Skip to main content
ASIRI
Resources/Plain-English guide

NDPA 2023, translated for product teams.

Skip the legalese. Seven chapters, real examples, and the citations your DPO will recognise.

What's inside

Seven chapters every Nigerian privacy program needs.

NDPA §2–§3
01
Scope & definitions

Who the NDPA 2023 applies to, what counts as personal data, and the controller/processor split — in plain English.

NDPA §24
02
Principles of processing

The seven principles every Nigerian data controller must satisfy, with worked examples from fintech and health.

NDPA §25–§27
03
Lawful bases

When you can rely on consent vs legitimate interest, contract, vital interest, public interest, or legal obligation.

NDPA §28–§38
04
Data subject rights

Access, rectification, erasure, portability, objection — and the 30-day clock you must answer them on.

NDPA §40
05
Breach notification

When the 72-hour clock starts, what to file with the NDPC, and what to tell affected subjects.

NDPA §41–§43
06
Cross-border transfers

Adequacy decisions, SCCs, and the supplementary measures you need for non-adequate jurisdictions.

NDPA §44–§45
07
DPIAs & accountability

When a DPIA is mandatory, when prior consultation is needed, and how to evidence the rest of §44.

Use the guide

How teams ship from this PDF.

  1. 01Share with engineering — they need it more than you think.
  2. 02Map your processing activities against chapters 03 and 07 first.
  3. 03Run the chapter 04 checklist against your DSR portal today.
  4. 04Schedule a quarterly re-read; the NDPC’s guidance evolves quickly.