Governance, Risk & Compliance
The Nigeria Data Protection Commission has enforcement powers and is using them. Knowing what the NDPA 2023 requires is not the same as being able to demonstrate compliance when the NDPC asks.
Who this is for: Organisations processing personal data in Nigeria, including those facing an NDPC inquiry or preparing for registration.
The problem: Most organisations cannot say what personal data they hold, why they hold it, or what their lawful basis is.
The outcome: A documented, audit-ready NDPA 2023 compliance programme aligned to GAID 2025, not a generic template.
The problem
Most Nigerian organisations processing personal data cannot answer three basic questions: what personal data do we hold, why do we hold it, and what is our lawful basis for processing it. The NDPA 2023 requires clear answers to all three. The NDPC can investigate, audit, and fine organisations up to 2% of annual gross revenue for failing to provide them.
The NDPA 2023 is not the NDPR with a new name. It introduces stronger obligations, a more powerful regulator, and detailed implementation requirements set out in the GAID 2025 that many organisations have not yet read. Applying a generic GDPR template to your Nigerian operations will not satisfy the NDPC.
For organisations operating in both Nigeria and the UK, running two separate compliance programmes for largely overlapping obligations wastes time and creates inconsistency. One misaligned privacy notice in one jurisdiction creates risk in both.
Enforcement is no longer theoretical. The NDPC has issued fines against organisations for data protection violations and opened compliance investigations into large numbers of companies at once. Organisations that treated the NDPA 2023 as a low-priority policy update are now reassessing that decision under regulatory pressure, which is a harder position to work from than starting the programme properly the first time.
A recurring failure point is the registration question. Many organisations do not know whether they qualify as a Data Controller of Major Importance, so they either register unnecessarily or miss an actual registration obligation. Both outcomes carry cost, one in wasted administrative effort, the other in regulatory exposure.
What we do
FortressPoint builds NDPA 2023 compliance programmes for organisations across Nigerian markets, and for international organisations with Nigerian operations. We start with a data inventory, mapping what personal data you hold, where it comes from, where it goes, and what you do with it.
From the inventory we assess your lawful basis for each processing activity, identify the gaps, and build the documentation and procedures to close them. We align the programme to the GAID 2025 requirements that sit alongside the Act itself, because most compliance programmes built on the Act alone are missing critical implementation detail.
For organisations with UK operations we build one programme that satisfies both UK GDPR and NDPA 2023. You do not run parallel compliance tracks for the same controls.
We assess your Data Controller of Major Importance status early in the engagement, because it determines your registration obligations and the depth of documentation the NDPC expects. Getting this classification right at the start avoids both unnecessary registration and the risk of missing a real one.
Where an organisation needs a Data Protection Officer and does not have one, we can act as your outsourced DPO or help you appoint and brief an internal one, so the role is properly defined from day one rather than added on as an afterthought once a compliance gap has already appeared.
Who this is for
What you get
Why FortressPoint
We do not apply a UK GDPR framework with Nigerian labels. The NDPA 2023 differs from UK GDPR in specific ways that matter, particularly on cross-border transfers, retention obligations under GAID 2025, and the registration requirements for Data Controllers of Major Importance. We know the differences and we build for them.
For organisations in both markets we build one programme covering both regimes. Your privacy notices say the same thing in both jurisdictions, your breach procedures meet both timelines, and your data inventory covers both operations. No duplication.
We produce documentation the NDPC can review, not paperwork designed to look complete. Compliance programmes that look good internally but cannot withstand regulatory scrutiny are not compliance programmes.
We track how the NDPC is actually enforcing the Act, not just what the Act says on paper. Recent fines and investigations tell you what regulators are prioritising in practice, and we build programmes that address those priorities directly rather than treating every clause of the Act as equally urgent.
Common questions
The Nigeria Data Protection Act 2023 is Nigeria’s primary data protection law. It replaced the earlier Nigeria Data Protection Regulation and established the Nigeria Data Protection Commission, the NDPC, as an independent regulator with investigation, audit, and enforcement powers, including fines of up to 2% of an organisation’s annual gross revenue.
NDPA 2023 has the force of primary legislation, where the NDPR was a regulation issued under a narrower legal basis. NDPA 2023 also created a dedicated, better-resourced regulator, introduced stronger enforcement powers, and is supported by the General Application and Implementation Directive 2025, which sets out detailed compliance requirements that go beyond what the NDPR specified.
Organisations classified as a Data Controller or Data Processor of Major Importance must register with the NDPC. This classification depends on factors including the volume and nature of personal data processed, the sector you operate in, and whether you process data that carries higher sensitivity. A proper data inventory and assessment is the reliable way to determine whether your organisation meets this threshold.
An NDPC audit typically examines your data inventory, lawful basis documentation, privacy notices, data subject rights procedures, breach notification history, and (where applicable) your registration status. Organisations that already hold this documentation in an organised, current state generally have a materially easier audit than those assembling it under time pressure.
Yes, and the pace has picked up. The NDPC has publicly reported fines against major organisations for data protection violations, including a ₦766 million penalty against MultiChoice and a ₦555.8 million penalty against Fidelity Bank. In August 2025 the NDPC opened a compliance probe covering 1,369 companies at once. This is enforcement activity at a scale that changes the calculation for any organisation still treating the Act as a low-priority policy update.
Either can work, depending on your size and risk profile. An internal DPO needs sufficient independence, time, and NDPA 2023 knowledge to do the role properly. An outsourced DPO service suits organisations that need qualified oversight without a full-time hire, or that want an internal appointee properly briefed and supported during the first stages of the role.
If your organisation processes personal data in Nigeria and you are not confident about your NDPA 2023 position, contact us.