Resources · NDPA glossary
Twenty-four words that decide whether you are compliant.
The Act is not hard because the ideas are hard. It is hard because it is written for lawyers. Here is each term as the Act puts it, and then as somebody would actually say it — because a rule you cannot restate is a rule you cannot follow.
NDPA 2023 · Section 65
Data controller
“…a person who, either alone or jointly with others, determines the purposes for and the manner in which personal data is processed or is to be processed.”
You decided why the data was collected. So you answer for it.
Deciding the purpose is what makes you a controller — not holding the data
The whole vocabulary
Every term, and what it obliges you to do
A definition that does not tell you what changes on Monday morning is trivia. Each one here ends with the thing you actually have to do.
- Data controller
The company that decides why personal data is collected and what happens to it. Deciding is the test — you can be a controller over data sitting entirely in someone else’s system.
You are the one the Commission writes to, and the one who files the annual return.
- Data processor
A company that handles personal data on your instructions and for your purposes. The moment it decides a purpose of its own, it stops being one.
Every processor needs written terms before it receives a single record.
- Data subject
The living individual the data is about. Not a customer, not a user — a person, including your own staff and your agents.
They can ask you what you hold, and you must answer without undue delay. The Act sets no number of days.
- Data protection officer
The person accountable for data protection, named to the Commission and reachable by anyone who asks.
Their name and address go on your public notice. A form that goes nowhere fails this.
- DPCO
A Data Protection Compliance Organisation licensed by the Commission to audit and file on behalf of controllers.
Only a licensed DPCO can sign the audit return that goes to the Commission.
- Personal data
Any information relating to an identifiable person. A phone number on its own qualifies; so does a device identifier that resolves to one.
If you can single somebody out with it, it is in scope — including your logs.
- Sensitive personal data
Health, genetic and biometric data, race, religion, political opinion, trade union membership and sex life. A short list, deliberately.
Consent for these must be explicit, and legitimate interest is not available at all.
- Pseudonymised
Identifiers swapped for a key you still hold. Reversible by design, which is the point and the problem.
It reduces risk, it does not take the data out of scope. It is still yours to answer for.
- Anonymised
Irreversibly stripped, with no key anywhere and no realistic route back to a person.
Genuinely anonymised data leaves the Act entirely. Almost nothing companies call anonymised is.
- Consent
A clear affirmative act. Silence, pre-ticked boxes and bundled terms are not consent, and it must be as easy to withdraw as to give.
Record what they saw, when, and which version of the notice — or you cannot prove it later.
- Legitimate interest
Processing you need for a real business reason, where that reason does not override the person’s rights. It requires a written balancing test.
The person can object, and if you cannot show the test you lose the argument.
- Contract
Processing genuinely necessary to give somebody what they asked for. Necessary means the service fails without it.
Marketing is not necessary to deliver a loan. That is a separate purpose and a separate basis.
- Record of processing activities
A written register of what you do with personal data, why, who receives it, and how long you keep it.
The Commission asks for this first. Not having one is the finding that opens every other one.
- Retention schedule
A stated period for each category of data, tied to the reason you hold it rather than to convenience.
“As long as necessary” is not a schedule. Seven years after account closure is.
- Data subject request
A person asking to see, correct, delete, port or object to what you hold. The wait starts when the request arrives, not when you recognise it.
There is no deadline to work back from. §38(3)(b) reserves timing to the Commission and it has prescribed none, so a schedule is not a defence and answering quickly is not automatically answering in time.
- Seventy-two hours
The window to tell the Commission about a notifiable breach, counted from when you became aware, not from when you finished investigating.
A supplier discovering it counts as you becoming aware. Say so in their contract, in hours.
- Cross-border transfer
Personal data going to a recipient outside Nigeria — including a cloud region, a support desk, or an analytics tool.
Each one needs a named mechanism on file before the first record moves.
- Adequacy
The Commission has decided a country protects data adequately, so transfers there need nothing further.
Check the list rather than assume. Most destinations companies use are not on it.
- Standard contractual clauses
Pre-approved contract terms that carry the protection with the data when there is no adequacy decision.
They must be signed before the transfer starts, not backfilled when someone asks.
- Certification
An accredited registrar examined you and issued a certificate with a number, a scope and an expiry — and can withdraw it.
Only ISO-family standards and PCI work this way. Say certified only about these.
- Attestation
An independent firm examined you over a period and wrote a report. There is no certificate, and the report is usually confidential.
SOC 2 is this. “SOC 2 certified” is a sentence that costs you credibility.
- Self-assessment
Your own honest evaluation against a framework, with nobody independent involved.
All anyone can do for GDPR and NIST CSF. Saying so plainly beats implying otherwise.
- Annual audit return
The yearly submission to the Commission covering the previous year’s handling of personal data, signed by a licensed DPCO where required.
Due each March. The tier you fall into decides whether an audit is required at all.
- GAID 2025
The General Application and Implementation Directive, which sets the thresholds, tiers and filing mechanics the Act leaves open.
It is what decides your tier, your fee and whether you must file at all.
The one who decides
Your supplier
The person
The named human
Licensed firm
Anything that identifies
The narrow list
Still personal data
No longer personal data
Freely given, specific, informed
Your interest, balanced
Necessary to deliver
The RoPA
How long, and why
Without undue delay
The breach clock
Data leaving Nigeria
The country is approved
The usual fallback
A body issued it
A firm reported
You checked yourself
The filing
The directive
Six pairs that get swapped
Most compliance failures are a word used loosely
Not fraud, not negligence — a term borrowed from the neighbouring idea because it sounded close enough. These are the six that cost the most, and the difference in each case is a single sentence.
Often said
SOC 2 certified
A phrase with no referent — there is no SOC 2 certificate and no body that issues one.
Actually means
SOC 2 attested
A CPA firm reported on a period. The report is confidential and its window closes twelve months from its date.
A buyer’s counsel spots this in about four seconds, and everything else on the page gets read more sceptically afterwards.
Often said
Anonymised
Used for data with the names removed but the account references still in place.
Actually means
Pseudonymised
Reversible with a key you hold, which means it never left the Act’s scope at all.
Companies delete an access request on the grounds that the data is anonymous, when it is still perfectly linkable — and that is a refusal of a right, not a technicality.
Often said
We have consent
Usually means a tick box in a sign-up flow that also accepted the terms.
Actually means
Consent for that purpose
Specific to each purpose, recorded against the notice version they actually saw.
Bundled consent collapses the moment somebody asks which purpose they agreed to. Then every downstream use of that data is unlawful, not just the marketing.
Often said
Our processor
Applied to any supplier that touches customer data.
Actually means
A joint controller
A supplier that decides a purpose of its own is a controller too, and answers directly.
Treating a controller as a processor puts liability in the wrong place — and the contract you signed will not move it back.
Often said
We told them
The information exists somewhere in a policy the person never opened.
Actually means
They were informed
Told in a form a reasonable person would encounter and understand, at the time it mattered.
Three thousand one hundred agents being monitored under a paragraph nobody read is the difference between a notice and a disclosure.
Often said
Deleted
Removed from the live system, still sitting in backups and in a supplier’s copy.
Actually means
Erased
Gone from every system that holds it, including processors, with the outcome recorded.
An erasure you cannot evidence across your suppliers is an erasure you did not perform — and the person is entitled to ask you to prove it.
Ask Eri in the words you would use with a colleague
You should not have to know the vocabulary to ask the question. Type “can we email people who never signed up” and the answer comes back with the section it rests on, not the other way round.