Skip to content
ASIRI

NDPA modules · Children and age

A child becomes an adult the moment somebody types a date.

Every activity in your register says “no children”. Here is how that sentence stops being true, in three moves, none of which anybody noticed.

  1. Move one

    An agent types a date of birth

  2. Move two

    An adult account opens

  3. Move three

    Support finds out he is 16

Agent app · new customer

Agent paid ₦250 per sign-up
Full nameTobi Ajayi
Phone number+234 81… 9925
Date of birth

Nothing is checked against a document. The field accepts whatever the agent has time to type.

Core banking · two minutes later

Account opened

Adult limits · LP-8890-3341

Age recorded
36
Age verified
No
Parental consent
Not required
Added to marketing list
Yes

Every one of these answers is correct given what the form said. That is the problem with a typed field.

Support · four months later

Hi, I want to apply for the small loan but it keeps failing.

Let me check. Can you confirm your date of birth?

My mum has to do it with me — I'm 16.

PER-0308 · under 18, no parental consent, on the marketing list

Asiri raised it by reading the support conversation against the birth date on the account. Nothing else in your stack connects those two records.

The evidence

One date carries 214 of them

Birth dates on the 6,400 accounts an agent typed by hand, one bar per date. App sign-ups are excluded because NIN and BVN carry a verified date — only the typed ones are plotted here.

1 Jan1 Apr1 Jul1 Oct31 Dec

A typed field looks like this when nobody means it: an agent paid per sign-up reaches for the first date the keyboard allows. Some of those 214 people are children, and the register cannot say which.

Five ways in

Asking someone's age is not the same as knowing it

Two of your five entry points verify against a document that carries a date of birth. One asks a person to type it. Two ask nothing at all — and both of those feed the marketing list.

  • App sign-up

    Checks by NIN or BVN, which both carry a date of birth.

    Verified

    The strongest gate you have. An under-18 cannot pass it.

  • Agent-assisted sign-up

    Checks by an agent typing in a date of birth.

    Asked, never checked

    An agent paid per sign-up is the wrong person to check a birth date. This is where all 214 first-of-January accounts came from.

  • Junior savings product

    Checks by verifying the parent and naming the child.

    Lawful, unprovable

    Deliberately holds children’s data, which is permitted — but 1,890 parental consents are on paper in branches and none reach Asiri.

  • Website waitlist

    Checks by nothing at all.

    No check

    Email addresses only, so the risk is small — but it feeds the marketing list, and you cannot say none of those belong to a child.

  • Refer a friend

    Checks by nothing at all.

    No check

    Contacts are uploaded from a phone book. School contacts arrive this way, and nobody consented on their behalf.

Four findings, raised as findings

Each of these has an owner and a date, not a colour

A dashboard that turns amber tells you nothing about who is fixing it. These four sit in the same queue as everything else, and the two critical ones block the annual filing until they are resolved or consciously accepted.

  • 31 accounts state an age under 18

    All came through agent sign-up. Under the Act these need a parent’s consent, which you do not hold for any of them.

    critical
  • 214 accounts with a birth date of 1 January

    Typed rather than verified, so the real ages are unknown. Some of these people are likely to be children.

    high
  • Junior savings consent lives on paper

    1,890 parental consents in branch files, none recorded here, so none can be produced for the NDPC.

    high
  • The marketing list is not age-screened

    The lapsed-customer campaign sends to everyone on the list, including the 31 above.

    medium

What the Act actually asks

Holding children's data is allowed. Not knowing you hold it is not.

Your junior savings product is entirely lawful — a verified parent, a named child, a clear purpose. The problem there is filing, not principle: 1,890 parental consents sit in paper files in branches, so not one of them can be shown to the NDPC.

  • NDPA §31

    A child cannot consent for themselves

    Under 18, consent has to come from a parent or guardian — and you have to be able to show which one gave it, and when.

  • NDPA §31(2)

    Verification has to be proportionate

    You are expected to make a reasonable effort using available technology. Typing a date into a field is not a reasonable effort.

  • NDPA §24

    No marketing to a child on legitimate interest

    Which means an unscreened marketing list is a violation the moment one child is on it, regardless of what you sent.

  • NDPA §37

    Assess before you target children at all

    Any processing aimed at children needs an impact assessment first. Discovering them afterwards is the wrong order.

Plot your own birth dates before somebody else does

It is one read of one system, and it is the single fastest way to find out whether your register's most confident claim is true.