Skip to content

Evidence request lists

Nigeria Data Protection Act 2023 (NDPA)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border Transfers

NG-NDPA-7
Cross-Border Data Transfers and International Cooperation

Conduct cross-border data transfers per NDPA Section 41(CBT) using adequate level of protection mechanisms including: countries on NDPC Whitelist (adequacy) + Binding Corporate Rules (BCR) approved by NDPC + Standard Contractual Clauses approved by NDPC + explicit consent + necessary for performance of contract + public interest + legal claims + vital interests. Conduct Transfer Impact Assessments for transfers to high-risk jurisdictions. Coordinate with Mauritius + Ghana + Kenya + Senegal + AU Convention 2014 on cyber security and personal data protection.

Artefacts an auditor will ask for
  • Transfer mechanism inventory
  • NDPC Whitelist tracking
  • Approved SCCs
  • BCR approval
  • TIA register
  • African DPA cooperation
Where this commonly fails
  • No transfer inventory
  • Unapproved SCCs
  • Missing TIA
  • No African coordination

DPO and Vendors

NG-NDPA-6
Data Protection Officer, DPCO, and Processor Agreements

Appoint Data Protection Officer (DPO) per NDPA Section 41 where required (public authority + core activities involving regular systematic monitoring + core activities involving large-scale sensitive data processing). Engage Data Protection Compliance Organisations (DPCOs) licensed by NDPC for audit + reporting + advisory services. Maintain processor contracts per Section 41 with NDPA-required clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality + NDPA compliance attestation). Notify NDPC of DPO appointment.

Artefacts an auditor will ask for
  • DPO appointment letter
  • NDPC DPO notification
  • DPCO engagement letter
  • Annual DPCO audit report
  • Processor contract template
  • Annual processor audit
Where this commonly fails
  • No DPO
  • Unregistered DPCO
  • Missing NDPC notification
  • Processor contracts incomplete

Data Subject Rights

NG-NDPA-4
Data Subject Rights and Automated Decision-Making

Honour data subject rights per NDPA Sections 32-37 including: right to information + right of access + right to rectification + right to erasure + right to restriction of processing + right to data portability + right to object + right not to be subject to automated decision-making producing legal or similarly significant effects. Respond within 30 days (extendable). Apply Section 37 controls for automated decision-making and profiling including meaningful information + safeguards + right to human review.

Artefacts an auditor will ask for
  • Rights procedure
  • Rights request log
  • 30-day response tracking
  • ADM register
  • Human review process
  • Safeguards documentation
Where this commonly fails
  • Late responses
  • No rights procedure
  • No ADM controls
  • Missing human review

Enforcement and DCMI

NG-NDPA-8
Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

Acknowledge NDPC enforcement per NDPA Section 45 with administrative penalties up to NGN 10 million + 2% annual gross revenue (lower of) for serious violations + lesser penalties for minor breaches + compensation for affected data subjects + criminal penalties for individuals (Section 47). Maintain Data Controllers of Major Importance (DCMI) registration per Section 44 where: processing on large scale or critical/sensitive nature. Submit annual returns. Pay annual NDPC levy. Maintain compliance documentation including records of processing activities (RoPA) + staff training + direct marketing controls + miscellaneous statutory obligations.

Artefacts an auditor will ask for
  • DCMI registration
  • Annual returns to NDPC
  • NDPC levy payment
  • RoPA register
  • Annual training records
  • Direct marketing controls
  • Penalty exposure analysis
  • Compliance attestation
Where this commonly fails
  • No DCMI registration
  • Missed annual returns
  • No RoPA
  • Missing training
  • No penalty risk analysis

Lawful Basis and Principles

NG-NDPA-2
Lawful Basis, Consent, and Data Protection Principles

Apply lawful bases for processing per NDPA Section 25 including consent + contractual necessity + legal obligation + vital interests + public interest + legitimate interests. Obtain valid consent per Section 26 requirements (informed + specific + freely given + capable of withdrawal). Apply NDPA Section 24 data protection principles: lawfulness/fairness/transparency + purpose limitation + data minimisation + accuracy + storage limitation + integrity/confidentiality + accountability. Provide privacy notice with NDPA-mandated disclosures.

Artefacts an auditor will ask for
  • Lawful basis matrix per processing activity
  • Consent records with Section 26 elements
  • Privacy Notice with NDPA disclosures
  • Principle compliance evidence
  • Annual review
Where this commonly fails
  • Missing lawful basis matrix
  • Inadequate consent records
  • Incomplete privacy notice
  • Weak principle evidence

Scope and Governance

NG-NDPA-1
Scope, Applicability, and Establishment of Nigeria Data Protection Commission

Comply with Nigeria Data Protection Act 2023 (NDPA) signed by President Bola Ahmed Tinubu on 12 June 2023 (Act No. 37 of 2023). Replaces Nigeria Data Protection Regulation (NDPR) 2019 issued by NITDA. NDPA establishes the Nigeria Data Protection Commission (NDPC) as the independent supervisory authority replacing NITDA Bureau + headed by National Commissioner (Vincent Olatunji appointed February 2023, confirmed under NDPA) + Governing Council + Secretary to Council. Applies to controllers and processors processing personal data of Nigerian data subjects + controllers/processors established in Nigeria + extra-territorial application for monitoring or offering goods/services to Nigerians.

Artefacts an auditor will ask for
  • NDPA applicability analysis
  • NDPC registration certificate (where DCMI)
  • Governance structure documentation
  • NDPC liaison appointment
  • Annual NDPA compliance review
Where this commonly fails
  • No NDPA analysis
  • Missing NDPC registration
  • No DCMI status determination
  • Stale compliance review

Security and Accountability

NG-NDPA-5
Security of Processing, Breach Notification, and DPIA

Implement appropriate technical and organisational measures per NDPA Section 40 including encryption + pseudonymisation + integrity protection + confidentiality + restoration capabilities + regular testing. Notify NDPC of personal data breaches within 72 hours per Section 40 + notify data subjects when high risk per Section 40(4). Conduct Data Protection Impact Assessments (DPIA) per Section 39 for high-risk processing including profiling + systematic monitoring + large-scale sensitive data processing. Consult NDPC for high residual risk.

Artefacts an auditor will ask for
  • Technical and organisational measures
  • 72-hour NDPC breach notification capability
  • Breach register
  • DPIA register
  • NDPC prior consultation records
  • Annual security review
Where this commonly fails
  • Missing technical measures
  • Late breach notification
  • No DPIA
  • No prior consultation

Sensitive Data and Children

NG-NDPA-3
Sensitive Personal Data, Children, and Special Categories

Apply enhanced protection for sensitive personal data per NDPA Section 27 covering: genetic data + biometric data + health data + sex life + sexual orientation + religion/belief + race/ethnic origin + political opinions + trade union membership + criminal convictions + financial data. Obtain explicit consent or specific lawful basis. Process children personal data per NDPA Section 27 with parental/guardian consent for under 18 (Nigeria sets higher age than GDPR). Apply Child Rights Act 2003 + Cybercrimes (Prohibition Prevention etc) Act 2015 + Federal Government child protection policies.

Artefacts an auditor will ask for
  • Sensitive data inventory
  • Section 27 consent records
  • Parental consent procedures (under 18)
  • Age verification mechanism
  • Child Rights Act alignment
Where this commonly fails
  • No sensitive inventory
  • Inadequate consent
  • No age verification
  • Missing parental consent for under 18
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nigeria Data Protection Act 2023 (NDPA) framework page.