Nigeria Data Protection Act 2023 (NDPA)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border Transfers
Conduct cross-border data transfers per NDPA Section 41(CBT) using adequate level of protection mechanisms including: countries on NDPC Whitelist (adequacy) + Binding Corporate Rules (BCR) approved by NDPC + Standard Contractual Clauses approved by NDPC + explicit consent + necessary for performance of contract + public interest + legal claims + vital interests. Conduct Transfer Impact Assessments for transfers to high-risk jurisdictions. Coordinate with Mauritius + Ghana + Kenya + Senegal + AU Convention 2014 on cyber security and personal data protection.
- Transfer mechanism inventory
- NDPC Whitelist tracking
- Approved SCCs
- BCR approval
- TIA register
- African DPA cooperation
- No transfer inventory
- Unapproved SCCs
- Missing TIA
- No African coordination
DPO and Vendors
Appoint Data Protection Officer (DPO) per NDPA Section 41 where required (public authority + core activities involving regular systematic monitoring + core activities involving large-scale sensitive data processing). Engage Data Protection Compliance Organisations (DPCOs) licensed by NDPC for audit + reporting + advisory services. Maintain processor contracts per Section 41 with NDPA-required clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality + NDPA compliance attestation). Notify NDPC of DPO appointment.
- DPO appointment letter
- NDPC DPO notification
- DPCO engagement letter
- Annual DPCO audit report
- Processor contract template
- Annual processor audit
- No DPO
- Unregistered DPCO
- Missing NDPC notification
- Processor contracts incomplete
Data Subject Rights
Honour data subject rights per NDPA Sections 32-37 including: right to information + right of access + right to rectification + right to erasure + right to restriction of processing + right to data portability + right to object + right not to be subject to automated decision-making producing legal or similarly significant effects. Respond within 30 days (extendable). Apply Section 37 controls for automated decision-making and profiling including meaningful information + safeguards + right to human review.
- Rights procedure
- Rights request log
- 30-day response tracking
- ADM register
- Human review process
- Safeguards documentation
- Late responses
- No rights procedure
- No ADM controls
- Missing human review
Enforcement and DCMI
Acknowledge NDPC enforcement per NDPA Section 45 with administrative penalties up to NGN 10 million + 2% annual gross revenue (lower of) for serious violations + lesser penalties for minor breaches + compensation for affected data subjects + criminal penalties for individuals (Section 47). Maintain Data Controllers of Major Importance (DCMI) registration per Section 44 where: processing on large scale or critical/sensitive nature. Submit annual returns. Pay annual NDPC levy. Maintain compliance documentation including records of processing activities (RoPA) + staff training + direct marketing controls + miscellaneous statutory obligations.
- DCMI registration
- Annual returns to NDPC
- NDPC levy payment
- RoPA register
- Annual training records
- Direct marketing controls
- Penalty exposure analysis
- Compliance attestation
- No DCMI registration
- Missed annual returns
- No RoPA
- Missing training
- No penalty risk analysis
Lawful Basis and Principles
Apply lawful bases for processing per NDPA Section 25 including consent + contractual necessity + legal obligation + vital interests + public interest + legitimate interests. Obtain valid consent per Section 26 requirements (informed + specific + freely given + capable of withdrawal). Apply NDPA Section 24 data protection principles: lawfulness/fairness/transparency + purpose limitation + data minimisation + accuracy + storage limitation + integrity/confidentiality + accountability. Provide privacy notice with NDPA-mandated disclosures.
- Lawful basis matrix per processing activity
- Consent records with Section 26 elements
- Privacy Notice with NDPA disclosures
- Principle compliance evidence
- Annual review
- Missing lawful basis matrix
- Inadequate consent records
- Incomplete privacy notice
- Weak principle evidence
Scope and Governance
Comply with Nigeria Data Protection Act 2023 (NDPA) signed by President Bola Ahmed Tinubu on 12 June 2023 (Act No. 37 of 2023). Replaces Nigeria Data Protection Regulation (NDPR) 2019 issued by NITDA. NDPA establishes the Nigeria Data Protection Commission (NDPC) as the independent supervisory authority replacing NITDA Bureau + headed by National Commissioner (Vincent Olatunji appointed February 2023, confirmed under NDPA) + Governing Council + Secretary to Council. Applies to controllers and processors processing personal data of Nigerian data subjects + controllers/processors established in Nigeria + extra-territorial application for monitoring or offering goods/services to Nigerians.
- NDPA applicability analysis
- NDPC registration certificate (where DCMI)
- Governance structure documentation
- NDPC liaison appointment
- Annual NDPA compliance review
- No NDPA analysis
- Missing NDPC registration
- No DCMI status determination
- Stale compliance review
Security and Accountability
Implement appropriate technical and organisational measures per NDPA Section 40 including encryption + pseudonymisation + integrity protection + confidentiality + restoration capabilities + regular testing. Notify NDPC of personal data breaches within 72 hours per Section 40 + notify data subjects when high risk per Section 40(4). Conduct Data Protection Impact Assessments (DPIA) per Section 39 for high-risk processing including profiling + systematic monitoring + large-scale sensitive data processing. Consult NDPC for high residual risk.
- Technical and organisational measures
- 72-hour NDPC breach notification capability
- Breach register
- DPIA register
- NDPC prior consultation records
- Annual security review
- Missing technical measures
- Late breach notification
- No DPIA
- No prior consultation
Sensitive Data and Children
Apply enhanced protection for sensitive personal data per NDPA Section 27 covering: genetic data + biometric data + health data + sex life + sexual orientation + religion/belief + race/ethnic origin + political opinions + trade union membership + criminal convictions + financial data. Obtain explicit consent or specific lawful basis. Process children personal data per NDPA Section 27 with parental/guardian consent for under 18 (Nigeria sets higher age than GDPR). Apply Child Rights Act 2003 + Cybercrimes (Prohibition Prevention etc) Act 2015 + Federal Government child protection policies.
- Sensitive data inventory
- Section 27 consent records
- Parental consent procedures (under 18)
- Age verification mechanism
- Child Rights Act alignment
- No sensitive inventory
- Inadequate consent
- No age verification
- Missing parental consent for under 18
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nigeria Data Protection Act 2023 (NDPA) framework page.