Nigeria Court: Your Contact's Consent Isn't Yours to Give

A Lagos High Court has drawn a line that could complicate how digital platforms build products from other people's contacts: one person's permission to share a phonebook does not automatically give a company permission to process the personal data of everyone in it. In a September 14, 2026 ruling seen by TechCabal, the court said Truecaller could not rely on a user's consent to process the phone numbers of people in their contacts who had never used the app. But it also denied damages to the people whose data was processed, creating a striking gap in Nigeria's emerging privacy regime.
The Consent Problem Nobody Wanted to Solve
The dispute centres on a feature of everyday digital life that most people rarely think about. You download a caller-identification app, grant it access to your contacts, and expect it to tell you who is calling. But the people saved in your phonebook may never have downloaded the app, accepted its privacy terms, or even heard of the company. Their names, numbers, and labels can nevertheless be added to a searchable database. That disconnect between the person who gives permission and the person whose data is exposed was at the heart of the case brought by the Incorporated Trustees of the Data Privacy Lawyers Association on behalf of members who did not use Truecaller. The applicants argued that the company harvested, stored, and disclosed their phone numbers without consent, violating their constitutional right to privacy and the Nigeria Data Protection Act of 2023.
What the Court Actually Decided
Under Sections 26 and 65 of the Nigeria Data Protection Act, consent must be voluntary, informed, specific, and unambiguous, and the data controller must demonstrate that valid consent was obtained. The court rejected the premise that one person could simply provide consent on behalf of everyone in their phonebook. Olumide Babalola, chair of the Nigerian Bar Association's Data Protection Committee and counsel involved in the litigation, told TechCabal: "You cannot use consent by implication or consent by proxy." Truecaller had argued it did not extract contact data from phones in Nigeria itself, that users could voluntarily upload contacts through an optional Enhanced Search feature, and that users represented they were authorised to share the information. The court's reasoning turned on whether the company could rely on a user's assurance as proof that non-users had consented. It said no.
The Damages Gap: Half Bread Is Still Bread
Although the court found Truecaller could not rely on the consent argument presented, it did not award damages. According to Babalola, the court did not find sufficient evidence that the applicants had suffered material harm from the disclosure of their numbers. That leaves the case with what he called "half bread." Privacy advocates gained an important declaration about the inadequacy of proxy consent, but claimants did not obtain a monetary remedy for the loss of control over their information or the anxiety of learning their numbers were searchable. The court's approach reflects a developing tension in Nigerian privacy litigation. The NDPA allows claims for injury or harm, but the concepts are not exhaustively defined. Courts are therefore being asked to decide whether a privacy injury exists only when it results in measurable financial loss, proven harassment, identity theft, or reputational damage, or whether unauthorised collection and disclosure of personal data is itself an actionable injury.
What This Means for Platforms and Users
The ruling does not on its own dictate the exact operational changes Truecaller must make. The applicants sought declarations, injunctions preventing further collection and processing, mandatory deletion of non-user data, and ₦300 million ($225,496) in general and exemplary damages. Yet the court's treatment of the consent issue raises a direct question: what lawful basis, if any, supports the continued processing of Nigerian non-users' telephone numbers when user-provided consent is insufficient? Truecaller may appeal, change its processing practices, rely on other legal grounds, or seek to clarify its position before regulators and courts. The case also presents difficult questions about jurisdiction, cross-border processing, and the legal status of technical safeguards such as hashing and deletion workflows. For companies that rely on contact lists, access to address books, or crowdsourced identity databases, the decision raises questions about how they obtain lawful consent. The important question is no longer merely whether an app obtains contact access from a user. It is whether the company receiving, storing and monetising information about non-users can independently show a lawful basis for doing so.
Key Takeaways
- A Lagos High Court ruled that one person's consent cannot justify processing another person's phone number under Nigeria's Data Protection Act.
- The court denied damages because applicants could not prove measurable harm, exposing a gap in Nigeria's privacy enforcement.
- The ruling departs from an earlier Federal High Court decision that treated users who uploaded phonebooks as controllers of non-users' data.
- Platforms relying on contact-list uploads now face a harder question: what lawful basis supports processing non-users' data?
- Nigerian courts have yet to settle how intangible privacy harms like loss of control or emotional distress should be valued.
Keep Reading


