Skip to content
ASIRI

Resources · NDPA glossary

Twenty-four words that decide whether you are compliant.

The Act is not hard because the ideas are hard. It is hard because it is written for lawyers. Here is each term as the Act puts it, and then as somebody would actually say it — because a rule you cannot restate is a rule you cannot follow.

NDPA 2023 · Section 65

Data controller

“…a person who, either alone or jointly with others, determines the purposes for and the manner in which personal data is processed or is to be processed.”

You decided why the data was collected. So you answer for it.

Deciding the purpose is what makes you a controller — not holding the data

The whole vocabulary

Every term, and what it obliges you to do

A definition that does not tell you what changes on Monday morning is trivia. Each one here ends with the thing you actually have to do.

Who is who
Data controller

The one who decides

The company that decides why personal data is collected and what happens to it. Deciding is the test — you can be a controller over data sitting entirely in someone else’s system.

You are the one the Commission writes to, and the one who files the annual return.

Who is who
Data processor

Your supplier

A company that handles personal data on your instructions and for your purposes. The moment it decides a purpose of its own, it stops being one.

Every processor needs written terms before it receives a single record.

Who is who
Data subject

The person

The living individual the data is about. Not a customer, not a user — a person, including your own staff and your agents.

They can ask you what you hold, and you must answer without undue delay. The Act sets no number of days.

Who is who
Data protection officer

The named human

The person accountable for data protection, named to the Commission and reachable by anyone who asks.

Their name and address go on your public notice. A form that goes nowhere fails this.

Who is who
DPCO

Licensed firm

A Data Protection Compliance Organisation licensed by the Commission to audit and file on behalf of controllers.

Only a licensed DPCO can sign the audit return that goes to the Commission.

The data
Personal data

Anything that identifies

Any information relating to an identifiable person. A phone number on its own qualifies; so does a device identifier that resolves to one.

If you can single somebody out with it, it is in scope — including your logs.

The data
Sensitive personal data

The narrow list

Health, genetic and biometric data, race, religion, political opinion, trade union membership and sex life. A short list, deliberately.

Consent for these must be explicit, and legitimate interest is not available at all.

The data
Pseudonymised

Still personal data

Identifiers swapped for a key you still hold. Reversible by design, which is the point and the problem.

It reduces risk, it does not take the data out of scope. It is still yours to answer for.

The data
Anonymised

No longer personal data

Irreversibly stripped, with no key anywhere and no realistic route back to a person.

Genuinely anonymised data leaves the Act entirely. Almost nothing companies call anonymised is.

Grounds
Consent

Freely given, specific, informed

A clear affirmative act. Silence, pre-ticked boxes and bundled terms are not consent, and it must be as easy to withdraw as to give.

Record what they saw, when, and which version of the notice — or you cannot prove it later.

Grounds
Legitimate interest

Your interest, balanced

Processing you need for a real business reason, where that reason does not override the person’s rights. It requires a written balancing test.

The person can object, and if you cannot show the test you lose the argument.

Grounds
Contract

Necessary to deliver

Processing genuinely necessary to give somebody what they asked for. Necessary means the service fails without it.

Marketing is not necessary to deliver a loan. That is a separate purpose and a separate basis.

Duties
Record of processing activities

The RoPA

A written register of what you do with personal data, why, who receives it, and how long you keep it.

The Commission asks for this first. Not having one is the finding that opens every other one.

Duties
Retention schedule

How long, and why

A stated period for each category of data, tied to the reason you hold it rather than to convenience.

“As long as necessary” is not a schedule. Seven years after account closure is.

Duties
Data subject request

Without undue delay

A person asking to see, correct, delete, port or object to what you hold. The wait starts when the request arrives, not when you recognise it.

There is no deadline to work back from. §38(3)(b) reserves timing to the Commission and it has prescribed none, so a schedule is not a defence and answering quickly is not automatically answering in time.

Duties
Seventy-two hours

The breach clock

The window to tell the Commission about a notifiable breach, counted from when you became aware, not from when you finished investigating.

A supplier discovering it counts as you becoming aware. Say so in their contract, in hours.

Abroad
Cross-border transfer

Data leaving Nigeria

Personal data going to a recipient outside Nigeria — including a cloud region, a support desk, or an analytics tool.

Each one needs a named mechanism on file before the first record moves.

Abroad
Adequacy

The country is approved

The Commission has decided a country protects data adequately, so transfers there need nothing further.

Check the list rather than assume. Most destinations companies use are not on it.

Abroad
Standard contractual clauses

The usual fallback

Pre-approved contract terms that carry the protection with the data when there is no adequacy decision.

They must be signed before the transfer starts, not backfilled when someone asks.

Assurance
Certification

A body issued it

An accredited registrar examined you and issued a certificate with a number, a scope and an expiry — and can withdraw it.

Only ISO-family standards and PCI work this way. Say certified only about these.

Assurance
Attestation

A firm reported

An independent firm examined you over a period and wrote a report. There is no certificate, and the report is usually confidential.

SOC 2 is this. “SOC 2 certified” is a sentence that costs you credibility.

Assurance
Self-assessment

You checked yourself

Your own honest evaluation against a framework, with nobody independent involved.

All anyone can do for GDPR and NIST CSF. Saying so plainly beats implying otherwise.

Assurance
Annual audit return

The filing

The yearly submission to the Commission covering the previous year’s handling of personal data, signed by a licensed DPCO where required.

Due each March. The tier you fall into decides whether an audit is required at all.

Assurance
GAID 2025

The directive

The General Application and Implementation Directive, which sets the thresholds, tiers and filing mechanics the Act leaves open.

It is what decides your tier, your fee and whether you must file at all.

Six pairs that get swapped

Most compliance failures are a word used loosely

Not fraud, not negligence — a term borrowed from the neighbouring idea because it sounded close enough. These are the six that cost the most, and the difference in each case is a single sentence.

Often said

SOC 2 certified

A phrase with no referent — there is no SOC 2 certificate and no body that issues one.

Actually means

SOC 2 attested

A CPA firm reported on a period. The report is confidential and its window closes twelve months from its date.

A buyer’s counsel spots this in about four seconds, and everything else on the page gets read more sceptically afterwards.

Often said

Anonymised

Used for data with the names removed but the account references still in place.

Actually means

Pseudonymised

Reversible with a key you hold, which means it never left the Act’s scope at all.

Companies delete an access request on the grounds that the data is anonymous, when it is still perfectly linkable — and that is a refusal of a right, not a technicality.

Often said

We have consent

Usually means a tick box in a sign-up flow that also accepted the terms.

Actually means

Consent for that purpose

Specific to each purpose, recorded against the notice version they actually saw.

Bundled consent collapses the moment somebody asks which purpose they agreed to. Then every downstream use of that data is unlawful, not just the marketing.

Often said

Our processor

Applied to any supplier that touches customer data.

Actually means

A joint controller

A supplier that decides a purpose of its own is a controller too, and answers directly.

Treating a controller as a processor puts liability in the wrong place — and the contract you signed will not move it back.

Often said

We told them

The information exists somewhere in a policy the person never opened.

Actually means

They were informed

Told in a form a reasonable person would encounter and understand, at the time it mattered.

Three thousand one hundred agents being monitored under a paragraph nobody read is the difference between a notice and a disclosure.

Often said

Deleted

Removed from the live system, still sitting in backups and in a supplier’s copy.

Actually means

Erased

Gone from every system that holds it, including processors, with the outcome recorded.

An erasure you cannot evidence across your suppliers is an erasure you did not perform — and the person is entitled to ask you to prove it.

Ask Eri in the words you would use with a colleague

You should not have to know the vocabulary to ask the question. Type “can we email people who never signed up” and the answer comes back with the section it rests on, not the other way round.