SNAG Process in Nigeria: Handling Privacy Complaints

Snag process in Nigeria banner with businessman reviewing documents in office.

SNAG Process in Nigeria: How to Handle Data Privacy Complaints Before NDPC Escalation

The GAID introduced a formal complaint mechanism that most Nigerian businesses have never prepared for. It is called a Standard Notice to Address Grievance, or SNAG, and it gives an aggrieved data subject a standardised way to ask an organisation to address an alleged data privacy violation before the matter goes further.

A SNAG can also be served by someone acting under the data subject’s authority or by a civil society organisation acting in the public interest.

Most compliance discussions cover registration, DPOs, and data breach response. The SNAG process gets far less attention, despite carrying real response obligations and a reporting line to the NDPC. A business with no process for receiving and handling one has a gap worth closing.

This article explains what a SNAG is, who can send one, what the NDPC can see, and what a proper response requires.

It is part of PlanetWeb’s GAID compliance series. For the foundational framework, see GAID Nigeria Data Protection Directive: What Every Business Must Know. For the broader data subject rights that SNAGs typically enforce, see Data Subject Rights in Nigeria.

What a SNAG Is

A SNAG is a standardised complaint mechanism introduced by the General Application and Implementation Directive (GAID) 2025, issued by the Nigeria Data Protection Commission under the authority of Section 61 of the Nigeria Data Protection Act (NDPA) 2023.

Article 40 of GAID establishes the process, and Schedule 9 sets out the standardised notice format. The full GAID text is available as a PDF on the NDPC’s website.

The purpose of the SNAG is to create a structured internal remediation pathway. Rather than going straight to a regulator, a data subject can send a SNAG to the organisation believed to have violated their privacy rights, giving that organisation an opportunity to investigate and respond.

A data subject can go directly to the Commission at any time, without first issuing a SNAG. A SNAG is an alternative internal route available to a data subject, rather than a mandatory step before approaching the Commission.

In practice, a SNAG represents a real chance to resolve a data complaint before it becomes a regulatory matter, and it carries real compliance obligations regardless of whether the sender later escalates.

Who Can Send One and What Can Trigger It

The GAID recognises three categories of senders.

The first is the data subject themselves: any individual whose personal data an organisation collects, holds, or processes. That includes customers, website visitors, newsletter subscribers, and job applicants.

The second is an authorised representative: typically a lawyer or any person formally acting on behalf of the data subject.

The third category warrants particular attention: a civil society organisation acting in the public interest, such as an NGO or advocacy group.

The threshold for issuing a SNAG is a reasonable belief that a data privacy right has been violated. Common scenarios include an access request that was ignored or not answered within the required timeframe, continued use of personal data after the data subject withdrew consent, and sharing of personal data with a third party without authorisation.

Other frequent triggers include a data breach that exposed the sender’s personal information, and failure to delete or anonymise data following a valid erasure request. Data Subject Rights in Nigeria covers each of these rights in detail, including the conditions and limits that apply.

One scenario that catches many Nigerian employers off guard: employees can send SNAGs to their own employer. An employee who believes their HR records, monitoring data, or payroll information has been mishandled can issue a SNAG against their employer.

Employee Data Protection in Nigeria explains the specific data rights that apply in the employment context.

A SNAG can be delivered through any reasonable means: email, physical address, telephone messaging, courier, or other written correspondence. There is no requirement to use a specific channel, though a designated inbox for privacy-related correspondence makes routing and logging considerably more reliable.

What the NDPC Can See

Many organisations that receive a SNAG treat it as a private exchange to be managed quietly, an assumption GAID does not support.

Under the GAID, an organisation that receives a SNAG is required to communicate its decision on that SNAG to the NDPC through an electronic platform the Commission may create to track these complaints.

This gives the Commission a route into the process even though a SNAG is initially addressed to the organisation rather than the regulator. Article 40 provides that the Commission may take executive notice of a SNAG that appears unresolved and institute a direct investigation.

For businesses already registered with the NDPC as data controllers or processors of major importance, the SNAG tracking dimension adds another layer of accountability to an existing compliance framework. For organisations that have not yet established a documented process for handling data protection complaints, a SNAG can quickly expose that gap.

Responding to a SNAG

Article 40 sets no fixed number of days for an organisation to communicate its decision to the NDPC, unlike the separate complaint process the NDPC runs once a matter reaches it directly.

Where the Schedule 9 notice template includes a timeframe, it reflects what the complainant requested rather than a separate statutory deadline the organisation must meet.

The absence of a statutory deadline under Article 40 does not mean a SNAG can be left unanswered indefinitely. An unresolved notice remains one of the circumstances that can prompt the Commission to step in on its own initiative.

Responding promptly is therefore a practical recommendation rather than a statutory deadline with a specific number attached. An organisation that acknowledges a SNAG quickly, investigates properly, and communicates a clear decision is better placed to explain how it handled the complaint if the matter reaches the Commission.

The decision itself needs substance: whether the organisation upholds the complaint and what remedial action follows, or declines it and on what specific legal basis. A vague acknowledgement that data privacy is taken seriously falls short of the decision GAID requires an organisation to report.

What to Do Internally When a SNAG Arrives

Most Nigerian businesses do not have a defined process for this. The following should already be in place before a SNAG arrives rather than assembled once one lands.

Designate a Receiving Channel

A dedicated contact point for privacy-related correspondence, a monitored email address such as [email protected], is the most practical option. This address should be accessible to someone with the authority to act on it and visible in the organisation’s privacy policy and on its website.

Without a designated channel, a SNAG sent to a general customer service inbox can sit unread while a response goes overdue.

Route It to the Right Person

On receipt, escalate a SNAG to the organisation’s Data Protection Officer, if one has been appointed, or to whoever is responsible for data compliance. Data Protection Officers in Nigeria breaks down when organisations must appoint a DPO and what the role must cover in practice.

The matter should be handled by someone with sufficient compliance knowledge and the authority to investigate, respond, and report to the NDPC.

Log It Properly

Every SNAG an organisation receives should be recorded in a complaints log. The entry should capture the date the notice was received, the nature of the complaint, the steps taken to investigate, the decision reached, the date and content of the response sent to the data subject, and the date of the report to the NDPC.

This record gives an organisation evidence of how it received, investigated, and resolved the complaint if the matter is later reviewed by the Commission. GAID Compliance Checklist sets out the broader documentation standards an organisation should maintain across its data operations.

Investigate Before Responding

A SNAG should not be dismissed without reviewing the underlying complaint. That means pulling the relevant data: checking the Record of Processing Activities for the processing in question, confirming the lawful basis relied on, and reviewing consent records where applicable. The real question is whether the sender’s rights were engaged and whether the organisation’s conduct was compliant.

A review may confirm that no violation occurred, or it may reveal a genuine gap in the organisation’s processes. Either way, a defensible answer depends on that investigation happening before a reply goes out, rather than being skipped in favour of speed.

Report to the NDPC

Once a decision is reached and communicated to the sender, it should be reported to the NDPC through the SNAG tracking platform. This step is a GAID obligation under Article 40, independent of how the sender responds.

When You Cannot Uphold the Complaint

Not every SNAG will result in remedial action. There are legitimate grounds for declining certain data subject requests, and declining one does not constitute a compliance failure, provided the refusal is handled correctly.

An erasure request may be refused where an organisation is legally required to retain the data. Central Bank of Nigeria (CBN) guidelines impose record-keeping obligations on financial institutions, Nigeria Revenue Service (NRS) regulations require tax record retention for defined periods, and NDPC sector guidelines set retention rules for health data.

Deleting records in response to an erasure request while breaching one of these instruments trades one compliance problem for another.

An access request may be declined where it is manifestly unfounded or excessive. A right to object to processing can be overridden where there are compelling legitimate grounds, though an objection to direct marketing is absolute and cannot be refused under any circumstances.

Data Subject Rights in Nigeria sets out the conditions and limits that apply to each right in detail, including where the distinction between absolute and qualified rights matters most.

The standard for a defensible refusal is consistent: state the specific legal basis in writing, inform the sender that they retain the right to escalate to the NDPC, and document everything. A justified refusal communicated clearly and logged properly is a tenable position. A justified refusal communicated poorly, or not communicated at all, is a compliance failure regardless of the merits of the underlying position.

The Escalation Path If It Goes Further

It is worth being precise about the sequence here. What follows describes a separate process, one a data subject can pursue instead of, before, or after sending a SNAG, rather than an automatic escalation the SNAG itself triggers.

A data subject who is unsatisfied with an organisation’s response, or who chose to file with the NDPC without sending a SNAG at all, may bring a complaint to the Commission directly.

Under the GAID, the NDPC will conduct a preliminary evaluation of the complaint. If it concludes that a violation may have occurred, it opens a case file and serves a notice of investigation on the organisation. From that point, the respondent has 21 days to respond to the notice.

The Commission may then convene a Pre-Action Conference to examine the facts and available evidence from both parties. Where the NDPC determines that a violation of the NDPA has occurred, it will direct remedial action and communicate its decision to the affected parties within seven days.

StageWho ActsTimeframe
Preliminary evaluation of the complaintNDPCNo fixed period specified
Notice of investigation served on the organisationNDPCNot specified
Response to the notice of investigationOrganisation21 days
Pre-Action Conference, where convenedNDPCAs needed
Decision communicated to affected partiesNDPC7 days after a violation is determined

This is a distinct process from a SNAG, with its own actors and its own timeframes, which is exactly why the two should not be confused with each other.

The Commission’s enforcement powers extend beyond financial penalties. The Nigeria Data Protection Commission covers the full range of tools available to it.

For context on the penalty structure, GAID Nigeria Data Protection Directive: What Every Business Must Know walks through the financial exposure in detail.

How an organisation handled the original SNAG carries into this later stage: it becomes part of what the Commission can review once a formal investigation is under way.

If a data breach triggered the SNAG in question, Responding to Data Breaches in Nigeria addresses the parallel notification obligations an organisation must meet under the GAID.

Get Help With SNAG Compliance

If it’s still unclear how your organisation would handle a SNAG today, that’s a reasonable place to start rather than a sign you’re behind.

Our IT consulting work covers reviewing SNAG handling procedures, data subject request processes, and broader GAID compliance positions. Get in touch to talk through where your organisation currently stands.

Frequently Asked Questions

Is a SNAG mandatory before going to the NDPC?
No. A SNAG is not a required precondition for filing a complaint with the NDPC or taking legal action. A data subject can go directly to the Commission at any time without sending one first.
How long does a business have to respond to a SNAG?
Article 40 does not prescribe a fixed number of days for an organisation to communicate its decision on a SNAG to the NDPC. Any timeframe on the Schedule 9 notice template reflects what the complainant has requested, not a separate statutory deadline. Responding promptly remains the sensible approach.
What happens if a business ignores a SNAG?
The NDPC may take executive notice of a SNAG that appears unresolved and institute a direct investigation. The organisation is also required to communicate its decision on the SNAG to the Commission through the designated electronic platform.
Does a business have to report a SNAG to the NDPC?
Yes. Article 40 requires the organisation to communicate its decision on the SNAG to the NDPC through the Commission’s designated tracking platform. The Commission can also monitor complaints that appear unresolved and may open an investigation as a result.
Can an employee send a SNAG to their employer?
Yes. Employees are data subjects under the NDPA and can exercise applicable data protection rights over their employment data. An employee who believes their HR or payroll data was mishandled can issue a SNAG to their employer.
Share this article:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top