The dual-reporting mandate
Nigerian fintechs can have duties under the NDPA, CBN rules tied to their licence, contracts, card-scheme rules, and partner agreements. Create one reporting matrix with the event type, deadline, recipient, owner, approval path, and secure channel.
Confirm the CBN rule for your licence
Use the current CBN framework and circulars that cover your licence. Record the deadline, recipient, format, and escalation owner in the incident plan.
The 72-Hour NDPC Window
NDPA Section 40 requires notice within 72 hours of awareness when the breach is likely to risk people's rights and freedoms. Record when the company became aware and why the risk test was met.
Data Subject Notification
When the breach is likely to create a high risk, tell affected people immediately in plain language. State the data involved, likely harm, work completed, and steps they can take.
What to include in your notification
Regulators do not expect a complete forensic report within 72 hours, but they do expect a structured preliminary notification. Your submission should include:
- Nature of the breach: How the breach occurred (e.g., unauthorized API access, compromised employee credentials).
- Scope of exposure: The categories and approximate number of individuals affected, and the type of data compromised (e.g., 10,000 users; names, email addresses, and encrypted passwords).
- Immediate mitigation: Steps your engineering team has already taken to contain the breach (e.g., isolating servers, rotating API keys, forcing password resets).
- Point of contact: The name and contact details of your Data Protection Officer (DPO) or Chief Information Security Officer (CISO).
Recovering from a security incident? You need a post-breach assessment to ensure the vulnerability is closed.
Request Incident Response SupportCustomer communication best practices
Drafting the customer notification email requires tight coordination between engineering, legal, and communications. The NDPA requires this notice to be clear and in plain language.
Do not use vague euphemisms like "we experienced a data security incident." State clearly what happened, what specific data of theirs was involved, what you are doing to protect them (e.g., invalidating sessions), and what steps they need to take immediately (e.g., enabling MFA, changing passwords across other sites).
The role of the post-breach pentest
After containment and notification, test the exact attack path and nearby controls. A post-breach penetration test can record the failed control, fix, retest result, remaining risk, and scope limit. Give regulators and partners the evidence they request through an approved channel.
The cost of concealment
Globally and locally, regulators are aggressively penalizing companies not just for getting breached, but for failing to report the breach promptly. Engaging external legal counsel specializing in Nigerian data protection law within the first hour of a suspected breach is crucial to navigating the reporting liability.
Related reading
Guides: After a Breach (Incident Response) · NDPR/NDPA Compliance
Blog: NDPR Privacy Checklist
Frequently asked questions
How long do we have to report a breach to the CBN?
Use the reporting timeline and channel that apply to your licence and the current CBN framework or circular. Put that exact rule in the incident plan and confirm it with compliance before an incident.
What is the notification timeline for the NDPC?
The Nigeria Data Protection Act (NDPA) requires data controllers to notify the NDPC within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of individuals.
Do we have to tell our customers?
A controller must immediately tell affected people when the breach is likely to create a high risk to their rights and freedoms. The message must use plain language and give steps that reduce harm.