The Pan-African Paradigm of Digital Consent and Institutional Accountability
A single tap on a permissions screen in Lagos has just been ruled incapable of speaking for millions of strangers. In a September 14 judgment, a Lagos High Court found that Truecaller, the caller-identification platform used widely across Nigeria, could not rely on a user’s consent to process the personal data of everyone stored in that user’s phone contacts- the non-users who never opened the app, accepted its terms, or, in many cases, knew it existed. The ruling, brought by the Data Privacy Lawyers Association on behalf of affected non-users, is being described by the lawyer who argued the case as a declaration that consent by proxy has no standing under Nigeria’s 2023 Data Protection Act. For a continent still building the institutional and legal architecture to govern how multinational platforms extract value from African users’ data, the case is a meaningful marker: proof that domestic courts can draw hard lines against extraction models designed elsewhere and exported without full accountability to the jurisdictions where the data actually originates. Yet the court’s simultaneous refusal to award damages exposes how far that architecture still has to travel before legal victory translates into material redress. Reclaiming genuine data sovereignty will mean closing that gap between principle and remedy.
Consent That Cannot Travel
The legal question at the center of the case was narrow but consequential: can one person’s agreement to share their phonebook substitute for the consent of everyone listed inside it? The court said no. Under the Nigeria Data Protection Act, consent must be voluntary, informed, specific and unambiguous, and the burden falls on the data controller, in this case, Truecaller, to demonstrate that such consent was properly obtained. Olumide Babalola, chair of the Nigerian Bar Association’s Data Protection Committee and counsel in the case, put the court’s reasoning plainly: many non-users do not even know Truecaller exists, so they cannot have implicitly consented to a company whose existence is unknown to them. That principle reverses a 2019-era Federal High Court decision that had treated uploading users as the data controllers of their own contacts, a framing that had effectively shielded Truecaller by locating legal responsibility with individual phone owners rather than the platform harvesting and monetizing that data at scale.
What the Company Disputed
Truecaller’s defense rested on the claim that it does not extract contact data directly from Nigerian devices, relying instead on an optional feature through which users voluntarily upload contacts and represent that they hold authorization to share that information. The company also argued its caller-identification and spam-detection functions serve a public-safety purpose, and that non-users retain the option to request deletion of their data, after which the platform says it retains only a one-way hash to prevent reintroduction. The court’s ruling did not dismiss the public-safety rationale outright. Still, it rejected the deeper premise that a useful service automatically supplies its own lawful basis for processing data about people who never opted in, a distinction with implications well beyond Truecaller for any platform, from messaging apps to identity-verification services, built around contact-list access.
The Compensation the Law Did Not Deliver
Despite finding that Truecaller lacked a lawful basis for processing non-users’ numbers, the court declined to award the roughly two hundred and twenty-five thousand dollars in damages the applicants had sought, citing insufficient evidence of concrete harm. That outcome leaves claimants with what Babalola calls half bread: a legal declaration without financial remedy, and a broader unresolved question about whether intangible injuries, loss of control over personal information, exposure to unsolicited contact, and the anxiety of discovering one’s number is searchable constitute compensable harm under Nigerian law absent quantifiable financial loss. Nigerian courts have shown similar caution in related cases, including a 2018 Court of Appeal ruling that substantially reduced damages for unsolicited promotional messages despite finding a privacy breach, and a more recent case involving a bank’s data misuse that resulted in a token cost award rather than substantive compensation.
Toward Enforcement That Matches the Declaration
The Truecaller ruling establishes an important principle for how Nigerian courts will treat proxy consent in the future, and it may prompt scrutiny of other platforms whose products depend on contact-list access without direct engagement from every individual whose data ends up being processed. But a legal system that can identify unlawful data processing while consistently declining to compensate the people affected risks producing declarations that shift corporate behavior only marginally, since the financial incentive to redesign extractive business models remains muted without meaningful liability attached. Nigeria’s Data Protection Act is still young, and its courts are still calibrating how to value harms that resist easy financial quantification. This calibration will determine whether African data-protection law becomes a genuine deterrent against extraction, or a body of principled rulings that companies can absorb as a cost of doing business. Closing that gap, between the declaration secured in this case and the material accountability still missing from it, is the next test for Nigeria’s still-maturing privacy regime.

