The Nigeria Data Protection Regulation (NDPR) has been in force since January 2019. For the first few years, enforcement was light and many organisations treated compliance as a distant concern. That era is over.
The Nigeria Data Protection Commission (NDPC) — established under the Nigeria Data Protection Act 2023 — is now actively issuing notices, conducting audits, and imposing sanctions. If your organisation collects, stores, processes, or transfers personal data about Nigerian citizens, NDPR compliance is not optional. It is a legal obligation with teeth.
This guide sets out what the law requires, where most organisations fall short, and the practical steps to get compliant.
Who Does NDPR Apply To?
NDPR applies to any organisation that processes the personal data of Nigerian citizens — regardless of where that organisation is based. This includes:
- Nigerian companies of all sizes across all sectors
- Government agencies and parastatals
- Foreign companies processing data of Nigerian residents
- NGOs, educational institutions, and healthcare providers
Personal data under NDPR is broadly defined: names, email addresses, phone numbers, BVN, NIN, financial information, health records, IP addresses, location data, and any other information that can identify an individual. If your business touches any of this — and virtually every business does — NDPR applies to you.
Key distinction: The Nigeria Data Protection Act 2023 (NDPA) supersedes the original 2019 NDPR but retains its core principles. References to "NDPR compliance" in practice now encompass both instruments. The NDPC is the regulatory authority responsible for enforcement.
The Core Obligations
1. Lawful Basis for Processing
You must have a lawful basis for every category of personal data you process. The most common bases are: consent (explicit, informed, and freely given), contract (processing necessary to fulfil a contract with the data subject), legal obligation, and legitimate interests (where the organisation's interests do not override individual rights).
Many Nigerian organisations rely on buried consent clauses in T&Cs that do not meet the standard. Consent under NDPR must be specific, granular, and withdrawable.
2. Privacy Policy and Notice
Every organisation must maintain a clear, plain-English privacy policy that explains: what data is collected, why it is collected, how long it is retained, who it is shared with, and how data subjects can exercise their rights. This policy must be accessible before data is collected — not buried in a 40-page document after the fact.
3. Data Subject Rights
Individuals have the right to: access their data, correct inaccurate data, request deletion ("right to be forgotten"), object to processing, and data portability. Your organisation must have processes in place to respond to these requests within 30 days.
4. Data Security
NDPR requires "appropriate technical and organisational measures" to protect personal data. This is deliberately broad, but regulators expect: access controls, encryption of sensitive data at rest and in transit, regular security assessments, and incident response procedures.
5. Data Breach Notification
In the event of a personal data breach, you must notify the NDPC within 72 hours of becoming aware of the breach. If the breach is likely to result in high risk to individuals, those individuals must also be notified without undue delay. Most Nigerian organisations have no breach notification process whatsoever.
6. Data Protection Officer (DPO)
Organisations that process personal data as a core activity must appoint a Data Protection Officer (DPO) and register with the NDPC. The DPO can be internal or an external consultant, but must have appropriate expertise.
7. Cross-Border Data Transfers
Personal data on Nigerian citizens can only be transferred outside Nigeria to countries with equivalent data protection standards, or where appropriate safeguards (contracts, binding rules) are in place. If you use cloud services hosted outside Nigeria — AWS, Azure, Google Cloud, Salesforce — you need to assess whether your data transfer arrangements are compliant.
⚠️ Penalties for Non-Compliance
The NDPA 2023 provides for significant sanctions including:
- Fines of up to 2% of annual gross revenue or ₦10 million (whichever is higher) for general violations
- Fines of up to 2.5% of annual gross revenue for aggravated violations
- Criminal liability for deliberate data breaches
- Reputational damage, regulatory notices, and mandatory audits
Where Most Nigerian Organisations Fall Short
After working with organisations across financial services, healthcare, and the public sector, the gaps we most commonly encounter are:
- No data inventory. Organisations don't know what personal data they hold, where it lives, or who has access to it. You cannot protect — or comply with — data you can't see.
- Inadequate consent mechanisms. Pre-ticked boxes, bundled consent, or no consent at all for marketing communications.
- No breach response plan. 72-hour notification is legally required. Most organisations would take days just to identify that a breach had occurred.
- Unmanaged third-party risk. HR platforms, payroll systems, CRMs, and cloud storage often hold personal data managed by vendors who have not been assessed for compliance.
- Weak access controls. Shared passwords, ex-employees with active accounts, no principle of least privilege. Personal data accessible to anyone who knows where to look.
Your NDPR Compliance Checklist
Compliance Checklist
- Complete a data mapping exercise — document what personal data you collect, where it is stored, and who processes it
- Establish and document a lawful basis for each category of data processing
- Publish a NDPR-compliant privacy policy on your website and customer touchpoints
- Implement processes to handle data subject requests within 30 days
- Appoint a Data Protection Officer and register with the NDPC
- Conduct a Data Protection Impact Assessment (DPIA) for high-risk processing activities
- Encrypt personal data at rest and in transit; implement access controls
- Build a data breach detection, notification, and response procedure
- Review and update contracts with all third-party data processors
- Assess cross-border data transfers and implement appropriate safeguards
- Train staff on data protection responsibilities and acceptable use
- Schedule annual compliance audits and policy reviews
The Technical Controls That Matter Most
From an IT infrastructure perspective, NDPR compliance requires a set of controls that are often absent or poorly implemented in Nigerian organisations:
Encryption
Personal data in databases, file shares, email, and backup systems should be encrypted. For data in transit, enforce TLS 1.2 or higher across all web applications and APIs. For data at rest, full-disk encryption on endpoints and volume encryption on servers and cloud storage are the minimum standard.
Identity and Access Management
Implement role-based access control (RBAC) so that staff can only access personal data relevant to their role. Review and revoke access for former employees immediately upon offboarding. Multi-factor authentication (MFA) should be mandatory for all accounts with access to personal data.
Audit Logging
Enable and retain audit logs for access to systems containing personal data. Logs should capture who accessed what, when, and from where. These logs are essential for breach detection and are increasingly reviewed by regulators during audits.
Endpoint Security
Deploy endpoint detection and response (EDR) across all devices that access personal data. Implement mobile device management (MDM) to enforce encryption and remote wipe capability on staff phones and laptops.
Getting Started
For most organisations, the best starting point is a data protection gap assessment — a structured review of your current practices against NDPR requirements that produces a prioritised remediation plan. This gives you a clear picture of your compliance status and the specific actions needed to close the gaps.
BNG Technologies works with Nigerian organisations to implement the technical controls that underpin NDPR compliance — from access management and encryption to breach detection and response. We also partner with data protection consultants who can assist with the legal and policy dimensions.
The time to act is now. Regulators are watching, enforcement is real, and the cost of a breach — financial, regulatory, and reputational — far exceeds the cost of getting compliant.
Need help with NDPR compliance?
Our engineers can implement the technical controls your compliance programme requires — encryption, access management, audit logging, and breach response.