Skip to content
ASIRI
← All articles

Asiri blog

NDPA Software for Nigerian Health Providers in 2026

NDPA compliance software built for the Nigerian regulatory environment gives your team the registers, evidence trails, and workflows you need to prove that patient data is handled the way the Act requires.

Abraham Esandayinze Tanta

Founder/CEO

Published Updated
NDPA software

Nigerian digital health is one of the fastest-growing sectors on the continent, handling millions of patient records, diagnostic results, and insurance claims every year. The Nigeria Data Protection Act 2023 treats every diagnosis, prescription, and lab result as sensitive personal data. The rules for collecting, storing, and sharing health information are strict and specific.

NDPA compliance software built for the Nigerian regulatory environment gives your team the registers, evidence trails, and workflows you need to prove that patient data is handled the way the Act requires.

This guide walks you through what to look for when evaluating NDPA compliance software for a health or HealthTech operation. You will find the specific obligations the Act places on health data controllers, the software capabilities that map directly to those obligations, and the decision criteria that matter when your team sits down to choose a platform.

Key Takeaways: NDPA Software for Nigerian Health Providers

  • Health data is classified as sensitive personal data under the NDPA, requiring explicit consent or a specific legal permission for processing.
  • NDPA compliance software should read your systems and show provenance for every figure, not ask you to type what you believe.
  • The 72-hour breach notification window starts from the moment of awareness, making automated clock tracking critical for health providers.
  • Asiri maps NDPA health data workflows to the Act's own language, with registers built for Nigerian law from the first line of code.
  • Evaluating software means checking evidence quality, lawful basis tracking, data subject request handling, and audit-readiness in one pass.

Why Health Data Gets Special Treatment Under the NDPA

Section 30 of the Nigeria Data Protection Act 2023 names health data as a special category of personal data. That classification is not cosmetic. It changes the legal basis you are allowed to rely on, the consent standard you must meet, and the severity assessment the NDPC applies when something goes wrong.

A diagnosis, a prescription, a lab result, a biometric login at a clinic entrance: each of these is special category data under the Act. Contract alone is not enough to justify processing them. You need explicit consent that names the specific purpose, or a legal permission the Act recognises, documented and dated.

For digital health teams, this means that the compliance gap between ordinary personal data and health data is not a matter of degree. It is a different regime. Software that treats all data the same way leaves you exposed on the exact category the NDPC will scrutinise most carefully.

What the NDPA Requires from Health Data Controllers

Lawful Basis and Additional Conditions for Health Data

Processing health data under Section 25 of the NDPA requires one of six lawful grounds. Section 30 adds an additional condition: for sensitive data, you must also identify a specific permission that justifies the processing.

In practice, that means recording explicit consent with a versioned notice, or documenting a named legal permission tied to the specific processing activity.

A general privacy policy alone does not satisfy this standard. Each activity that touches health data needs its own documented basis and its own additional condition, linked to the actual records your team processes.

The 72-Hour Breach Notification Window

Section 40 of the NDPA gives you 72 hours to notify the NDPC after becoming aware of a personal data breach. For health records, the stakes are higher. Breaches involving health data almost always trigger the obligation to notify affected patients as well, because the risk to their rights is inherently high.

The clock starts at the moment of awareness, not at the moment a committee decides the event qualifies as a breach. A nurse who notices results filed under the wrong patient record has started the 72-hour window.

Software that does not capture that moment and start counting immediately leaves you building your timeline from memory after the fact.

Data Subject Request Handling

Patients have the right to access, correct, erase, and port their health data under Part IV of the NDPA. The Act does not prescribe a fixed response window for all request types, but the obligation to respond without undue delay applies, and the NDPC has indicated it takes delay seriously.

For a health provider, that means tracking every request from the moment it arrives, verifying the identity of the person making it, and recording both the response and the proof that the response was actually honoured across every system that holds a copy of the data.

Cross-Border Transfers and Cloud Hosting

Section 43 of the NDPA restricts transfers of personal data outside Nigeria. If your telemedicine platform sends SMS results through a gateway hosted abroad, or your analytics warehouse sits on infrastructure outside the country, each of those transfers needs a documented legal basis and appropriate safeguards.

Health data transferred without documentation is not a minor gap. It is a specific compliance finding, and the NDPA's own provisions make clear that the responsibility sits with the controller, regardless of where the processor operates.

What NDPA Compliance Software Needs to Do for Health Providers

Read Systems Instead of Relying on Questionnaires

Questionnaire-based compliance tools ask your team to type what they believe about data flows, retention, and processing activities. The problem is that belief drifts from reality over time. A new integration, a changed vendor, or an updated schema can make your register inaccurate the day after you filled it in.

Software that connects to your systems and reads what is actually there gives you figures with provenance. When your auditor asks how many records you hold, the answer comes from a database read, not from someone's estimate.

Asiri connects to the systems that hold the data and shows where every figure came from: a verified read, a structural check, or a declared value from a system with no interface.

Classify Health Data Automatically

A medication list discloses a condition, which means it inherits the condition's protection under the NDPA. Appointment history is ordinary personal data until the clinic name reveals the diagnosis, at which point it becomes sensitive. These distinctions matter for lawful basis, consent, and breach severity.

Your software should classify each field as it is read, flagging which records qualify as special category data and which processing activities require an additional condition. Manual classification at scale is where gaps accumulate, because the person filling in the register does not always see the inference chain.

Track Consent with Versioned Notices

Consent under the NDPA must be explicit, specific, and documented. For health data, that means recording exactly which version of your privacy notice the patient agreed to, when they agreed, and through which channel.

If version 5 of your notice broadens what you do with lab results, a patient who consented to version 2 has not agreed to the new scope.

Asiri records consent decisions with the version of the notice attached, and tracks how many patients sit on an older version when the scope changes. Withdrawal is tracked to the system level: a withdrawal that never reached the marketing platform or the SMS gateway is not a withdrawal the NDPC will accept.

Run the Breach Clock from the Moment of Awareness

The 72-hour notification window under Section 40 does not start when someone opens a form. It starts when the first person in your organisation becomes aware that a breach may have occurred. Software that waits for a formal incident declaration to begin counting puts you behind the clock before you have started.

Your compliance platform should log the awareness event, start the countdown immediately, and surface the open clock to on-call staff through alerts. Every hour spent debating whether an event qualifies as a breach is an hour the NDPC will count against your notification timeline.

Handle Data Subject Requests with Audit Trails

An access request from a patient is not a single event. It involves verification, a search across every system that holds data about that person, and a response that covers all the records, including copies nobody remembered existed.

A deletion request adds another layer: proving that the data was removed from every system, including backups and analytics copies where it may have been replicated.

Your software needs to track each request from intake through fulfilment, with timestamps, named owners, and a record of what was found in each system. Asiri handles DSR intake, verification, SLA tracking, and response packaging with a trail that shows both what was answered and what was honoured.

Document Cross-Border Transfers with Evidence

Every transfer of personal data outside Nigeria needs a documented mechanism under the NDPA: an adequacy determination, standard contractual clauses approved by the NDPC, binding corporate rules, or explicit consent.

For health providers, this covers not only your primary cloud infrastructure but also every vendor that receives patient data, including SMS gateways, referral platforms, and lab-result delivery services.

Your software should identify which of your vendors trigger a cross-border transfer, document the safeguard in place for each, and flag any transfer that has no mechanism on file. A register that lists seven active transfers but shows a mechanism for only six tells you exactly where the gap is.

How to Evaluate NDPA Compliance Software for Your Health Organisation

Check Whether Evidence Comes from Systems or from People

Ask to see how the platform populates its registers. If every figure is typed by a person, you are buying a structured spreadsheet. If the platform reads your systems and labels each figure with its source (verified, structural, declared, or unverifiable), you have evidence that holds up to scrutiny.

In a regulatory environment where the NDPC can request proof of your data handling at any time, the difference between a register full of declarations and a register backed by system reads is the difference between a credible filing and one that collapses under a sample check.

Ask How the Platform Handles Health Data Classification

Request a demonstration with health data fields. Watch whether the software flags a medication list as sensitive because it discloses a condition. Check whether appointment history is classified correctly when the clinic name reveals a diagnosis. If classification depends entirely on manual tagging, you are building a register that will lag behind your actual data flows.

Test the Breach Response Workflow

Simulate an incident. Does the software start counting from the moment you log awareness, or does it wait for a formal declaration? Can you see the open clock from a mobile device at 2 a.m.? Does the platform generate the notification content the NDPC requires, or does your team have to assemble it from scratch?

The 72-hour window is not generous. Software that adds delay to the notification process costs you the one resource you do not have: time.

Verify That Audit Evidence Is Exportable and Provenance-Tagged

Your licensed DPCO needs evidence they can sign. Your auditor needs working papers they can review. Your enterprise buyers need trust signals they can verify.

The platform should export evidence packs with provenance labels attached, so everyone who receives the evidence knows whether each figure was read from a system, derived from a schema, or declared by a person.

Asiri assembles audit evidence packs from your operational registers and labels each figure with its source, so the gaps show up in the filing pack rather than in the auditor's findings.

Confirm Nigerian Law Comes First, Not as an Afterthought

Many compliance platforms were built for GDPR and extended to cover the NDPA as an additional framework. The workflows, the terminology, and the default assumptions in those platforms reflect European law first and Nigerian law second.

That matters because the NDPA has its own tier system, its own filing obligations through licensed DPCOs, its own breach notification structure, and its own enforcement posture.

Asiri was built around the NDPA from the first line of code. The registers, the clocks, the filing workflow, and the terminology map to Nigerian law as it is actually enforced. The NDPC's tier system (OHL, EHL, UHL) is how the platform structures obligations, not a bolt-on category.

When you need to file your annual registration renewal, the system knows that only a licensed DPCO firm may submit the audit return. The submit control is absent for everyone else.

Where Global Compliance Platforms Fall Short for Nigerian Health Providers

Compliance platforms designed for the US or European markets share a common pattern: they start with SOC 2 or GDPR and treat other frameworks as modules you add later. For a Nigerian health provider, that architecture creates practical problems.

The NDPA's filing obligation runs through a licensed DPCO, not through the controller directly. The tier classification (ordinary, elevated, ultra-high) determines which obligations apply and which do not.

The GAID directive adds requirements that did not exist at the time of enactment. A platform that does not model these distinctions will show you compliance tasks that do not apply to your tier, or miss obligations that do.

ASIRI Compliance Ltd built Asiri for this exact problem. The platform does not start with a foreign framework and add Nigerian labels. It starts with the NDPA and maps outward to SOC 2, ISO 27001, and GDPR where your buyers or partners ask for them.

That direction matters because the workflows, the language, and the evidence structure all reflect the law you are actually governed by.

Building a Health Data Privacy Programme with NDPA Compliance Software

Step 1: Map Your Data Flows and Identify Sensitive Fields

Start with an inventory of every system that touches patient data. Your electronic medical records system, your appointment scheduling platform, your lab information system, your billing engine, your SMS gateway, your analytics warehouse. For each one, document what data it holds, where it sends data, and what comes back.

Mark every field that qualifies as special category data under Section 30. Diagnoses, test results, prescriptions, genetic markers, biometric identifiers used for authentication. Pay particular attention to fields that become sensitive by inference, such as appointment history at a specialist clinic.

Step 2: Document Lawful Basis and Additional Conditions

For each processing activity that involves health data, record the lawful basis (consent, contract, legal obligation, vital interests, public interest, or legitimate interest) and the additional condition required for sensitive data. Where you rely on consent, record the version of the privacy notice the patient agreed to, the date, and the channel.

Where you rely on a legal permission (for example, public health reporting), document the specific provision and the scope of the permission. A general reference to "legal obligations" does not satisfy the NDPA's specificity requirement.

Step 3: Set Up Automated Clocks and Escalation Paths

Configure your platform to start the 72-hour breach clock from the moment of awareness, route alerts to your on-call team, and generate the notification content required by the NDPC. Set up escalation paths so that a clock approaching its deadline reaches the right person, not a shared inbox.

For data subject requests, configure SLA tracking from the moment of intake and assign named owners for each step: verification, search, response, and confirmation that the response was honoured across all systems.

Step 4: Connect Your Systems and Review the Register

Connect your compliance platform to the systems that hold patient data. Review the register that results. Where the platform was able to read data directly, the figures carry verified provenance. Where it read the schema only, the figures carry a structural label. Where nothing could be read, the gaps are named rather than hidden.

That register is what your licensed DPCO will work from when preparing your annual filing. The gaps in it will show up in the audit, which is the point: you want them visible now, not during fieldwork.

Step 5: Publish a Trust Center with Provenance-Tagged Evidence

Your enterprise buyers, HMO partners, and insurer counterparties want to see your compliance posture before they send you patient data. A Trust Center generated from your operational registers shows them what you can prove, with each entry coloured by its basis: verified from a system read, self-assessed, or still under way.

On every Asiri plan, including the free tier, you can publish a Trust Center at your own URL. The content comes from the registers you maintain for the NDPC, not from a separate set of statements written for the page. When an attestation expires, the Trust Center stops displaying it the same day.

The Role of the Licensed DPCO in Health Data Compliance

Under the NDPA, a Data Protection Compliance Organisation (DPCO) is the only entity authorised to submit your audit return to the NDPC. Your compliance software can assemble the evidence, package the filing, and surface the gaps, but the filing itself must carry the signature of a licensed firm.

This distinction matters for health providers because health data breaches and processing activities attract closer NDPC scrutiny. Your DPCO needs evidence they can independently verify, not a summary your team prepared. Software that gives your DPCO direct access to the registers, the evidence trail, and the audit working papers reduces the back-and-forth and makes the filing defensible.

Asiri's DPCO Marketplace connects you with licence-verified firms ranked by fit, not by who paid for position. Your DPCO works from the same registers you do, and the audit working papers are built from the same evidence. If a licence lapses, Asiri watches the NDPC register and tells you, rather than relying on the firm's own word.

Compliance Is Not a One-Time Project for Health Providers

A compliance programme that produces a filing once a year and goes quiet until the next deadline is a programme that drifts out of accuracy between filings. Patient data flows change when you onboard a new lab partner.

Consent versions expire when you update your privacy notice. A new SMS gateway introduces a cross-border transfer that was not in your original register.

Your software should surface these changes as they happen, update the registers from system reads, and adjust your compliance score based on current evidence. A score that was accurate six months ago is not a score you can file today.

According to a 2025 academic study in LexScriptio, Nigeria's health data governance landscape still contains regulatory fragmentation that heightens compliance risk for digital health providers. Staying current requires operational registers that update from your systems rather than from periodic manual reviews.

In Conclusion: Choosing NDPA Compliance Software for Your Health Organisation

The Nigeria Data Protection Act places specific, enforceable obligations on every organisation that processes health data. The 72-hour breach clock, the explicit consent requirement for sensitive data, the cross-border transfer documentation, and the mandatory filing through a licensed DPCO are not abstract policy goals. They are obligations your team must evidence on a regular cadence.

The software you choose should read your systems rather than rely on your memory, classify health data based on what the fields actually reveal, and produce audit evidence your DPCO can sign. Nigerian law should be the starting point of the platform's design, not a framework bolted onto a foreign product.

ASIRI Compliance Ltd built Asiri for exactly this: a compliance platform that starts with the NDPA, reads your systems, names every gap plainly, and hands your DPCO a filing pack they can defend. Prove trust, from Nigeria to the world.

FAQs About NDPA Software for Nigerian Health Providers

What makes health data different under the NDPA?

Health data is classified as sensitive personal data under Section 30 of the Nigeria Data Protection Act 2023. Processing it requires an additional condition beyond the six standard lawful bases, typically explicit consent or a specific legal permission.

Does Asiri handle health data classification automatically?

Asiri classifies each data field as it is read from your systems, flagging which records qualify as special category data. Fields like medication lists are identified as sensitive because they disclose a health condition, which means they inherit the condition's protection under the NDPA.

How does the 72-hour breach clock work in practice?

The NDPA requires notification to the NDPC not later than 72 hours after becoming aware of a breach. Asiri starts the clock from the moment of awareness, surfaces the countdown to your on-call team, and generates the notification content the Commission requires. Late notification is its own finding, separate from the underlying breach.

Can NDPA compliance software replace a licensed DPCO?

No. Under the NDPA, only a licensed Data Protection Compliance Organisation may submit your audit return to the NDPC. Asiri assembles the evidence pack and audit working papers, but the filing itself carries the DPCO's signature. The platform connects you with licence-verified firms through its DPCO Marketplace.

What should I check during an NDPA compliance software demo?

Ask to see how the platform populates its registers (from system reads or manual entry), how it classifies sensitive health data fields, whether the breach clock starts from awareness or from a formal declaration, and whether evidence exports carry provenance labels. These four checks tell you whether the platform is built for accountability or for appearances.

Does Asiri support frameworks beyond the NDPA?

Asiri manages seven frameworks mapped requirement by requirement onto the same evidence: NDPA, SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, PCI DSS, and GDPR. Evidence collected once satisfies every framework it maps to, so your team does not duplicate work for each buyer or regulator that asks for a different standard.

About the author

Abraham Esandayinze Tanta

Founder/CEO

Founder, Asiri — compliance infrastructure for Nigeria's NDPA · Creator of ndpr-toolkit (open source) · Security engineering → privacy tooling

More articles →

Ready to put the ideas into practice? Try the readiness check.