Nigeria Data Protection Regulation (NDPR)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Audit Enforcement and Transition
Conduct annual Data Protection Audit per NDPR Section 2.8 by NITDA-licensed DPCO and submit annual returns to NITDA (now NDPC) including processing inventory + compliance attestation + DPO report. Acknowledge enforcement and penalties: for controllers processing personal data of more than 10000 data subjects up to NGN 10 million or 2 percent of annual gross revenue (lower of) + for processing personal data of less than 10000 data subjects up to NGN 2 million or 1 percent of annual gross revenue (lower of). Maintain transition plan to NDPA 2023 including DCMI registration + ongoing NDPC compliance + records of processing activities + staff training + direct marketing controls + storage and retention limitation.
- Annual NDPC submission
- DPCO audit report
- NDPA transition plan
- DCMI registration
- RoPA register
- Annual training records
- Direct marketing controls
- Retention schedule
- No annual audit
- No NDPA transition
- No DCMI registration
- Missing training
Cross-Border Transfers
Conduct cross-border data transfers per NDPR Section 2.7 (CBT) using adequacy decision by Attorney General + Standard Contractual Clauses + Binding Corporate Rules + explicit consent + necessity for contract performance + public interest + legal claims + vital interests. Maintain transfer mechanism inventory + impact assessments + AG/NDPC notification where applicable. Coordinate with AU Convention on Cyber Security and Personal Data Protection 2014 + ECOWAS supplementary act on personal data protection.
- Transfer inventory
- Approved SCCs
- BCR approval
- TIA register
- AU Convention coordination
- No transfer inventory
- Unapproved SCCs
- No TIA
DPO and DPCOs
Appoint Data Protection Officer (DPO) per NDPR Section 4 where required (controllers processing large volumes of personal data or sensitive data). Engage Data Protection Compliance Organisations (DPCOs) licensed by NITDA (now NDPC) for compliance audit + reporting + advisory per NDPR Section 4-DPCO. Maintain processor contracts with NDPR-required clauses including instructions + duration + purposes + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality.
- DPO appointment
- DPCO engagement letter
- Annual DPCO audit
- Processor contract template
- No DPO
- Unlicensed DPCO
- Missing processor clauses
Data Subject Rights
Honour data subject rights per NDPR Section 3.1.4 including: right of access + right to rectification + right to erasure + right to restriction + right to data portability + right to object. Respond within 30 days. Apply controls for automated decision-making and profiling including meaningful information + human review + right to object.
- Rights procedure
- Rights request log
- ADM register
- Human review process
- Late responses
- No procedure
- No ADM controls
Lawful Basis and Principles
Apply NDPR Section 2.1 governing principles of data processing: lawfulness + purpose limitation + adequacy + accuracy + storage limitation + integrity/confidentiality + accountability. Apply NDPR Section 2.2 lawful bases for processing including consent + contract + legal obligation + vital interests + public interest + legitimate interests. Obtain NDPR Section 2.3 consent meeting freely given + specific + informed + unambiguous standards.
- NDPR 2.1 principle compliance
- NDPR 2.2 lawful basis matrix
- NDPR 2.3 consent records
- Annual review
- Missing principle evidence
- No lawful basis matrix
- Inadequate consent
Scope and NITDA Governance
Comply with Nigeria Data Protection Regulation 2019 (NDPR) issued by the National Information Technology Development Agency (NITDA) on 25 January 2019 under powers conferred by NITDA Act 2007 Section 6(c). Applies to all data controllers and processors processing personal data of Nigerian residents. Effective 25 January 2019. Note that NDPR transitions to Nigeria Data Protection Act 2023 (NDPA) which establishes the NDPC as successor regulator; NDPR remains operative as transitional regulation in conjunction with NDPA. Coordinate with NITDA Director-General (Kashifu Inuwa Abdullahi reappointed 2023) + NITDA Data Protection Bureau (now transferred to NDPC).
- NDPR applicability memo
- NITDA registration
- Transitional NDPA alignment
- Annual review
- No NDPR memo
- Missing NITDA registration
- No NDPA transition plan
Security and Accountability
Implement appropriate technical and organisational measures per NDPR Section 2.6-Security including encryption + pseudonymisation + integrity protection + access controls + regular testing. Notify NITDA (now NDPC) of personal data breaches within 72 hours + notify data subjects when high risk. Conduct Data Protection Impact Assessments (DPIA) for high-risk processing including systematic monitoring + large-scale sensitive data processing.
- Technical measures
- 72-hour breach notification capability
- Breach register
- DPIA register
- Annual security review
- Missing measures
- Late notification
- No DPIA
Sensitive Data and Notice
Apply NDPR Section 2.5 sensitive personal data protections covering racial or ethnic origin + religion + political opinions + trade union membership + health + sexual orientation + biometric + genetic data + criminal records. Process children personal data with parental consent under 13. Publish privacy policy per NDPR Section 2.6 with mandated disclosures including data categories + purposes + lawful basis + rights + complaints procedure + DPO contact.
- Sensitive data inventory
- Parental consent records
- NDPR 2.6 compliant Privacy Policy
- Annual review
- No inventory
- No parental consent
- Missing 2.6 elements
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nigeria Data Protection Regulation (NDPR) framework page.