Privacy policy
Our Privacy Policy
At CardinalStone Pensions, your privacy is our priority. We are committed to safeguarding your personal information and being transparent about how we collect, use, and protect your data. This Privacy Policy outlines our practices regarding your information and your rights under applicable data protection laws.
CardinalStone Pensions Limited (“we”, “us”, “our”) is a Pension Fund Administrator licensed by the National Pension Commission (PenCom), registered in Nigeria with RC No.: 717566, with registered address at 12A Adeola Hopewell, Victoria Island, Lagos.
We are the Data Controller in respect of your personal data processed in connection with your pension account and our digital services.
Data Protection Officer (DPO):
Email: dpo@cardinalstonepensions.com
Phone: 07060522249
Address: 12A Adeola Hopewell, Victoria Island, Lagos
Response: within 5 working days
Regulatory supervisor: Nigeria Data Protection Commission (NDPC) — info@ndpc.gov.ng
We collect and process the following categories of personal data:
Identity and contact data: Full name, date of birth, gender, residential and correspondence address, telephone numbers, email address, and next-of-kin details.
Government-issued identity data: National Identification Number (NIN), Bank Verification Number (BVN), international passport number, driver’s licence number, or voter’s card number.
Employment and financial data: Employer name and address, salary and grade information, pension contribution amounts, RSA/PPP account numbers, bank account details, and transaction history.
Sensitive / special category data: Biometric reference data (via NIN linkage); health or disability information where voluntarily provided in support of a benefit application. See section 4 for the additional safeguards applicable to this category.
Digital and technical data: IP address, browser type and version, device identifiers, pages visited, time and duration of visits, and cookie identifiers. See section 7 for our cookie policy.
We process your personal data only where a lawful basis under the Nigeria Data Protection Act 2023 (NDPA) applies. The table below sets out each purpose and the applicable basis:
Purpose | Lawful basis (NDPA s.2) |
Opening and managing your RSA/PPP account | Performance of contract |
Processing contributions and benefit payments | Performance of contract |
PenCom, NRS, and MLPA regulatory compliance | Legal obligation |
Fraud detection and transaction monitoring | Legitimate interests (fraud prevention) |
Service improvement and analytics | Legitimate interests / consent |
Marketing and newsletter communications | Consent (freely given, revocable) |
Identity verification and KYC | Legal obligation (PRA 2014, MLPA 2022) |
Where we process sensitive personal data (including biometric reference data linked to your NIN, or health and disability information submitted in support of a benefit application), we do so only on the following additional grounds:
(a) your explicit consent;
(b) the establishment, exercise, or defence of legal claims; or
(c) compliance with obligations under employment and social security law, including the Pension Reform Act 2014.
We apply enhanced access controls, encryption, and audit logging to all special category data.
We implement appropriate technical and organizational security measures including:
(a) AES-256 encryption of personal data at rest and TLS 1.3 in transit;
(b) role-based access controls with multi-factor authentication on all systems processing personal data;
(c) annual third-party penetration testing and quarterly vulnerability scanning;
(d) ISO 27001-aligned information security management system;
(e) binding Data Processing Agreements with all vendors and sub-processors;
(f) mandatory employee data protection training on appointment and annually thereafter; and
(g) a documented, board-approved incident response plan, tested biannually.
No method of transmission over the internet is completely secure. In the event of a confirmed personal data breach, we will notify the NDPC within 72 hours and affected individuals without undue delay, as required by NDPA 2023 s.40(3).
We share your personal data only in the following circumstances and with the following categories of recipient, each bound by a Data Processing Agreement:
Regulatory and statutory bodies: PenCom, NDPC, NRS, NFIU, and other regulators as required by law.
Pension infrastructure: PCRS, licensed custodian banks, and Transfer Window operators.
Technology and cloud service providers: Hosting, cybersecurity, and application support partners operating under binding data processing agreements.
Digital analytics and marketing platforms: Website analytics providers, subject to standard contractual clauses where processing occurs outside Nigeria.
Identity verification services: NIMC-accredited KYC and identity verification providers.
We will never sell your personal data to third parties for commercial purposes. A current list of our data processors is available on written request to the DPO.
International transfers: Where we transfer personal data outside Nigeria, we do so only to jurisdictions designated as adequate by the NDPC, or under NDPC-approved standard contractual clauses, or with your explicit consent.
Data category | Retention period | Basis |
RSA / PPP account records | Relationship + 10 years | PRA 2014 s.85; PenCom guidelines |
Identity documents (NIN, passport) | Relationship + 7 years | NRS; MLPA 2022 |
Transaction / contribution records | 10 years from transaction | PRA 2014; FIRS |
Digital / analytics data | 13 months | GAID 2025 Art.22; consent |
Marketing consent records | 3 years from last engagement | NDPA 2023 s.2.1(a) |
Complaints records | 6 years from resolution | Limitation Act |
Under the NDPA 2023, you have the following rights. Contact our DPO to exercise any right. We will respond within one (1) month, extendable to three months for complex requests:
Right to access (s.34) — Request a copy of the personal data we hold about you.
Right to rectification (s.36) — Request correction of inaccurate or incomplete data.
Right to erasure (s.37) — Request deletion, subject to retention obligations under pension and tax law.
Right to restriction (s.39) — Request limitation of processing in specified circumstances.
Right to data portability (s.38) — Receive your data in a structured, machine-readable format.
Right to object (s.39) — Object to processing based on legitimate interests or for direct marketing.
Right not to be subject to automated decisions (s.40) — Request human review of any automated decision producing legal or significant effects on you.
Right to withdraw consent (s.35) — Withdraw consent at any time without affecting prior processing.
Right to complain — Lodge a complaint with the NDPC (info@ndpc.gov.ng) or PenCom.
We may use automated tools to assist with fraud detection, transaction monitoring, and regulatory screening. No decision producing a legal or similarly significant effect on you will be made solely by automated means without human review. You have the right to request human intervention, express your view, and contest any such decision. Contact our DPO to exercise this right.
We use cookies and similar technologies. We categorize these as strictly necessary (no consent required), functional, analytics, and marketing. We will not place analytics or marketing cookies without your prior, freely given consent. Manage your preferences via our Cookie Preferences Centre or withdraw consent at any time. See our full Cookie Policy for a complete list of cookies, purposes, and retention durations.
We review this Notice at least annually and following any material change to our processing activities or applicable law. The effective date and version number at the top of this page will be updated on each revision. We will notify you of material changes by email or prominent notice on our website.