Skip to content
ASIRI

Frameworks · GDPR · no certification scheme

There is no such thing as a GDPR certificate

Every badge you have seen claiming one is a self-assessment. Asiri will map your NDPA work onto the Regulation, article by article — and then print the honest word on the badge, which is self-assessed.

Nothing goes here.
No body issues it.

Article by section

Most of it, you have already written in Nigerian

The Act was drafted with the Regulation in view, so the overlap is unusually clean. Where the two genuinely differ, this table says so rather than smoothing it over.

GDPR

Maps

NDPA 2023

Art. 6 · Lawfulness of processing

Six lawful bases, consent among them rather than above them.

Same

s. 25 · Lawful basis

Six bases, with legitimate interest drawn slightly narrower.

Art. 15 · Right of access

One month, extendable by two for complex requests.

No period set

s. 34 · Data subject request

No period at all. §38(3)(b) reserves timing to the Commission, which has prescribed none — the standard is without undue delay, so there is nothing to extend.

Art. 30 · Records of processing

The ROPA every EU supervisory authority opens first.

Same

s. 24 · Register of activities

The register your annual return is built on.

Art. 33 · Breach notification

72 hours to the supervisory authority.

Same

s. 40 · Breach notification

72 hours to the Commission, from awareness.

Art. 35 · Data protection impact assessment

Required for high-risk processing, with defined triggers.

Same

s. 28 · Impact assessment

Same instrument, and the same evidence satisfies both.

Art. 37 · Data protection officer

Mandatory for public bodies and large-scale processing.

Different

s. 32 · DPO, plus DPCO filing

The Act adds a licensed DPCO who signs the return. The EU has no equivalent role.

Art. 44–49 · Transfers

Adequacy, SCCs, binding corporate rules.

Different

s. 41–43 · Transfers

Adequacy list differs, and Nigeria is not on the EU’s. Both directions need papering.

Where they part company

Four things the Regulation wants and the Act does not

These are the gaps that catch Nigerian companies serving EU customers. None of them is enormous; all of them are separate work.

Art. 27

An EU representative

If you have no establishment in the Union but target people in it, you must appoint someone there in writing. Nothing in the Act asks for this.

Art. 22

Automated decisions

A right not to be subject to solely automated decisions with legal effect, including a right to human review. The Act is quieter here.

Art. 20

Data portability

A machine-readable export of the data the person gave you. Distinct from the right of access, and usually missed.

Art. 45

Adequacy in both directions

Nigeria is not on the EU adequacy list, so transfers into the Union need a mechanism even where the Act is satisfied.

What your badge will say

A self-assessment that admits it is one is worth more

A buyer's counsel can tell the difference in about four seconds. The company that overclaims loses the room; the company that publishes its own limits keeps it.

Refused

GDPR certified · GDPR compliant

No accreditation body issues either. The second one is worse, because it sounds like a finding.

Printed instead

GDPR self-assessment · [n] of [articles assessed] evidenced · dated [the day it ran]

Your figures, read on the day the badge is cut, with every unevidenced article named on the page rather than omitted from it. No specimen count is shown here: a number on this page is a number somebody quotes.

Serving EU customers from Lagos? Start from what you have.

Asiri will map your registers onto the Regulation article by article, evidence what it can read, and name what is genuinely additional work.