Data Protection Compliance in Nigeria: From Policy to Evidence
Knowing the NDPA 2023 exists is not the same as being able to demonstrate compliance with it. Copied privacy notices, informal consent practices, and data maps nobody has revisited since they were first drafted are common enough, and none of them hold up once an inquiry begins.
Enforcement is no longer theoretical. The NDPC fined Fidelity Bank ₦555.8 million in August 2024 and MultiChoice Nigeria ₦766.2 million in July 2025. For organisations building a compliance programme, both cases underline the same point: policies only count if they can be demonstrated when scrutinised.
This article is part of PlanetWeb’s NDPA compliance series. For the legal framework itself, see key features of the NDPA. For organisations just starting out, particularly NGOs and small businesses, see the NDPA compliance starting-point guide.
Building a compliance programme means producing evidence beyond policy alone: what to prioritise first, what a regulator will ask to see, and what changes depending on the organisation’s sector.
Where Does Your Business Stand?
Before prescribing strategies, it helps to know where you’re starting. Most Nigerian businesses fall into one of three stages.
| Stage | Indicators |
|---|---|
| Reactive | No documented data inventory. Privacy notice copied or absent. Consent handled informally or not at all. No DPO or designated responsible person. Compliance is considered only after a complaint or incident. |
| Developing | Some policies exist but are applied inconsistently. A data inventory was started but is incomplete or outdated. NDPC registration is initiated or in progress. Vendor contracts exist but lack data processing clauses. |
| Mature | A documented data map is reviewed at least annually. Lawful basis is recorded for each processing activity. NDPC registration is in place where required. A DPO is designated where required. Vendor contracts include DPAs. A breach response plan has been tested. Training records exist. |
Most businesses reading this sit at Reactive or early Developing. Organisations at that stage with little prior NDPA exposure, including many NGOs and small businesses, may find it more useful to begin with the NDPA compliance starting-point guide before returning to the strategy below.
The Real Cost of Compliance vs. the Cost of Getting It Wrong
The cost of non-compliance goes beyond the penalty itself. It includes being unable to demonstrate, when asked, that the organisation does what it claims to. A privacy notice describing careful data handling means little if nobody can produce the records behind it.
The Fidelity Bank and MultiChoice fines illustrate the scale that is now possible, and the Nigeria Data Protection Commission goes into the Commission’s enforcement powers in more depth.
Beyond the fine itself, the NDPC can issue orders halting data processing entirely, which in practice can mean a CRM, payment system, or HR portal suspended mid-investigation.
The foundational work looks modest by comparison: a data audit, documented lawful basis, updated privacy notices, NDPC registration, and vendor contract review. It is primarily a time investment rather than an infrastructure one. Organisations that build this proactively have a materially easier audit experience than those assembling it retrospectively, because the difference is visible to whoever’s asking.
Start with a Data Map
Every other compliance activity depends on this one. Documenting a lawful basis, responding to a data subject request, or demonstrating accountability to the NDPC all require first knowing what personal data an organisation holds, where it lives, and what it is used for.
A data map should record the category of personal data, where it was collected, where it is stored, the purpose of collection, the lawful basis relied on, how long it is retained, and who has access, including third-party vendors and cloud platforms.
The common failure points are predictable: maps that cover customer data but ignore employee data, maps that miss records sitting in individual spreadsheets, and maps completed once and never reviewed. A data map twelve months out of date is itself evidence of neglect once an audit is underway.
Building the map depends on business knowledge spread across departments. Finance knows what payroll data exists. HR knows what employee records exist. Sales knows what the CRM contains. For organisations using Microsoft 365, SharePoint NDPA compliance explains how the platform’s own access and retention features can support this exercise.
The Legal Grounds for Processing
The most common compliance error is treating consent as the default lawful basis for every processing activity, when the NDPA provides six and consent is not always the right one, or a valid one. Key features of the NDPA walks through all six in detail.
For an audit-readiness programme, the most important point is documentation: for every category of personal data in the data map, you need to record the lawful basis relied on and the reasoning behind it. This is the kind of information an organisation needs to be able to produce when its processing practices come under scrutiny, and a data map without this layer is only half-built.
NDPC Registration
Registration is mandatory for organisations that fall within the NDPC’s classification as data controllers or processors of major importance. The requirements differ by category: Ultra-High Level (UHL) and Extra-High Level (EHL) organisations register once and file Compliance Audit Returns annually, while Ordinary High Level (OHL) organisations renew their registration annually and do not file annual returns.
Organisations classified as data controllers or processors of major importance also have additional obligations, including DPO designation under Section 32 of the NDPA, and for UHL and EHL organisations, annual Compliance Audit Returns filed through a licensed DPCO unless otherwise approved by the Commission.
Key features of the NDPA sets out the full three-tier classification, and the GAID registration guide handles the registration process itself in detail.
Data Protection Impact Assessments
DPIA work becomes part of being audit-ready where an organisation’s processing presents the kind of risk that requires an assessment. What matters for a compliance programme is not running the assessment once; it is being able to produce it when asked, alongside the decision it led to.
Data protection impact assessments in Nigeria details exactly when one is required and how to run it.
Vendor Risk and Data Processing Agreements
Every business uses vendors that touch personal data, including payroll platforms, CRM systems, payment gateways, and email marketing tools. Using a processor does not remove the controller’s own data protection responsibilities. The controller still needs to know how the data is being handled and whether the processor is meeting its obligations.
A Data Processing Agreement needs to cover the subject matter and duration of processing, the categories of data and data subjects involved, the processor’s obligations and restrictions, security requirements, breach notification timelines, restrictions on sub-processing, and what happens to the data when the contract ends.
Many local vendors do not proactively offer DPAs, and international vendors often have standard agreements that do not fully satisfy NDPA requirements. Requesting, reviewing, and negotiating these agreements is the controller’s responsibility, not the vendor’s, and assuming a DPA exists because a vendor is reputable is not a compliance position.
If a vendor causes a breach or mishandles personal data, the controller’s relationship with that vendor becomes part of the compliance picture. The organisation should be able to show what the vendor was authorised to do, what safeguards were agreed, and how the relationship was being managed.
Where the request itself came from a data subject, data subject rights in Nigeria sets out how those requests should be handled.
Record-Keeping: Your Compliance Defence
The NDPC does not take an organisation’s word for compliance. An auditor asks for evidence, and record-keeping is what converts good intentions into a defensible position.
Organisations should maintain records of the data map and its revision history, lawful-basis documentation, consent records, data subject request logs, DPIAs for high-risk activities, staff training logs, vendor contract reviews, and breach records including the outcome of each assessment.
The mistake most organisations make is treating record-keeping as something to organise after the programme is built. Records need to be created as part of the process itself; an auditor can tell the difference between records maintained over time and records assembled the week before an inquiry.
Building a Compliance Culture
Policies will not protect a business if staff do not follow them. Most data incidents result from human error: a file shared with the wrong person, a phishing email that bypasses controls, a customer database exported to a personal device.
Effective training covers what personal data means under the NDPA, what lawful basis means for each specific role, how to recognise and respond to a data subject request, and what to do when a potential breach is discovered. A customer-facing sales team has different obligations from a finance team processing payroll, and training that treats every role the same is often remembered by none of them.
Compliance that lives only with a compliance officer will not take hold. Leadership needs to treat data protection as an ongoing operational priority, revisited as the business changes.
What an NDPC Audit or Investigation Looks Like
An organisation does not become audit-ready by having policies. It becomes audit-ready when it can demonstrate those policies reflect what the organisation does, which is the point every section above has been building toward.
What Can Bring the NDPC Into the Picture
A data subject complaint, a sector-wide review, media reporting on a breach, or an organisation’s own breach notification can all trigger scrutiny. The NDPC can investigate suspected breaches and complaints, and it can also take regulatory action where it identifies compliance concerns on its own initiative.
What the Organisation May Be Asked to Provide
An inquiry can reasonably request the data map, lawful-basis documentation, consent records, DPAs with vendors, DPIAs for relevant activities, training records, and data subject request logs. This is exactly why each of them needs to exist well before any notice arrives.
How the Organisation Should Respond
Cooperation and timely, accurate documentation are what an inquiry responds to. An organisation that can produce what is asked for promptly is in a materially different position from one that needs weeks to locate records that should already exist.
What Happens if Gaps Are Found
The NDPC can issue compliance orders requiring specific remedial steps, alongside financial penalties where the violation warrants them. The Commission’s enforcement framework allows factors such as cooperation and the degree of impact on privacy to be considered when determining how a matter is resolved, which makes documented evidence of an organisation’s response and corrective action worth having.
Outcomes range from a compliance order with a remediation timeline to the financial penalties Fidelity Bank and MultiChoice both faced, plus the operational disruption of a processing halt when the NDPC deems it necessary.
How Sector and Organisation Type Change the Compliance Picture
The core obligations apply to every organisation processing personal data in Nigeria, but audit readiness looks different by sector.
Financial Services
Financial institutions in Nigeria typically face overlapping NDPC and CBN oversight, and open banking consent differs from general service consent and needs separate management. The NDPA vs. GDPR comparison addresses cross-border considerations relevant to institutions operating internationally.
Healthcare
Patient data is sensitive personal data, subject to enhanced security expectations. Role-based access is particularly important here: clinical staff should access only records relevant to their own patients, and that access should be logged, not assumed.
E-Commerce
Consent management at checkout is one area where compliance gaps can easily arise. A single checkbox cannot cover order processing, marketing emails, and data sharing with partners as one blanket agreement. Retaining customer data indefinitely after account closure, without a documented reason, is a retention gap worth addressing.
NGOs and Smaller Organisations
The same obligations apply regardless of mission or size, and NGOs often hold beneficiary and donor data that qualifies as personal data, without anyone treating it that way.
For organisations at this stage, particularly those without prior compliance infrastructure, the NDPA compliance starting-point guide is the more useful starting point before returning to the fuller programme above.
Get Your Compliance Programme Audit-Ready
Building a compliant programme is ongoing work. What is built now needs regular maintenance to stay useful.
Our IT consulting work covers assessing where your current programme stands, closing the gaps that would surface in an audit, and building the record-keeping that makes compliance demonstrable. Contact us to talk through where your organisation stands.






