Frameworks · GDPR · no certification scheme
There is no such thing as a GDPR certificate
Every badge you have seen claiming one is a self-assessment. Asiri will map your NDPA work onto the Regulation, article by article — and then print the honest word on the badge, which is self-assessed.
Nothing goes here.
No body issues it.
Article by section
Most of it, you have already written in Nigerian
The Act was drafted with the Regulation in view, so the overlap is unusually clean. Where the two genuinely differ, this table says so rather than smoothing it over.
GDPR
NDPA 2023
Art. 6 · Lawfulness of processing
Six lawful bases, consent among them rather than above them.
s. 25 · Lawful basis
Six bases, with legitimate interest drawn slightly narrower.
Art. 15 · Right of access
One month, extendable by two for complex requests.
s. 34 · Data subject request
No period at all. §38(3)(b) reserves timing to the Commission, which has prescribed none — the standard is without undue delay, so there is nothing to extend.
Art. 30 · Records of processing
The ROPA every EU supervisory authority opens first.
s. 24 · Register of activities
The register your annual return is built on.
Art. 33 · Breach notification
72 hours to the supervisory authority.
s. 40 · Breach notification
72 hours to the Commission, from awareness.
Art. 35 · Data protection impact assessment
Required for high-risk processing, with defined triggers.
s. 28 · Impact assessment
Same instrument, and the same evidence satisfies both.
Art. 37 · Data protection officer
Mandatory for public bodies and large-scale processing.
s. 32 · DPO, plus DPCO filing
The Act adds a licensed DPCO who signs the return. The EU has no equivalent role.
Art. 44–49 · Transfers
Adequacy, SCCs, binding corporate rules.
s. 41–43 · Transfers
Adequacy list differs, and Nigeria is not on the EU’s. Both directions need papering.
Where they part company
Four things the Regulation wants and the Act does not
These are the gaps that catch Nigerian companies serving EU customers. None of them is enormous; all of them are separate work.
Art. 27
An EU representative
If you have no establishment in the Union but target people in it, you must appoint someone there in writing. Nothing in the Act asks for this.
Art. 22
Automated decisions
A right not to be subject to solely automated decisions with legal effect, including a right to human review. The Act is quieter here.
Art. 20
Data portability
A machine-readable export of the data the person gave you. Distinct from the right of access, and usually missed.
Art. 45
Adequacy in both directions
Nigeria is not on the EU adequacy list, so transfers into the Union need a mechanism even where the Act is satisfied.
What your badge will say
A self-assessment that admits it is one is worth more
A buyer's counsel can tell the difference in about four seconds. The company that overclaims loses the room; the company that publishes its own limits keeps it.
Refused
GDPR certified · GDPR compliant
No accreditation body issues either. The second one is worse, because it sounds like a finding.
Printed instead
GDPR self-assessment · [n] of [articles assessed] evidenced · dated [the day it ran]
Your figures, read on the day the badge is cut, with every unevidenced article named on the page rather than omitted from it. No specimen count is shown here: a number on this page is a number somebody quotes.
Serving EU customers from Lagos? Start from what you have.
Asiri will map your registers onto the Regulation article by article, evidence what it can read, and name what is genuinely additional work.