Security

§ Security

A Plain-Language NDPA Checklist for Nigerian SMEs

The Nigeria Data Protection Act carries penalties of up to 2% of annual gross revenue or ₦10 million, whichever is greater and the NDPC has already fined Meta $220 million and MultiChoice ₦766.2 million. Here's what actually applies to a small business.

DiscoveryTech Hub

DiscoveryTech Hub

· 7 min read
Close-up of a hand reviewing a data privacy compliance document at a desk

Nigeria's Data Protection Act (NDPA) became law on June 12, 2023, replacing the older Nigeria Data Protection Regulation (NDPR) of 2019, and established the Nigeria Data Protection Commission (NDPC) as an independent regulator with real enforcement power. It applies well beyond banks and telecoms: any organization public or private that processes the personal data of people in Nigeria falls under it, which covers the overwhelming majority of businesses collecting customer names, phone numbers, or payment details.

Enforcement is no longer theoretical

The NDPC has already demonstrated it will act on large violations: it imposed a $220 million fine against Meta Platforms and a ₦766.2 million fine against MultiChoice Nigeria, and separately fined Fidelity Bank over ₦500 million for privacy violations in 2024, according to compliance research from Secure Privacy and reporting on Nigerian data breach cases. For SMEs, the maximum statutory penalty is up to 2% of annual gross revenue or ₦10 million (roughly $6,500), whichever is greater a threshold that's genuinely reachable for a growing business, not just a large one.

Who counts as an "organization of major importance"

The NDPA applies different obligation levels depending on scale. A business is classified as an organization of "major importance" triggering stricter requirements, including designating a Data Protection Officer if it processes personal data of more than 200 data subjects within a six-month period, or operates in specific sectors like finance, communications, or health, according to NDPC guidance. Many small service businesses, e-commerce operations, and consultancies will cross the 200-data-subject threshold faster than they expect once customer records, order forms, and email lists are all counted together.

Know what you're actually collecting

Most businesses underestimate how much personal data they hold once order forms, WhatsApp chat logs, and spreadsheet-based customer lists are all counted. The first real step toward compliance is auditing what exists and where it lives not assuming that because data isn't in a formal database, it doesn't count under the Act. It does.

The core obligations that apply to nearly everyone

Regardless of size, the NDPA requires data controllers to: maintain an accessible, up-to-date privacy policy; implement technical and organizational security safeguards proportionate to the sensitivity and volume of data handled; keep records of data processing activities; and be able to demonstrate compliance if the NDPC asks, not merely claim it. Data controllers of major importance must additionally notify the NDPC within 72 hours of learning about a breach that could pose a high risk to individuals' rights, notify affected individuals directly where the risk is high, and maintain a breach register documenting causes and remedies.

Limit access before you limit anything else

Restricting who on the team can view customer data rather than leaving a shared spreadsheet open to everyone closes off the most common and least technical kind of data exposure. This single change, which costs nothing to implement, addresses a meaningful share of the "who's responsible when something leaks" problem before it ever becomes a legal question.

Have a plan before you need one

A short written note on what the business would do if customer data were exposed who gets notified, how quickly, and through what channel puts a business in a fundamentally different position than one improvising under the 72-hour reporting clock. Given that Nigeria recorded over 119,000 data breach incidents in Q1 2025 alone, treating "if" as "when" is the more realistic planning assumption.

Cross-border data transfers

If customer data is ever processed or stored outside Nigeria (a common situation for businesses using foreign-hosted tools or cloud services), the NDPA requires the receiving country or organization to provide an adequate level of protection comparable to Nigeria's own standard, or for the transfer to fall under a specific exception such as informed consent. This is worth checking against whatever tools CRMs, email platforms, hosting providers a business already relies on, since many popular platforms are hosted abroad by default.