Digitplus
Industry & Policy

What the NDPR Means for Nigerian Businesses

The Nigeria Data Protection Regulation creates real compliance obligations for any business that handles personal data, which is nearly every business. Here is what it actually requires and how to build a credible compliance posture.

Digitplus Editorial Team9 min read
An abstract blue mesh net texture with a swirling web-like pattern

The Nigeria Data Protection Regulation, issued by NITDA and now given additional statutory foundation under the Nigeria Data Protection Act, is not a regulation for the future, it is in force now, and the enforcement posture of the Nigeria Data Protection Commission has been growing more active. For any Nigerian business that collects, stores, or processes personal data, which, in practical terms, is nearly every business, compliance is a current operational obligation, not a future project.

The problem is that NDPR compliance is widely misunderstood. It is often treated as a policy-writing exercise: produce a privacy notice, get a lawyer to review it, file it somewhere, and consider the obligation met. That reading is incorrect. The NDPR creates substantive operational requirements: for how data is collected, stored, and handled; for the rights of individuals whose data you hold; for what happens when data is breached; and for the contractual controls you must have over third parties who process data on your behalf.

Understanding what it actually requires is the first step to managing it credibly.

Who is covered, and why the answer is almost everyone

The NDPR applies to any organisation that processes the personal data of Nigerian residents, regardless of where the organisation is based. For Nigerian businesses operating domestically, the scope is effectively universal: if you have employees, you hold personal data. If you have customers, you hold personal data. If you process loan applications, patient records, student registrations, or supplier invoices that identify individuals, you are processing personal data.

The regulation distinguishes between data controllers, organisations that determine the purpose and means of processing, and data processors, organisations that process data on behalf of a controller. Both have obligations under the NDPR, but controllers carry the primary accountability for compliance. If your organisation uses a third-party payroll provider, cloud service, or software platform that processes personal data, you are a controller; your vendor is a processor. Your obligations as a controller include ensuring that your processor meets an adequate standard of data protection, and having a written agreement in place that specifies this.

The core compliance requirements

1. A lawful basis for every processing activity

The NDPR requires that every act of personal data processing rests on a lawful basis. The most familiar of these is consent, the individual's clear agreement to the specific processing. But consent is not the only lawful basis, and it is not always the most appropriate one. Contractual necessity (processing required to fulfil a contract with the individual), legal obligation, vital interests, and legitimate interests are all available bases under the regulation.

The practical requirement is to identify, for each category of personal data you process, what the lawful basis is, and to document it. This is not a theoretical exercise. A regulatory inquiry or a data subject complaint that you cannot answer with a clear statement of lawful basis is a compliance failure regardless of what your privacy notice says.

2. Data subject rights

Individuals whose data you hold have enforceable rights under the NDPR. These include the right to access their data, the right to correct inaccurate data, the right to erasure in certain circumstances, and the right to object to processing. Meeting these rights requires operational processes, a mechanism for receiving and tracking requests, a way to retrieve or delete the relevant data, and a timeline for responding that the regulation specifies.

For organisations without these processes in place, a data subject rights request is a disruptive event. For organisations that have built the process into their operations, it is routine. Building the process is not complex; the barrier is usually that it has never been prioritised.

3. Data breach notification

If your organisation suffers a personal data breach, unauthorised access, accidental disclosure, loss or destruction of personal data, the NDPR requires notification to the Nigeria Data Protection Commission within 72 hours of becoming aware of the breach (where feasible), and notification to affected data subjects if the breach is likely to result in high risk to their rights and freedoms.

72 hours is a short window. Meeting it requires that the organisation knows it has suffered a breach within a reasonable time of its occurrence, which in turn requires security monitoring adequate to detect unusual data access or exfiltration. It also requires a pre-established process for escalating a suspected breach, assessing its scope, and initiating the notification procedure.

Organisations that discover breaches weeks or months after they occurred, through external notification rather than internal detection, are not in a position to meet this requirement.

A data breach you cannot detect is one you cannot report, and one you cannot stop.

For banking and financial services organisations, this obligation sits alongside CBN's own cyber incident reporting requirements. The two are not identical, and organisations in that sector need to map both sets of obligations to their incident response process.

4. Data processing agreements with third parties

Every third party that processes personal data on your behalf must be covered by a written data processing agreement. This is not optional and is not satisfied by a general service agreement. The NDPR specifies what these agreements must contain: the scope and purpose of the processing, security obligations, restrictions on sub-processing, and the handling of data upon termination of the relationship.

For many organisations, establishing a full inventory of third-party processors is itself a discovery exercise. Cloud services, payroll providers, CRM platforms, email services, and software-as-a-service tools all frequently process personal data. Each relationship that involves personal data processing requires a compliant agreement in place.

5. Technical and organisational security measures

The NDPR requires that personal data be protected by appropriate technical and organisational measures. What is "appropriate" is contextual, it depends on the sensitivity of the data, the volume of individuals affected, and the state of technology. But the standard is not aspirational: it requires that the organisation has actually implemented controls, not merely that it has described controls in a policy.

Minimum technical expectations include access controls limiting who can see personal data, encryption for data stored and transmitted, logging of access to sensitive data, and regular assessment of security measures. Organisational measures include staff training on data protection obligations, a clear internal ownership of the compliance function, and a process for conducting privacy impact assessments before implementing new processing activities.

Building a compliance posture that is maintainable

NDPR compliance is not a project that ends, it is an operating discipline. The data landscape of an organisation changes continuously: new systems are adopted, new customer categories are served, new third-party relationships are formed. A compliance posture built around a one-time audit and an annual review is structurally insufficient.

The organisations that manage NDPR compliance most credibly are those that have built it into operating processes: privacy considerations are part of procurement due diligence, data processing agreements are a standard element of vendor onboarding, and data subject rights processes are embedded in the customer-facing operations of the business. This is not a heavy overhead, it is the overhead of having thought through the process once and documented it, rather than recreating the answer every time the question comes up.

For organisations that are starting from a compliance gap, a structured approach, data inventory, lawful basis mapping, gap assessment, and a prioritised remediation plan, produces a credible path to compliance faster than attempting to address all obligations simultaneously.

Working with a technology advisory partner who understands both the technical controls and the regulatory requirements allows compliance to be implemented in a way that is operationally realistic rather than theoretically complete but practically unworkable.


Frequently asked questions

Does the NDPR apply to small businesses and sole traders?

The NDPR applies to all controllers and processors of personal data in Nigeria, without a small-business exemption. However, the scale of what is required is proportionate to the nature and scale of the processing. A sole trader who holds a simple client contact list has different obligations from a hospital or a bank holding sensitive personal data at scale. The obligations exist in both cases, but the implementation will look very different.

What is the penalty for non-compliance with the NDPR?

The penalties available to the Nigeria Data Protection Commission include fines scaled to the severity and nature of the violation. For organisations that are data controllers of major importance, a category that includes organisations processing the data of large numbers of individuals or particularly sensitive data, the requirements and potential penalties are more significant. Beyond formal penalties, non-compliance creates reputational risk, particularly in sectors where clients and partners are themselves NDPR-sensitive.

Is a privacy policy on a website sufficient for NDPR compliance?

No. A website privacy notice is one element of compliance, it fulfils the obligation to provide transparency to data subjects about how their data is processed. It does not fulfil the obligations relating to lawful basis documentation, data subject rights processes, data processing agreements, security measures, or breach notification procedures. Organisations that believe their website privacy policy constitutes their NDPR compliance have significantly underestimated the scope of the regulation.

How does NDPR interact with sector-specific data regulations in Nigeria?

The NDPR sets a general framework for data protection that applies across all sectors. Sector-specific regulations, the CBN's cybersecurity framework for financial institutions, the National Health Act's provisions on health data, NITDA's sector-specific guidance, layer on top of NDPR and may impose additional or more specific requirements. Organisations in regulated sectors need to map both the NDPR requirements and the sector-specific overlay to understand their full compliance obligations. The NDPR does not supersede sector regulation; compliance with both is required.

  • NDPR
  • data protection
  • compliance
  • NITDA
  • Nigeria
Share

Related to this: Technology Advisory.

Have a project that needs this thinking?

Tell us what you’re planning. We’ll come back with practical next steps and a clear, line-itemised proposal, no obligation.