PERSONAL INFORMATION VERIFICATION

Verify the request before you share personal information.

A request for your personal information is not automatically proof that the requester is legitimate or that every detail requested is necessary. Verify the requester, understand the purpose and share only what is reasonably needed.

Do not answer a data request before you verify the request.

Personal information can be useful for legitimate services, but unnecessary or exposed information can also support impersonation, fraud and social engineering.

Before sharing sensitive information, verify who is asking, why it is needed, who will receive it and whether you can provide less information without preventing the legitimate service.

What information should I treat carefully?
Treat information such as identity numbers, identity documents, bank details, account credentials, recovery information, one-time codes, home addresses and other information that could help someone impersonate you or access an account with care. The risk depends on what the information can enable and what other information is already available.
How do I verify a request from an organisation?
Do not rely on the message, caller ID, social-media profile or contact details supplied in the request. Open the organisation's official website or app yourself, or use a phone number you already had before the request. Ask whether the request is genuine and what information is actually required.
What if the request is legitimate?
A legitimate request can still be more detailed than necessary. Ask what the information is for, who will receive it and whether a less sensitive alternative is available. Share only what is needed for the legitimate purpose.
Should I ever give someone my OTP or password to verify me?
No. Passwords, PINs, one-time verification codes and wallet recovery phrases are authentication secrets. Do not disclose them to someone who contacts you and claims they need them to confirm your identity. Use the service's official verification or support process instead.
DATA REQUEST VERIFICATION

Use these steps before sharing.

Use this process when a person, business, platform, caller or message asks for personal information.

STEP 01

Identify exactly what is being requested

Do not answer a vague request for your personal information with a blanket yes.

What should I do?
Ask exactly what information is needed. For example, distinguish between a name and phone number, an address, a bank detail, an identity document, an account password or a verification code. Different information creates different risks.
STEP 02

Ask why it is needed

A legitimate organisation should be able to explain the purpose of the request.

What should I do?
Ask what the information will be used for and whether it is necessary for the service. If the requester cannot explain the purpose clearly, stop before sharing sensitive information.
STEP 03

Verify who is requesting it

Do not use the request itself as proof that the requester is genuine.

What should I do?
Find the organisation's official website or use a phone number you already had before the request. Contact the organisation independently and ask whether the request is genuine and what information is actually required.
STEP 04

Check whether less information is enough

A legitimate purpose does not automatically mean every requested detail is necessary.

What should I do?
Ask whether a less sensitive piece of information, a partial document or another verification method would meet the same legitimate purpose. Share only what is reasonably necessary.
STEP 05

Protect high-risk information

Some information can give someone a much stronger opportunity to impersonate you or access your accounts.

What should I do?
Never disclose passwords, PINs, one-time verification codes or wallet recovery phrases just because someone says they need them to verify your identity. Legitimate support should not require you to reveal secrets that authenticate you.
STEP 06

Use a safe channel

Even a legitimate organisation can be impersonated through a message, social account or phone call.

What should I do?
If the request came through WhatsApp, SMS, email or social media, leave that conversation and contact the organisation through its official website, official app or independently published contact details.
REAL-WORLD EXAMPLES

Put the verification habit into practice.

The goal is not to refuse every request for information. The goal is to verify the request and reduce unnecessary exposure.

Example 1: 'Send your NIN to qualify for the giveaway'

A message says you have been selected for a giveaway and asks for your NIN, phone number and bank details. Instead of sending them, find the organisation's official website and independently confirm whether the promotion exists and what information is genuinely required. If the offer cannot be verified, do not provide the requested data.

Example 2: A caller asks for an OTP to confirm your identity

Someone claims to be from your bank and says they need the code sent to your phone to confirm that you are the account owner. The code is itself an authentication secret. Do not disclose it. End the call and contact the bank through the official app, website or a phone number you already trust.

Example 3: A company requests a full identity document

A service provider asks you to send a complete identity document through an ordinary chat. Before sending it, verify the company independently, ask why the document is required, who will receive it, how it will be used and whether a safer or less detailed verification method is available.

Example 4: A 'support agent' asks for your password

A person contacts you through social media and says your account needs to be verified. They ask for your password and recovery code. Do not provide either. Open the service's official website or app yourself and use its legitimate account-security or support process.

Example 5: A form asks for more than the purpose requires

A simple registration form asks for your full home address, date of birth, identity document and several account details even though the stated service does not clearly require them. Pause and ask which fields are necessary. Avoid providing extra information simply because a form contains a field for it.

Before you share personal information, confirm:

1. Request: Do I know exactly what information is being requested?

2. Purpose: Has the requester clearly explained why it is needed?

3. Requester: Did I verify who is asking through an independent channel?

4. Necessity: Is every requested detail actually necessary for the legitimate purpose?

5. Secrets: Am I being asked for a password, PIN, OTP or recovery phrase that should never be disclosed?

6. Channel: Am I sharing through a legitimate and appropriate channel rather than an unexpected message or account?

A request for information is not proof that the requester is genuine.

Verify the requester independently, understand the purpose and provide only what is reasonably necessary. If you cannot verify the request, stop before sharing sensitive information.

VERIFY BEFORE YOU TRUST.