SchoolFees.NG
Homepage
Legally Binding FrameworkJurisdiction: Federal Republic of Nigeria & International Best Practices

Data Protection & Institutional Security Policy

Comprehensive technical, organizational, and regulatory security standards safeguarding school, student, and bursary data under the Nigeria Data Protection Act (NDPA 2023).

Effective DateJanuary 1, 2025
Last RevisedSeptember 2026
ApplicabilitySchools, Bursars, Parents & Students
NDPA 2023 Regulatory Commitment:SchoolFees.NG complies fully with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Commission (NDPC) guidelines, and international standards for safeguarding student academic and financial records.

1. Core Principles of Educational Data Governance

Every byte of institutional and personal data processed across SchoolFees.NG is governed by six fundamental principles:

Lawfulness & PurposeData is collected solely for explicit, legitimate educational management, bursary invoicing, and academic assessment.
Data MinimizationWe process only the minimum necessary information required to generate report cards, invoices, and attendance logs.
Accuracy & IntegrityRobust automated validation rules prevent duplicate admissions, corrupt grades, or corrupted transaction tallies.
Storage LimitationRecords are retained only for the duration of active institutional licensing and statutory school archival periods.
Confidentiality & SecurityProtected by AES-256 encryption at rest, TLS 1.3 in transit, and immutable role-based access controls.
AccountabilityTamper-evident audit trails record every user action, fee revision, and cashier receipt void for statutory audits.

2. Technical & Cryptographic Architecture

SchoolFees.NG utilizes modern edge-native security architectures to prevent breaches, snooping, or data corruption:

  • End-to-End Transport Security (TLS 1.3):All web communication, mobile requests, desktop cloud synchronization, and webhook callbacks are forced over encrypted HTTPS using modern TLS 1.3 cryptographic suites with HSTS enforcement.
  • Database Encryption at Rest (AES-256):All relational records, student rosters, parent contacts, and fee balances stored on Cloudflare D1 distributed databases and local Windows desktop SQLite caches are encrypted at rest using AES-256 cipher blocks.
  • Secure Password Hashing (PBKDF2 / SHA-256):Staff and parent passwords are salted and hashed with 100,000 PBKDF2 iterations using Web Crypto primitives. Constant-time signature verification prevents timing side-channel attacks.

3. Role-Based Access Control (RBAC) & Least Privilege

Every user inside the school workspace is confined to strict, cryptographically enforced role boundaries:

School Owner / Super AdminFull institutional authority, staff account creation, settlement bank configuration, fee blueprint locking, and audit log inspection.
Bursar & Cashier RolesScoped strictly to fee collection, invoice raising, receipt printing, and daily cashier balancing. Zero access to modify report card remarks or school legal records.
Academic Staff / TeachersRestricted exclusively to their assigned classroom arms for score entry (CA/Exam) and roll call attendance. Zero visibility into school bank balances or bursary summaries.
Parents & StudentsIsolated portal access restricted exclusively to the specific student's unpaid invoices, payment receipts, and generated termly report cards.

4. Tamper-Evident Audit Trails & AI Fraud Engine

Continuous Integrity Monitoring:

All critical bursary operations (including invoice creation, manual discount concessions, fee item deletion, cashier session closures, and receipt voiding) automatically append an immutable record to the institutional Audit Trail.

Our embedded 24/7 AI Fraud & Shadow Void Auditor continuously scans transaction graphs to detect anomalous cashier overrides, duplicate admission numbers, or suspicious out-of-hours cash collections, generating real-time security alerts for the school proprietor.

5. Disaster Recovery & Offline Continuity

Recognizing that Nigerian schools frequently operate in environments with intermittent power or fiber connectivity:

  • Decentralized Local Vault: The Windows Desktop application operates from an encrypted local SQLite database, allowing bursary cashiers to collect fees and print POS receipts during complete internet blackouts.
  • Automated Cloud Replication: When internet connection is restored, the offline engine executes two-way differential synchronization to merge verified receipts into the cloud database without data collisions.
  • Geographically Redundant Snapshots: Cloud databases undergo automated daily cryptographic snapshots archived across distributed data centers with 99.999999999% (11 9s) durability.

6. Incident Response & 72-Hour Breach Notification SLA

In compliance with Section 40 of the Nigeria Data Protection Act 2023:

Statutory Notification Protocol:

In the unlikely event of a confirmed security incident involving unauthorized exposure or tampering of personal data, SchoolFees.NG will notify the affected School Data Controllers and the Nigeria Data Protection Commission (NDPC) within seventy-two (72) hours of verification.

The incident notification will detail the nature of the event, categories of data affected, containment measures taken, and recommended institutional remedial steps.

7. Security Audits & DPO Inquiries

For institutional security assessments, vulnerability disclosures, or Data Protection compliance audits:

Security Operations & Data Protection Desk

Email: security@schoolfees.ng / dpo@schoolfees.ng

Emergency Security Hotline: Available inside verified School Owner dashboards.

Have Questions Regarding Our Legal Terms?

Our dedicated Data Protection and Legal Compliance desk is available to assist school owners, legal counsel, and educational boards.