NDPA Compliance for Small Businesses: Where to Start

Learn NDPA compliance for small businesses: where to start with privacy meeting guidance.

NDPA Compliance for Small Businesses: A Practical Starting Point for NGOs and Small Organisations

The NDPA doesn’t stop applying because an organisation is small or is not “data-heavy”. A five-person NGO holding beneficiary and donor records falls within its scope. So does a retailer with a customer contact list, or a community group running a mailing list. None of them need to have read the Act for it to apply.

This article is written for organisations with little or no NDPA awareness who need to know where to start, not organisations already deep into a compliance programme.

For the legal detail behind each requirement, key features of the NDPA covers that ground, and audit readiness picks up once a formal programme already exists.

Why This Applies Even If You Don’t Think of Yourself as a “Data Business”

Personal data doesn’t require a data-driven business model to trigger the Act. It requires personal data, and most organisations hold more of it than they realise: a spreadsheet of beneficiary names and phone numbers, a donor mailing list built up over years, an HR file for two employees, a WhatsApp group of members sharing contact details.

None of that looks like the kind of processing the NDPA seems written for, but it can all fall within the Act’s scope. Beneficiary data collected as part of programme delivery carries the same obligations as any other personal data, including where beneficiaries are children, survivors of abuse, or other groups the organisation has a particular duty of care toward.

Operating for a charitable or social purpose doesn’t put an organisation outside the Act either. If it collects, stores, or uses personal data, it needs to understand what obligations apply.

What Personal Data Does Your Organisation Hold?

Before anything else, an organisation needs to know where its personal data lives, since it’s rarely in one place.

CategoryCommon Examples
Employee and volunteer recordsContact details, ID documents, bank details for payment
Member, donor, or beneficiary recordsNames, contact details, donation or service history
Contact and mailing listsNewsletter subscribers, community group members
Identification and payment informationNational ID numbers, BVNs, payment card details
Photos, recordings, and event dataEvent registration forms, photos from programmes or activities

Most of this data doesn’t sit in a dedicated system. It’s scattered across email inboxes, WhatsApp chats, spreadsheets, cloud storage folders, and whatever SaaS tools the organisation has picked up over time.

Locating it is the first real step, and it’s a more useful starting point than buying a compliance tool before anyone knows what needs protecting.

When You Need Consent, Get It Right

Consent is one lawful basis among several, not the default basis for everything an organisation does. Asking for consent when another lawful basis genuinely applies can create an unnecessary problem later, particularly if the person withdraws consent and the organisation has treated it as the only justification for processing.

Key features of the NDPA covers all six lawful bases in more depth.

Where consent is the right basis, it has to hold up against three common failure modes.

Pre-Ticked Boxes

A pre-ticked box isn’t valid consent, since the person hasn’t actively agreed to anything. Consent has to be an action the person takes, not a default they have to notice and undo.

Bundled Consent

Bundling consent into an agreement to a broader set of terms, so that accepting one thing quietly accepts several others, doesn’t hold up either. Where consent is being used for different purposes, those purposes need to be clearly explained rather than hidden behind a single blanket agreement.

Consent Buried in Terms and Conditions

Consent buried inside a long terms-and-conditions document that nobody reads isn’t meaningfully informed. If the person couldn’t reasonably be expected to have seen it, it isn’t valid consent regardless of where it technically appears.

Withdrawing consent also needs to be roughly as easy as giving it. An organisation that makes opting in a single click and opting out a multi-step process is creating exactly the kind of imbalance the Act is designed to prevent.

What to Do When Someone Asks About Their Data

At some point, someone will ask what data an organisation holds about them, or ask for it to be corrected or deleted. Having no process for this moment is itself the gap, regardless of how the organisation would otherwise handle the request.

A workable minimum is straightforward: know who receives these requests when they come in, confirm the person making the request is who they say they are, locate what’s held about them, and respond within the Act’s timeframes rather than however long it takes to get around to it.

None of this requires sophisticated tooling. It requires someone who knows the request landed and what to do next.

Working With Vendors and Other Processors

Most small organisations already hand personal data to other companies without thinking of it that way: email marketing platforms, CRM systems, cloud storage, website hosting, accounting software, payment platforms, and messaging tools all process data on the organisation’s behalf.

NGOs often add donor management platforms and grant-reporting systems to that list, often without anyone checking how those vendors handle the beneficiary and donor data being uploaded. Using them doesn’t remove the organisation’s own data protection responsibilities; it just adds another party into the picture.

For each vendor handling personal data directly, a handful of questions matter more than a generic “have a Data Processing Agreement” checkbox.

QuestionWhy It Matters
Where does the data go once it leaves the organisation?Determines what jurisdiction and safeguards apply
Who at the vendor can access it?Unrestricted vendor access is still the organisation’s exposure to manage
Is the vendor acting as a processor, or an independent controller?Changes who’s accountable for what if something goes wrong
Is there a signed agreement covering how the data is handled?Sets out the parties’ responsibilities and how the data is to be handled
What happens to the data when the relationship ends?Undefined offboarding often means data sitting indefinitely with a vendor no longer in use
Does the vendor use the data for anything of its own?Reuse beyond the agreed service is a separate processing activity requiring its own basis
Does any of it leave Nigeria in the process?Triggers the Act’s cross-border transfer requirements

A vendor that can’t answer these questions, or treats them as an odd thing to ask, is worth walking away from before a problem forces the conversation.

Sending Data Outside Nigeria

For most small organisations, sending data abroad doesn’t look like a deliberate decision to transfer a database internationally. It looks like using Gmail, hosting a website with an overseas provider, or running a CRM based in Europe or the United States.

For NGOs specifically, it often also means reporting beneficiary data back to an international donor or funder based outside Nigeria, since that reporting relationship carries the same transfer obligations as any other.

Those arrangements can involve international transfers of personal data under the NDPA, whether or not anyone thought of them that way when the tool was chosen. The Act permits international transfers subject to the applicable conditions and safeguards. Key features of the NDPA covers the specific mechanisms.

If a Breach Happens

An organisation with little NDPA awareness is as likely to find this article after something has already gone wrong as before. If that’s the situation, a few things matter immediately: preserve whatever evidence exists rather than deleting logs or records to “clean up,” establish what happened and what data may have been affected, and escalate internally rather than letting one person quietly try to handle it alone.

Notification obligations, including the Act’s specific deadlines, are covered in key features of the NDPA. The immediate priority is containing the situation and preserving evidence; the legal timeline matters, but it starts from an accurate account of the incident, not a rushed one.

Where to Start, In What Order

Faced with all of the above at once, the honest answer is that it doesn’t all have to happen simultaneously. The sequence looks like this:

Find the personal data the organisation holds and where it lives. Identify why each category is being processed, and whether that reason is a genuine lawful basis. Assign someone to own this work, even informally, before asking anyone to act on the previous two steps: nothing here moves forward if no one is responsible for moving it.

Review the vendors currently handling data on the organisation’s behalf. Identify which of those relationships involve data leaving Nigeria. Fix the most obvious, highest-risk gaps first, rather than trying to build a complete programme immediately. Once the basics are in place, decide what still needs deeper professional review.

Assigning someone responsibility doesn’t mean appointing a formal Data Protection Officer. A five-person NGO doesn’t need to appoint a formal DPO to get started; it needs one person who knows this is now part of their job. Whether a formal DPO is required, and what that role involves, is covered in Data Protection Officers in Nigeria.

When to Bring in Outside Help

Not every organisation working through this needs a consultant to do it. Outside expertise tends to earn its cost where the data involved is large in volume or particularly sensitive, where the lawful basis for a given activity isn’t clear, or where third-party processing is extensive.

The same applies where data genuinely crosses borders as a core part of operations, where a breach is suspected, where regulatory requirements from different sources conflict, or where nobody internally can own the work at all. An organisation that has already been contacted by the NDPC falls into this category by default.

Get Started on NDPA Compliance

If working through the sequence above raises more questions than it answers, that’s a normal place to be, not a sign of being behind.

Our IT consulting work covers helping small organisations map their data, review vendor relationships, and build a compliance approach sized to what they need. Contact us to talk through where your organisation currently stands.

Frequently Asked Questions

Does the NDPA apply to NGOs and small businesses?
Yes. The Act applies based on whether personal data is being processed, not on organisational size or sector. A small business collecting customer contact details, or an NGO holding a donor list, is processing personal data in exactly the sense the Act covers.
Do we need a Data Protection Officer if we're a small organisation?
Not automatically. Formal DPO appointment is required for organisations classified as data controllers or processors of major importance, and may also be required for other organisations depending on the nature of their processing. Every organisation needs someone who owns this work day to day, whether or not that rises to a formal DPO appointment.
What's realistically the first thing to fix?
Knowing what personal data exists and where it’s kept. Most other decisions, including which lawful basis applies and which vendors need reviewing, depend on having that picture first.
Can one person handle this at a small organisation?
For the initial steps, generally yes. One person can map the data, review consent practices, and start working through the vendor list. Where the organisation’s processing is more extensive or higher risk, that single point of ownership may need professional support behind it rather than being expected to cover everything alone.
Share this article:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top