This legal thesis evaluates the adequacy and effectiveness of the Nigerian legal framework in regulating the deployment of Artificial Intelligence (AI) and automated systems within the education sector. It specifically investigates how laws like the Nigeria Data Protection Act (NDPA) 2023 and the 1999 Constitution protect students' personal/biometric data and guarantee legal accountability and fair hearing when automated systems make high-stakes decisions regarding grading, admissions, and misconduct flagging.
Key Focus & Core Issues Addressed
Algorithmic Opacity & Due Process: Analyzes the risks posed by "black-box" assessment tools used by examination bodies (e.g., JAMB, WAEC) where students are subjected to automated decisions without clear explanations or direct mechanisms to challenge errors.
Student Data Privacy & Minors: Evaluates the vulnerabilities surrounding the harvesting of biometric, behavioral, and academic data, particularly for minors, under Section 31 (Children's Data) and Section 37 (Automated Decision-Making) of the NDPA 2023.
Diffusion of Responsibility: Examines the confusion regarding legal liability between data controllers (educational bodies) and software vendors (data processors) when systemic software or grading failures occur.
Theoretical Framework & Methodology
Research Approach: Doctrinal legal research integrated with a comparative legal analysis (juxtaposing Nigerian legislation with the EU GDPR, EU AI Act, and UNICEF/UNESCO frameworks).
Underpinning Theories: Grounded in the Theory of Informational Self-Determination, Algorithmic Accountability Theory, the Best Interests of the Child Principle, and Constitutional Due Process (Fair Hearing) under Section 36 of the Nigerian Constitution.
Primary Findings
Generic Regulatory Approach: Existing frameworks (NDPA 2023, Cybercrimes Act) are broad and lack education-specific enforcement rules or guidelines tailored to student realities.
Untested Rights & Accessible Remedy Gap: While Section 37 of the NDPA provides rights against solely automated decision-making, these rights remain largely untested in Nigerian courts, leaving affected students with limited practical remedies.
Lack of High-Risk Classification: Unlike the EU AI Act (Annex III), Nigeria does not officially classify educational and assessment AI tools as high-risk technologies requiring mandatory pre-deployment impact assessments.
Core Recommendations
Sector-Specific AI Code of Conduct: Recommends that the NDPC issue tailored guidelines for AI usage in education, leveraging UNESCO and UNICEF child-rights guidance.
High-Risk Classification & Mandatory DPIA: Suggests presumptively classifying all automated systems processing minors' data as high-risk, making Data Protection Impact Assessments (DPIAs) mandatory.
Clear Fair-Hearing Procedures: Establishes that examination bodies must create formal "notice-and-hearing" channels before penalizing or failing candidates based on algorithmic or biometric flags.