Skip to content
ASIRI

Trust Center · the page your buyers read

The colour of the block is the basis, not the framework.

Certified, independently examined, self-assessed, still under way — four different things, and a page that renders them the same way is making its weakest claim look like its strongest. Here they cannot be confused at a glance.

trust.lagospay.ng
LPLagosPay's Trust Center
SubscribeAsk a questionRequest documents

How LagosPay handles personal data

Generated from the registers we keep for the Commission rather than written for this page — so it says what those registers say, including where that is uncomfortable.

ISO 27001Certifiedto 17 Sep 2027PCI DSSCertifiedto 3 Mar 2027NDPAIndependently examinedVeritas Data ComplianceSOC 2In progresswith Ernst & YoungGDPRSelf-assessednobody independent has checkedNIST CSFSelf-assessedno certificate exists for it

Two certified, two independently examined, one self-assessed, one still under way and claiming nothing yet. Certified means a body that can take it away issued it. Self-assessed is all anyone can do for GDPR — no certificate exists for it.

OverviewWhat we do 8Documents 11Updates 3Questions

Who we are

Published

LagosPay Limited, RC 1544019, registered with the Commission.

Registered RC 1544019Sector Financial services

Who to contact

Published

Tunde Adeyemi is the data protection officer. Write to dpo@lagospay.ng.

Named to the Commission yesReports to management twice a year

What we do with personal data

Published

12 activities are on the register, each with the lawful basis it rests on.

Activities 12Systems holding data 9

Where the data lives

Published

4 transfers leave Nigeria, each listed with the mechanism it rests on.

Transfers out of Nigeria 4

Who else touches it

Published

9 suppliers see personal data, all named.

Suppliers 9

How it is protected

Published

24 measures are in force, counted from the register rather than described.

Measures in force 24 of 31

When something went wrong

Not published

Not published. The board has not agreed a wording, and the November incident is the reason — which is the thing a reader would most want to know.

What you can ask us for

Published

Access, correction, erasure, objection and portability. Answered without undue delay, which is the standard the Act sets and the only one there is.

Rights honoured fiveAnswered Without undue delay
Generated by Asiri from LagosPay's own registers. The statements are theirs; what Asiri guarantees is that the figures match the registers on the date shown.Version 3 · published 2 Jul 2026 by Tunde Adeyemi · 1 section withheld

Four bases, four treatments

Three of these are not interchangeable, and one of them claims nothing at all

Asiri takes the wording from the assurance behind the claim, then colours the block to match. A reviewer scanning the row sees the basis before they read a word.

Certified

A body issued it, and can take it away

An accredited registrar examined you and put a number on it. Scope, number and expiry are all checkable with the issuer.

ISO 27001 · PCI DSS

Examined

Somebody reported on you

An independent firm looked and wrote it down, but there is no certificate to hold. The report is the whole of the assurance.

NDPA audit · SOC 2 report

Self-assessed

You checked yourself

Which is all anyone can do for GDPR, because no certificate exists for it. Saying so plainly is worth more than implying otherwise.

GDPR · NIST CSF

In progress

Claiming nothing yet

An observation window is open and a firm is engaged. Until the report is issued the badge asserts nothing at all, and says so.

SOC 2 · window closes 30 Jun

Updates · written by a person, not generated

Every post opens with the sentence a reviewer would decide on

Not the summary that flatters — the verdict. And each one names the register entries it touches, with the count already in them, which is the thing neither a blog nor a status page can do.

Incidents10 March 2026

3,100 agents were monitored without being told

This one is our fault, it affected 3,100 people, and it is not yet fixed.

Our anti-fraud system profiles agent behaviour continuously. The onboarding pack does not mention it, no separate notice exists, and none of the forty agents our auditor sampled had heard of it. On that basis all 3,100 are affected.

The monitoring continues in the meantime, because stopping it would leave the network exposed to the fraud it detects. That is a judgement we have made and we accept it is arguable. We are publishing this before the fix rather than after — a disclosure that only appears once it is safe to make is not a disclosure.

What this touches on our register

Anti-fraud screeningactivity register · 3,100 people
Finding F-002-3critical · open
Sub-processors18 July 2026

Kuda Collections declined an audit request, and what we did about it

Your data was not exposed. What we cannot yet show you is what happens to it after we hand it over.

Our auditor asked Kuda Collections for its processing logs, to test what happens to customer records after we pass them on. Kuda declined, citing its own confidentiality obligations. Two audit tests could not be performed at all.

All six erasure requests passed to Kuda in the period were deleted from our systems; we hold written confirmation for none of them. Our contract contains no right of audit — that is the underlying problem rather than their refusal. Our auditor has recorded it as a limitation on their opinion, and we are not asking for it to be softened.

What this touches on our register

Kuda Collectionssupplier register · 8,400 people
Two audit testsrecorded as could not be tested

Eleven documents, four levels of access

Two of them are named here and will never be sent to you

Listing a document you refuse to share, with the reason, tells a reviewer more than quietly omitting it. And a request is released by the company, never by Asiri — who asked, for what and why becomes part of their audit trail whichever way they decide.

Open

Downloadable now. No request, no NDA.

ISO/IEC 27001 certificate

Certificate · 2 pages · 18 Sep 2024

Data processing agreement, template

Agreement · 9 pages · 11 Feb 2026

Sub-processor list

Register · generated by Asiri · 2 Jul 2026
On request

Ask, and somebody there decides. Usually answered within two working days.

NDPA audit return, 2024

Audit file · 22 pages · includes the qualified opinion

DPO report to management, H1 2025

Report · signed by the officer
Under NDA

Ask, and sign a mutual non-disclosure agreement first. The agreement is the reason this can be shared at all.

ISO 27001 statement of applicability

Report · 34 pages · names the 2 excluded controls

PCI DSS attestation of compliance

Attestation · 12 pages · signed by the QSA

Penetration test summary, Q1 2026

Report · 8 pages · summary only
Not released

Named here so you know it exists. Not shared outside the company, and the reason is stated rather than left blank.

NDPA audit return, 2025

At review and unsigned — a draft opinion is not an outcome

Penetration test, full report

61 pages · names live weaknesses and where they sit

What Asiri will not do

It will not publish this page on your behalf

Asiri holds every register a trust page needs and could generate one for any company on it. It does not. A trust page is a statement a company chooses to make, and one produced without that choice would be Asiri's claim about them rather than their own.

Visit the address of a company that has not published, and the page says exactly that — then tells you the Act still gives you every right it describes, and to ask them directly.

Every publication is kept

Changes to this page

Version 32 Jul 2026

Supplier list regenerated and the security measures re-counted from the register. The incident section was held back for a board wording.

Version 214 Mar 2026

Added the transfer to the marketing platform in the United States, and the clauses it rests on.

Version 19 Feb 2025

First published, on registration with the Commission.

A page that moves silently underneath you cannot be cited later. This one carries a version, so it can.

Answer the security questionnaire once, in public

Most of what a buyer sends you is already on this page. Send the link, and what comes back is the handful of questions that genuinely need a person — which is a better meeting than the rest of them. Included from Growth up, on your own domain.