NDPA modules · Incidents
The seventy-two hours started while everyone was still asking whether it counted.
Discovery starts the clock, not confirmation. INC-2026-0007 was found at 08:14 on 21 July, contained by lunchtime, and debated for three days. The window closed on the 24th. It is still not notified.
Past the deadline by
48h
2,140 people affected. The NDPC has not been told, and neither have they.
INC-2026-0007 · contained, unreported
The hours as they happened
Nobody decided to miss it. It was missed by committee
Every hour below has a name attached, because that is what the NDPC will ask for. Asiri writes this timeline as it happens rather than reconstructing it afterwards from memory and Slack.
And it counts from 08:14 — the moment a person noticed something wrong — not from the moment somebody agreed it was reportable.
21 Jul · 08:14 · hour 0
An operations analyst notices the export went out twice
This is the moment the clock starts. Not the escalation, not the confirmation — the noticing.
21 Jul · 09:40 · hour 1.5
The scheduled export is disabled
Contained fast, which is the part that went well and the part that made everyone relax.
21 Jul · 14:20 · hour 6
Scope established: 2,140 customers, one merchant
Names, phone numbers and last-four card digits. Enough to matter, not enough to feel like a catastrophe.
22 Jul · hour 30
Legal asks whether last-four digits count as personal data
They do, alongside a name and a phone number. Three days of discussion started here.
24 Jul · 08:14 · hour 72
The NDPC window closes with nothing filed
No decision was taken to miss it. The question of whether it was reportable was still open.
Now · hour 120
Still unreported, and the customers still do not know
A late notification is materially better than none. Asiri’s advice is to file today and say plainly that it is late.
Five incidents this year
Two of these never needed reporting, and the register says so
A tool that treats every event as a breach teaches people to stop logging events. The bucket misconfiguration with no access found and the phishing email that landed nowhere are recorded, assessed, and closed — with the reasoning kept.
| Incident | What was exposed | Clock |
|---|---|---|
| A customer export went to the wrong merchantINC-2026-0007 · high · contained · Tunde A. | Names, phone numbers, last-four card digits · 2,140 people | 48h overdue |
| Staff laptop stolen in IkejaINC-2026-0008 · medium · open · Ngozi E. | 40 merchant contacts on an encrypted disk | 31h left |
| Support agent pasted BVNs into a chat toolINC-2026-0006 · medium · notified · Segun O. | 18 BVNs and full names | Notified in 41 min |
| Misconfigured storage bucket, no access foundINC-2026-0005 · low · closed · Segun O. | Nothing confirmed accessed | Not reportable |
| Phishing email to the finance teamINC-2026-0004 · low · closed · Ngozi E. | No data left the company | Not reportable |
Two clocks, not one
Telling the regulator is not telling the people
The NDPC gets seventy-two hours. The people affected get “without undue delay”, which in practice means sooner, and which is the obligation companies forget because it is the one with no number attached.
For INC-2026-0007 both are overdue. Asiri runs them as separate clocks so satisfying one cannot look like satisfying both.
Is it a personal data breach at all
Loss, alteration, unauthorised disclosure or access — accidental counts. A bucket left open with no access found is an incident, and the assessment is the evidence.
Is there a risk to the people in it
If yes, the NDPC is told within seventy-two hours. Asiri drafts the notification from the incident record so the filing is not a separate writing exercise.
Is the risk high
Then the people themselves are told too, without undue delay, in language they can act on. Last-four digits with a name and number clears this bar.
What you knew at each hour
The regulator’s question is rarely “what happened”. It is “when did you know, and what did you do next” — which only a contemporaneous timeline answers.
The clock runs whether or not anybody is watching it
Asiri starts it on discovery, counts in real time, and escalates by name at 24, 48 and 60 hours — so missing the window has to be a decision rather than an accident.