The Rainbow Strategy’s four-day training for Abia State senior officials points to a larger shift in Nigeria’s digital economy: protecting citizens’ data is moving from the IT department into the boardroom and the machinery of government.
Data protection is often treated as a technical problem. Passwords must be secured, databases protected and breaches reported. But as governments digitise the delivery of public services, the more important question is becoming who is accountable when the information being collected, processed and shared belongs to millions of citizens.
That question was at the centre of a four-day Data Protection Compliance Awareness Training Programme conducted by The Rainbow Strategy for directors and senior officials of the Abia State Government. Convened through the Office of the Chief Information Officer to the Governor and inaugurated by the Commissioner for Budget and Planning, Kingsley Ndidi Anosike, the programme brought together officials from key ministries, departments and agencies. It concluded on September 14, 2026, with the Chief Information Officer, Gerald Ilukwe, closing the programme on behalf of Governor Alex Otti.
The significance lies less in the four days of classroom instruction than in what the programme reveals about the changing economics and governance of public-sector data. Abia is collecting and processing information through systems covering civil-service identification, taxation, education and healthcare. Each additional digital service expands not only the state’s capacity to deliver services but also its exposure to privacy breaches, unauthorised access and regulatory risk.
From Compliance to Corporate-style Governance
The programme was undertaken against the framework of the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025. More importantly, its design
placed responsibility at directorate and senior-management level rather than treating data protection as a specialist function to be delegated downwards. That distinction matters.
In a traditional public-sector bureaucracy, compliance can easily become a document on a shelf, an annual seminar or the responsibility of a legal or information-technology officer. Data governance makes that model increasingly difficult to sustain. A tax authority deciding what information to collect, a hospital digitising patient records or an education ministry operating an online learning platform is making data-governance decisions whether or not it calls them that.
Abia’s approach therefore has a distinctly managerial character. The programme combined legal and regulatory instruction with data-subject rights, breach management, Data Protection Impact Assessments, audit protocols and governance frameworks. Participants were also expected to leave with ministry-specific compliance action roadmaps and a data-protection toolkit rather than simply a certificate of attendance.
That is an important difference between training people about compliance and designing an organisation capable of complying.
Why the Sector-Specific Approach Matters
The most interesting element of the programme was its attempt to connect data protection to the actual business of government.
The Finance Ministry’s sessions examined systems involving ABSSIN, payroll and tax administration. Education officials dealt with student registries and e-learning platforms, including the additional considerations surrounding children’s data. Health officials considered telemedicine, biometric health information and medical-data breaches, while Justice officials examined litigation records, witness and victim information and inter-agency data sharing. This is where data protection ceases to be an abstract regulatory obligation.
A citizen’s tax record is an economic asset. A patient’s medical record is highly sensitive information. A child’s educational profile can follow that child for years. A civil-service database can contain identity, employment and financial information. The value of digitisation is therefore inseparable from the responsibility to govern the information created by it.
The CIO’s observation captures the issue neatly: “A digital government that grows without growing its data governance is not a stronger government – it is a more exposed one.”
The Emerging Economics of Data Risk
There is a wider business lesson here. Organisations have traditionally thought about assets in physical terms – buildings, equipment, cash and infrastructure. Digital transformation has changed that equation. Databases, customer records, behavioural information and transaction histories can now be among an organisation’s most strategically valuable assets.
But data has an unusual characteristic: the same information that creates value can also create liability when it is poorly governed. That is why the statement by Abia’s CIO that personal data should be regarded as a strategic asset rather than merely information is more than a matter of
semantics. It reflects a fundamental principle of digital governance: an asset without adequate protection can become a source of financial, legal and reputational exposure.
For businesses dealing with government, the implications are equally significant. Contractors, technology providers, consultants, financial institutions and other vendors may have access to public-sector information. Data protection therefore extends beyond the government agency itself into the wider ecosystem of suppliers and service providers.
The Rainbow Strategy’s emphasis on vendor accountability in its programme reflects this increasingly important dimension of data governance.
Abia’s most consequential commitment may be what comes next
Perhaps the most significant announcement in the programme was not the training itself but the commitment by the Office of the Chief Information Officer to establish a permanent State Data Privacy Service Unit. The stated intention is to create governance infrastructure that survives changes in individual personnel and carries data-protection responsibilities into the state’s continuing digital development. That is an important test.
Training can raise awareness. A permanent institutional structure can turn awareness into process, accountability and continuity.
The real measure of the programme will consequently not be how many directors attended the four-day exercise. It will be whether privacy requirements subsequently become embedded in procurement, technology deployment, vendor management, system design, staff responsibilities, incident response and executive decision-making. In other words, compliance becomes meaningful when it changes how an organisation operates.
BrandiQ Analysis: What the Abia Initiative Signals
The first signal is that data governance is becoming a leadership issue. Governments are among the largest custodians of personal information, and their digital transformation programmes are expanding the volume and sensitivity of that information. Leaving data protection exclusively to IT specialists or compliance officers is increasingly difficult to justify.
The second is that Nigeria’s data-protection market is likely to become more institutionalised. As organisations move from awareness to implementation, demand should increasingly centre on impact assessments, audits, privacy-by-design, breach management, vendor due diligence, data governance structures and continuing executive education. The Rainbow Strategy itself describes its service offering in these terms, including Data Protection Impact Assessments, annual compliance audits, DPO-as-a-Service and regulatory advisory.
The third is that digital transformation without governance creates a paradox. The more successfully a state digitises taxation, healthcare, education and administration, the more valuable its information infrastructure becomes – and the greater the consequences of getting data governance wrong. Digital maturity and privacy maturity therefore need to develop together.
The fourth is the importance of institutional memory. The proposed permanent State Data Privacy Service Unit is potentially more consequential than a one-off training programme
because government systems survive individual administrations and officials. A governance mechanism that is embedded in the institution has a better chance of surviving personnel changes than knowledge that resides primarily with individuals.
Finally, the Abia programme points towards a broader question for Nigeria’s states. If one state begins systematically embedding data protection into digital government, procurement and administrative processes, the issue stops being simply one of regulatory compliance and becomes part of the quality of public administration itself. The Rainbow Strategy describes the programme as a model that could be replicated across the other states and the FCT; that is an organisational aspiration rather than an established national outcome, but the structure of the programme provides a practical template for considering such replication.
BrandiQ Takeaway
The important story in Abia is not that government officials attended a data-protection course. It is that data has become too important to be governed casually.
As governments and businesses build increasingly digital relationships with citizens and customers, privacy is becoming part of institutional reputation, operational risk and ultimately trust. A tax platform that makes revenue collection more efficient, a hospital system that makes patient care more accessible or an education platform that expands learning all create value-but only if the information supporting those systems is responsibly governed.
For Nigeria’s emerging digital economy, that may be the real test of data maturity: not simply how much data an organisation can collect, but whether it has built the governance capacity to deserve the trust that comes with collecting it.
Abia’s experiment is therefore worth watching – not merely as a compliance exercise, but as an early example of what data-governed digital government could look like at the sub-national level.
Abia’s Data Protection Push: Why State Governments Are Turning Privacy into a Governance Issue
Martin Ogumah, is BrandiQ Head of Content Assets and Marketing. He is a graduate of sociology, with a master’s degree in political science, and over 15 years’ experience in content development, marketing and public relations.
Leave a Comment



