
Data protection has become a trending subject since the introduction of the EU GDPR. Several works in past literature focused on consumer behaviour towards privacy in the western context. However, little research has been done to ascertain the effectiveness of data protection regulation in emerging economies like Nigeria.
To cover the gap in the literature, this thesis explores the data protection practices in Nigerian travel agencies given the recently introduced Nigerian data protection regulation (NDPR).
A case study approach was adopted to gain deep insight into the data protection practices in Nigeria. The case study was carried on four travel agencies covering international student recruitment and leisure travel. A cross-case analysis of the themes generated from the interviews and desk research was discussed. The main findings suggest all four agencies were not fully compliant based on varying criteria. In addition, data collected from desk research suggests that out of 155 registered travel agencies, 59% did not have a data protection policy in place, 20% had a policy but only 3% were partly compliant due to lack of awareness of the Nigerian data protection regulation (NDPR). Hence, an implementation framework is proposed to aid effective data protection practice within organizations in Nigeria. This thesis concludes that more effort needs to be made in sensitizing data controllers and data subjects on the need for effective data protection practices. This research brings immerse benefits suggesting a possible improvement to NDPR regulation which affects all citizens of Nigeria. The implications of this research for the policymakers (Nigerian government), data controllers (travel agencies), data processors, and the data subject (consumers), limitation, and future research have been discussed appropriately.