The Law Changed, and Most Nigerian SMEs Missed It
If you're still talking about "NDPR compliance," you're referencing a regulation that no longer exists. The Nigeria Data Protection Regulation (NDPR) of 2019 was repealed and replaced by the Nigeria Data Protection Act (NDPA) in 2023. The regulatory body changed too — from NITDA to the Nigeria Data Protection Commission (NDPC), now led by the National Commissioner.
In 2025, the NDPC issued the General Application and Implementation Directive (GAID), which operationalized the NDPA with specific compliance requirements, timelines, and a tiered registration system.
Here's what hasn't changed: the persistent belief among Nigerian SMEs that data protection laws only apply to banks and telecoms. That belief is wrong. And it's getting more expensive by the year.
The NDPA applies to any organization that collects, stores, or processes personal data. Personal data means names, phone numbers, email addresses, payment details, and employee records — the basic information every business handles every single day. There is no small business exemption.
First: Figure Out Your Classification
The GAID 2025 introduced a three-tier system for classifying data controllers and processors. Your classification determines your registration requirements, filing obligations, and fees. Most Nigerian SMEs will fall into the first tier — but you need to confirm.
You are a Data Controller or Processor of Major Importance (DCPMI) if you process personal data of 200 or more data subjects in a six-month period, or if you operate in specified regulated sectors. Otherwise, you are a data controller not of major importance — still subject to baseline NDPA obligations, but exempt from registration.
| Tier | Data Subjects (6 mo) | Examples | Registration | Annual CAR |
|---|---|---|---|---|
| Ordinary-High (OHL) | 200 – 1,000 | Schools, primary health centres, small hotels, independent labs | ₦10,000/year | Not required |
| Extra-High (EHL) | 1,000 – 5,000 | Microfinance banks, higher institutions, mortgage banks, secondary hospitals | ₦100,000 one-time | Required by 31 March |
| Ultra-High (UHL) | 5,000+ | Commercial banks, telecoms, insurance, fintechs, oil & gas, multinationals | ₦250,000 one-time | Required by 31 March |
Non-major importance entities (traders with fewer than 15 employees keeping only routine contacts, social media community groups, artisans not transmitting data commercially) are exempt from registration but must still comply with baseline NDPA obligations: a privacy policy, lawful basis for processing, data security measures, and respect for data subject rights.
How to register: Visit the NDPC portal at ndpc.gov.ng. For EHL and UHL entities, registration is a one-time process. OHL entities renew annually.
The Seven Things Every Nigerian SME Must Have in Place
Registration alone is not compliance. The NDPA imposes ongoing obligations that apply regardless of your classification. Here are the seven core requirements.
1. A Published Privacy Policy (That References Nigerian Law)
Your privacy policy must be publicly accessible, written in plain language, and explicitly reference the NDPA 2023. It must state the lawful basis for each processing activity, data retention periods, NDPC contact details, and how data subjects can exercise their rights. A privacy policy that only references GDPR or CCPA wasn't written for Nigerian compliance.
2. Records of Processing Activities (ROPA)
You need a documented inventory of all personal data you collect: purpose, legal basis, who has access, any third-party sharing, retention period, and security measures. This is your evidence base — the document the NDPC will ask for first in any audit or investigation.
3. Data Processing Agreements With Every Vendor
Every third party that touches your data — payroll providers, CRM platforms, bulk SMS services, email marketing tools, cloud hosting, accounting software, payment gateways — needs a written Data Processing Agreement (DPA). Vendor terms and conditions alone are not sufficient. The DPA must address the nature of processing, security obligations, breach notification timelines, and sub-processing rules.
This is the requirement most Nigerian SMEs overlook entirely. If your payroll provider suffers a breach and you don't have a DPA in place, you share the liability.
4. A Data Protection Officer (DPO)
You must appoint a Data Protection Officer. This can be an existing staff member or an external professional — but they must report to management level, be free from conflicts of interest, and have their contact details published and communicated to the NDPC. For small businesses, engaging a licensed Data Protection Compliance Organisation (DPCO) as an external DPO is often the most practical approach.
5. Technical and Organizational Security Measures
The NDPA requires "appropriate technical and organizational measures" to protect personal data. For SMEs, the practical baseline includes:
- HTTPS (SSL/TLS) on all customer-facing websites
- Multi-factor authentication on email, cloud storage, and business systems
- Role-based access controls — staff only see what they need to see
- Regular automated backups with offsite copies, tested at least annually
- Device encryption on laptops and portable drives
- Immediate access revocation when staff leave
- A policy prohibiting transfer of personal data via unencrypted WhatsApp or personal email
6. A 72-Hour Breach Notification Process
The NDPA requires notification to the NDPC within 72 hours of becoming aware of a personal data breach that poses a risk to individuals. This applies to cyberattacks, lost devices, accidental emails, ransomware, and unauthorized staff access. Your notification must include the nature of the breach, affected categories and numbers, your DPO's contact details, likely consequences, and measures taken.
You need this process documented before an incident happens. Assign roles. Have template notifications ready. Know who to contact.
7. Data Subject Rights Procedures
You must have documented processes for handling requests from individuals to access, correct, delete, or transfer their data. You need a dedicated contact point (email or web form) and should aim to respond within 72 hours. Under the GAID, data subjects must issue a formal grievance notice to your organization before escalating to the NDPC — so your internal grievance mechanism is your first line of defence.
The Annual Compliance Audit: What EHL and UHL Entities Need to Know
If you're classified as EHL or UHL, you must file a Compliance Audit Return (CAR) annually through a licensed DPCO by 31 March. This is not optional. Late filing attracts a 50% penalty on the stipulated filing fee.
CAR filing fees are based on your tier and number of data subjects:
- UHL (50,000+ data subjects): ₦1,000,000
- UHL (25,000 – 49,999): ₦750,000
- UHL (below 25,000): ₦500,000
- EHL (10,000+): ₦250,000
- EHL (5,000 – 9,999): ₦200,000
- EHL (below 5,000): ₦100,000
For entities established after 12 June 2023, the first CAR is due within 15 months of establishment, then annually thereafter.
OHL entities do not need to file annual CAR but must renew registration annually at ₦10,000.
Additional Requirements That Catch SMEs Off Guard
Data Protection Impact Assessments (DPIAs)
You must conduct a DPIA before any high-risk processing activity. This is especially relevant if you use AI for credit scoring, recruitment screening, or automated marketing decisions. The NDPA gives Nigerians the right to contest decisions made solely by automated processing — so if your AI tool makes decisions about customers without human review, you need a DPIA documenting why that's justified and what safeguards are in place.
Cross-Border Data Transfers
If your customer data sits on servers outside Nigeria — which is the case with most cloud-based business tools — you need to understand cross-border transfer rules. The NDPA requires either an adequacy decision from the NDPC or specific legal safeguards (such as standard contractual clauses) before personal data leaves Nigeria. Free AI tools that store data on servers in California or Dublin without these safeguards create compliance exposure.
Staff Training
You need regular privacy awareness training for all staff who handle personal data. This doesn't need to be a week-long seminar. It means ensuring your team knows: what counts as personal data, who can access it, when not to share it, how to spot phishing, and what to do if something goes wrong. Document this training — it's part of your compliance evidence.
Consent That Meets the GAID Standard
Under the GAID 2025, consent for marketing and data processing must be explicit, freely given, specific, informed, and as easy to withdraw as it is to give. Pre-ticked checkboxes are illegal. One-click unsubscribe in marketing emails is mandatory. If your newsletter signup or customer onboarding doesn't meet this standard, it's a compliance gap.
The Reality for Most Nigerian SMEs
A 2025 study by the Centre for the Study of the Economies of Africa (CSEA) surveyed 528 digitally-enabled Nigerian firms across Lagos, Port Harcourt, and Abuja. The findings paint a clear picture of the compliance gap:
This isn't a matter of bad intentions. Most SME owners simply don't know what the law requires. The NDPA is relatively new. The GAID is even newer. There hasn't been a widespread compliance education campaign. And for a business owner focused on making payroll and finding customers, "data protection compliance" sounds like a problem for the legal department they don't have.
But the NDPC is actively enforcing the law. Fidelity Bank's ₦855.8 million fine wasn't a warning shot — it was a statement. And the Commission has signalled that enforcement will expand beyond the banking sector.
A Practical 30-Day Compliance Sprint for SMEs
If you're starting from zero, here's a realistic roadmap. Don't try to do everything at once. Work through it methodically over 30 days.
Week 1 — Assessment and Registration
- Determine your classification (OHL, EHL, UHL, or non-major importance)
- Register with the NDPC if required (ndpc.gov.ng)
- Identify every third party that processes data on your behalf
- List all the personal data you collect and where it's stored
Week 2 — Documentation
- Draft or update your privacy policy to reference the NDPA 2023
- Create your Records of Processing Activities (ROPA) document
- Begin drafting Data Processing Agreements for your key vendors
- Appoint your DPO (internal or external via a DPCO)
Week 3 — Security and Procedures
- Enable MFA on all business accounts
- Review access controls — who has access to what?
- Document your breach notification procedure
- Set up your data subject rights request process (a dedicated email is sufficient to start)
Week 4 — Training and Audit Prep
- Conduct staff privacy awareness training and document it
- Review consent mechanisms on your website and marketing
- If EHL/UHL, engage a licensed DPCO for your CAR preparation
- Conduct a DPIA for any high-risk processing activities
How VIJOSAK Helps With Compliance
While VIJOSAK is not a DPCO and doesn't provide legal advice, our platform is built with Nigerian compliance requirements in mind from the ground up.
Legal identity you can verify. VIJOSAK Technology Limited is registered with the Corporate Affairs Commission under RC 9036268. We exist as a legal entity in Nigeria, subject to Nigerian law and NDPC jurisdiction.
Payments through CBN-licensed infrastructure. Every transaction on VIJOSAK is processed through Paystack — a CBN-licensed, PCI-DSS Level 1 certified payment processor. Your financial data never touches our servers.
Privacy policy written for Nigeria. Our privacy policy explicitly references the NDPA 2023, not just GDPR. It's written in plain language for Nigerian business owners.
Consent built in. Every signup, newsletter subscription, and marketing communication on VIJOSAK uses explicit opt-in consent with one-click unsubscribe. No pre-ticked boxes. No dark patterns.
Your data stays yours. We don't use your business data to train AI models. We don't share it. We don't sell it. Your workspace files are private to you and your team.
Compliance tools you can use. Our Regulatory Watch tool tracks NDPC announcements, regulatory changes, and compliance deadlines. Our Compliance Calendar helps you stay on top of filing dates. Free, always.