Security

NDPR Compliance Checklist for Nigerian SaaS Products

TechAgency Team5 min read

The Nigeria Data Protection Regulation has real teeth. This 12-point checklist covers data residency, consent capture, breach notification timelines, and what your privacy policy must contain.


The Nigeria Data Protection Regulation (NDPR) was issued by NITDA in 2019 and updated with the Data Protection Act (NDPA) in 2023. Non-compliance now carries fines of up to 2% of annual gross revenue or ₦10 million — whichever is higher. The regulation applies to any organisation that processes the personal data of Nigerian citizens, regardless of where the company is incorporated.

Start with a data audit. Map every data point you collect: name, phone, BVN, location, device fingerprint, IP address. Classify each one by sensitivity and document your lawful basis for processing it — consent, contract, or legitimate interest. This audit becomes the spine of your privacy policy, which must be written in plain English (not legalese) and presented before you collect any data.

Consent must be freely given, specific, and easy to withdraw. Pre-ticked checkboxes don't qualify. Users must be able to request data deletion and receive a response within 30 days. Store consent records — timestamp, IP, policy version — so you can prove consent was obtained if challenged.

For data storage, sensitive personal data must be encrypted at rest and in transit. If you process payment data, do not store card numbers — let Paystack or Flutterwave handle that via tokenisation. Breach notification timelines are strict: 72 hours to NITDA, 7 days to affected users. Build your incident response playbook before you need it, not during a crisis.

#nigeria-tech#security#techagency

Work with us

Need help implementing this?

Our engineers have shipped production systems across every topic we write about.

Get a free quote