NewsStocksTruecaller says Nigerians can remove their numbers after privacy ruling

Truecaller says Nigerians can remove their numbers after privacy ruling

Author: Techcabal·

Key Takeaways

  • •The Lagos State High Court dismissed all reliefs sought by non-users who challenged Truecaller's handling of their contact data, including injunctions and ₦300 million ($225,992) in damages.
  • •The court held that a user's acceptance of Truecaller's terms or consent to upload contacts is insufficient to establish implied consent from non-users whose numbers appear in that phonebook.
  • •The dismissal rested on the applicants' failure to attach credible evidence of injury or constitutional privacy violation, not on an endorsement of Truecaller's consent model, according to the applicants' lawyer.
  • •Truecaller will not suspend or redesign its Nigerian service and says anyone can remove their number at any time through its unlisting portal, with a non-reversible hash retained to prevent re-upload.
  • •The applicants plan to appeal the court's treatment of injury from privacy violations, leaving questions about remedies under Nigerian data-protection law unresolved.
Truecaller says Nigerians can remove their numbers after privacy ruling

Truecaller says any Nigerian can remove their phone number from its caller-identification service after the Lagos State High Court dismissed a privacy case brought by people who do not use the platform.

Non-users’ details can enter Truecaller’s database through contact lists uploaded by its users, which is how the names and numbers of people who never installed the app can surface in its caller-identification results.

The company told TechCabal that its unlisting tool allows non-users to request the removal of their phone numbers and associated caller identities from its active, searchable database.

“The Lagos State High Court dismissed this suit and refused all the reliefs sought,” a Truecaller spokesperson said in a statement on Monday. “We welcome the court’s recognition that caller identification and spam detection serve an important public-safety purpose in protecting Nigerians from scams, fraud and harassment.”

The statement followed TechCabal’s earlier report on the dispute over how Truecaller processes the phone numbers and names of people who have not signed up for its service: https://techcabal.com/2026/09/23/nigerian-court-says-truecallers-consent-doesnt-cover-contacts/

The applicants, including the Incorporated Trustees of the Data Privacy Lawyers Association, acting on behalf of non-users, asked the court to declare that Truecaller’s collection, storage and disclosure of non-users’ phone numbers violated privacy rights under Section 37 of the Nigerian Constitution and Part V, Sections 34–38, of the Nigeria Data Protection Act (NDPA), Nigeria’s principal data-protection law.

They also sought orders stopping Truecaller from processing non-user data, requiring the company to delete data it already held and awarding ₦300 million ($225,992) in general and exemplary damages.

The Lagos High Court dismissed the applicants’ injury claims and rejected their requests for prohibitory and mandatory injunctions, as well as damages. However, excerpts of the judgment reviewed by TechCabal distinguish between the court’s findings on consent and its final decision on whether the applicants established an actionable violation of their fundamental rights.

On consent, the court rejected the argument that a user’s acceptance of Truecaller’s terms, or consent to upload contacts, automatically constituted consent from non-users whose numbers appeared in that user’s phonebook.

“The user of the app voluntarily consented to the upload of contact details on the user’s phone to the respondent is insufficient to establish implied consent,” the court held. It said accepting Truecaller’s theory of implied consent “would completely eviscerate the rule of privacy and the definition of consent as provided by the Act.”

The court also said Truecaller, acting as both a data controller and a data processor in the circumstances under consideration, had a duty to safeguard personal data and ensure that it was not released to third parties without legitimate justification.

Olumide Babalola, chair of the Nigerian Bar Association’s Data Protection Committee and the applicants’ lawyer, said the dismissal should not be interpreted as a complete endorsement of Truecaller’s consent model.

“The only issue the court found, which helps them, is that we did not attach evidence of damages,” Babalola told TechCabal on Monday. “That does not detract from the findings on lack of consent and legitimate interest.”
Truecaller said consent was not its only legal basis for processing the information. The company relied on the public-interest and legitimate-interest provisions in Section 25 of the NDPA, as well as the public-safety exception in Section 45 of the Constitution.

It said its caller-identification, spam-detection and fraud-screening functions help users identify suspicious and malicious calls. In its statement to TechCabal, the company said the court accepted that caller identification could serve a public-safety purpose and that its operations could be justified under lawful grounds beyond implied consent.

“The court’s recognition that caller identification and spam detection serve an important public-safety purpose” was central to the outcome, the spokesperson said.

The court’s reasoning, however, as reflected in the excerpts, did not say that public interest or legitimate interest automatically overrides a data subject’s privacy rights. The judgment noted that legitimate interest under Section 25(1)(b)(v) is limited when it overrides the fundamental rights, freedoms and interests of the person whose data is being processed.

The court then considered a separate question: whether the applicants had provided credible evidence showing that their constitutional right to privacy had been infringed.

Truecaller’s defence was that its search function operates as a “number-for-name” system. A person seeking an identity must already have the phone number before a name can be displayed, the company argued. It said this did not expose private contact details to unknown third parties.

The company also said it does not automatically upload users’ address books. According to the court ruling, contact information is uploaded only when a user activates an optional Enhanced Search feature in certain non-store versions of the app—those distributed outside official app stores—and confirms that they are authorised to share the contacts.

Truecaller said it would not suspend or redesign its Nigerian service as a result of the decision. The company argued that the court had rejected requests to halt its processing of non-user data and to compel the deletion of data already held by the company.

“Moreover, we empower every individual who is not a user and does not want their caller ID to be available on the service to be able to unlist themselves on their own by visiting the Unlisting portal: truecaller.com/unlisting and unlist their number,” the company said.

Truecaller said it retains a one-way cryptographic hash after a number is unlisted to prevent that deleted number from being accidentally re-uploaded when an active user synchronises a phonebook. The company said the hash is non-reversible.

“Anyone, whether or not they use Truecaller, can remove their number from our service at any time through our unlisting page,” the spokesperson said. “We take our obligations under the Nigeria Data Protection Act seriously and will continue to engage constructively on these issues.”

The ruling ends the case at the Lagos High Court for now. Babalola said the applicants plan to appeal the court’s treatment of injury arising from privacy violations. The case therefore leaves important questions about remedies under Nigerian data-protection law unresolved.

The court found that consent from an app user was not sufficient, by itself, to establish implied consent from a non-user. It also emphasised that legitimate interest cannot override fundamental rights. At the same time, it dismissed the claim after finding that the applicants had not established a constitutional privacy violation with sufficient evidence.

That distinction could influence future disputes involving apps that rely on contact lists, caller-identification services, social-discovery tools and other systems built on data supplied by one person about another.