
A recent ruling by the Lagos State High Court has raised important questions about how technology companies collect and process personal information belonging to people who never directly signed up for their services.
The case concerns Truecaller, the caller-identification and spam-detection platform, and its handling of phone numbers belonging to people who are not users of the application. On September 14, 2026, Justice N. O. Ojuromi of the Lagos State High Court held that consent given by a Truecaller user does not automatically amount to consent from people whose telephone numbers appear in that user’s contact list.
The issue arises from a familiar smartphone action: granting an application access to contacts. A user may give permission to access their phonebook, but the information contained there can belong to hundreds of other people who have never downloaded the app, accepted its terms or interacted with the company.
In the Truecaller dispute, applicants argued that processing and exposing their telephone numbers without their consent violated their privacy rights and lacked a lawful basis under Nigeria’s data-protection framework. Truecaller, however, argued that users could voluntarily upload contact information and represent that they had obtained the necessary consent from the people whose details were being shared.
The Lagos court rejected the central idea that this could amount to consent from non-users. Its reasoning focused on a basic principle of data protection: permission granted by one person should not automatically become permission to process another person’s personal data.
That distinction could have implications well beyond Truecaller. Many digital platforms use contact lists for features such as social discovery, messaging, caller identification, invitations and account matching. If companies cannot establish an appropriate legal basis for processing information belonging to people who never directly engaged with them, contact-book data could become a more complicated compliance issue.
Nigeria’s Data Protection Act 2023 places significant emphasis on lawful, transparent and purpose-specific processing. The Nigeria Data Protection Commission also identifies consent as one possible lawful basis and recognises data-subject rights including access, objection to processing, data portability and erasure.
The ruling also represents a significant development because an earlier Federal High Court case involving Truecaller had taken a different approach under the previous Nigeria Data Protection Regulation. That earlier decision accepted, in substance, that Truecaller could rely on representations made by its users concerning consent for contacts stored in their phonebooks. The Lagos State High Court’s 2026 reasoning moves away from that interpretation under the newer legal framework.
However, the ruling does not mean the applicants received every remedy they sought. Reports on the judgment indicate that the court did not award damages because the applicants did not establish the required harm.
The broader significance is therefore about accountability as much as compensation. The case puts pressure on digital platforms to consider whose data they are processing, what legal basis supports that processing and whether the person concerned actually received meaningful notice.
For Nigeria’s rapidly expanding digital economy, that distinction could become increasingly important. As apps turn personal data into valuable infrastructure, the question is no longer simply whether a user clicked “allow.” It is whether that permission legitimately covers everyone whose information sits behind that click.
Leave a Reply