The 2026 NDPA Compliance Checklist

data protection

The Nigeria Data Protection Act (NDPA) 2023 has changed the way businesses in Nigeria are expected to collect, use, store and protect personal data. But having a privacy policy on your website—or simply registering with the Nigeria Data Protection Commission (NDPC)—does not, by itself, mean that your organisation is fully compliant.

The NDPA, together with the NDPC’s General Application and Implementation Directive (GAID) 2025, establishes a broader framework of accountability for organisations processing personal data. The GAID became effective on 19 September 2025 and provides practical guidance on matters including registration, compliance audit returns, accountability, enforcement and cross-border data transfers.

So, how can a Nigerian business determine whether it is actually compliant?

The 2026 NDPA Compliance Checklist
1. Know What Personal Data Your Business Processes

The first question is deceptively simple:

What personal data does your organisation collect and why?

Personal data includes information relating to an identified or identifiable individual—such as names, telephone numbers, email addresses, identification details, financial information, employee records and online identifiers.

Businesses should conduct data mapping (systematically identifying what personal data is collected, where it comes from, where it is stored, who has access to it and where it goes).

If you cannot clearly account for the personal data your organisation holds, it is difficult to demonstrate effective compliance.

2. Establish a Lawful Basis for Processing

Personal data should not simply be collected because it is useful or because a customer has provided it.

Your organisation should identify the appropriate lawful basis (the legal justification for processing personal data) for each significant processing activity.

Depending on the circumstances, this may include consent, contractual necessity, legal obligation or another lawful basis recognised under the NDPA.

Importantly, consent is not the only lawful basis for processing personal data. Businesses should avoid using “consent” as a blanket justification for every form of processing.

3. Review Your Privacy Notices

Can your customers, employees and other data subjects easily understand:

  • What information you collect?
  • Why you collect it?
  • How you use it?
  • Who you share it with?
  • How long you retain it?
  • What rights they have?
  • How they can exercise those rights?

A privacy notice is more than a legal document hidden somewhere on a website. It is an important transparency mechanism through which an organisation explains its data-processing activities to data subjects.

The NDPC itself maintains a privacy policy addressing matters including lawful processing, data-subject rights, third-party transfers, cookies, security, retention and deletion.

4. Determine Whether Your Organisation Needs a DPO

A Data Protection Officer (DPO) is responsible for supporting an organisation’s data-protection governance and compliance activities.

Businesses should determine whether they fall within the requirements applicable to a Data Controller or Processor of Major Importance (DCPMI) and whether the nature, scale or circumstances of their processing require a DPO.

The DPO role should not be treated as a ceremonial appointment. Effective data protection requires appropriate authority, knowledge, resources and access to relevant parts of the organisation.

5. Check Your Contracts with Vendors and Data Processors

Your organisation may not be the only party handling its customers’ or employees’ personal data.

Cloud providers, payroll companies, marketing platforms, HR systems, IT providers, payment processors and other vendors may process personal data on your behalf.

This makes data-processing agreements (DPAs) and appropriate contractual safeguards essential.

Businesses should establish who is the data controller (the party determining the purposes and means of processing) and who is the data processor (the party processing personal data on behalf of the controller).

Your contracts should address matters such as confidentiality, security, permitted processing, subcontractors, breach notification, data retention and deletion.

6. Have You Implemented Appropriate Security Measures?

Data protection is not only a legal issue. It is also an information-security issue.

The NDPA requires organisations to take appropriate measures to protect personal data. This includes technical and organisational measures (TOMs)—the policies, procedures and security controls used to protect information.

Businesses should consider controls such as:

  • Access management
  • Password and authentication controls
  • Encryption where appropriate
  • Backup and recovery
  • Employee security awareness
  • Malware and endpoint protection
  • Incident-response procedures
  • Secure disposal of information
  • Regular security assessments

This is also where ISO/IEC 27001 can provide significant value by establishing an Information Security Management System (ISMS)—a structured, risk-based framework for managing information security.

7. Have You Prepared for a Data Breach?

A data breach can happen through hacking, ransomware, accidental disclosure, lost devices, compromised credentials or even an employee sending information to the wrong recipient.

Compliance therefore requires more than hoping a breach never happens.

Your organisation should have a documented data breach response plan covering detection, containment, investigation, risk assessment, notification where required, remediation and lessons learned.

The NDPC provides specific mechanisms for privacy breach reporting and identifies breach remediation and impact assessment among recognised data-protection compliance services.

8. Respect Data-Subject Rights

Under the NDPA, individuals have important rights concerning their personal data, including rights relating to access, rectification, objection, restriction, portability and erasure in applicable circumstances.

Your organisation should therefore have a process for handling Data Subject Access Requests (DSARs) and other privacy requests.

The question is not merely whether your privacy policy says that these rights exist. The real question is:

Can your organisation actually respond when someone exercises those rights?

9. Assess High-Risk Processing

Some processing activities may create greater risks to individuals’ privacy and rights.

A Data Protection Impact Assessment (DPIA) is a structured assessment used to identify and mitigate privacy risks before or during high-risk processing activities.

This can be particularly important where organisations introduce new technologies, process sensitive information, undertake large-scale processing or engage in activities involving significant privacy risks.

The NDPC identifies DPIA administration as one of its key regulatory processes under the current framework.

10. Maintain Evidence of Compliance

One of the most overlooked aspects of data protection compliance is accountability.

It is not enough to say:

“We comply with the NDPA.”

Your organisation should be able to demonstrate how it complies.

This may include:

  • Data inventories and processing records
  • Privacy policies and notices
  • Data-processing agreements
  • DPO documentation
  • Staff training records
  • DPIAs
  • Security policies
  • Incident-response procedures
  • Data-retention schedules
  • Internal compliance reviews
  • Compliance Audit Returns where applicable

The NDPC has specifically identified governance, DPO arrangements, documentation and data-processing activities among the areas considered in compliance auditing.

Compliance Is a Continuous Process

NDPA compliance should not be treated as a one-time exercise undertaken simply because a regulator may conduct an investigation.

Your business, technology, vendors, customers and data-processing activities change. Your compliance framework must therefore change with them.

The 2026 approach should be proactive rather than reactive: identify your data, understand your obligations, assess your risks, implement appropriate controls and maintain evidence that those controls are working.

Is Your Organisation Truly NDPA Compliant?

If you answered “no” or “I’m not sure” to several of the questions above, your organisation may have compliance gaps that require attention.

As a Data Protection Compliance Organisation (DPCO), Hastrup Solicitors provides data-protection and privacy advisory services, compliance assessments, privacy audits, data-protection documentation, contractual advisory, breach-response support and related compliance services. The NDPC recognises these among the services that licensed DPCOs may provide.

We can help your organisation move beyond having a privacy policy to building a practical, documented and sustainable data-protection compliance framework.

Need to assess your organisation’s NDPA compliance? Contact Hastrup Solicitors for a professional data-protection compliance assessment.

Leave a Reply

Your email address will not be published. Required fields are marked *