NDPA modules · Children and age
A child becomes an adult the moment somebody types a date.
Every activity in your register says “no children”. Here is how that sentence stops being true, in three moves, none of which anybody noticed.
Move one
An agent types a date of birth
Move two
An adult account opens
Move three
Support finds out he is 16
Agent app · new customer
Agent paid ₦250 per sign-upNothing is checked against a document. The field accepts whatever the agent has time to type.
Core banking · two minutes later
Account opened
Adult limits · LP-8890-3341
- Age recorded
- 36
- Age verified
- No
- Parental consent
- Not required
- Added to marketing list
- Yes
Every one of these answers is correct given what the form said. That is the problem with a typed field.
Support · four months later
Hi, I want to apply for the small loan but it keeps failing.
Let me check. Can you confirm your date of birth?
My mum has to do it with me — I'm 16.
PER-0308 · under 18, no parental consent, on the marketing list
Asiri raised it by reading the support conversation against the birth date on the account. Nothing else in your stack connects those two records.
The evidence
One date carries 214 of them
Birth dates on the 6,400 accounts an agent typed by hand, one bar per date. App sign-ups are excluded because NIN and BVN carry a verified date — only the typed ones are plotted here.
A typed field looks like this when nobody means it: an agent paid per sign-up reaches for the first date the keyboard allows. Some of those 214 people are children, and the register cannot say which.
Five ways in
Asking someone's age is not the same as knowing it
Two of your five entry points verify against a document that carries a date of birth. One asks a person to type it. Two ask nothing at all — and both of those feed the marketing list.
App sign-up
Checks by NIN or BVN, which both carry a date of birth.
Verified
The strongest gate you have. An under-18 cannot pass it.
Agent-assisted sign-up
Checks by an agent typing in a date of birth.
Asked, never checked
An agent paid per sign-up is the wrong person to check a birth date. This is where all 214 first-of-January accounts came from.
Junior savings product
Checks by verifying the parent and naming the child.
Lawful, unprovable
Deliberately holds children’s data, which is permitted — but 1,890 parental consents are on paper in branches and none reach Asiri.
Website waitlist
Checks by nothing at all.
No check
Email addresses only, so the risk is small — but it feeds the marketing list, and you cannot say none of those belong to a child.
Refer a friend
Checks by nothing at all.
No check
Contacts are uploaded from a phone book. School contacts arrive this way, and nobody consented on their behalf.
Four findings, raised as findings
Each of these has an owner and a date, not a colour
A dashboard that turns amber tells you nothing about who is fixing it. These four sit in the same queue as everything else, and the two critical ones block the annual filing until they are resolved or consciously accepted.
- critical
31 accounts state an age under 18
All came through agent sign-up. Under the Act these need a parent’s consent, which you do not hold for any of them.
- high
214 accounts with a birth date of 1 January
Typed rather than verified, so the real ages are unknown. Some of these people are likely to be children.
- high
Junior savings consent lives on paper
1,890 parental consents in branch files, none recorded here, so none can be produced for the NDPC.
- medium
The marketing list is not age-screened
The lapsed-customer campaign sends to everyone on the list, including the 31 above.
What the Act actually asks
Holding children's data is allowed. Not knowing you hold it is not.
Your junior savings product is entirely lawful — a verified parent, a named child, a clear purpose. The problem there is filing, not principle: 1,890 parental consents sit in paper files in branches, so not one of them can be shown to the NDPC.
NDPA §31
A child cannot consent for themselves
Under 18, consent has to come from a parent or guardian — and you have to be able to show which one gave it, and when.
NDPA §31(2)
Verification has to be proportionate
You are expected to make a reasonable effort using available technology. Typing a date into a field is not a reasonable effort.
NDPA §24
No marketing to a child on legitimate interest
Which means an unscreened marketing list is a violation the moment one child is on it, regardless of what you sent.
NDPA §37
Assess before you target children at all
Any processing aimed at children needs an impact assessment first. Discovering them afterwards is the wrong order.
Plot your own birth dates before somebody else does
It is one read of one system, and it is the single fastest way to find out whether your register's most confident claim is true.