Who the NDPR applies to
NDPR applies to any Nigerian business (or foreign business targeting Nigerian citizens) that processes the personal data of Nigerian residents. In practice this means:
Any website with a contact form, newsletter signup, or user registration.
Any business that stores customer records, staff data, or patient records.
Any app that collects user data, including phone number, location or financial information.
Any business using HR software, CRM systems, or customer loyalty programmes.
Any company receiving personal data from Nigerian citizens, even if based outside Nigeria.
What NDPR requires you to do
Have a Privacy Policy
Published on your website, covering what data you collect, why, how long you keep it, and what rights users have over their data.
Obtain consent before collecting data
You must tell people what you are collecting their data for and get their consent. Pre-ticked boxes do not count. This applies to contact forms, newsletter signups, and cookies.
Limit data to what is necessary
Only collect data you actually need for the stated purpose. Collecting extra fields 'just in case' is a violation.
Provide data subject rights
Users have the right to access, correct, or delete their data. You must be able to action these requests within 72 hours for erasure requests.
Report data breaches
Any breach that puts personal data at risk must be reported to the Nigeria Data Protection Commission (NDPC) within 72 hours of discovery.
Appoint a Data Protection Officer (for large processors)
Businesses processing data of more than 10,000 Nigerians per year must appoint a DPO and file an annual data audit with a licensed NDPC-accredited data protection compliance organisation (DPCO).
What the penalties look like
The NDPA 2023 increased the penalty regime significantly. For private sector organisations:
| Violation type | Penalty |
|---|---|
| Processing without legal basis | Higher of ₦2 million or 2% of global annual revenue |
| Failure to report a breach | Up to ₦10 million or 2% of global annual revenue |
| Obstructing the NDPC | Criminal penalty: up to 3 years imprisonment |
| Failure to file annual audit (large processors) | ₦2 million per violation |
The practical 5-step NDPR compliance checklist
Audit what data you are collecting
Map every point where your business collects personal data: website forms, WhatsApp conversations, spreadsheets, CRM and HR software. You cannot protect what you have not documented.
Write or update your Privacy Policy
Your Privacy Policy must state what you collect, the legal basis, how long you keep it, who you share it with, and how users exercise their rights. This must be accessible from every page of your website.
Implement proper consent collection
Review every form on your website and ensure consent is explicit, specific, and unambiguous. Cookie banners need to meet the standard. Pre-consenting users does not work.
Secure your data properly
Encrypt stored personal data. Use HTTPS on all web properties. Restrict access to data to people who need it. Have a documented process for responding to breaches.
File your annual data audit if required
If you process data of more than 10,000 Nigerians per year, you must engage a licensed DPCO and file an annual audit with the NDPC. This is a legal requirement, not optional.
NDPR-READY SOFTWARE
We build software with NDPR compliance built in
When we build customer-facing applications, CRMs, or web platforms, we implement consent management, data access controls, audit logs, and privacy policies as part of the standard delivery, not as an afterthought.