Legal

Compliance

Our commitment to the highest standards of regulatory and operational excellence.


Overview

At HIDDIKEL, compliance is not a checkbox. It is a core pillar of how we build, operate, and deliver infrastructure services to our enterprise clients. We understand that the businesses and organisations that trust us with their critical infrastructure operate in some of the most regulated and security-sensitive environments in Nigeria and across the region.

Our compliance framework is designed to give enterprise clients the confidence that their data, operations, and infrastructure are managed to the highest standards of security, privacy, and regulatory alignment at every layer of our platform.


Our Compliance Framework

HIDDIKEL's compliance programme covers four core dimensions: regulatory compliance, data protection, physical and operational security, and environmental and sustainability standards. Together, these dimensions form the foundation of a compliance posture that meets the demands of enterprise clients across financial services, telecommunications, healthcare, government, and beyond.


1. Regulatory Compliance

HIDDIKEL operates in full compliance with all applicable Nigerian and international laws and regulations governing the provision of digital infrastructure and data centre services.


Nigeria Data Protection Regulation (NDPR) 2019

HIDDIKEL is fully compliant with the Nigeria Data Protection Regulation, 2019, which governs the collection, processing, storage, and transfer of personal data in Nigeria. Our data protection practices are built around the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity.


Nigerian Communications Commission (NCC) Regulations

HIDDIKEL operates in compliance with the regulatory framework established by the Nigerian Communications Commission, ensuring that all connectivity, carrier, and network services delivered through our platform meet the standards required of licensed operators in Nigeria.


Central Bank of Nigeria (CBN) Guidelines

For clients in the financial services sector, HIDDIKEL's facilities and operational standards are aligned with the Central Bank of Nigeria's requirements for data centre infrastructure, including certification standards for the hosting of critical financial data and systems.


Nigerian Information Technology Development Agency (NITDA) Guidelines

HIDDIKEL supports and complies with NITDA's data localisation guidelines, which require that Nigerian businesses host their data within the country. Our platform is designed to help enterprise clients meet this requirement efficiently and without operational compromise.


ISO/IEC 27001 — Information Security Management

HIDDIKEL's information security management practices are aligned with the internationally recognised ISO/IEC 27001 standard, ensuring that our systems, processes, and controls meet the global benchmark for information security management.


Uptime Institute Tier Standards

Our facilities are designed and operated in alignment with Uptime Institute Tier Standards for data centre infrastructure, providing enterprise clients with independently verified assurance of our facility reliability, redundancy, and operational resilience.


2. Data Protection and Privacy

HIDDIKEL takes data protection seriously, not as a regulatory obligation alone, but as a fundamental commitment to the enterprises and individuals whose data passes through our infrastructure.

Our data protection framework is governed by our Privacy Policy and is built around the following principles:

  • Data is collected and processed only for clearly defined and legitimate purposes.
  • Personal data is stored securely, with access restricted to authorised personnel only.
  • Data retention periods are clearly defined, and data is securely deleted when no longer required.
  • Clients retain full ownership and control of their data at all times.
  • All data processing activities are documented and auditable.

For enterprise clients with specific data protection requirements, including sector-specific regulatory obligations, HIDDIKEL works directly with client teams to ensure that our infrastructure and operational practices support full compliance with applicable frameworks.


3. Physical and Operational Security

The physical security of our facilities and the operational integrity of our infrastructure are fundamental to our compliance posture. HIDDIKEL's facilities are designed and operated to meet the security standards demanded by enterprise clients in regulated industries.


Physical Access Controls

Access to our facilities is strictly controlled through multi-layer physical security measures, including biometric authentication, security personnel, CCTV surveillance, and access logging. All access events are recorded and auditable.


24/7 Security Operations Centre (SOC)

Our dedicated Security Operations Centre monitors all infrastructure, systems, and network activity around the clock, detecting, analysing, and responding to security threats in real time.


Incident Response

HIDDIKEL maintains a comprehensive incident response framework that defines clear procedures for the identification, escalation, containment, and resolution of security incidents. All incidents are documented, reviewed, and used to continuously improve our security posture.


Penetration Testing and Vulnerability Management

Our infrastructure undergoes regular penetration testing and vulnerability assessments to identify and address potential security weaknesses before they can be exploited. All findings are remediated in accordance with a risk-prioritised schedule.


Business Continuity and Disaster Recovery

HIDDIKEL maintains robust business continuity and disaster recovery plans that are tested regularly to ensure our ability to maintain operations and restore services in the event of a significant disruption. Our recovery time and point objectives are clearly defined and aligned with the expectations of enterprise clients.


4. Environmental and Sustainability Compliance

HIDDIKEL is committed to operating our infrastructure in an environmentally responsible manner and in compliance with all applicable environmental regulations and standards.

Our environmental compliance programme covers:

  • Energy efficiency and Power Usage Effectiveness (PUE) management.
  • Responsible waste management and disposal of electronic equipment.
  • Compliance with all applicable environmental regulations governing the operation of data centre facilities in Nigeria.
  • A long-term commitment to reducing our carbon footprint through investment in cleaner, more sustainable power sources.

We recognise that the data centre industry carries a significant environmental responsibility, and we are committed to operating our facilities in a manner that minimises environmental impact while delivering the reliability and performance our clients demand.


5. Supply Chain and Vendor Compliance

HIDDIKEL's compliance obligations extend to our supply chain and vendor ecosystem. We work only with vendors, partners, and suppliers who meet our standards for quality, security, and regulatory compliance. All third-party providers are subject to due diligence assessments before engagement and are required to maintain compliance with applicable laws and standards throughout the duration of their relationship with HIDDIKEL.


6. Audit and Assurance

HIDDIKEL supports enterprise clients in meeting their own audit and assurance requirements. We provide clients with access to relevant compliance documentation, facility audit reports, and performance data through our account management and support channels.

Our facilities and operational practices are subject to regular internal and independent external audits to verify compliance with applicable standards, certifications, and regulatory requirements. Audit findings are reviewed at the senior leadership level and used to drive continuous improvement across our compliance programme.


7. Compliance Certifications and Accreditations

HIDDIKEL maintains the following certifications and accreditations as part of our ongoing commitment to operational and regulatory excellence:

  • ISO/IEC 27001 — Information Security Management System
  • Uptime Institute Tier Certification — Facility Design and Operational Sustainability
  • Nigeria Data Protection Regulation (NDPR) Compliance — Data Protection and Privacy
  • CBN Data Centre Certification — Financial Services Infrastructure Standards

For enterprise clients requiring specific certification documentation or compliance evidence for their own regulatory obligations, please contact our compliance team directly.


8. Reporting a Compliance Concern

HIDDIKEL is committed to maintaining the highest standards of ethical conduct and regulatory compliance across all aspects of our operations. If you have a compliance concern, wish to report a potential breach, or require clarification on any aspect of our compliance framework, please contact our compliance team directly.

All compliance concerns are treated with the utmost seriousness, investigated promptly, and handled with full confidentiality.


Contact Our Compliance Team

For all compliance-related enquiries, audit requests, certification documentation, or regulatory questions, please contact us at:

  • Email: compliance@hiddikel.com
  • Support Portal: support.hiddikel.com
  • Address: HIDDIKEL Data Centre, Nigeria

HIDDIKEL's compliance programme is reviewed annually and updated to reflect changes in applicable law, regulation, and industry standards. Our commitment to compliance is not static; it evolves with the regulatory landscape and the expectations of the enterprise clients we serve.

Ready to Power Your Infrastructure?

Connect with our solutions team to discover how Hiddikel can support your enterprise with world-class data center services.