← Back to Knowledge Center
KNOWLEDGE CENTER

Identity Information: Share Only What Is Needed

Identity Protectionen-NG
BEFORE YOU BEGIN

Understand the issue before you decide what to do.

This lesson is designed to explain the subject in practical terms so that you can understand not only what the risk is, but why it matters, how it can appear in real situations and what you can do to reduce your exposure.

Read the explanation carefully before acting on a suspicious message, request, transaction, account notification or other security-related situation.

FULL LESSON

Understanding the subject

Take your time with this explanation. The goal is not simply to recognise a warning sign, but to understand what is happening and make a safer decision when you encounter it.

IDENTITY INFORMATION: SHARE ONLY WHAT IS NEEDED

BEFORE YOU SHARE

Your identity information helps organisations identify you, open accounts, provide services, complete transactions and meet legitimate requirements. It can also help an attacker impersonate you, answer security questions, create convincing scam messages or combine information from different sources.

The goal is not to hide every piece of information about yourself.

The goal is to control unnecessary exposure.

A safer question is not:

"Can I give them this information?"

Ask:

"Who is asking, why do they need it, what exactly do they need, how will it be used, and what is the safest legitimate way to provide it?"

VERIFY BEFORE YOU TRUST.

THE CORE PRINCIPLE

SHARE THE MINIMUM INFORMATION THAT IS REASONABLY NECESSARY FOR A LEGITIMATE PURPOSE, THROUGH A TRUSTED CHANNEL, AFTER VERIFYING WHO IS RECEIVING IT.

1. WHAT COUNTS AS IDENTITY INFORMATION?

Identity information is information that can identify you directly, distinguish you from another person, help verify who you are, or be combined with other information to build a detailed profile about you.

Examples can include:

  • Full name
  • Phone number
  • Email address
  • Date of birth
  • Residential or workplace address
  • NIN and other government-issued identifiers
  • BVN and other financial identifiers
  • Passport details
  • Driver's licence details
  • Voter information
  • Identity-document photographs
  • Signature
  • Account details
  • Employment or school information
  • Information about family relationships
  • Photographs that reveal documents, addresses, account details or other identifiers

Some of these details may be ordinary in everyday life. That does not mean every request for them is safe.

Risk depends on the information, the recipient, the purpose, the channel and what other information is already available.

2. NOT ALL INFORMATION HAS THE SAME RISK

Think about information in layers.

LOWER-RISK INFORMATION

A first name or general public professional information may not be highly sensitive by itself.

However, even ordinary information can become useful when combined with other details.

MORE SENSITIVE INFORMATION

Phone numbers, dates of birth, addresses, identity documents, financial identifiers and account information can provide more material for impersonation, targeted scams or identity abuse.

HIGH-RISK SECRETS

Passwords, PINs, one-time passwords, authentication codes, recovery codes, wallet recovery phrases and similar authentication secrets should not be disclosed simply because someone claims to be helping you.

A person can legitimately need to know who you are without needing your password or OTP.

This distinction is important:

IDENTITY INFORMATION CAN HELP VERIFY YOU.

AUTHENTICATION SECRETS HELP CONTROL ACCESS.

Do not confuse the two.

3. START WITH THE PURPOSE

Before sharing information, ask:

  • What service or transaction am I trying to complete?
  • Why does this organisation need this particular information?
  • Which parts are genuinely necessary?
  • What will happen if I do not provide a particular field?
  • Is there a legitimate alternative that requires less information?

A request should make sense in relation to its stated purpose.

For example, a service may reasonably need some identity information to establish an account. That does not automatically mean it needs your password, OTP, full contact list or unrelated financial information.

A legitimate purpose does not make every requested piece of information necessary.

4. VERIFY WHO IS ASKING

Do not decide whether to share information based only on how professional the request looks.

A scammer can use:

  • A company logo
  • A familiar name
  • A copied profile
  • A professional-looking form
  • A WhatsApp account
  • A convincing caller ID
  • A message containing some information about you
  • A document that looks official

These features can create an appearance of legitimacy without proving who is actually receiving the information.

When the request matters, verify the requester independently.

For an organisation:

  • Open its official website yourself.
  • Use the official app where one exists.
  • Call a published number.
  • Contact an established representative you already know.
  • Use the organisation's official support process.

Do not use the phone number, link or contact account supplied by a suspicious request as the only proof that the request is genuine.

5. VERIFY THE CHANNEL, NOT JUST THE ORGANISATION

Even when the organisation itself is genuine, the person contacting you may not be.

EXAMPLE

A real bank exists.

That does not mean every person claiming to be a bank employee is genuine.

A real company has a customer-service department.

That does not mean every WhatsApp account using the company's logo belongs to that department.

A real school, employer, agent or service provider may need identity information.

That does not mean every form or personal account claiming to represent them should receive it.

Always verify the actual channel through which the information will be submitted.

6. USE DATA MINIMISATION

Data minimisation means avoiding unnecessary collection or disclosure of personal information.

The Nigerian data-protection framework recognises the principle that personal data should be adequate, relevant and limited to what is necessary for the stated purpose. The Nigeria Data Protection Commission's materials also describe purpose limitation, data minimisation and storage limitation as important principles.

This does not mean a person should refuse every request for personal information.

It means the request should be connected to a legitimate purpose and limited to what is reasonably necessary.

A useful test is:

PURPOSE → NECESSITY → MINIMUM → SAFE CHANNEL

If a field does not appear necessary, ask why it is required before providing it.

7. ASK QUESTIONS WHEN A REQUEST IS TOO BROAD

You do not have to respond to an unclear request by immediately providing everything requested.

Useful questions include:

  • Why do you need this information?
  • Which specific fields are required?
  • Who will have access to it?
  • How will it be used?
  • How long will it be kept?
  • Is there a less intrusive alternative?
  • Can I provide only the information needed for this particular service?

A legitimate organisation should be able to explain its information requirements through an appropriate channel.

If the explanation is unclear, contradictory or pressure-filled, pause before sharing.

8. IDENTITY DOCUMENTS DESERVE EXTRA CARE

An identity document can contain many pieces of information in one image.

A photograph of an ID may reveal:

  • Full name
  • Date of birth
  • Document number
  • Photograph
  • Signature
  • Address
  • Nationality
  • Other identifying details

Before sending an identity document, ask:

  1. Who exactly will receive it?
  2. Why is it required?
  3. Which information is actually necessary?
  4. Is the request coming through a legitimate channel?
  5. Is a less detailed alternative acceptable?
  6. How will the document be stored and protected?

Do not send a full identity document simply because someone says:

"Send your ID."

Ask what is required and why.

9. BE CAREFUL WITH PHOTOS AND SCREENSHOTS

People often expose identity information accidentally.

Before posting or sending a photograph, inspect the entire image.

Look for:

  • ID numbers
  • NIN or other identifiers
  • BVN-related information
  • Bank account details
  • Addresses
  • QR codes
  • Barcodes
  • Signatures
  • Phone numbers
  • Email addresses
  • School or workplace information
  • Travel documents
  • Payment references
  • Documents visible in the background

A photograph can expose information that was not the intended subject of the photograph.

This is especially important when posting documents publicly or sending screenshots to people you do not know well.

10. REDACT WHEN APPROPRIATE

If a legitimate service does not require the full contents of a document, ask whether a more limited copy or alternative is acceptable.

Where appropriate, unnecessary information may be redacted before sharing.

However, do not alter a document in a way that makes a legitimate verification impossible or misleading.

The correct approach is:

  • Ask what is required.
  • Confirm whether redaction is acceptable.
  • Remove only information that is genuinely unnecessary.
  • Keep the original secure.
  • Send the reduced version through the legitimate channel.

Do not assume that adding a watermark automatically makes an unsafe disclosure safe. A watermark can help in some situations, but it does not prevent the recipient from seeing the information that remains visible.

11. NEVER GIVE AUTHENTICATION SECRETS TO "VERIFY YOUR IDENTITY"

This is one of the most important distinctions in the entire lesson.

A caller may know your name, phone number or other personal details and still be an impostor.

They may then say:

"To confirm that you are the account owner, read the code we just sent you."

Do not do it.

A one-time code is generally part of an authentication process. Giving it to someone else can help them complete an action that the code was intended to authorize.

The same caution applies to:

  • Passwords
  • PINs
  • OTPs
  • Authentication codes
  • Recovery codes
  • Security answers
  • Wallet recovery phrases

If someone needs information to identify you, verify the request through the organisation's official process rather than handing over an authentication secret.

12. BE CAREFUL WITH NIN, BVN AND OTHER IDENTIFIERS

In Nigeria, identifiers such as NIN and BVN can be important for legitimate services.

That does not mean every request for them is legitimate.

Be especially cautious when the request arrives unexpectedly through:

  • WhatsApp
  • Facebook
  • Instagram
  • Telegram
  • SMS
  • An unsolicited phone call
  • An unfamiliar website
  • A social-media giveaway
  • A job or investment offer
  • A person claiming to be customer support

A request such as:

"Send your NIN, BVN and bank login so we can release your prize"

contains multiple warning signs.

Do not provide credentials or unnecessary identity information. Verify the organisation and the actual offer independently.

13. WATCH FOR SOCIAL ENGINEERING

Attackers may use information about you to make a request sound more convincing.

For example, someone may already know:

  • Your name
  • Your workplace
  • Your bank
  • Your school
  • Your relative's name
  • Your phone number
  • Your location

They may use those details to create the impression that they already know you.

KEY TAKEAWAY

KNOWING SOMETHING ABOUT YOU DOES NOT PROVE THAT THE REQUESTER IS TRUSTWORTHY.

Use independent verification.

14. PUBLIC INFORMATION CAN BECOME MORE SENSITIVE WHEN COMBINED

A phone number may be public.

Your workplace may be public.

Your birthday may appear on social media.

Your family relationships may be visible.

Individually, each detail may appear harmless.

Together, they can help someone construct a convincing impersonation or targeted scam.

This is why privacy is not simply about hiding one secret.

It is about reducing unnecessary information that can be combined and misused.

15. BE CAREFUL WITH ONLINE FORMS

Before completing a form, check:

  • Who operates the form?
  • What is the purpose?
  • Is the website or app genuine?
  • Which fields are mandatory?
  • Are the requested details relevant?
  • Does the form request a password or OTP?
  • Does it ask for more identity information than the service appears to require?
  • Where will the information be submitted?

A professional-looking form is not proof that it is safe.

If a form requests information that seems excessive, stop and verify through the organisation's official channel.

16. BE CAREFUL WITH JOB, GRANT, GIVEAWAY AND PROMOTION REQUESTS

Offers can create pressure to disclose information quickly.

Examples include:

"You have been selected for a grant."

"You won a giveaway."

"Send your NIN to confirm your eligibility."

"Send your BVN so we can release the funds."

"Upload your ID and bank details before the interview."

"Pay a small processing fee and send your details."

The reward does not prove the request is legitimate.

Verify:

  • Who is offering it?
  • Is the organisation real?
  • Is the offer actually published through its official channels?
  • What information is genuinely required?
  • Does the request make sense for the stated purpose?
  • Are they asking for passwords, PINs or OTPs?

17. BUSINESS AND WORKPLACE REQUESTS

The same principle applies at work.

A colleague, manager, supplier or customer may legitimately need some information.

But a request should still be verified when it is unusual, broad or sensitive.

EXAMPLE

A person asks an employee to send a spreadsheet containing customer names, phone numbers, addresses and financial information to a personal email address.

Do not assume that the request is safe because the person appears to work for the organisation.

Confirm:

  • The business purpose
  • The intended recipient
  • The approved sharing method
  • The minimum information required
  • Any internal data-handling rules

Use approved business channels and access controls for sensitive information.

18. CHILDREN'S AND OTHER PEOPLE'S INFORMATION

Your responsibility does not stop with your own information.

Be careful before sharing:

  • A child's school information
  • A child's full name and date of birth
  • Family phone numbers
  • Home addresses
  • Medical or educational documents
  • Another person's identity document
  • Customer or employee information

Do not assume that because you possess information, you are automatically entitled to publish or forward it.

Consider whether the disclosure is necessary, appropriate and authorised.

19. WHAT TO DO IF YOU ALREADY SHARED TOO MUCH

Do not panic.

First identify what was shared and where it went.

If you shared a password:

  • Change it immediately through the official service.
  • Change it anywhere else you reused it.
  • Review active sessions and account-security settings.
  • Enable stronger authentication where available.

If you shared an OTP or authentication code:

  • Contact the affected service through its official channel immediately.
  • Review recent account activity.
  • Secure the account and follow the provider's recovery process.

If you shared identity information:

  • Record what information was disclosed.
  • Keep copies of relevant messages, forms, emails and phone numbers.
  • Watch for unusual account, SIM, financial or identity-related activity.
  • Contact the affected organisation through an official channel if misuse is possible.
  • Report suspected fraud or identity misuse through appropriate official channels.

Do not continue communicating with a suspected scammer just because you want an explanation.

20. A SIMPLE DECISION FRAMEWORK

Before sharing identity information, run through these six questions:

  1. WHO is asking?
  2. WHY do they need it?
  3. WHAT exactly do they need?
  4. HOW will I verify the requester?
  5. WHERE will I submit it?
  6. CAN I provide less?

If you cannot answer these questions confidently, pause.

21. FIVE REAL-WORLD EXAMPLES

EXAMPLE 1: THE GIVEAWAY

A message says you have won ₦200,000 and asks for your NIN, BVN and bank login details to release the prize.

Safer response:

Do not provide the credentials or unnecessary identity information. Verify the promotion independently through the organisation's official channels.

Why?

A prize claim does not prove that the person requesting your information is legitimate.

EXAMPLE 2: THE BANK CALL

Someone calls claiming to be from your bank and asks for the OTP that just arrived on your phone.

Safer response:

Do not disclose the OTP. End the call and contact the bank using an official number or the bank's official app or website.

Why?

An authentication code should not be treated as ordinary identity information.

EXAMPLE 3: THE FULL ID COPY

A person arranging a routine service asks for a full photograph of your identity document but cannot explain why every field is necessary.

Safer response:

Ask what information is required, why it is required and whether a safer or more limited alternative is available. Verify the recipient and channel before sending anything.

Why?

A legitimate service requirement does not automatically justify unnecessary exposure of every document detail.

EXAMPLE 4: THE SUPPORT ACCOUNT

A WhatsApp account uses a company's logo and says it is customer support. It asks for your password and a screenshot of your banking app.

Safer response:

Do not provide the password or sensitive banking information. Verify the support contact through the company's official website or another trusted channel.

Why?

A logo and business name do not prove that the account is genuine.

EXAMPLE 5: THE EXCESSIVE FORM

A legitimate-looking registration form asks for your full identity details, account password and one-time code before allowing you to continue.

Safer response:

Stop and verify what information is genuinely required through the organisation's official channel. Never provide a password or one-time authentication code as part of a routine identity request.

Why?

A legitimate service can still be impersonated, and a legitimate purpose does not justify collecting authentication secrets.

22. AVOID THESE COMMON MISTAKES

MISTAKE: "They know my name, so they must be genuine."

Better approach: Verify the requester independently.

MISTAKE: "The form looks professional."

Better approach: Verify the website, organisation and purpose.

MISTAKE: "They only need my ID for verification."

Better approach: Ask what parts are required and why.

MISTAKE: "The person is asking for an OTP just to confirm my identity."

Better approach: Never disclose authentication codes to an unsolicited person.

MISTAKE: "It is only a phone number."

Better approach: Consider what other information could be combined with it.

MISTAKE: "I can send the full document now and ask questions later."

Better approach: Understand the purpose before disclosure.

MISTAKE: "A watermark makes any document safe to share."

Better approach: Reduce unnecessary exposure first, then use appropriate safeguards when legitimate sharing is required.

23. THE FIVE-SECOND CHECK

Before pressing SEND, ask:

WHO?

WHY?

WHAT?

WHERE?

LESS?

If the request is unclear, unexpected, unusually broad or pressure-filled, stop and verify.

24. FINAL CHECKLIST

Before sharing identity information:

□ I know who is requesting it. □ I understand the purpose. □ I know which information is actually necessary. □ I have verified the requester independently when appropriate. □ I am using a legitimate channel. □ I have checked the document or image for unnecessary information. □ I am not sending a password, PIN, OTP, recovery code or wallet recovery phrase. □ I have considered whether a safer or more limited alternative exists. □ I know what happens to the information after I submit it. □ I would be comfortable explaining why I shared it.

FINAL PRINCIPLE

Your identity information is not automatically safe just because someone asks politely, uses official-looking language or claims to have a legitimate purpose.

Pause.

Understand the purpose.

Verify the requester.

Share only what is necessary.

Use a trusted channel.

Protect authentication secrets.

VERIFY BEFORE YOU TRUST.

APPLY WHAT YOU LEARNED

Turn understanding into a security habit.

Knowing the definition is only the beginning. The real value of cybersecurity education is being able to recognise the situation and make a safer decision when it happens to you.

How should you use what you learned?

Understanding a cybersecurity concept is useful only when it changes how you make decisions. When you encounter a similar situation in real life, slow down and identify what is being requested before you respond.

Ask yourself who is making the request, what they are asking you to do, what information or access is involved, and whether the request can be independently verified.

Do not allow urgency, fear, authority, familiarity or the promise of a reward to replace independent verification.

What if I still do not understand something?

Cybersecurity concepts can sometimes involve technical terms or situations that are difficult to interpret from a single lesson. If something is unclear, do not guess when the decision could affect your money, identity, account access, device or sensitive information.

You can seek further guidance through the consultancy channel. Explain the situation clearly, but never include passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A convincing message, familiar name, professional appearance or urgent request is not proof of legitimacy. Verify the important facts independently before taking an action that could be difficult to reverse.