The dual-reporting mandate

Nigerian fintechs can have duties under the NDPA, CBN rules tied to their licence, contracts, card-scheme rules, and partner agreements. Create one reporting matrix with the event type, deadline, recipient, owner, approval path, and secure channel.

01

Confirm the CBN rule for your licence

Use the current CBN framework and circulars that cover your licence. Record the deadline, recipient, format, and escalation owner in the incident plan.

02

The 72-Hour NDPC Window

NDPA Section 40 requires notice within 72 hours of awareness when the breach is likely to risk people's rights and freedoms. Record when the company became aware and why the risk test was met.

03

Data Subject Notification

When the breach is likely to create a high risk, tell affected people immediately in plain language. State the data involved, likely harm, work completed, and steps they can take.

What to include in your notification

Regulators do not expect a complete forensic report within 72 hours, but they do expect a structured preliminary notification. Your submission should include:

Recovering from a security incident? You need a post-breach assessment to ensure the vulnerability is closed.

Request Incident Response Support

Customer communication best practices

Drafting the customer notification email requires tight coordination between engineering, legal, and communications. The NDPA requires this notice to be clear and in plain language.

Do not use vague euphemisms like "we experienced a data security incident." State clearly what happened, what specific data of theirs was involved, what you are doing to protect them (e.g., invalidating sessions), and what steps they need to take immediately (e.g., enabling MFA, changing passwords across other sites).

The role of the post-breach pentest

After containment and notification, test the exact attack path and nearby controls. A post-breach penetration test can record the failed control, fix, retest result, remaining risk, and scope limit. Give regulators and partners the evidence they request through an approved channel.

Legal Precedent

The cost of concealment

Globally and locally, regulators are aggressively penalizing companies not just for getting breached, but for failing to report the breach promptly. Engaging external legal counsel specializing in Nigerian data protection law within the first hour of a suspected breach is crucial to navigating the reporting liability.

Related reading

Guides: After a Breach (Incident Response) · NDPR/NDPA Compliance

Blog: NDPR Privacy Checklist

Frequently asked questions

How long do we have to report a breach to the CBN?

Use the reporting timeline and channel that apply to your licence and the current CBN framework or circular. Put that exact rule in the incident plan and confirm it with compliance before an incident.

What is the notification timeline for the NDPC?

The Nigeria Data Protection Act (NDPA) requires data controllers to notify the NDPC within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of individuals.

Do we have to tell our customers?

A controller must immediately tell affected people when the breach is likely to create a high risk to their rights and freedoms. The message must use plain language and give steps that reduce harm.