Responding to Data Breaches in Nigeria: The 72-Hour Rule

Responding to Data Breaches in Nigeria: The 72 Hour Rule cybersecurity banner in modern office.

Responding to Data Breaches in Nigeria Under the NDPA

A security incident can move quickly from an IT problem to a data protection issue. A compromised vendor or an exposed database is enough to put an organisation on the clock under the Nigeria Data Protection Act (NDPA) 2023: notification deadlines, documentation, and regulatory scrutiny follow.

Having a breach response plan is no longer optional. What matters is whether that plan holds up when the Nigeria Data Protection Commission (NDPC) looks at it.

This guide is the practical companion to the Data Protection Compliance Strategies guide. That article covers building a compliance program. This one covers what happens when something goes wrong inside it.

It is part of PlanetWeb’s GAID compliance series. For the foundational framework, see GAID Nigeria Data Protection Directive: What Every Business Must Know and Key Features of the NDPA 2023.

What Counts as a Data Breach Under the NDPA

A security incident is any event that affects the confidentiality, integrity, or availability of personal data. A notifiable breach is a narrower category: one likely to risk the rights and freedoms of the individuals whose data is affected.

Security IncidentNotifiable Breach
DefinitionAny event affecting confidentiality, integrity, or availability of dataAn incident likely to result in a risk to the rights and freedoms of data subjects
Typical examplesAn attempted phishing attack that did not compromise personal data, a misdirected email, a lost encrypted laptopRansomware, an exposed unencrypted database, a vendor breach affecting customer records
NDPC notificationNot usually requiredRequired within 72 hours of awareness

The NDPA defines a personal data breach as a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. That covers ransomware, misdirected salary spreadsheets, exposed databases, and compromised vendor systems holding customer data.

The type and sensitivity of the personal data are among the factors used to assess risk. A breach involving health, biometric, financial, or other sensitive data may therefore require closer scrutiny than an otherwise similar breach involving less sensitive information.

What Triggers the 72-Hour Notification Requirement

The NDPA has two separate notification obligations, and they operate independently.

Notifying the NDPC

The NDPA requires notification to the NDPC within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of data subjects. A higher threshold, high risk, applies to notifying affected individuals directly, covered below.

The operative phrase is “becoming aware”: the clock starts when the organisation becomes aware of the breach, not when the investigation is complete.

Waiting for a complete forensic picture can cause the 72-hour window to expire. The NDPA anticipates this: an initial notification is acceptable when the full scope is not yet known, and organisations can provide supplementary information in phases.

Risk assessment considers factors including the nature and sensitivity of the data, the number of people affected, available safeguards such as encryption, and the likelihood of consequences such as fraud, identity theft, or exposure of sensitive information.

When NDPC Notification Is Not Required

Not every security incident is a notifiable breach. The organisation should document its assessment and reasoning, including where it decides notification is not required.

The standard is whether the breach is likely to risk the rights and freedoms of individuals, not whether a breach occurred in a technical sense. Notification may not be required, for instance, where the data was encrypted and the key remains secure, or where the incident involves only internal operational data with no affected personal data.

Notifying Affected Individuals

Individual notification is a separate, higher obligation than NDPC notification: it applies where the breach is likely to result in a high risk to the rights and freedoms of the individuals concerned, not merely a risk. Not every NDPC-notifiable breach clears that bar.

The notification should be directed to the affected individuals and written in plain language; a general notice on a company website should not substitute for direct notification where required. It must explain what happened, what data was affected, what the organisation has done in response, what steps individuals should take, and a direct contact point for follow-up.

Corporate language that obscures accountability satisfies neither the legal obligation nor the individuals reading it, and where financial data is involved, offering practical remedies such as account monitoring guidance or a dedicated contact line is worth considering.

The Breach Register

The NDPA requires organisations to maintain a record of personal data breaches, including those that do not require notification to the NDPC. The register gives the organisation an audit trail for its breach decisions and remedial actions.

The register should record when the incident was discovered, the nature of the breach and data involved, the number of individuals affected, the likely cause, the harm risk assessment, actions taken, whether NDPC notification was made and when, and the outcome.

DPO Certification and Semi-Annual Reporting Connection

The breach register and the obligations of the Data Protection Officer (DPO) under GAID connect, though they are not the same thing. The register is the operational record: every incident, assessed and logged as it happens. Article 13 of GAID separately requires the DPO to compile a semi-annual data protection report covering the organisation’s broader compliance position, security matters and breach notifications among the areas it addresses.

Data Protection Officers in Nigeria covers the semi-annual report and the DPO’s certification requirements in full.

Before a Breach Happens: What Preparation Requires

The Incident Response Plan

An incident response plan (IRP) needs to be specific enough to use under pressure.

Disaster Recovery Plan in Nigeria covers restoring systems and data after a disruption, and Business Continuity Planning in Nigeria covers keeping the business operating while that happens; a serious breach can trigger both.

The IRP should identify named individuals, rather than only job titles, for each response role. Pre-approved NDPC notification templates save valuable time during an active response.

It should set out escalation authority, external communication responsibilities, pre-vetted forensic and legal contacts, and a decision log so every judgment call during a response is recorded as it is made.

Who Needs to Be in the Room from the Start

Legal counsel should be involved early where the incident may lead to regulatory action or litigation.

The data protection officer or compliance lead should be the primary interface with the NDPC, not IT or communications. A single spokesperson for external communication should be designated before a breach occurs; conflicting statements from different parts of an organisation during an active incident are common and damaging.

Testing the Plan

The plan should be tested periodically through tabletop exercises, including a vendor-breach scenario with no data processing agreement in place, covered below. The exercise should test escalation, decision-making, notification, and communication, rather than simply confirming that the document exists.

The NIST Computer Security Incident Handling Guide (SP 800-61) provides a widely referenced framework for structuring these exercises.

The GAID Compliance Checklist: 24-Point Self-Audit includes breach response among its core audit areas, useful for checking whether these controls are genuinely in place before an incident.

Ongoing Security Monitoring

Preparation is not only about the plan for when something goes wrong. GAID Article 29 separately requires organisations to monitor, evaluate, and maintain their data security systems on an ongoing basis, covering access controls, authentication checks, vulnerability testing, and encryption reviews.

This is a standing obligation, not a one-time setup: an organisation that built solid security controls at launch and has not revisited them since may no longer be meeting that obligation, even without an incident to show for it.

The First 72 Hours

These phases typically overlap rather than run in a strict sequence, but each has a distinct job:

PhasePriority
Immediately on discoveryContain the incident and preserve evidence
Early hoursAssess scope and escalate internally
Before 72 hoursDecide on notification and prepare it

Contain Without Destroying Evidence

Isolating affected systems, disabling compromised accounts, changing credentials, and blocking suspicious access come first. Systems should not be wiped or reimaged before forensic investigators have cleared them; logs should be preserved and write-blocking enabled where possible.

Evidence destroyed during containment can make it impossible to establish what happened, and it weighs against the organisation in any regulatory review. Escalation follows the authority the IRP already sets out, to the DPO or compliance lead, legal counsel, and the board, rather than being decided in the moment.

Start the Notification Process Immediately

If there is any reasonable possibility that the breach meets the notification threshold, preparing the NDPC notification should begin before the forensic assessment is complete.

An initial notification acknowledging the breach and what is known, with a commitment to follow up as the investigation progresses, is the right approach; waiting for certainty can cause organisations to miss the 72-hour window.

Vendor Breach Scenarios

When a vendor is breached and customer data is affected, the controller still needs to assess the incident and meet its own notification obligations. The processor also has its own obligations under Section 40 to notify the controller and provide the information needed for compliance.

The absence of a data processing agreement does not reduce the controller’s notification obligation, but it can create a separate compliance issue of its own. The guide to insider threats in Nigeria covers related third-party and internal risk in more depth.

Notifying the NDPC and Other Regulators

What the NDPC Notification Must Contain

A complete notification should cover the nature of the breach, the categories and approximate number of data subjects and records affected, the contact details of the DPO or other contact point, the likely consequences, and the measures taken or proposed.

If full information is not available within 72 hours, it should include what is known and a realistic timeline for supplementary details. The guide to the Nigeria Data Protection Commission covers its notification requirements and enforcement powers in more depth.

Managing Simultaneous Notifications in Regulated Sectors

For regulated organisations, notification obligations stack. A fintech may need to notify both the NDPC and the Central Bank of Nigeria (CBN), with different information requirements and potentially different timelines. Healthcare organisations may have additional sector-specific obligations.

Notifications for each regulator should be prepared separately, with the timing of each documented independently; notifying one regulator should never be assumed to satisfy obligations to another.

What Happens After Notification, and What a Late One Costs

The NDPC may close the matter, request further information, or open an investigation. The exposure involved is not theoretical: under Section 48 of the NDPA, a Data Controller or Processor of Major Importance may face a maximum penalty of the greater of ₦10 million or 2% of annual gross revenue for broader NDPA non-compliance; other organisations face the greater of ₦2 million or 2%.

The NDPC’s fines against MultiChoice Nigeria (₦766,242,500, July 2025) and Fidelity Bank (₦555.8 million, August 2024) show these figures apply in practice. Neither case was a breach-notification penalty specifically, but they illustrate the scale of exposure a poorly handled compliance failure, breach-related or otherwise, can carry.

If the 72-hour period is missed, notification should still be made as soon as possible, with the reason for the delay explained.

Cyber Insurance: What It Covers and What Voids a Claim

A well-structured cyber liability policy typically covers the practical costs of a breach: forensic investigation, legal fees from regulatory investigations or third-party claims, individual notification, and business interruption during recovery. It does not replace the response itself. Notification still has to happen. Containment still has to happen. The policy pays for that work rather than performing it.

The IBM Cost of a Data Breach Report points to faster identification and containment as key drivers of lower breach costs, and recommends regularly testing incident response plans, reinforcing the case for preparation over reaction.

Policy terms may reduce or exclude coverage where, for example, notification requirements were missed, known vulnerabilities cited in the underwriting application went unpatched, or representations made during underwriting were inaccurate.

Policy wording varies, and notification and cooperation clauses should be reviewed carefully before an incident occurs; waiting until the response is complete to notify the insurer can jeopardise coverage where the policy requires prompt notification.

After the Breach: Learning and Remediation

A formal post-incident review should produce a root cause analysis, an updated IRP, a revised training plan for any identified staff failures, and a board briefing for material incidents.

It should also feed back into the compliance program itself: policies get updated to close the gap that was exploited, vendor contracts get revisited if a third party was involved, and whatever fix was put in place gets tested rather than assumed to work.

The review is also the point to check whether the processing activity behind the breach should have had a Data Protection Impact Assessment in the first place. Where a GAID required one, and it was never carried out, that is a separate compliance failure sitting alongside the breach itself.

Article 28(6) also provides for a potential restriction on the platforms through which the organisation has contact with data subjects. Data Protection Impact Assessments in Nigeria covers when a DPIA is required and how to conduct one.

Get Help With Breach Response

Our IT consulting work covers building and testing breach response functions, from incident response plans to vendor agreements and the documentation the NDPC expects to see. Get in touch if your business needs help putting this in place.

Frequently Asked Questions

What counts as a personal data breach under the NDPA?
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Not every security incident meets this bar; the question is whether it affects personal data specifically.
When does a breach have to be reported to the NDPC?
Within 72 hours of becoming aware of a breach likely to result in a risk to data subjects’ rights and freedoms. The clock starts when the organisation becomes aware, not once the investigation is complete.
Does every breach have to be reported?
No. The NDPA requires notification to the NDPC where a breach is likely to result in a risk to the rights and freedoms of data subjects. Every personal data breach should still be assessed and documented, including those that do not meet that threshold.
What should a business do in the first 72 hours?
Contain the incident and preserve evidence immediately, assess scope in the early hours, and begin preparing NDPC notification well before the deadline rather than waiting for a complete forensic picture.
What happens if a business reports late?
Late notification does not remove the obligation to report the breach. The organisation should notify the NDPC as soon as possible and explain why the 72-hour period was missed.
Share this article:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top