Frequently Asked Questions (FAQ)

1. What is Amstel Consulting?

Amstel Consulting is a data protection, privacy, governance and cybersecurity advisory firm supporting private companies, regulated businesses, multinational organisations and public-sector institutions in Nigeria and internationally.

2. Is Amstel Consulting a licensed DPCO?

Yes. Amstel Consulting is a licensed Data Protection Compliance Organisation (DPCO), providing organisations with professional support in meeting their obligations under Nigeria’s data protection framework.

3. What services does Amstel Consulting provide?

We provide data protection compliance, outsourced DPO services, Compliance Audit Return (CAR) support, privacy audits, DPIAs, ROPA, privacy documentation, staff training, vendor assessments, breach response support and cybersecurity advisory services.

4. What is a Data Protection Compliance Organisation (DPCO)?

A DPCO is an organisation licensed to provide professional data protection compliance services, including compliance assessments, audits and regulatory support under Nigeria’s data protection framework.

5. What is an outsourced Data Protection Officer (DPO)?

An outsourced DPO provides the organisation with an external privacy professional who performs the DPO function without the organisation having to maintain a full-time internal DPO.

6. Does my organisation need a DPO?

Certain organisations are required to designate a Data Protection Officer depending on their processing activities and applicable regulatory requirements. We can assess your organisation and advise on the appropriate DPO structure.

7. Can Amstel Consulting act as our outsourced DPO?

Yes. We provide outsourced DPO services supported by a multidisciplinary team of privacy, compliance, legal and cybersecurity professionals.

8. What is a Compliance Audit Return (CAR)?

A Compliance Audit Return is part of the NDPC’s accountability framework for assessing and documenting an organisation’s compliance with applicable data protection requirements.

9. Does my organisation need to file a Compliance Audit Return?

CAR requirements depend on your organisation’s activities and its applicable classification under Nigeria’s data protection framework. We can assess your organisation and determine the compliance and filing requirements that apply.

10. Can Amstel Consulting handle our CAR filing?

Yes. Where your organisation is required to file a CAR, we can manage the process from compliance assessment and remediation through verification, preparation and submission of the return.

11. What happens during a data protection audit?

We review your organisation’s data processing activities, governance framework, policies, procedures, security measures and compliance documentation to identify gaps and recommend practical corrective actions.

12. What is an NDPA Gap Assessment?

An NDPA Gap Assessment evaluates your current privacy and data protection practices against applicable requirements and identifies areas requiring improvement, remediation or further review.

13. What is a Data Protection Impact Assessment (DPIA)?

A DPIA is a structured assessment used to identify and manage privacy risks associated with processing activities that may present heightened risks to individuals.

14. What is a Record of Processing Activities (ROPA)?

A ROPA documents how personal data is collected, used, stored, shared and otherwise processed across an organisation. It provides an important foundation for effective privacy governance and accountability.

15. Can you prepare our privacy policies and compliance documentation?

Yes. We assist organisations with privacy notices, internal data protection policies, data retention frameworks, consent documentation, data processing agreements, breach procedures and other compliance documentation.

16. Do you provide data protection training for employees?

Yes. We provide practical data protection and privacy training for employees, management teams, DPOs and other personnel, tailored to the organisation’s sector, operations and risk profile.

17. Can you help if our organisation experiences a data breach?

Yes. We can support your organisation in assessing the incident, coordinating the privacy and compliance response, documenting the breach, evaluating notification obligations and strengthening controls following the incident.

18. Do you provide cybersecurity services as well as data protection services?

Yes. Our multidisciplinary approach combines privacy and data protection compliance with cybersecurity advisory, helping organisations address both governance requirements and technical risks.

19. Do you work with organisations outside Nigeria?

Yes. Our network includes professionals across Nigeria, Europe and the Americas, enabling us to support Nigerian and international organisations dealing with Nigerian data protection requirements and broader privacy and governance considerations.

20. How do we get started with Amstel Consulting?

Start with a free NDPA Gap Assessment or contact our advisory team directly. We will review your organisation’s requirements and recommend the appropriate compliance, DPO, audit, training or cybersecurity support.