Nigeria Data Protection Act 2023 (NDPA)
Security and Accountability

Nigeria Data Protection Act 2023 (NDPA) NG-NDPA-5: Security of Processing, Breach Notification, and DPIA

Implement appropriate technical and organisational measures per NDPA Section 40 including encryption + pseudonymisation + integrity protection + confidentiality + restoration capabilities + regular testing. Notify NDPC of personal data breaches within 72 hours per Section 40 + notify data subjects when high risk per Section 40(4). Conduct Data Protection Impact Assessments (DPIA) per Section 39 for high-risk processing including profiling + systematic monitoring + large-scale sensitive data processing. Consult NDPC for high residual risk.

What else in your programme already covers this

This control maps to 383 controls across 141 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-3 Opt-Out Rights for Targeted Advertising, Sale, and Profiling
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties

ISO 22320:2018 · 6 controls

ISO/IEC 27400:2022 · 6 controls

ISO/IEC 29100:2024 · 6 controls

APPI · 5 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA

Bahrain PDPL · 5 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-2 Section 2 - Interpretation
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

GDPR · 5 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.9 Processing of special categories of personal data

ISO/IEC 29134:2023 · 5 controls

  • 3.3 Configure Data Access Control Lists
  • 3.6 Encrypt Data on End-User Devices
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.
  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup

South Korea ISMS-P · 5 controls

  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

ISO/IEC 23894:2023 · 4 controls

ISO/IEC 27014:2020 · 4 controls

ISO/IEC 30111:2019 · 4 controls

API 1164 · 3 controls

  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 29147:2018 · 3 controls

  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training

South Korea PIPA · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.7 Emergency and Incident Response
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • CA-10 Selects and Develops Control Activities
  • CA-12 Deploys Through Policies and Procedures
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO 56002 · 2 controls

  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling

OWASP Top 10:2025 · 2 controls

  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • DS-2 Ensure software supply chain security
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor

ISO 20000-1 · 1 control

ISO 27043 · 1 control

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27003:2017 · 1 control

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/SAE 21434 · 1 control

ITIL 4 · 1 control

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-171 · 1 control

  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards

OWASP ASVS · 1 control

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)

OWASP MASVS · 1 control

  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VPSHR-3 Implementation Guidance and Reporting
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 383 it maps to, and the evidence behind each claim, over MCP and REST.