What the NDPA Trust Mark actually certifies, and what it does not
The Trust Mark is the clearest compliance signal available to an agent network. It is also widely misread. Here is what it covers, what it leaves to us, and why we publish the certificate rather than describing it.
Every agent who joins our network asks a version of the same question in the first ten minutes: is this outfit legitimate. It is the right question. Agent banking puts a person in a shop between a customer and their money, and the paperwork behind that arrangement is the only thing standing between a working network and a scandal.
The Nigeria Data Protection Act 2023 created an obligation and a visible marker of that obligation being met. We think the marker is worth explaining rather than simply displaying.
What it covers
The Trust Mark speaks to how an organisation handles personal data. In our case that data is unusually sensitive, because agent banking runs on identity: a BVN, a date of birth, a photograph, a fingerprint, an address. Certification means an assessment of how that information is collected, where it is stored, who inside the organisation can reach it, how long it is kept, and what happens when someone asks for it to be deleted.
- The lawful basis on which each category of data is collected
- Storage, retention periods and deletion routines
- Internal access controls, and which roles can see what
- The route a data subject takes to exercise their rights
- Breach notification procedure and timelines
What it does not cover
This is the part that gets skipped. The Trust Mark is not a banking licence. It says nothing about whether an organisation is authorised to handle transactions, and it is not a substitute for the CBN licence position that lets an agent network operate at all. An organisation can hold a valid Trust Mark and still have no business running an agent counter.
Why we publish the certificate
An unverifiable claim is weaker than a verifiable one. Writing “NDPA compliant” in a footer costs nothing and proves nothing. Publishing the certificate, with its issue and expiry dates visible, lets an aggregator put it in their own file and check it independently, which is what an aggregator evaluating us should be doing.
It also creates a useful pressure on us. A certificate with a visible expiry date is a commitment we cannot quietly let lapse.
What this means for an agent
Practically: the customer details you capture at your counter are governed. You are not free to keep a photograph of someone’s identification on your personal phone, or to note down BVNs in a book under the counter. Our onboarding covers this, and it is not bureaucratic decoration. It is the specific obligation the certification rests on.
The paperwork is not the opposite of the work. In this industry it is a precondition of it.
Written by Lukeport Compliance · Published 2 July 2026