A Lagos High Court has drawn a line that could complicate how digital platforms build products from other people’s contacts: one person’s permission to share a phonebook does not automatically give a company permission to process the personal data of everyone in it.
In a September 14, 2026, ruling seen by TechCabal, the court said Truecaller could not rely on a user’s consent to process the phone numbers of people in their contacts who had never used the app.
But it also denied damages to the people whose data was processed, creating a striking gap in Nigeria’s emerging privacy regime: a company can lack a lawful basis to process someone’s data, while that person may still receive no compensation without proving concrete harm.
The ruling is therefore both a warning to digital platforms and a test of how far Nigerian privacy laws can go in protecting people who never agreed to be part of a digital service. For companies that rely on contact lists, access to address books or crowdsourced identity databases, the decision raises questions about how they obtain lawful consent. For individuals, it raises another question: what remedy exists when their personal information is used without their knowledge, but the harm is difficult to quantify?
The dispute centres on a feature of everyday digital life that most people rarely think about. You download a caller-identification app, grant it access to your contacts, and expect it to tell you who is calling. But the people saved in your phonebook may never have downloaded the app, accepted its privacy terms, or even heard of the company. Their names, numbers, and labels can nevertheless be added to a searchable database.
That disconnect between the person who gives permission and the person whose data is exposed was at the heart of the case brought by the Incorporated Trustees of the Data Privacy Lawyers Association on behalf of members who did not use Truecaller. The applicants argued that the company harvested, stored, and disclosed their phone numbers without consent, violating their constitutional right to privacy and the provisions of the Nigeria Data Protection Act (NDPA) of 2023.
Truecaller disputed that account. In court filings, the company said it did not extract contact data from phones in Nigeria itself. Instead, it said users could voluntarily upload contact information through an optional “Enhanced Search” feature available in certain versions of the app, and that users represented that they were authorised to share the information and had obtained the necessary consent. Truecaller also argued that its caller identification and spam detection functions serve public safety purposes and that non-users could request the removal of their data.
The court rejected the central premise that one person could simply provide consent on behalf of everyone in their phonebook. Under Sections 26 and 65 of the Nigeria Data Protection Act, consent must be voluntary, informed, specific, and unambiguous, and the data controller must demonstrate that valid consent was obtained. That creates a difficult legal fit for a system in which one person grants a platform to another person’s number and effectively vouches for that person’s consent.
“Consent under the Nigeria Data Protection Act is an expression that is voluntary, informed, specific and an unambiguous indication or agreement for somebody else to process personal data,” Olumide Babalola, chair of the Nigerian Bar Association’s Data Protection Committee and counsel involved in the litigation, said in an interview with TechCabal on Sunday, September 20, 2026. “You cannot use consent by implication or consent by proxy.”
The legal significance of that principle reaches beyond Truecaller. Many applications request access to a user’s contact list to improve messaging, social discovery, invitations, caller identification, or account matching. Uploading a phonebook can feel routine, almost invisible. But it involves a platform receiving data about people who did not accept its terms and may not know that their information is being processed.
In the Truecaller case, the petitioners argued that telephone numbers are personal data and that Truecaller collected and exposed their numbers without a lawful basis. One of them said a vendor with whom she had no prior relationship told her he had discovered her identity and phone number through Truecaller. They said the practice had exposed non-users to unsolicited messages, surveillance, risks of identity theft, loss of control over their personal information, and distress.
The company disputed important parts of that description. Its court filings stated that it has no Nigerian office, server, or operational facility, and that its technical infrastructure is located in India. It also said that the public-safety functions of caller identification and spam detection were available regardless of whether a user activated the optional upload feature. A user could disable the feature, it said, and a non-user could request deletion, after which Truecaller said it retained only a one-way hash designed to prevent accidental reintroduction of data.
But the court’s reasoning, as Babalola describes it, turned on the more fundamental question of whether the company could rely on a user’s assurance as proof that non-users had consented.
“The court said no, you cannot use the consent of non-users as if it is consent of users,” Babalola said. “Some non-users do not even know that anything called Truecaller exists. So how can they give implied consent to an entity that they do not know exists?”
A reversal of legal logic
The ruling represents a departure from a previous Nigerian court decision involving Truecaller. In the earlier Federal High Court case, brought under the Nigeria Data Protection Regulation of 2019, the court accepted that users who uploaded their phonebooks were the controllers of non-users’ data and therefore bore responsibility for obtaining consent.
That decision gave Truecaller substantial legal protection. If the user, rather than the platform, was the effective data controller for the uploaded contacts, the company could present itself as a recipient of information from someone who had already handled the consent question. The company’s role would appear more distant from the original collection.
But the new case was decided under the more detailed Nigeria Data Protection Act, which came into force in June 2023. The Act requires a controller to demonstrate consent and does not recognise implied consent in the loose sense suggested by the earlier ruling. It also requires consent to be tied to particular processing purposes.
That specificity matters. Permission to collect a number is not automatically permission to store it indefinitely. Permission to store it is not automatically permission to display it to other users. Permission to use it for caller identification is not automatically permission to make it searchable through a premium service. The same number may be used to send messages, build profiles, make identity inferences, facilitate search or share data with others. The law requires clarity over what is being authorised.
“If I just say I give you consent to collect, you cannot use consent to collect as consent to share,” Babalola said. “For anything you want to do on my telephone number, the law requires that before I can give consent, first of all, you must seek the consent, and when you are seeking the consent, you must be explicit as to what it will be put to.”
The ruling does not, on its own, dictate the exact operational changes Truecaller must make. The applicants sought declarations, injunctions preventing further collection and processing, mandatory deletion of non-user data, and ₦300 million ($225,496) in general and exemplary damages. Yet the court’s treatment of the consent issue raises a direct question for the company: what lawful basis, if any, supports the continued processing of Nigerian non-users’ telephone numbers when user-provided consent is insufficient?
“From a data-protection perspective, you cannot process data without a lawful basis,” he said. “In this judgment, the court has not been able to find a lawful basis for them.”
That conclusion should be treated as the view of the applicants’ counsel rather than a final determination of Truecaller’s future operations. The company may appeal, change its processing practices, rely on other legal grounds, or seek to clarify its position before regulators and courts. The case also presents difficult questions about jurisdiction, cross-border processing and the legal status of technical safeguards such as hashing and deletion workflows.
Still, the decision shifts the debate. The important question is no longer merely whether an app obtains contact access from a user. It is whether the company receiving, storing and monetising information about non-users can independently show a lawful basis for doing so.
The missing payout
The more complicated part of the decision is what the applicants did not receive.
Although the court found that Truecaller could not rely on the consent argument presented, it did not award damages. According to Babalola, the court did not find sufficient evidence that the applicants had suffered material harm from the disclosure of their numbers.
That leaves the case with what Babalola called “half bread.” Privacy advocates gained an important declaration about the inadequacy of proxy consent. But claimants did not obtain a monetary remedy for the loss of control over their information, the anxiety of learning that their numbers were searchable, or the possibility that their data could be misused.
“The court found that Truecaller could not rely on consent,” Babalola said. “The only thing that did not allow the court to award damages against them was that the court did not see evidence of damage—the kind of evidence that the court wanted.”
The court’s approach reflects a developing tension in Nigerian privacy litigation. The NDPA allows claims for injury or harm. But the concepts are not exhaustively defined. Courts are therefore being asked to decide whether a privacy injury exists only when it results in measurable financial loss, proven harassment, identity theft, or reputational damage, or whether the unauthorised collection and disclosure of personal data is itself an actionable injury.
For Babalola, however, the issue goes beyond money. “What about emotional damage? What about loss of control over personal data? What about loss of autonomy? What about dignity?” he asked.
Nigerian courts have yet to settle how such intangible harms should be valued. They have traditionally been cautious about awarding substantial damages where a claimant cannot show direct financial loss or a concrete consequence. A person whose exposed phone number leads to fraud, extortion, threats, discrimination, job loss or treatment for emotional distress may therefore have a stronger claim for compensation than someone who can show only that their data was processed without valid consent.
That approach is reflected in Emerging Markets Telecommunication Services Ltd (9mobile) v. Eneye (2018) LPELR-46193(CA). The case involved persistent unsolicited promotional SMS messages that the subscriber argued violated his constitutional right to privacy under Section 37 of the 1999 Constitution. The Court of Appeal agreed that the messages breached his privacy but substantially reduced the damages awarded by the lower court, finding that the subscriber had suffered no concrete financial loss or physical injury beyond minor annoyance.
Babalola pointed to the kinds of evidence that could potentially establish a more serious injury: identity theft linked to a phone number, sustained harassment, death threats, evidence that someone obtained the claimant’s number through the platform, or derogatory labels attached to the number within the app.
The result is that the law may prohibit a certain form of processing without fully compensating every person affected. That can create an enforcement problem. If a company’s exposure is limited, where claimants cannot quantify the injury, the financial incentive to redesign a business model may be weaker. Conversely, courts may be wary of allowing technical or administrative breaches to automatically give rise to claims for large damages where no concrete loss is shown.
A related Federal High Court decision involving First City Monument Bank illustrates this judicial caution. In that case, a claimant alleged that FCMB had misused personal data to open an account without consent. The bank investigated, found irregularities connected to a phone number associated with the claimant’s father, and permanently closed the account before the case reached court. The court found no proven financial loss, identity theft, or reputational damage, rejected claims totalling ₦100 million ($75,130), and awarded ₦500,000 ($375.94) in costs against the claimant.[
The FCMB case and the Truecaller ruling are not identical. FCMB involved a discrete, closed account, whereas Truecaller’s model involves a potentially ongoing database of names and numbers sourced from users’ contact lists. But both show Nigerian courts resisting the notion that a technical breach or unauthorised processing necessarily creates an automatic right to a large damages award.
The wider platform question
Truecaller’s case matters because it sits at the boundary between a useful consumer product and a data-protection problem. Caller identification can help people avoid scams, block nuisance calls, and decide whether to answer calls from unfamiliar numbers. The public-safety rationale is not frivolous. The court appears to have acknowledged that the company’s purpose could be commendable.
But a valuable service does not eliminate the need for a lawful basis. A platform cannot necessarily justify any method of collecting information simply because the service it provides is useful. That is the central principle emerging from the Lagos decision.
The ruling may also prompt scrutiny of other platforms that request access to contact lists. Babalola distinguishes Truecaller from services such as WhatsApp on the grounds that Truecaller makes names and numbers more accessible and easier to search.
“WhatsApp does not readily make other people’s telephone numbers available on their website,” he said. “But that is what Truecaller does.”
Not every contact-access feature operates the same way, and not every service displays or commercialises the data it receives in the same manner. But the broader lesson is uncomfortable for the technology industry: a user’s click on a permission screen does not automatically resolve the rights of every other person whose information is stored on that user’s device.















