Legal · Compliance

NDPR Compliance Statement

Last updated: 1 June 2026

This statement covers TechAgency Africa's compliance with the Nigeria Data Protection Regulation 2019 (NDPR) and the Nigeria Data Protection Act 2023 (NDPA), which together form the primary data protection framework for Nigeria. We also build NDPR/NDPA compliance into every product we ship for clients.

Our compliance measures

Lawful basis for every data point

We document the lawful basis (consent, contract, or legitimate interest) for every category of personal data we process. We do not collect data we cannot justify.

Consent management

Where we rely on consent, it is freely given, specific, informed, and unambiguous. We record consent timestamps and policy versions. Consent can be withdrawn at any time via email to privacy@techagency.africa.

Data minimisation

We collect only the minimum data required to deliver our services. Personal data is not shared between systems unnecessarily.

Encryption at rest and in transit

All personal data is encrypted at rest (AES-256) and transmitted exclusively over TLS 1.3. We do not store plaintext passwords or card numbers.

Data residency

Primary data storage is within infrastructure that complies with NDPA guidance on data residency for Nigerian citizens' personal data.

Access controls

Personal data is accessible only to team members who require it for their role. All access is protected by two-factor authentication and logged.

Breach notification

In the event of a data breach, we are committed to notifying NITDA within 72 hours and affected data subjects within 7 days, as required by the NDPA.

Third-party processor agreements

All third-party services that process personal data on our behalf have signed Data Processing Agreements (DPAs) or provide equivalent compliance commitments.

Data retention and deletion

We maintain a data retention schedule. Personal data is deleted when the retention period expires or upon request from the data subject.

Annual audit

We conduct an annual internal audit of our data processing activities and update our records of processing activities (ROPA) accordingly.

NDPR compliance in client projects

Every product we build for clients includes NDPR/NDPA compliance as a default, not an optional add-on. This includes: privacy policy templates, consent capture flows, data deletion workflows, cookie consent banners, and secure data handling practices. We will advise clients on their specific compliance obligations during the discovery phase.

Your data subject rights

Under the NDPA 2023, you have the right to access, correct, delete, and port your personal data. See our full Privacy Policy for details on how to exercise these rights.

Complaints

If you believe we have not handled your data in accordance with the NDPA, please contact us first at privacy@techagency.africa. You also have the right to lodge a complaint directly with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

Contact

Data Protection Officer: privacy@techagency.africa
TechAgency Africa · Lagos, Nigeria