Identify exactly what they want
Do not treat every request for 'your ID' as the same request.
Identity information can be necessary for legitimate services, but a request for your name, NIN, identity document, date of birth or other personal details is not automatically proof that the requester is genuine or that every requested detail is necessary. Verify the requester, understand the purpose and share only what is reasonably required.
Your identity information can connect different parts of your life. A single detail may look harmless on its own, but a collection of names, phone numbers, dates of birth, addresses, identity documents and other records can create a much more complete picture of you.
The Nigeria Data Protection Commission's data-protection framework includes purpose limitation and data minimisation. In practical terms, a request should have a clear purpose and the information collected should be appropriate for that purpose rather than simply collecting everything available.
Apply the sequence whenever someone asks for identity information, whether the request arrives in person, by phone, WhatsApp, SMS, email, social media or a web form.
Do not treat every request for 'your ID' as the same request.
A request can sound official without having a clear or legitimate purpose.
A logo, staff name, caller ID or profile picture is not independent proof of identity.
A legitimate purpose does not automatically justify collecting every available detail.
Your identity information and your account secrets are not interchangeable.
A real organisation can still be impersonated through WhatsApp, SMS, email or social media.
The risk does not end when the information leaves your phone.
You do not have to complete a questionable identity request just because someone says it is urgent.
A document can contain more information than the requester needs. Treat the document itself as sensitive data and verify the complete submission process.
Prefer the organisation's official website, app, office or established customer-service channel. Do not let an unexpected message choose the upload destination for you.
Ask whether the full document is required or whether an approved alternative or limited set of details is sufficient.
Know which organisation or authorised party will receive the document. Do not send it to an unexplained personal account merely because the person claims to work there.
Do not keep sending the same ID to multiple people or services when one verified submission is enough. Each additional copy creates another exposure point.
Where appropriate and accepted by the recipient, a visible watermark such as the purpose and intended recipient can help discourage reuse of a document. Do not add markings that make an official document invalid or interfere with a required verification process.
A full identity document may reveal your name, photograph, date of birth, document number, signature, address or other information. The exact contents depend on the document. That is why the question is not simply, "Can I send my ID?" The better question is, "Who needs it, for what verified purpose, through which trusted channel, and do they genuinely need all of it?"
If the answer to those questions is unclear, stop and verify before uploading or sending the document.
The correct response is not always "never share." It is "verify first, minimise the information, and use the right channel."
A WhatsApp message says you have won a giveaway and asks for your NIN, phone number, date of birth and bank details. Do not start by sending the information. Find the organisation's official website independently and check whether the promotion exists. If it is genuine, confirm what information is actually required and use the organisation's legitimate channel. NIMC specifically warns against fake social accounts and unauthorised portals collecting NIN or BVN information.
A caller claims to be helping you resolve an account problem and asks for the one-time code just sent to your phone. The code is an authentication secret, not ordinary identity information. Do not read it out. End the call and contact the bank through its official app, website or a phone number you already trust.
A company you want to do business with asks you to send a full identity document through a personal WhatsApp account. The company may have a legitimate reason to verify identity, but the request still needs checking. Verify the company independently, ask why the document is needed, who will receive it and whether the company has an official secure upload or verification process.
A social-media account claiming to be support says your account will be suspended unless you provide your password and recovery code. Do not provide either. Open the service yourself, check your account security notifications and use the platform's official support process. A person who needs your password or recovery secret is asking for information that can enable account access, not merely identity verification.
You are registering for a simple service and the form asks for your full home address, date of birth, NIN, identity document, bank details and several account credentials. Do not assume every field is necessary because it appears on the form. Ask which fields are required, why they are required and whether the service can be completed with less information.
A person using a new WhatsApp number says they are a family member and asks for your ID details to help with a registration. Familiarity is not proof. Contact the relative using the old number or another channel you already trust. Do not use the new number to verify itself.
Not every identity request is a scam. An organisation may legitimately need identification for a service. The safe response is not automatic refusal. Verify the organisation, understand the purpose, confirm the exact information required and submit it through an official channel. A legitimate request can still be handled safely and deliberately.
1. WHO? Do I know who is requesting this information, and did I verify that identity independently?
2. WHY? Is there a clear and legitimate reason for the request?
3. WHAT? What exact information is being requested, and does every part of it have a clear purpose?
4. WHERE? Am I submitting it through the organisation's official or otherwise appropriate channel?
5. LESS? Could the same legitimate purpose be completed with less information or a safer verification method?
One warning sign does not prove fraud, but several together should trigger a pause and independent verification.
"Send it now or you will lose the opportunity." Pressure reduces the chance that you will question the request.
The requester wants multiple identity details without explaining why each one is necessary.
A supposed official request arrives through a personal account, newly created social profile or unexpected messaging contact.
The request moves from identity details to passwords, PINs, OTPs, card security codes or recovery phrases.
You are asked to pay a fee and provide sensitive identity information through an unverified account or portal.
The requester becomes evasive, angry or threatening when you ask why the information is required or how it will be handled.
Do not panic and do not give the same person even more information in an attempt to "fix" the situation. First identify exactly what was shared, when it was shared, who received it and through which channel.
If account credentials or authentication secrets were exposed, secure the affected account through its official service. If financial information was involved, contact the financial institution through an official channel and monitor the relevant account. Preserve messages, numbers, URLs, receipts and other evidence that may help explain what happened.
For identity-document or identity-number exposure, be cautious about follow-up calls or messages that use the information you already disclosed to sound more convincing. An attacker may use genuine details to create a false sense of legitimacy.
You do not need to reject every request for identity information. You need to make the decision deliberately. Verify the requester, understand the purpose, limit the information and use the proper channel.
VERIFY BEFORE YOU TRUST.