The Law Changed, and Most Nigerian SMEs Missed It

If you're still talking about "NDPR compliance," you're referencing a regulation that no longer exists. The Nigeria Data Protection Regulation (NDPR) of 2019 was repealed and replaced by the Nigeria Data Protection Act (NDPA) in 2023. The regulatory body changed too — from NITDA to the Nigeria Data Protection Commission (NDPC), now led by the National Commissioner.

In 2025, the NDPC issued the General Application and Implementation Directive (GAID), which operationalized the NDPA with specific compliance requirements, timelines, and a tiered registration system.

Here's what hasn't changed: the persistent belief among Nigerian SMEs that data protection laws only apply to banks and telecoms. That belief is wrong. And it's getting more expensive by the year.

₦10M
Maximum penalty under the NDPA: ₦10 million or 2% of annual gross revenue — whichever is greater. Fidelity Bank was fined ₦855.8 million for data privacy breaches.

The NDPA applies to any organization that collects, stores, or processes personal data. Personal data means names, phone numbers, email addresses, payment details, and employee records — the basic information every business handles every single day. There is no small business exemption.


First: Figure Out Your Classification

The GAID 2025 introduced a three-tier system for classifying data controllers and processors. Your classification determines your registration requirements, filing obligations, and fees. Most Nigerian SMEs will fall into the first tier — but you need to confirm.

You are a Data Controller or Processor of Major Importance (DCPMI) if you process personal data of 200 or more data subjects in a six-month period, or if you operate in specified regulated sectors. Otherwise, you are a data controller not of major importance — still subject to baseline NDPA obligations, but exempt from registration.

Tier Data Subjects (6 mo) Examples Registration Annual CAR
Ordinary-High (OHL) 200 – 1,000 Schools, primary health centres, small hotels, independent labs ₦10,000/year Not required
Extra-High (EHL) 1,000 – 5,000 Microfinance banks, higher institutions, mortgage banks, secondary hospitals ₦100,000 one-time Required by 31 March
Ultra-High (UHL) 5,000+ Commercial banks, telecoms, insurance, fintechs, oil & gas, multinationals ₦250,000 one-time Required by 31 March

Non-major importance entities (traders with fewer than 15 employees keeping only routine contacts, social media community groups, artisans not transmitting data commercially) are exempt from registration but must still comply with baseline NDPA obligations: a privacy policy, lawful basis for processing, data security measures, and respect for data subject rights.

How to register: Visit the NDPC portal at ndpc.gov.ng. For EHL and UHL entities, registration is a one-time process. OHL entities renew annually.


The Seven Things Every Nigerian SME Must Have in Place

Registration alone is not compliance. The NDPA imposes ongoing obligations that apply regardless of your classification. Here are the seven core requirements.

1. A Published Privacy Policy (That References Nigerian Law)

Your privacy policy must be publicly accessible, written in plain language, and explicitly reference the NDPA 2023. It must state the lawful basis for each processing activity, data retention periods, NDPC contact details, and how data subjects can exercise their rights. A privacy policy that only references GDPR or CCPA wasn't written for Nigerian compliance.

2. Records of Processing Activities (ROPA)

You need a documented inventory of all personal data you collect: purpose, legal basis, who has access, any third-party sharing, retention period, and security measures. This is your evidence base — the document the NDPC will ask for first in any audit or investigation.

3. Data Processing Agreements With Every Vendor

Every third party that touches your data — payroll providers, CRM platforms, bulk SMS services, email marketing tools, cloud hosting, accounting software, payment gateways — needs a written Data Processing Agreement (DPA). Vendor terms and conditions alone are not sufficient. The DPA must address the nature of processing, security obligations, breach notification timelines, and sub-processing rules.

This is the requirement most Nigerian SMEs overlook entirely. If your payroll provider suffers a breach and you don't have a DPA in place, you share the liability.

4. A Data Protection Officer (DPO)

You must appoint a Data Protection Officer. This can be an existing staff member or an external professional — but they must report to management level, be free from conflicts of interest, and have their contact details published and communicated to the NDPC. For small businesses, engaging a licensed Data Protection Compliance Organisation (DPCO) as an external DPO is often the most practical approach.

5. Technical and Organizational Security Measures

The NDPA requires "appropriate technical and organizational measures" to protect personal data. For SMEs, the practical baseline includes:

6. A 72-Hour Breach Notification Process

The NDPA requires notification to the NDPC within 72 hours of becoming aware of a personal data breach that poses a risk to individuals. This applies to cyberattacks, lost devices, accidental emails, ransomware, and unauthorized staff access. Your notification must include the nature of the breach, affected categories and numbers, your DPO's contact details, likely consequences, and measures taken.

You need this process documented before an incident happens. Assign roles. Have template notifications ready. Know who to contact.

7. Data Subject Rights Procedures

You must have documented processes for handling requests from individuals to access, correct, delete, or transfer their data. You need a dedicated contact point (email or web form) and should aim to respond within 72 hours. Under the GAID, data subjects must issue a formal grievance notice to your organization before escalating to the NDPC — so your internal grievance mechanism is your first line of defence.


The Annual Compliance Audit: What EHL and UHL Entities Need to Know

If you're classified as EHL or UHL, you must file a Compliance Audit Return (CAR) annually through a licensed DPCO by 31 March. This is not optional. Late filing attracts a 50% penalty on the stipulated filing fee.

CAR filing fees are based on your tier and number of data subjects:

For entities established after 12 June 2023, the first CAR is due within 15 months of establishment, then annually thereafter.

OHL entities do not need to file annual CAR but must renew registration annually at ₦10,000.


Additional Requirements That Catch SMEs Off Guard

Data Protection Impact Assessments (DPIAs)

You must conduct a DPIA before any high-risk processing activity. This is especially relevant if you use AI for credit scoring, recruitment screening, or automated marketing decisions. The NDPA gives Nigerians the right to contest decisions made solely by automated processing — so if your AI tool makes decisions about customers without human review, you need a DPIA documenting why that's justified and what safeguards are in place.

Cross-Border Data Transfers

If your customer data sits on servers outside Nigeria — which is the case with most cloud-based business tools — you need to understand cross-border transfer rules. The NDPA requires either an adequacy decision from the NDPC or specific legal safeguards (such as standard contractual clauses) before personal data leaves Nigeria. Free AI tools that store data on servers in California or Dublin without these safeguards create compliance exposure.

Staff Training

You need regular privacy awareness training for all staff who handle personal data. This doesn't need to be a week-long seminar. It means ensuring your team knows: what counts as personal data, who can access it, when not to share it, how to spot phishing, and what to do if something goes wrong. Document this training — it's part of your compliance evidence.

Consent That Meets the GAID Standard

Under the GAID 2025, consent for marketing and data processing must be explicit, freely given, specific, informed, and as easy to withdraw as it is to give. Pre-ticked checkboxes are illegal. One-click unsubscribe in marketing emails is mandatory. If your newsletter signup or customer onboarding doesn't meet this standard, it's a compliance gap.


The Reality for Most Nigerian SMEs

A 2025 study by the Centre for the Study of the Economies of Africa (CSEA) surveyed 528 digitally-enabled Nigerian firms across Lagos, Port Harcourt, and Abuja. The findings paint a clear picture of the compliance gap:

20–25%
Only one in five Nigerian firms uses data encryption or conducts regular audits. Most rely on passwords and restricted logins — and nothing more. Employee data protection training? Just 18.8% of firms do it.

This isn't a matter of bad intentions. Most SME owners simply don't know what the law requires. The NDPA is relatively new. The GAID is even newer. There hasn't been a widespread compliance education campaign. And for a business owner focused on making payroll and finding customers, "data protection compliance" sounds like a problem for the legal department they don't have.

But the NDPC is actively enforcing the law. Fidelity Bank's ₦855.8 million fine wasn't a warning shot — it was a statement. And the Commission has signalled that enforcement will expand beyond the banking sector.

"You don't need to be perfect on day one. But you do need to start. Documentation is your best defence."

A Practical 30-Day Compliance Sprint for SMEs

If you're starting from zero, here's a realistic roadmap. Don't try to do everything at once. Work through it methodically over 30 days.

Week 1 — Assessment and Registration

Week 2 — Documentation

Week 3 — Security and Procedures

Week 4 — Training and Audit Prep


How VIJOSAK Helps With Compliance

While VIJOSAK is not a DPCO and doesn't provide legal advice, our platform is built with Nigerian compliance requirements in mind from the ground up.

Legal identity you can verify. VIJOSAK Technology Limited is registered with the Corporate Affairs Commission under RC 9036268. We exist as a legal entity in Nigeria, subject to Nigerian law and NDPC jurisdiction.

Payments through CBN-licensed infrastructure. Every transaction on VIJOSAK is processed through Paystack — a CBN-licensed, PCI-DSS Level 1 certified payment processor. Your financial data never touches our servers.

Privacy policy written for Nigeria. Our privacy policy explicitly references the NDPA 2023, not just GDPR. It's written in plain language for Nigerian business owners.

Consent built in. Every signup, newsletter subscription, and marketing communication on VIJOSAK uses explicit opt-in consent with one-click unsubscribe. No pre-ticked boxes. No dark patterns.

Your data stays yours. We don't use your business data to train AI models. We don't share it. We don't sell it. Your workspace files are private to you and your team.

Compliance tools you can use. Our Regulatory Watch tool tracks NDPC announcements, regulatory changes, and compliance deadlines. Our Compliance Calendar helps you stay on top of filing dates. Free, always.