Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA)
Nigeria Data Protection Regulation (NDPR) 2019, which provides initial data protection rules, and the Nigeria Data Protection Act (NDPA) 2023, which supersedes the NDPR and introduces expanded obligations, breach notification, and higher penalties.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (30)
Accountability
| Code | Title |
|---|---|
| NDPA-S33-ACCOUNTABILITY | Accountability and Records (Section 33) |
Audit
| Code | Title |
|---|---|
| NDPR-ART4-AUDIT | Annual Compliance Audit Return (Article 4.1.7) |
Automated Processing
| Code | Title |
|---|---|
| NDPA-S37-ADM | Automated Decision-Making (Section 37) |
Children Data
| Code | Title |
|---|---|
| NDPA-S31-CHILDREN | Children and Persons Lacking Capacity (Section 31) |
Complaints
| Code | Title |
|---|---|
| NDPA-S46-COMPLAINTS | Complaints to the Commission (Section 46) |
Consent
| Code | Title |
|---|---|
| NDPA-S26-CONSENT | Conditions for Valid Consent (Section 26) |
DPCO
| Code | Title |
|---|---|
| NDPA-DPCO | Data Protection Compliance Organisation Engagement |
Data Subject Rights
| Code | Title |
|---|---|
| NDPA-S34-RIGHTS | Data Subject Rights (Section 34-37) |
| NDPA-S35-ERASURE | Right to Erasure (Section 35) |
| NDPA-S38-PORTABILITY | Data Portability (Section 38) |
Disclosure
| Code | Title |
|---|---|
| NDPR-ART2-3RDPARTY | Third-Party Data Sharing Notice (Article 2.11) |
Enforcement
| Code | Title |
|---|---|
| NDPA-S48-PENALTY | Enforcement and Penalties (Section 48) |
Governance
| Code | Title |
|---|---|
| NDPA-S32-DPO | Data Protection Officer Appointment (Section 32) |
HR Data
| Code | Title |
|---|---|
| NDPA-S43-EMPLOYMENT | Employment Data Processing (Section 43) |
Implementing Rules
| Code | Title |
|---|---|
| NDPA-GAID-2025 | General Application and Implementation Directive (GAID) 2025 |
Incident Response
| Code | Title |
|---|---|
| NDPA-S40-BREACH | Personal Data Breach Notification (Section 40) |
International Transfers
| Code | Title |
|---|---|
| NDPA-S41-TRANSFER | Cross-Border Transfers Adequacy (Section 41) |
| NDPA-S42-SAFEGUARDS | Transfer Safeguards and Derogations (Section 42) |
Lawful Basis
| Code | Title |
|---|---|
| NDPA-S24-LAWFUL | Lawful Basis for Processing (Section 25) |
Marketing
| Code | Title |
|---|---|
| NDPA-S38-OBJECT-MARKETING | Right to Object to Direct Marketing (Section 36) |
Principles
| Code | Title |
|---|---|
| NDPA-S24-PRINCIPLES | Data Protection Principles (Section 24) |
Privacy by Design
| Code | Title |
|---|---|
| NDPA-DPBP | Privacy by Design and Default (Section 39(3)) |
Public Sector
| Code | Title |
|---|---|
| NDPR-ART2-LAWFUL-PI | Public Institutions Use of Personal Data (Guideline 2020) |
Registration
| Code | Title |
|---|---|
| NDPA-S44-REG | Registration of Data Controllers/Processors of Major Importance (Section 44) |
Regulator
| Code | Title |
|---|---|
| NDPA-S5-NDPC | Establishment and Functions of NDPC (Section 5) |
Regulator Powers
| Code | Title |
|---|---|
| NDPA-S45-INSPECT | Investigations and Inspections (Section 45) |
Retention
| Code | Title |
|---|---|
| NDPA-S24-RETENTION | Retention and Erasure (Section 24(1)(e)) |
Risk Assessment
| Code | Title |
|---|---|
| NDPA-S28-DPIA | Data Protection Impact Assessment (Section 28) |
Security
| Code | Title |
|---|---|
| NDPA-S39-SECURITY | Security of Processing (Section 39) |
Special Categories
| Code | Title |
|---|---|
| NDPA-S30-SENSITIVE | Sensitive Personal Data Processing (Section 30) |
Third Parties
| Code | Title |
|---|---|
| NDPA-S29-PROCESSOR | Controller-Processor Contracts (Section 29) |
Training
| Code | Title |
|---|---|
| NDPR-ART3-AWARENESS | Privacy Awareness and Training (Article 3.1.4) |
Transparency
| Code | Title |
|---|---|
| NDPA-S27-PRIVACY-NOTICE | Information to Data Subjects (Section 27) |
Frequently Asked Questions
What is Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA)?
Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) is a compliance framework from Nigeria with 30 domains and 33 controls. Nigeria Data Protection Regulation (NDPR) 2019, which provides initial data protection rules, and the Nigeria Data Protection Act (NDPA) 2023, which supersedes the NDPR and introduces expanded obligations, breach notification, and higher penalties. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) have?
Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) has 33 controls organised across 30 domains. The largest domains are Data Subject Rights (3 controls), International Transfers (2 controls), Accountability (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) map to?
Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) compliance?
Start your Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Nigeria Data Protection Regulation (NDPR) and Nigeria Data Protection Act (NDPA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required