Skip to content

Evidence request lists

Nigeria Data Protection Regulation (NDPR)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Audit Enforcement and Transition

NGNDPR-8
Annual Data Protection Audit, Penalties, and NDPA Transition

Conduct annual Data Protection Audit per NDPR Section 2.8 by NITDA-licensed DPCO and submit annual returns to NITDA (now NDPC) including processing inventory + compliance attestation + DPO report. Acknowledge enforcement and penalties: for controllers processing personal data of more than 10000 data subjects up to NGN 10 million or 2 percent of annual gross revenue (lower of) + for processing personal data of less than 10000 data subjects up to NGN 2 million or 1 percent of annual gross revenue (lower of). Maintain transition plan to NDPA 2023 including DCMI registration + ongoing NDPC compliance + records of processing activities + staff training + direct marketing controls + storage and retention limitation.

Artefacts an auditor will ask for
  • Annual NDPC submission
  • DPCO audit report
  • NDPA transition plan
  • DCMI registration
  • RoPA register
  • Annual training records
  • Direct marketing controls
  • Retention schedule
Where this commonly fails
  • No annual audit
  • No NDPA transition
  • No DCMI registration
  • Missing training

Cross-Border Transfers

NGNDPR-7
Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT

Conduct cross-border data transfers per NDPR Section 2.7 (CBT) using adequacy decision by Attorney General + Standard Contractual Clauses + Binding Corporate Rules + explicit consent + necessity for contract performance + public interest + legal claims + vital interests. Maintain transfer mechanism inventory + impact assessments + AG/NDPC notification where applicable. Coordinate with AU Convention on Cyber Security and Personal Data Protection 2014 + ECOWAS supplementary act on personal data protection.

Artefacts an auditor will ask for
  • Transfer inventory
  • Approved SCCs
  • BCR approval
  • TIA register
  • AU Convention coordination
Where this commonly fails
  • No transfer inventory
  • Unapproved SCCs
  • No TIA

DPO and DPCOs

NGNDPR-6
Data Protection Officer, DPCOs, and Processor Obligations

Appoint Data Protection Officer (DPO) per NDPR Section 4 where required (controllers processing large volumes of personal data or sensitive data). Engage Data Protection Compliance Organisations (DPCOs) licensed by NITDA (now NDPC) for compliance audit + reporting + advisory per NDPR Section 4-DPCO. Maintain processor contracts with NDPR-required clauses including instructions + duration + purposes + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality.

Artefacts an auditor will ask for
  • DPO appointment
  • DPCO engagement letter
  • Annual DPCO audit
  • Processor contract template
Where this commonly fails
  • No DPO
  • Unlicensed DPCO
  • Missing processor clauses

Data Subject Rights

NGNDPR-4
Data Subject Rights and Automated Decision-Making

Honour data subject rights per NDPR Section 3.1.4 including: right of access + right to rectification + right to erasure + right to restriction + right to data portability + right to object. Respond within 30 days. Apply controls for automated decision-making and profiling including meaningful information + human review + right to object.

Artefacts an auditor will ask for
  • Rights procedure
  • Rights request log
  • ADM register
  • Human review process
Where this commonly fails
  • Late responses
  • No procedure
  • No ADM controls

Lawful Basis and Principles

NGNDPR-2
Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3

Apply NDPR Section 2.1 governing principles of data processing: lawfulness + purpose limitation + adequacy + accuracy + storage limitation + integrity/confidentiality + accountability. Apply NDPR Section 2.2 lawful bases for processing including consent + contract + legal obligation + vital interests + public interest + legitimate interests. Obtain NDPR Section 2.3 consent meeting freely given + specific + informed + unambiguous standards.

Artefacts an auditor will ask for
  • NDPR 2.1 principle compliance
  • NDPR 2.2 lawful basis matrix
  • NDPR 2.3 consent records
  • Annual review
Where this commonly fails
  • Missing principle evidence
  • No lawful basis matrix
  • Inadequate consent

Scope and NITDA Governance

NGNDPR-1
NDPR Scope, NITDA Administration, and Applicability

Comply with Nigeria Data Protection Regulation 2019 (NDPR) issued by the National Information Technology Development Agency (NITDA) on 25 January 2019 under powers conferred by NITDA Act 2007 Section 6(c). Applies to all data controllers and processors processing personal data of Nigerian residents. Effective 25 January 2019. Note that NDPR transitions to Nigeria Data Protection Act 2023 (NDPA) which establishes the NDPC as successor regulator; NDPR remains operative as transitional regulation in conjunction with NDPA. Coordinate with NITDA Director-General (Kashifu Inuwa Abdullahi reappointed 2023) + NITDA Data Protection Bureau (now transferred to NDPC).

Artefacts an auditor will ask for
  • NDPR applicability memo
  • NITDA registration
  • Transitional NDPA alignment
  • Annual review
Where this commonly fails
  • No NDPR memo
  • Missing NITDA registration
  • No NDPA transition plan

Security and Accountability

NGNDPR-5
Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security

Implement appropriate technical and organisational measures per NDPR Section 2.6-Security including encryption + pseudonymisation + integrity protection + access controls + regular testing. Notify NITDA (now NDPC) of personal data breaches within 72 hours + notify data subjects when high risk. Conduct Data Protection Impact Assessments (DPIA) for high-risk processing including systematic monitoring + large-scale sensitive data processing.

Artefacts an auditor will ask for
  • Technical measures
  • 72-hour breach notification capability
  • Breach register
  • DPIA register
  • Annual security review
Where this commonly fails
  • Missing measures
  • Late notification
  • No DPIA

Sensitive Data and Notice

NGNDPR-3
Sensitive Personal Data, Children, and Privacy Policy under NDPR Section 2.5-2.6

Apply NDPR Section 2.5 sensitive personal data protections covering racial or ethnic origin + religion + political opinions + trade union membership + health + sexual orientation + biometric + genetic data + criminal records. Process children personal data with parental consent under 13. Publish privacy policy per NDPR Section 2.6 with mandated disclosures including data categories + purposes + lawful basis + rights + complaints procedure + DPO contact.

Artefacts an auditor will ask for
  • Sensitive data inventory
  • Parental consent records
  • NDPR 2.6 compliant Privacy Policy
  • Annual review
Where this commonly fails
  • No inventory
  • No parental consent
  • Missing 2.6 elements
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nigeria Data Protection Regulation (NDPR) framework page.