Business 6 minutes read

Nigeria Data Protection Act Compliance Checklist for SMEs

A practical, risk-based checklist to help Nigerian SMEs understand the personal data they hold and build stronger privacy governance, security and response processes.

The Nigeria Data Protection Act 2023 applies across sectors and establishes rules for processing personal data, protecting data-subject rights and holding controllers and processors accountable. For a small business, compliance begins with a practical question: what personal data do we collect, why do we need it, who can access it and what could happen to the people concerned if it is misused or exposed?

This Nigeria Data Protection Act compliance checklist is an operational starting point, not legal advice. Exact registration, audit, filing, data-protection-officer and notification duties depend on the organisation’s activities, scale, risk and current guidance from the Nigeria Data Protection Commission (NDPC). Confirm material decisions with the NDPC, a licensed Data Protection Compliance Organisation or qualified legal adviser.

1. Identify your role and data activities

A data controller decides why and how personal data is processed. A processor handles personal data on a controller’s behalf. A business may be a controller for employee and customer data while also processing data for a client.

List each activity that uses information about an identifiable person: recruitment, payroll, visitor records, customer enquiries, sales, delivery, email marketing, CCTV, training registration, website analytics, payment support and vendor contacts.

Personal data lifecycle from collection purpose to secure deletion
Privacy control should follow personal data throughout its lifecycle.

2. Create a personal-data inventory

For each activity, record:

  • the people involved, such as customers, staff, applicants or visitors;
  • the data fields collected and whether any are sensitive;
  • the business purpose and applicable lawful basis;
  • where the data comes from and where it is stored;
  • employees, vendors or partners who receive it;
  • countries from which it may be accessed;
  • retention period and secure disposal method; and
  • security and privacy risks.

Do not write “all customer data.” Name the actual fields and systems. A clear inventory makes privacy notices, access control, retention and incident response possible.

3. Collect only what the purpose requires

Review every field on forms, spreadsheets and applications. If the business cannot explain why a field is necessary, stop collecting it. Do not reuse information for a new incompatible purpose simply because it is available.

Where consent is the appropriate basis, it should be informed, specific and demonstrable, with a workable way to withdraw it. Do not make unnecessary marketing consent a hidden condition of receiving a different service.

4. Write clear privacy information

At or before collection, explain the organisation’s identity, purpose, relevant basis, recipients, retention approach, rights, contact channel and other information required for the situation. Use short, readable notices near the form and link to fuller detail where appropriate.

Make sure the published notice matches reality. A borrowed privacy policy that names tools or practices the business does not use creates risk rather than compliance.

Six-part privacy compliance checklist for Nigerian SMEs
A practical privacy programme connects data, notices, rights, vendors, security and governance.

5. Build a data-subject rights process

Staff need a route for recognising and escalating requests involving access, correction, objection, restriction, portability or deletion where applicable. Record the request, verify identity proportionately, search relevant systems, review exceptions, respond securely and retain evidence of the decision.

Do not ask for more identity information than the request requires. Train customer-facing staff so a valid request is not lost inside a general inbox.

6. Control employee and administrator access

  • Give each user a named account and only the access their role requires.
  • Use strong multifactor authentication for email, cloud and administrative access.
  • Review permissions regularly and remove access immediately when roles change or employment ends.
  • Encrypt devices and sensitive transfers where appropriate.
  • Keep supported software updated and test backups.
  • Avoid sharing personal data through informal channels without approved protection.

Security must match the likely harm. Payroll records, identification documents, financial information, health information and children’s data demand especially careful treatment.

7. Manage vendors and processors

Before giving a payroll provider, cloud platform, marketing vendor, consultant or IT support company access to personal data, assess what it will handle, where, for how long and with what safeguards. Use a written contract that defines instructions, confidentiality, security, sub-processors, incident reporting, assistance with rights, return or deletion and audit evidence.

Keep a current vendor register. Turning off an application does not guarantee that the provider deleted exported files or backups.

8. Set retention and disposal rules

“Keep forever” is not a retention policy. Define a period or decision rule for each record category based on purpose, legal needs and risk. Include paper, shared drives, email attachments, messaging downloads, backups and archived systems.

At the end of the period, delete, destroy or anonymise the information securely. Pause disposal when a legitimate investigation or legal hold applies, and document the decision.

Personal data breach response stages from detection to improvement
Prepare the response before an incident so containment and decisions are not improvised.

9. Prepare for personal-data breaches

A breach may involve loss, unauthorised access, accidental disclosure, alteration or unavailability. Create a response path with named owners, internal reporting, containment, evidence preservation, risk assessment, recovery, communication and review.

Notification requirements and timing depend on the facts and applicable law. Escalate early so qualified decision-makers can assess likely harm and confirm any duty to notify the NDPC or affected people.

10. Confirm governance and filing obligations

Assign a responsible senior owner, train employees, keep a risk and incident register, review new high-risk projects before launch and conduct periodic compliance reviews. Check current NDPC classifications and guidance to determine whether the organisation is a data controller or processor of major importance and what registration or Compliance Audit Return obligations apply.

When outside expertise is required, use the NDPC’s register of licensed DPCOs. Do not rely on an unverified provider’s compliance badge.

A 30-day privacy action plan

  1. Week 1: appoint an owner and inventory the highest-risk customer and employee data.
  2. Week 2: correct excessive access, enable MFA and review the public privacy notice.
  3. Week 3: document rights requests, retention and breach escalation.
  4. Week 4: review critical vendors, confirm NDPC obligations and schedule the next risk-based audit.

Privacy works best when it is designed into business processes and staff training. G-Consulting supports organisational improvement, digital operations and capacity development. Explore our capabilities, see training options or start a conversation.

Frequently asked questions

Does the NDP Act apply only to large companies?

No. The Act regulates personal-data processing broadly, although specific registration, audit and filing duties can vary by classification, scale and risk.

Is a privacy policy enough for compliance?

No. A notice is one control. The business also needs lawful and limited processing, rights handling, vendor control, security, retention, incident response and accountable governance.

Do SMEs need a DPO or DPCO?

The answer depends on current legal and regulatory requirements and the organisation’s processing. Check NDPC guidance and obtain qualified advice for your situation.

What should happen first after a suspected breach?

Report it internally, contain further exposure safely, preserve evidence and begin a documented risk assessment. Do not delay escalation while trying to prove every detail.

Research sources

Start conversation