🛡️
BNG Technologies
Engineering & Security Practice

The Nigeria Data Protection Regulation (NDPR) has been in force since January 2019. For the first few years, enforcement was light and many organisations treated compliance as a distant concern. That era is over.

The Nigeria Data Protection Commission (NDPC) — established under the Nigeria Data Protection Act 2023 — is now actively issuing notices, conducting audits, and imposing sanctions. If your organisation collects, stores, processes, or transfers personal data about Nigerian citizens, NDPR compliance is not optional. It is a legal obligation with teeth.

This guide sets out what the law requires, where most organisations fall short, and the practical steps to get compliant.

Who Does NDPR Apply To?

NDPR applies to any organisation that processes the personal data of Nigerian citizens — regardless of where that organisation is based. This includes:

Personal data under NDPR is broadly defined: names, email addresses, phone numbers, BVN, NIN, financial information, health records, IP addresses, location data, and any other information that can identify an individual. If your business touches any of this — and virtually every business does — NDPR applies to you.

Key distinction: The Nigeria Data Protection Act 2023 (NDPA) supersedes the original 2019 NDPR but retains its core principles. References to "NDPR compliance" in practice now encompass both instruments. The NDPC is the regulatory authority responsible for enforcement.

The Core Obligations

1. Lawful Basis for Processing

You must have a lawful basis for every category of personal data you process. The most common bases are: consent (explicit, informed, and freely given), contract (processing necessary to fulfil a contract with the data subject), legal obligation, and legitimate interests (where the organisation's interests do not override individual rights).

Many Nigerian organisations rely on buried consent clauses in T&Cs that do not meet the standard. Consent under NDPR must be specific, granular, and withdrawable.

2. Privacy Policy and Notice

Every organisation must maintain a clear, plain-English privacy policy that explains: what data is collected, why it is collected, how long it is retained, who it is shared with, and how data subjects can exercise their rights. This policy must be accessible before data is collected — not buried in a 40-page document after the fact.

3. Data Subject Rights

Individuals have the right to: access their data, correct inaccurate data, request deletion ("right to be forgotten"), object to processing, and data portability. Your organisation must have processes in place to respond to these requests within 30 days.

4. Data Security

NDPR requires "appropriate technical and organisational measures" to protect personal data. This is deliberately broad, but regulators expect: access controls, encryption of sensitive data at rest and in transit, regular security assessments, and incident response procedures.

5. Data Breach Notification

In the event of a personal data breach, you must notify the NDPC within 72 hours of becoming aware of the breach. If the breach is likely to result in high risk to individuals, those individuals must also be notified without undue delay. Most Nigerian organisations have no breach notification process whatsoever.

6. Data Protection Officer (DPO)

Organisations that process personal data as a core activity must appoint a Data Protection Officer (DPO) and register with the NDPC. The DPO can be internal or an external consultant, but must have appropriate expertise.

7. Cross-Border Data Transfers

Personal data on Nigerian citizens can only be transferred outside Nigeria to countries with equivalent data protection standards, or where appropriate safeguards (contracts, binding rules) are in place. If you use cloud services hosted outside Nigeria — AWS, Azure, Google Cloud, Salesforce — you need to assess whether your data transfer arrangements are compliant.

⚠️ Penalties for Non-Compliance

The NDPA 2023 provides for significant sanctions including:

Where Most Nigerian Organisations Fall Short

After working with organisations across financial services, healthcare, and the public sector, the gaps we most commonly encounter are:

Your NDPR Compliance Checklist

Compliance Checklist

The Technical Controls That Matter Most

From an IT infrastructure perspective, NDPR compliance requires a set of controls that are often absent or poorly implemented in Nigerian organisations:

Encryption

Personal data in databases, file shares, email, and backup systems should be encrypted. For data in transit, enforce TLS 1.2 or higher across all web applications and APIs. For data at rest, full-disk encryption on endpoints and volume encryption on servers and cloud storage are the minimum standard.

Identity and Access Management

Implement role-based access control (RBAC) so that staff can only access personal data relevant to their role. Review and revoke access for former employees immediately upon offboarding. Multi-factor authentication (MFA) should be mandatory for all accounts with access to personal data.

Audit Logging

Enable and retain audit logs for access to systems containing personal data. Logs should capture who accessed what, when, and from where. These logs are essential for breach detection and are increasingly reviewed by regulators during audits.

Endpoint Security

Deploy endpoint detection and response (EDR) across all devices that access personal data. Implement mobile device management (MDM) to enforce encryption and remote wipe capability on staff phones and laptops.

Getting Started

For most organisations, the best starting point is a data protection gap assessment — a structured review of your current practices against NDPR requirements that produces a prioritised remediation plan. This gives you a clear picture of your compliance status and the specific actions needed to close the gaps.

BNG Technologies works with Nigerian organisations to implement the technical controls that underpin NDPR compliance — from access management and encryption to breach detection and response. We also partner with data protection consultants who can assist with the legal and policy dimensions.

The time to act is now. Regulators are watching, enforcement is real, and the cost of a breach — financial, regulatory, and reputational — far exceeds the cost of getting compliant.


Need help with NDPR compliance?

Our engineers can implement the technical controls your compliance programme requires — encryption, access management, audit logging, and breach response.

Related Articles