InsightsCompliance

COMPLIANCE · JULY 2026

NDPR Compliance in Nigeria: A Practical Guide

The Nigeria Data Protection Regulation (NDPR) has been in force since January 2019 and was substantially updated by the Nigeria Data Protection Act (NDPA) 2023. If your business collects, stores, or processes personal data, including names, email addresses, phone numbers, BVN and health records, the NDPR applies to you.

Who the NDPR applies to

NDPR applies to any Nigerian business (or foreign business targeting Nigerian citizens) that processes the personal data of Nigerian residents. In practice this means:

  • Any website with a contact form, newsletter signup, or user registration.

  • Any business that stores customer records, staff data, or patient records.

  • Any app that collects user data, including phone number, location or financial information.

  • Any business using HR software, CRM systems, or customer loyalty programmes.

  • Any company receiving personal data from Nigerian citizens, even if based outside Nigeria.

What NDPR requires you to do

Have a Privacy Policy

Published on your website, covering what data you collect, why, how long you keep it, and what rights users have over their data.

Obtain consent before collecting data

You must tell people what you are collecting their data for and get their consent. Pre-ticked boxes do not count. This applies to contact forms, newsletter signups, and cookies.

Limit data to what is necessary

Only collect data you actually need for the stated purpose. Collecting extra fields 'just in case' is a violation.

Provide data subject rights

Users have the right to access, correct, or delete their data. You must be able to action these requests within 72 hours for erasure requests.

Report data breaches

Any breach that puts personal data at risk must be reported to the Nigeria Data Protection Commission (NDPC) within 72 hours of discovery.

Appoint a Data Protection Officer (for large processors)

Businesses processing data of more than 10,000 Nigerians per year must appoint a DPO and file an annual data audit with a licensed NDPC-accredited data protection compliance organisation (DPCO).

What the penalties look like

The NDPA 2023 increased the penalty regime significantly. For private sector organisations:

Violation typePenalty
Processing without legal basisHigher of ₦2 million or 2% of global annual revenue
Failure to report a breachUp to ₦10 million or 2% of global annual revenue
Obstructing the NDPCCriminal penalty: up to 3 years imprisonment
Failure to file annual audit (large processors)₦2 million per violation

The practical 5-step NDPR compliance checklist

1

Audit what data you are collecting

Map every point where your business collects personal data: website forms, WhatsApp conversations, spreadsheets, CRM and HR software. You cannot protect what you have not documented.

2

Write or update your Privacy Policy

Your Privacy Policy must state what you collect, the legal basis, how long you keep it, who you share it with, and how users exercise their rights. This must be accessible from every page of your website.

3

Implement proper consent collection

Review every form on your website and ensure consent is explicit, specific, and unambiguous. Cookie banners need to meet the standard. Pre-consenting users does not work.

4

Secure your data properly

Encrypt stored personal data. Use HTTPS on all web properties. Restrict access to data to people who need it. Have a documented process for responding to breaches.

5

File your annual data audit if required

If you process data of more than 10,000 Nigerians per year, you must engage a licensed DPCO and file an annual audit with the NDPC. This is a legal requirement, not optional.

NDPR-READY SOFTWARE

We build software with NDPR compliance built in

When we build customer-facing applications, CRMs, or web platforms, we implement consent management, data access controls, audit logs, and privacy policies as part of the standard delivery, not as an afterthought.