to notify the party that engaged it on becoming aware of a breach.
If the fintech first became aware on Friday, its statutory 72-hour period would generally be assessed from Friday. But the provider's delay could still create contractual, regulatory and operational exposure. The fintech lost four days in which it could have contained the exposure and warned customers.
A data processing agreement with a clear, short notification deadline, checked during due diligence, would have reduced that risk.
Common Mistakes When Assessing a Provider's Data Protection
The first mistake is accepting a security page instead of evidence. A logo on a website is not the same as a current certificate or audit report.
The second is skipping the data processing agreement. Without one, the bank has little contractual control over how the provider handles data, and section 29(2) of the NDPA expects one.
The third is ignoring sub-processors. A provider's cloud host or biometrics partner may also handle customer data.
The fourth is treating due diligence as a one-off. Certifications expire, sub-processors change and providers move data. Reviews should be repeated regularly.
How Youverify Protects Customer Data
Youverify holds SOC 2 Type II attestation and ISO 27001, ISO 27018 and ISO 42001 certifications. Youverify is also registered with data protection authorities including the NDPC, Kenya's Office of the Data Protection Commissioner, South Africa's Information Regulator, Côte d'Ivoire's ARTCI and the UK Information Commissioner's Office.
Conclusion
When a bank or fintech hands customer data to a KYC or AML provider, it usually remains the controller of that data. The NDPA makes the controller's duties clear through its processor, DPIA, security, breach and transfer rules.
That makes data protection a core part of choosing a provider. Risk-based safeguards, scoped certifications, a signed data processing agreement and clear breach timelines are what to look for and insist on.
See How Youverify Protects Your Customers
If your team is reviewing for a KYC or AML provider who handles customer data the right way, book a free demo today.
Victoria Okere is a compliance content writer at Youverify, specializing in AML compliance, financial crime risk, regulatory technology, and emerging trends in financial services.
FAQs
Frequently Asked Questions
Customer data protection is the set of legal, technical and organisational measures a business uses to keep customers' personal information secure and used only for lawful purposes. It covers how data is collected, stored, accessed, shared and deleted, and it includes compliance with laws such as Nigeria's NDPA.
The seven principles most often cited come from the EU General Data Protection Regulation (GDPR): lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Nigeria's NDPA and GAID contain overlapping principles, and the NDPA also sets a duty of care on controllers and processors.
Organisations commonly group safeguards into administrative, technical and physical categories. Administrative safeguards cover policies, training and contracts. Technical safeguards cover encryption, access controls and monitoring. Physical safeguards cover facilities and hardware. This is a practical security framework, not a statutory list under the NDPA.
Customer due diligence (CDD) is the process of verifying and assessing customers to manage financial crime risk. Vendor due diligence (VDD) is the process of assessing suppliers and third parties before and during a business relationship. Banks need both: CDD on customers, and VDD on the KYC providers that help perform CDD.
Under section 40 of the NDPA 2023, a processor must notify the party that engaged it on becoming aware of a breach. The controller must notify the NDPC within 72 hours of becoming aware of a breach likely to risk individuals' rights and freedoms, and must tell affected individuals immediately where the risk to them is high.
Yes, where it acts as a processor. Section 29(2) of the NDPA says the controller's measures for overseeing a processor include a written agreement. It should cover processing instructions, confidentiality, security, sub-processors, assistance with data subject rights, breach notification, audit rights and deletion or return of data.