Legal

GoalWin Data Security

Technical and organisational measures protecting personal data across the mobile/VAS channel and the direct goalwinit.com channel.

Effective Date: 1 August 2026
Document
GoalWin Data Security Statement
Issued by
EsTu Digital Limited, RC [RC NUMBER]
Scope
GoalWin platform, VAS channel (SMS/USSD/WAP/carrier billing) and direct channel (goalwinit.com PWA, wallet, KYC, payments)
Audience
Mobile network operator partners; the NDPC and its licensed DPCOs; sector regulators; enterprise partners; auditors; subscribers on request
Version
1.0
Effective date
1 August 2026
Review cycle
Annually, and on material change to architecture, threat landscape or regulation
Owner
Chief Technology Officer, countersigned by the Data Protection Officer
Approved by
[BOARD / MANAGEMENT COMMITTEE], [DATE]
Framework alignment
NDPA 2023 s.39; GAID 2025; ISO/IEC 27001:2022; NIST CSF 2.0; OWASP ASVS 4.0; PCI DSS v4.0 through certified processors
  1. 1.Purpose and standard

    Section 39 NDPA requires a data controller to implement appropriate technical and organisational measures, taking into account the state of the art, cost of implementation, and the nature, scope, context and purposes of processing.

    This Statement sets out how GoalWin meets that duty on both channels. It is written as evidence that an MNO partner's security team, a licensed DPCO, or a regulator can test against.

    The VAS channel and the direct channel run on the same platform, identity and access model, encryption, monitoring and incident process. What differs is the data they hold and therefore the blast radius.

    • VAS: mobile number, subscription and charging events, gameplay. Main risks are unauthorised charging, consent-record integrity, MSISDN exposure and interconnect compromise.
    • Direct: identity documents, biometrics, bank and card metadata, wallet balances. Main risks are account takeover, payout fraud, KYC data exposure and AML control failure.
    • Sections 3-13 are common to both. Sections 15 and 16 set out channel-specific controls.
  2. 2.Governance and accountability

    RoleAccountability
    Board / Management CommitteeOwns data protection and security risk, approves this Statement and the security budget, and receives quarterly risk reporting.
    Data Protection OfficerMaintains the RoPA, runs DPIAs, handles data subject requests and SNAGs, acts as NDPC contact point, and reports to the highest management level.
    Chief Technology OfficerOwns technical controls, architecture, the SDLC and this Statement.
    Head of Security / Security LeadOwns monitoring, vulnerability management, incident response and third-party technical assurance.
    Head of Compliance / MLROOwns KYC/AML controls, suspicious transaction reporting and gaming licence conditions on the direct channel.
    Every employee and contractorBound by Acceptable Use, Access Control and Incident Reporting policies. Reporting a suspected incident is a duty.

    Swipe sideways to see the full table →

    Governance artefacts we maintain

    • Record of Processing Activities covering both channels, reviewed quarterly and on every material change.
    • Data Protection Impact Assessments for the VAS service, biometric verification, fraud profiling and any new high-risk processing.
    • Legitimate Interest Assessments on the GAID template for every legitimate-interest basis we rely on.
    • Data classification standard, retention schedule and disposal register.
    • Asset and data-flow inventory, including every interconnect and every processor.
    • Risk register with named owners, treatment plans and dates.
    • Breach register, DSR register, NDPC registration and annual Compliance Audit Return where required.
    • Information Security, Access Control, Cryptography, Secure Development, Change Management, Vendor Risk, Incident Response, Business Continuity, Acceptable Use, Data Retention, Remote Working and Clear Desk/Clear Screen policies.
  3. 3.Data classification and minimisation

    ClassExamplesHandling rule
    RestrictedNIN, BVN, identity document images, biometric captures, bank account numbers, MSISDN, payment tokens, credentials, encryption keys, draw seedsField-level encryption; named, ticketed, time-bound access; every access logged and reviewed; never in logs, tickets, screenshots, chats or non-production.
    ConfidentialWallet balances, transactions, gameplay tied to an identity, support transcripts, consent records, fraud case filesEncrypted at rest; role-based access; pseudonymised in analytics; masked in support tooling by default.
    InternalAggregate metrics, de-identified analytics, architecture documentation, runbooksAccess limited to staff and contractors under NDA.
    PublicThis Statement, privacy notices, terms, leaderboard display names, published winner announcementsNo restriction.

    Swipe sideways to see the full table →

    Minimisation in practice

    • Collect late: KYC is requested at payout or when a threshold makes it necessary, not at registration.
    • Store the decision, not the evidence: biometric captures and document images are deleted within 30 days of a verification decision.
    • Pseudonymise by default for analytics, product tooling, dashboards, BI and MNO reporting.
    • Mask at the glass: support agents see masked mobile numbers and account details by default.
    • Never in test: production personal data is prohibited in development, staging, QA and demo environments.
    • Tokenise money: card PAN, CVV and PIN never enter GoalWin systems.
  4. 4.Identity and access management

    • Single sign-on with mandatory phishing-resistant multi-factor authentication for every internal system.
    • Role-based access on least privilege and need-to-know; access is denied by default.
    • Privileged and production data access is just-in-time, ticketed, approved by a second person, time-boxed, auto-revoked and session-recorded.
    • Break-glass accounts are held in escrow, alarm on use, and require post-use justification within 24 hours.
    • Named accounts only. Shared or generic credentials are prohibited.
    • Joiner-mover-leaver access is automated from HR and revoked within one hour of termination.
    • Quarterly access recertification by system owners.
    • Segregation of duties across deployment, draw administration, logging and payouts.
    • Secrets are held in a managed vault with automatic rotation and continuous repository scanning.
  5. 5.Cryptography

    ControlStandard
    In transit - publicTLS 1.2 minimum, TLS 1.3 preferred; modern cipher suites only; HSTS with preload; certificate transparency monitoring; automated renewal.
    In transit - internal and interconnectMutual TLS between services; IPSec site-to-site tunnels to MNO and aggregator interconnects; no unencrypted internal hop carries personal data.
    At restAES-256 for databases, object storage, backups and snapshots; encrypted volumes on every node.
    Field levelApplication-layer encryption for MSISDN, NIN, BVN, bank account numbers and payment tokens.
    Key managementManaged KMS/HSM; envelope encryption; annual rotation and rotation on suspicion of compromise.
    PasswordsSalted, memory-hard hashing such as Argon2id or bcrypt. Never reversible, logged or transmitted to support.
    Tokens and sessionsShort-lived, rotating, bound to device and audience; secure, HttpOnly, SameSite cookies; server-side revocation.
    OTPsSingle-use, short-lived, rate-limited, attempt-capped and never reusable across channels.
    Draw randomnessCertified RNG; seeds under dual control; seed and outcome written to append-only, tamper-evident logs.

    Swipe sideways to see the full table →

  6. 6.Infrastructure and network security

    • Cloud hosting in [HOSTING REGION] with an independently certified provider.
    • Segmented VPC architecture with public ingress, application, data and management tiers separated.
    • Default-deny security groups and network ACLs, including egress filtering.
    • WAF, managed DDoS protection, bot management, rate limiting and anti-automation.
    • Telco interconnects terminate on dedicated, IP-allow-listed endpoints over IPSec tunnels.
    • Administrative access is brokered through an identity-aware proxy with session recording.
    • Infrastructure as code is peer-reviewed and version-controlled.
    • Container images are immutable, minimal, scanned at build and continuously in the registry.
    • Continuous cloud security posture management alarms on drift and misconfiguration.
  7. 7.Secure development

    • Security requirements and privacy-by-design review are entered at design.
    • Mandatory peer code review; no self-merge to a protected branch; signed commits.
    • SAST, SCA, dependency, container, IaC, secret and licence checks run in the pipeline.
    • Critical or High findings fail the build.
    • DAST runs against staging on every release candidate.
    • Software Bill of Materials is produced per release; dependencies are pinned.
    • Changes are ticketed, tested, peer-approved, deployed through the pipeline and reversible.
    • OWASP ASVS Level 2 is the application baseline.
    • Server-side authorisation is checked on every object reference.
  8. 8.Logging, monitoring and detection

    • Centralised, structured logs are shipped to a write-once store.
    • Personal data is scrubbed and identifiers tokenised at the logging layer.
    • SIEM alerting covers privileged access, mass export, out-of-hours admin activity, authentication anomalies, impossible travel, draw-system access, payout anomalies and Restricted data access.
    • Anomaly detection monitors money flows and charging flows.
    • Logs are retained 12 months online and searchable, longer only for live investigation or regulatory hold.
    • Authoritative NTP is used across the estate.
    • Alert runbooks have named owners and response times.
  9. 9.Vulnerability and patch management

    SeverityInternet-facing SLAInternal SLA
    Critical (9.0-10.0)24 hours or same-day compensating control72 hours
    High (7.0-8.9)7 days14 days
    Medium (4.0-6.9)30 days60 days
    Low (0.1-3.9)90 days or accepted with a dated, owned risk decision90 days
    Actively exploited in the wildImmediate; emergency change pathImmediate

    Swipe sideways to see the full table →

    • Authenticated vulnerability scanning runs at least monthly.
    • Independent penetration testing covers the platform, API, PWA and telco interconnect at least annually and before major architectural change.
    • Findings are tracked to closure with retest.
    • Responsible disclosure reports go to [SECURITY EMAIL] and are acknowledged in 3 working days.
    • Threat intelligence is monitored for our stack, sector and region.
  10. 10.Resilience, backup and continuity

    ControlStandard
    ArchitectureMulti-availability-zone by default; stateless application tier; managed database with automated failover.
    BackupsAutomated, encrypted, separate account/region, immutable and object-locked against ransomware.
    RPO[15 minutes] for transactional data with point-in-time recovery enabled.
    RTO[4 hours] for the core service; [24 hours] for full functional restoration.
    Restore testingQuarterly restore from backup to a clean environment, timed and evidenced.
    Disaster recoveryDocumented plan with triggers, roles and communications; exercised at least annually.
    Business continuityBCP covers region loss, key vendor loss, interconnect loss and key personnel loss.
    Vendor concentrationExit and portability plans for each critical vendor.

    Swipe sideways to see the full table →

  11. 11.Third parties, processors and the supply chain

    • Due diligence before engagement covers security questionnaires, certifications, penetration test summaries, data location, sub-processor chain, breach history and financial standing.
    • Contracts include a written data processing agreement meeting section 29 NDPA.
    • Aggregator and sub-processors are bound to no lesser standard.
    • Critical vendors are reviewed annually and whenever risk materially changes.
    • A current sub-processor list is published at [SUB-PROCESSOR LIST URL].
    • Exit requires certified deletion or return of personal data plus revocation of every credential, key and network path.
  12. 12.Incident response and breach notification

    Severity and response

    SeverityDefinitionResponse
    SEV-1Compromise of Restricted data, unauthorised charging at scale, draw integrity compromise or total service loss.Immediate escalation to CTO, DPO and CEO. War room within 30 minutes.
    SEV-2Exposure of Confidential data, targeted attack, partial service loss or material subscriber impact.Escalation within 1 hour. Incident commander appointed. DPO assesses notifiability.
    SEV-3Contained security event with no confirmed data impact.Handled in-hours, logged and reviewed weekly.
    SEV-4Near miss, policy breach or control weakness found before exploitation.Logged and tracked.

    Swipe sideways to see the full table →

    Notification clocks

    RecipientTriggerDeadline
    Nigeria Data Protection CommissionPersonal data breach likely to risk rights and freedoms.Within 72 hours of becoming aware.
    Data subjectsBreach likely to result in high risk.Without undue delay, directly and in plain language.
    MNO partnerIncident affecting the VAS channel, subscriber data or interconnect.Within 24 hours of awareness.
    Payment processors, banks, sector regulatorsPer contract and licence condition.Typically 24-72 hours.
    Law enforcementCriminal conduct.Where appropriate and lawful.
    Cyber insurerPer policy.Per policy.

    Swipe sideways to see the full table →

    The process

    • Detect through automated alerting, staff reporting, researcher disclosure, partner or regulator notification.
    • Triage and classify within 30 minutes of a credible signal.
    • Contain by isolating, revoking, rotating and blocking.
    • Preserve evidence and chain of custody.
    • Assess notifiability against section 40 and document the reasoning.
    • Notify under the clocks above.
    • Eradicate and recover with validation that the entry route is closed.
    • Review within 10 working days with tracked corrective actions.
  13. 13.People

    • Pre-employment screening proportionate to role.
    • Confidentiality and data protection obligations in every employment and contractor agreement.
    • Security and data protection training at onboarding and at least annually.
    • Quarterly phishing simulation with coaching.
    • Documented disciplinary process for wilful or reckless breach.
    • Termination checklist revokes access within one hour, returns assets, rotates keys and reconfirms confidentiality obligations.
  14. 14.Endpoints and physical

    • Company-managed devices only for Confidential or Restricted data.
    • Full-disk encryption, EDR, automatic screen lock, patching and remote wipe on every endpoint.
    • No bulk export to local storage; removable media blocked by default.
    • DLP for Restricted patterns in outbound email and file-sharing.
    • Remote work uses the identity-aware proxy only.
    • Offices at [LAGOS OFFICE] and [PORT HARCOURT OFFICE] have controlled entry, visitor logging and secure paper destruction.
    • No production personal data is held on premises.
  15. 15.Channel-specific controls - VAS

    These controls exist because carrier-billed channels have specific failure modes: a subscriber who never agreed, a charge they cannot explain, and a number that leaks into somebody's marketing list.

    Consent integrity

    • Double opt-in is enforced in the platform, not campaign configuration.
    • Consent records are written to append-only, hash-chained logs at capture.
    • Charge attempts without a complete consent record are rejected by the billing service.
    • Daily automated reconciliation compares consent records, charge attempts and MNO settlement.
    • DND suppression is applied at send time against the current list.
    • STOP terminates billing at receipt and re-subscription requires fresh double opt-in.

    Interconnect and data handling

    • IPSec site-to-site tunnels with mutual authentication and IP allow-listing.
    • Interconnect terminates in a segregated network tier.
    • MSISDNs are field-encrypted at rest and pseudonymised on ingest.
    • The aggregator is a processor and barred from independent use of MSISDNs.
    • Interconnect health, latency and anomalous volume are monitored continuously.

    Assurances to MNO partners

    • Full consent audit trail producible per MSISDN within 24 hours.
    • Incident notification to the MNO within 24 hours.
    • Right to audit against this Statement.
    • Compliance with NCC Consumer Code of Practice Regulations 2024, DND directive and *305# VAS framework.
    • No sharing, resale or enrichment of MNO subscriber identifiers.
  16. 16.Channel-specific controls - Direct

    Account security

    • Argon2id password hashing and breached-password checking.
    • Two-factor authentication available to every user and mandatory above payout thresholds.
    • Rate limiting, progressive delays, CAPTCHA escalation and credential-stuffing detection.
    • Notifications on password, email, payout-destination, 2FA and new-device changes.
    • Cooling-off hold on withdrawals after payout destination or SIM/device change signals.
    • Session binding, server-side revocation and forced re-authentication for sensitive actions.

    Money and payments

    • No PAN, CVV or PIN on GoalWin systems.
    • Hosted fields and tokenisation at PCI DSS v4.0 certified processors.
    • Double-entry, append-only wallet ledger.
    • Payout initiation and approval are separated.
    • Idempotency keys on every money-moving operation.
    • Velocity, threshold and pattern monitoring on deposits and withdrawals.

    KYC and biometric data

    • Verification is performed by a licensed provider acting as processor.
    • Document images and biometric captures are encrypted, segregated and deleted within 30 days of decision.
    • Explicit, separate consent for biometric processing with a manual alternative.
    • KYC records are retained for the statutory AML minimum and locked to that purpose.

    Game and draw integrity

    • Certified RNG and dual-control seed custody.
    • Seed and outcome are hash-chained to a tamper-evident log before publication.
    • No role can view, alter, re-run or delay a draw.
    • Entry pools are frozen and hashed at close.
    • Independent periodic audit of RNG and draw execution.
    • Bot, collusion and multi-account detection with human review where prizes are affected.
  17. 17.Compliance calendar and assurance

    ActivityFrequencyOwner
    NDPC registration maintained; significant changes notifiedWithin 60 days of any changeDPO
    Compliance Audit Return filed with NDPCAnnually, by 31 MarchDPO
    NDPA compliance auditInitial audit within 15 months of registration; annually thereafterDPO + DPCO
    DPO semi-annual data protection report to managementTwice yearlyDPO
    RoPA reviewQuarterly and on material changeDPO
    DPIA review for high-risk processingAnnually and before material changeDPO + CTO
    Independent penetration testAnnually and before major architectural changeSecurity Lead
    Access recertificationQuarterlySystem owners
    Backup restore testQuarterlyCTO
    DR and incident-response exerciseAnnually, at least one unannouncedCTO + Security Lead
    Critical vendor re-assessmentAnnuallySecurity Lead
    Policy set reviewAnnuallyCTO + DPO
    Security awareness training; phishing simulationAnnually; quarterlyPeople + Security
    MNO partner security reviewAnnually or on requestCTO
    Risk register review at management levelQuarterlyManagement Committee

    Swipe sideways to see the full table →

  18. 18.Annex A - Obligation-to-control mapping

    ObligationSourceWhere met
    Lawful basis for every processing activityNDPA s.25Privacy notices and this Statement
    Data protection principlesNDPA s.24This Statement ss.3, 5, 8, 12; both privacy notices
    Transparency and privacy notice contentNDPA s.27; GAID Art. 25Both privacy notices
    Record of Processing ActivitiesNDPA s.28This Statement s.2.1
    Data Protection Impact AssessmentNDPA s.28; GAID Art. 28This Statement s.2.1
    Processor contractsNDPA s.29This Statement s.11
    Registration and CAR filingNDPA s.44; GAID Arts. 9-10This Statement s.2.1 and s.17
    DPO designation and reportingNDPA s.32; GAID Art. 13This Statement s.2
    Appropriate technical and organisational measuresNDPA s.39This Statement, entire
    Breach notificationNDPA s.40This Statement s.12.2
    Cross-border transfer safeguardsNDPA ss.41-43Privacy notices
    Cardholder data securityPCI DSS v4.0This Statement s.16.2

    Swipe sideways to see the full table →

  19. 19.Annex B - Consolidated retention schedule

    Deletion is scheduled, automated where possible, logged and verified by sampling. Where deletion is not technically possible within immutable backup rotation, the data is isolated and destroyed on the next cycle.

    RecordChannelRetentionTrigger
    Consent / opt-in / opt-out audit trailVAS7 yearsEnd of subscription
    Subscription and charging eventsVAS7 yearsEvent date
    Gameplay, predictions, scoresBoth24 months, then aggregatedLast activity
    Service messages and delivery receiptsVAS12 monthsSend date
    Account profile and credentialsDirectLife of account + 30 daysAccount closure
    Wallet ledger and transactionsDirect7 yearsTransaction date
    KYC records, identity data, AML documentationDirect5 years minimumEnd of relationship
    Identity document images; biometric capturesDirect30 daysVerification decision
    Verification decision, score, provider referenceDirect5 yearsDecision date
    Draw entries, outcomes, winner and payout recordsBoth7 yearsDraw date
    Marketing consent state and suppression entriesBothWhile the Service operatesObjection date
    Support and complaint recordsBoth5 yearsClosure
    Security, application and access logsBoth12 monthsLog date
    Breach register entriesBoth7 yearsIncident closure
    BackupsBoth90 days maximum rollingBackup date

    Swipe sideways to see the full table →

  20. 20.Annex C - Processor and sub-processor register

    Maintained current and published at [SUB-PROCESSOR LIST URL]. Complete before issue.

    ProcessorFunctionData categoriesLocationTransfer safeguardDPA dateLast review
    [Cloud provider]Hosting, storage, backupAll[Region][Adequacy / BCC + TIA][Date][Date]
    [VAS aggregator]SMS/USSD transport, chargingMSISDN, message payloadsNigeriaN/A - domestic[Date][Date]
    [SMS/email provider]Service and marketing messagingContact identifier, content[Region][Safeguard][Date][Date]
    [KYC provider]Identity and biometric verificationName, DOB, ID number, document image, biometric[Region][Safeguard][Date][Date]
    PaystackCard and bank payment processingTransaction data, tokenised methodNigeriaN/A - domestic[Date][Date]
    OPayWallet and payoutTransaction data, account referenceNigeriaN/A - domestic[Date][Date]
    [Analytics]Product analyticsPseudonymised usage events[Region][Safeguard][Date][Date]
    [Logging/SIEM]Log aggregation and detectionTokenised identifiers, technical data[Region][Safeguard][Date][Date]
    [RNG certifier / draw auditor]Draw integrity assurancePseudonymised entry pools, seed/outcome logs[Region][Safeguard][Date][Date]

    Swipe sideways to see the full table →

  21. 21.Document control

    This Statement is a public commitment. Where a control described here is not in place at the point of reading, that is a defect in our operations and we want to know: [SECURITY EMAIL].

    VersionDateAuthorChangeApproved by
    1.01 August 2026[CTO], countersigned [DPO]Initial issue[BOARD / MANAGEMENT COMMITTEE]

    Swipe sideways to see the full table →

This Statement is a public commitment. Where a control described here is not in place, that is a defect in our operations and we want to know.

Have a question about data security? Contact us.