Nigerian Court Rules Truecaller Consent Invalid for Non-Users' Data
A Lagos High Court has ruled that Truecaller cannot use a user’s consent to process the personal data of individuals in their contacts who have not used the app. The decision underscores strict requirements for **explicit, individual consent** under Nigeria’s Data Protection Act (NDPA) and raises questions about the country’s approach to compensating intangible harms.
LazyFounders

A Lagos High Court has ruled that Truecaller cannot use a user’s consent to process the personal data of individuals in their contacts who have not used the app. The decision underscores strict requirements for explicit, individual consent under Nigeria’s Data Protection Act (NDPA) and raises questions about the country’s approach to compensating intangible harms.
30 SEC SUMMARY
- A Lagos High Court ruled that Truecaller cannot use a user’s consent to process the personal data of non-users in their contacts, citing violations of Nigeria’s Data Protection Act (NDPA).
- The court found no lawful basis for Truecaller’s processing of non-users' data but denied damages due to lack of evidence of concrete harm.
- The ruling highlights gaps in Nigeria’s privacy laws, particularly regarding compensation for intangible harms like loss of data control.
- Truecaller disputed claims of unauthorized data extraction, stating users voluntarily uploaded contact information.
- The case raises questions about implied consent and cross-border data processing under Nigerian law.
TABLE OF CONTENTS
- Court Rejects Truecaller’s Consent Model for Non-Users
- No Lawful Basis for Processing Non-Users' Data
- Damages Denied, Exposing Gaps in Privacy Protections
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- A Lagos High Court ruled that Truecaller cannot rely on a user’s consent to process the personal data of individuals in their contacts who have not used the app.
- The court found no lawful basis for Truecaller’s processing of non-users' data under Nigeria’s Data Protection Act (NDPA).
- Damages were denied due to lack of evidence of concrete harm, revealing gaps in Nigeria’s approach to compensating intangible harms.
- Truecaller disputed claims of unauthorized data extraction, stating users voluntarily uploaded contact information.
- The ruling emphasizes that consent under the NDPA must be voluntary, informed, specific, and unambiguous.
Court Rejects Truecaller’s Consent Model for Non-Users
A Lagos High Court ruled that Truecaller, the caller-identification app, cannot rely on a user’s consent to process the personal data of individuals in their contacts who have never used the service. According to TechCabal, the court determined that one person’s permission to share their phonebook does not automatically grant Truecaller the right to process the data of everyone listed in it. This decision interprets Nigeria’s Data Protection Act (NDPA) of 2023 as requiring individual, explicit consent for data processing, not implied or proxied consent.
No Lawful Basis for Processing Non-Users' Data
The case centered on allegations that Truecaller harvested, stored, and disclosed phone numbers without the consent of individuals who had never used the app. According to TechCabal, the petitioners, represented by the Incorporated Trustees of the Data Privacy Lawyers Association, argued that this practice violated their constitutional rights and the NDPA.
The court agreed that Truecaller lacked a lawful basis for processing the data of non-users. Under the NDPA, consent must be voluntary, informed, specific, and unambiguous. Olumide Babalola, Chair of the Nigerian Bar Association’s Data Protection Committee, emphasized in the ruling that "You cannot use consent by implication or consent by proxy." He added that many non-users are unaware of Truecaller’s existence, making implied consent impossible.
Truecaller disputed the claims, stating that users voluntarily uploaded contact information through an optional feature. The company also noted it has no Nigerian office, servers, or operational facilities, with its technical infrastructure based in India.
Damages Denied, Exposing Gaps in Privacy Protections
While the court ruled against Truecaller’s data processing practices, it denied the applicants’ request for ₦300 million ($225,496) in damages. According to TechCabal, the court found no sufficient evidence of concrete harm resulting from the disclosure of phone numbers.
This decision highlights a critical gap in Nigeria’s emerging privacy regime: the lack of clarity on compensating intangible harms. The court’s ruling suggests that unauthorized data collection and disclosure, while unlawful, may not be considered an actionable injury in Nigeria unless tangible harm is proven. Babalola’s remarks reflect this tension, noting that Nigerian courts have yet to establish how to value harms like loss of control over personal data, emotional damage, or loss of autonomy.
What this means
LazyFounders analysis — our interpretation, not reported fact.
This ruling is a wake-up call for startups and tech companies operating in Nigeria—or those processing data of Nigerian users—about the strict interpretation of consent under the Nigeria Data Protection Act (NDPA).
For founders, the key takeaway is that consent cannot be assumed, implied, or proxied. If your product relies on processing contact lists, address books, or other third-party data, you must ensure that every individual whose data is processed has given explicit, informed, and voluntary consent. This is not just a legal formality; it’s a fundamental requirement under the NDPA, and courts are increasingly scrutinizing it.
The denial of damages also reveals a broader challenge: Nigerian privacy laws currently lack clear mechanisms for compensating intangible harms, such as loss of control over personal data. This creates uncertainty for both users and companies. Founders should proactively mitigate risks by adopting stricter data collection practices, documenting consent meticulously, and ensuring compliance with cross-border data transfer rules.
For startups with global operations, this case underscores the importance of aligning with local data protection laws—not just in Nigeria, but in any market where user data is processed. Ignoring these requirements could lead to legal challenges, reputational damage, and operational disruptions.
Key takeaways
- Truecaller cannot rely on a user’s consent to process the personal data of non-users in their contacts under Nigeria’s Data Protection Act.
- The court found no lawful basis for Truecaller’s processing of non-users' data but did not award damages due to lack of evidence of harm.
- Nigeria’s privacy laws currently lack clear frameworks for compensating intangible harms like loss of data control.
- Startups must ensure explicit, informed, and voluntary consent for all individuals whose data is processed, not just their users.
- Cross-border data processing adds complexity, requiring companies to comply with local laws in every market they operate.
FAQ
What does the Nigeria Data Protection Act (NDPA) require for consent?
The NDPA requires consent to be voluntary, informed, specific, and unambiguous. This means companies cannot rely on implied or proxied consent, such as a user granting permission to process their entire contact list.
Why did the court deny damages in this case?
The court denied damages because the applicants did not provide sufficient evidence of concrete harm resulting from the disclosure of their phone numbers. Nigerian privacy laws currently lack clear frameworks for compensating intangible harms like loss of data control.
How does this ruling affect startups processing contact data?
Startups must ensure that every individual whose data is processed has given explicit consent. Relying on a user’s permission to process their contacts is insufficient under the NDPA, and non-compliance could lead to legal challenges.
Does Truecaller have operations in Nigeria?
According to reports, Truecaller has no Nigerian office, servers, or operational facilities. Its technical infrastructure is based in India, which adds complexity to cross-border data processing compliance.
Related on LazyFounders
Sources
- TechCabal · 2026-09-23
A Nigerian court says Truecaller’s consent doesn’t cover the data in your contacts
This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.


