IDENTITY INFORMATION VERIFICATION

Verify the identity request before you share your documents or details.

Identity information can be necessary for legitimate services, but a request for your name, NIN, identity document, date of birth or other personal details is not automatically proof that the requester is genuine or that every requested detail is necessary. Verify the requester, understand the purpose and share only what is reasonably required.

Identity verification should verify you, not expose more of you than necessary.

Your identity information can connect different parts of your life. A single detail may look harmless on its own, but a collection of names, phone numbers, dates of birth, addresses, identity documents and other records can create a much more complete picture of you.

The Nigeria Data Protection Commission's data-protection framework includes purpose limitation and data minimisation. In practical terms, a request should have a clear purpose and the information collected should be appropriate for that purpose rather than simply collecting everything available.

Is every identity request dangerous?
No. Banks, employers, government services, telecoms, schools, healthcare providers and other organisations may legitimately need identity information. The safety habit is to verify the requester, understand the purpose, confirm what is actually required and use the proper channel.
Why is NIN especially important to protect?
NIMC describes the NIN as a unique identifier used to establish or verify identity and says it should be closely guarded rather than disclosed to everyone. That does not mean you can never provide it. It means you should understand who is requesting it, why it is needed and whether the request is through an authorised channel.
Is an ID document the same as a password?
No. An identity document establishes or supports identity, while a password, PIN or one-time code is used to authenticate access. A legitimate identity-verification process may require an ID document, but that does not give the requester a reason to ask for your password, PIN, OTP or recovery phrase.
What if the organisation really needs my ID?
Verify the organisation independently, ask what the document is needed for, confirm the exact information required and use the organisation's official submission or verification channel. Do not let an unexpected caller or social-media account decide where you upload the document.
THE IDENTITY REQUEST CHECK

Use these steps before sharing.

Apply the sequence whenever someone asks for identity information, whether the request arrives in person, by phone, WhatsApp, SMS, email, social media or a web form.

STEP 01

Identify exactly what they want

Do not treat every request for 'your ID' as the same request.

What should I do?
Ask whether they want your name, phone number, address, NIN, BVN, date of birth, identity document, selfie, signature or another detail. Then ask whether they need the whole item or only a specific field. The more information a request exposes, the more carefully it should be checked.
STEP 02

Find out why it is needed

A request can sound official without having a clear or legitimate purpose.

What should I do?
Ask what service, transaction or legal requirement the information supports. A genuine organisation should be able to explain the purpose in a way that makes sense for the service. If the explanation is vague, changes when questioned or does not match the service, pause before sharing.
STEP 03

Verify who is asking

A logo, staff name, caller ID or profile picture is not independent proof of identity.

What should I do?
Leave the conversation that delivered the request. Open the organisation's official website or app yourself, or use a phone number you already had before the request. Ask the organisation whether the person, account or request is genuine and what information is actually required.
STEP 04

Apply the minimum-information test

A legitimate purpose does not automatically justify collecting every available detail.

What should I do?
Ask: 'What is the minimum information needed to complete this legitimate purpose?' If a name and phone number are enough, do not volunteer a full identity document. If an identity document is genuinely required, ask whether a specific page, field or approved verification method is sufficient.
STEP 05

Separate identity data from authentication secrets

Your identity information and your account secrets are not interchangeable.

What should I do?
Never give a password, PIN, one-time verification code, card PIN, security answer or wallet recovery phrase to someone who says they need it to verify your identity. Those items are used to authenticate or protect access. Use the service's official verification process instead.
STEP 06

Check the channel before uploading anything

A real organisation can still be impersonated through WhatsApp, SMS, email or social media.

What should I do?
Do not upload an identity document simply because a message contains an official-looking logo or link. Open the organisation's official website or app yourself and navigate to the service. Check the domain, account and upload destination before submitting anything.
STEP 07

Check what happens to the information

The risk does not end when the information leaves your phone.

What should I do?
Where appropriate, ask who will receive the information, what it will be used for, whether it will be shared with another party and how long it will be retained. For important requests, look for the organisation's privacy information and use an established service channel.
STEP 08

Stop when the request cannot be verified

You do not have to complete a questionable identity request just because someone says it is urgent.

What should I do?
If you cannot independently verify the requester, purpose and required information, do not send the sensitive information yet. A delay is safer than giving an unknown person a complete identity package that may be difficult to recover once copied.
IDENTITY DOCUMENTS

When someone asks for a copy of your ID.

A document can contain more information than the requester needs. Treat the document itself as sensitive data and verify the complete submission process.

Use the official service

Prefer the organisation's official website, app, office or established customer-service channel. Do not let an unexpected message choose the upload destination for you.

Confirm the exact document

Ask whether the full document is required or whether an approved alternative or limited set of details is sufficient.

Check the recipient

Know which organisation or authorised party will receive the document. Do not send it to an unexplained personal account merely because the person claims to work there.

Avoid unnecessary copies

Do not keep sending the same ID to multiple people or services when one verified submission is enough. Each additional copy creates another exposure point.

Consider protective markings

Where appropriate and accepted by the recipient, a visible watermark such as the purpose and intended recipient can help discourage reuse of a document. Do not add markings that make an official document invalid or interfere with a required verification process.

Think about the information hidden inside a document.

A full identity document may reveal your name, photograph, date of birth, document number, signature, address or other information. The exact contents depend on the document. That is why the question is not simply, "Can I send my ID?" The better question is, "Who needs it, for what verified purpose, through which trusted channel, and do they genuinely need all of it?"

If the answer to those questions is unclear, stop and verify before uploading or sending the document.

REAL-WORLD EXAMPLES

See how the same rule works in different situations.

The correct response is not always "never share." It is "verify first, minimise the information, and use the right channel."

Example 1: 'Send your NIN to qualify for this giveaway'

A WhatsApp message says you have won a giveaway and asks for your NIN, phone number, date of birth and bank details. Do not start by sending the information. Find the organisation's official website independently and check whether the promotion exists. If it is genuine, confirm what information is actually required and use the organisation's legitimate channel. NIMC specifically warns against fake social accounts and unauthorised portals collecting NIN or BVN information.

Example 2: A bank caller asks for an OTP

A caller claims to be helping you resolve an account problem and asks for the one-time code just sent to your phone. The code is an authentication secret, not ordinary identity information. Do not read it out. End the call and contact the bank through its official app, website or a phone number you already trust.

Example 3: A company asks for a full ID through ordinary chat

A company you want to do business with asks you to send a full identity document through a personal WhatsApp account. The company may have a legitimate reason to verify identity, but the request still needs checking. Verify the company independently, ask why the document is needed, who will receive it and whether the company has an official secure upload or verification process.

Example 4: 'Support' asks for your password and recovery code

A social-media account claiming to be support says your account will be suspended unless you provide your password and recovery code. Do not provide either. Open the service yourself, check your account security notifications and use the platform's official support process. A person who needs your password or recovery secret is asking for information that can enable account access, not merely identity verification.

Example 5: A form asks for far more than the service needs

You are registering for a simple service and the form asks for your full home address, date of birth, NIN, identity document, bank details and several account credentials. Do not assume every field is necessary because it appears on the form. Ask which fields are required, why they are required and whether the service can be completed with less information.

Example 6: Someone sends a new number claiming to be a relative

A person using a new WhatsApp number says they are a family member and asks for your ID details to help with a registration. Familiarity is not proof. Contact the relative using the old number or another channel you already trust. Do not use the new number to verify itself.

Example 7: An employer or service provider genuinely needs identification

Not every identity request is a scam. An organisation may legitimately need identification for a service. The safe response is not automatic refusal. Verify the organisation, understand the purpose, confirm the exact information required and submit it through an official channel. A legitimate request can still be handled safely and deliberately.

The five-question identity test

1. WHO? Do I know who is requesting this information, and did I verify that identity independently?

2. WHY? Is there a clear and legitimate reason for the request?

3. WHAT? What exact information is being requested, and does every part of it have a clear purpose?

4. WHERE? Am I submitting it through the organisation's official or otherwise appropriate channel?

5. LESS? Could the same legitimate purpose be completed with less information or a safer verification method?

WARNING SIGNS

Stop when identity verification starts looking like data collection.

One warning sign does not prove fraud, but several together should trigger a pause and independent verification.

Urgency

"Send it now or you will lose the opportunity." Pressure reduces the chance that you will question the request.

Unexplained quantity

The requester wants multiple identity details without explaining why each one is necessary.

Unusual channel

A supposed official request arrives through a personal account, newly created social profile or unexpected messaging contact.

Secrets mixed into identity checks

The request moves from identity details to passwords, PINs, OTPs, card security codes or recovery phrases.

Payment plus identity data

You are asked to pay a fee and provide sensitive identity information through an unverified account or portal.

Resistance to questions

The requester becomes evasive, angry or threatening when you ask why the information is required or how it will be handled.

If you have already shared too much

Do not panic and do not give the same person even more information in an attempt to "fix" the situation. First identify exactly what was shared, when it was shared, who received it and through which channel.

If account credentials or authentication secrets were exposed, secure the affected account through its official service. If financial information was involved, contact the financial institution through an official channel and monitor the relevant account. Preserve messages, numbers, URLs, receipts and other evidence that may help explain what happened.

For identity-document or identity-number exposure, be cautious about follow-up calls or messages that use the information you already disclosed to sound more convincing. An attacker may use genuine details to create a false sense of legitimacy.

Use the habit: PAUSE → IDENTIFY → QUESTION → VERIFY → MINIMISE → SHARE.

You do not need to reject every request for identity information. You need to make the decision deliberately. Verify the requester, understand the purpose, limit the information and use the proper channel.

VERIFY BEFORE YOU TRUST.