NDPR Compliance Statement
Last updated: 1 June 2026
This statement covers TechAgency Africa's compliance with the Nigeria Data Protection Regulation 2019 (NDPR) and the Nigeria Data Protection Act 2023 (NDPA), which together form the primary data protection framework for Nigeria. We also build NDPR/NDPA compliance into every product we ship for clients.
Our compliance measures
Lawful basis for every data point
We document the lawful basis (consent, contract, or legitimate interest) for every category of personal data we process. We do not collect data we cannot justify.
Consent management
Where we rely on consent, it is freely given, specific, informed, and unambiguous. We record consent timestamps and policy versions. Consent can be withdrawn at any time via email to privacy@techagency.africa.
Data minimisation
We collect only the minimum data required to deliver our services. Personal data is not shared between systems unnecessarily.
Encryption at rest and in transit
All personal data is encrypted at rest (AES-256) and transmitted exclusively over TLS 1.3. We do not store plaintext passwords or card numbers.
Data residency
Primary data storage is within infrastructure that complies with NDPA guidance on data residency for Nigerian citizens' personal data.
Access controls
Personal data is accessible only to team members who require it for their role. All access is protected by two-factor authentication and logged.
Breach notification
In the event of a data breach, we are committed to notifying NITDA within 72 hours and affected data subjects within 7 days, as required by the NDPA.
Third-party processor agreements
All third-party services that process personal data on our behalf have signed Data Processing Agreements (DPAs) or provide equivalent compliance commitments.
Data retention and deletion
We maintain a data retention schedule. Personal data is deleted when the retention period expires or upon request from the data subject.
Annual audit
We conduct an annual internal audit of our data processing activities and update our records of processing activities (ROPA) accordingly.
NDPR compliance in client projects
Every product we build for clients includes NDPR/NDPA compliance as a default, not an optional add-on. This includes: privacy policy templates, consent capture flows, data deletion workflows, cookie consent banners, and secure data handling practices. We will advise clients on their specific compliance obligations during the discovery phase.
Your data subject rights
Under the NDPA 2023, you have the right to access, correct, delete, and port your personal data. See our full Privacy Policy for details on how to exercise these rights.
Complaints
If you believe we have not handled your data in accordance with the NDPA, please contact us first at privacy@techagency.africa. You also have the right to lodge a complaint directly with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
Contact
Data Protection Officer: privacy@techagency.africa
TechAgency Africa · Lagos, Nigeria
