NDPA 2023 Alignment: A Strategic Checklist for Public and Private Sector Executives

Nigeria’s data protection landscape has evolved significantly with the Nigeria Data Protection Act (NDPA) 2023 and the General Application and Implementation Directive (GAID) 2025.

For boards, executives and senior management, data protection is no longer simply an IT or legal function. It is an organisation-wide governance responsibility that affects how personal data is collected, used, shared, secured and transferred.

The NDPA establishes principles for lawful and accountable processing, data subject rights, security obligations, breach management, Data Protection Officers (DPOs), Data Protection Impact Assessments (DPIAs), cross-border transfers and regulatory oversight. The GAID 2025 provides further guidance on how organisations should implement these obligations in practice.

Request a Free NDPA Gap Assessment

For organisations reviewing their compliance position, the following five areas provide a practical starting point.

1. Establish and Document Your Lawful Bases for Processing

Every organisation should understand why it processes personal data and ensure that an appropriate lawful basis supports each processing activity.

Under Section 25 of the NDPA, lawful bases include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or exercise of official authority, and legitimate interests, subject to the applicable conditions.

Consent should therefore not automatically be treated as the default basis for every processing activity.

Executive Checklist

Your organisation should be able to:

  • identify the personal data it processes and the purposes for which it is used;
  • establish the appropriate lawful basis for relevant processing activities;
  • provide clear and accessible privacy information to data subjects;
  • maintain appropriate records demonstrating how processing decisions have been made; and
  • review processing activities when purposes, systems, technologies or business operations change.

A well-maintained Record of Processing Activities (ROPA) can provide an important foundation for understanding and documenting an organisation’s data-processing environment.

2. Understand Your Regulatory Classification and DPO Obligations

The NDPA introduced the concept of a Data Controller or Data Processor of Major Importance, while the GAID 2025 provides further guidance for determining and classifying organisations falling within the applicable framework.

Organisations should therefore avoid relying solely on assumptions such as employee numbers, customer numbers or whether they process sensitive information. Their activities should be assessed against the applicable regulatory criteria.

Where an organisation is a Data Controller of Major Importance, Section 32 of the NDPA requires the designation of a Data Protection Officer with appropriate expertise in data protection law and practice. The Act permits the DPO to be an employee or engaged under a service contract.

Executive Checklist

Management should establish:

  • whether the organisation falls within an applicable DCPMI classification;
  • whether registration or other regulatory requirements apply;
  • whether the organisation is required to designate a DPO;
  • whether the DPO has appropriate access to senior management and sufficient resources to perform the role effectively; and
  • whether reporting structures appropriately address potential conflicts of interest.

For organisations without the resources or need to build a dedicated internal privacy function, an outsourced DPO arrangement may provide access to specialist expertise while maintaining an appropriate governance structure.

3. Build an Effective Data Breach Response Framework

Data protection compliance is not measured solely by an organisation’s ability to prevent incidents. Organisations must also be prepared to identify, assess, contain and respond appropriately when an incident occurs.

Section 40 of the NDPA establishes obligations relating to personal data breaches, including notification requirements where the applicable risk threshold is met. The legislation therefore should not be interpreted as requiring every security incident to be reported automatically; organisations need a process for assessing the nature and potential impact of a breach.

Executive Checklist

Organisations should maintain:

  • a documented incident and personal data breach response procedure;
  • clear internal escalation responsibilities;
  • mechanisms for assessing the nature, scope and likely consequences of a breach;
  • procedures for determining whether regulatory or data-subject notification is required;
  • appropriate documentation of incidents and decisions; and
  • coordination between privacy, legal, compliance, cybersecurity, IT and senior management functions.

Employees should also know how and where to report a suspected incident internally. A technically sophisticated breach-response plan has limited value if employees do not recognise an incident or know how to escalate it.

4. Embed Privacy Risk Assessment into Business Decisions

Section 28 of the NDPA requires a Data Protection Impact Assessment where processing is likely to result in a high risk to the rights and freedoms of data subjects.

A DPIA should therefore be viewed as a risk-management process rather than simply another compliance document.

It can help organisations identify privacy risks before introducing processing activities involving new technologies, extensive personal data processing or other circumstances capable of creating elevated risks for individuals.

The GAID 2025 provides additional guidance on DPIAs and their application.

Executive Checklist

Before implementing significant new processing activities, organisations should consider:

  • what personal data will be processed;
  • why the processing is necessary and proportionate;
  • which individuals may be affected;
  • whether the activity is likely to create high risks to their rights and freedoms;
  • what technical and organisational safeguards are available; and
  • whether a DPIA is required before processing begins.

As a matter of good governance, privacy considerations should also form part of procurement, technology implementation, product development and vendor-management processes.

This does not mean that every new system, supplier or technology automatically requires a DPIA. The appropriate assessment depends on the nature and risk of the proposed processing.

5. Maintain Evidence of Accountability and Regulatory Compliance

A central principle of modern data protection governance is accountability.

It is not enough for an organisation to state that it complies with the NDPA. It should be capable of demonstrating the policies, processes, controls and governance measures it has implemented to protect personal data.

The NDPA and GAID establish a broader compliance framework that may include registration, appropriate documentation, privacy governance, security measures, staff awareness and training, DPIAs, DPO arrangements and applicable Compliance Audit Return (CAR) requirements.

Executive Checklist

Senior management should consider whether the organisation can produce appropriate evidence of:

  • data protection policies and procedures;
  • Records of Processing Activities;
  • privacy notices and data subject procedures;
  • applicable DPIAs;
  • vendor and processor governance;
  • employee privacy awareness and training;
  • security and access controls;
  • breach-management procedures;
  • DPO oversight, where applicable; and
  • applicable registration, audit and regulatory filings.

Where a Compliance Audit Return is required, organisations should ensure that the assessment, supporting evidence and filing process are managed in accordance with the applicable NDPC framework. Licensed Data Protection Compliance Organisations (DPCOs) play a specific role in the CAR framework, including providing competent verification statements.

Data Protection as a Governance Priority

The NDPA should not be approached as a once-a-year compliance exercise.

Effective data protection requires coordination between leadership, legal, compliance, HR, procurement, technology, cybersecurity and operational teams. The objective is to establish a framework in which privacy considerations become part of ordinary organisational decision-making.

For boards and executives, this means asking more than whether the organisation has a privacy policy.

The more useful questions are:

Do we understand what personal data we hold? Why are we processing it? Who has access to it? Which third parties receive it? What risks does that processing create? And can we demonstrate the measures we have implemented to manage those risks?

Organisations that can answer those questions clearly are better positioned to demonstrate accountability, respond effectively to regulatory scrutiny and build confidence with customers, employees, partners and other stakeholders.

How Amstel Consulting Can Support Your Organisation

Amstel Consulting supports public and private sector organisations in developing practical data protection and privacy frameworks aligned with Nigeria’s evolving regulatory environment.

As a licensed Data Protection Compliance Organisation (DPCO), our multidisciplinary team provides support across data protection compliance assessments, outsourced DPO services, Compliance Audit Returns, DPIAs, Records of Processing Activities, privacy documentation, employee training, vendor governance and related privacy and cybersecurity advisory.

Our approach focuses on translating regulatory requirements into practical governance measures that work within the organisation’s existing operations.

Assess Your NDPA Compliance Position

If your organisation is reviewing its compliance framework or preparing for applicable regulatory requirements, Amstel Consulting can help identify existing gaps and establish a practical roadmap for strengthening data protection governance.

Request a Free NDPA Gap Assessment