NDPR Data Privacy Checklist for Nigerian Fintechs

Use the current law

The NDPA 2023 created the NDPC and gives it investigation and enforcement powers. Section 48 sets maximum penalties based on the organisation's class and annual gross revenue. See the official Act, NDPC registration requirements, and our Nigeria data protection guide.

CBN requirements layer on top

The CBN mandates CSAT cybersecurity assessments covering governance, risk management, technology controls, and incident response. False or incomplete submissions constitute a regulatory breach under BOFIA 2020. KYC, CDD, and AML obligations converge with data protection. See our CBN compliance guide.

Start with data mapping

BVNs, NINs, financial transaction records, device identifiers, location data, credit history, onboarding documents, behavioural event data, and third-party SDK data can identify or relate to a person. Record the purpose and lawful basis for each processing activity. “We use it to improve the product” does not name a lawful basis.

List every collection touchpoint: onboarding forms, in-app events, API integrations, and vendor connections. Document what data is collected, where stored, who can access it, how long retained, and actual usage. Map every instance of sharing with external processors. The data map also reveals where you need to stop collecting (data minimisation).

The NDPR data privacy checklist

1. DPO appointment and NDPC registration

Under NDPA Section 32, fintechs processing data at scale must appoint a DPO. Processing more than 1,000 individuals in six months or 2,000 in twelve months triggers major data controller status. This requires mandatory NDPC registration and annual CAR submission by March 15 through a licensed DPCO. See KPMG's NDPC registration guidance.

2. Consent management

Explicit, informed consent with no pre-ticked boxes, no bundled consent with T&Cs. Your privacy policy must be publicly available on all data collection mediums and cover data types, retention periods, third-party sharing, and user rights (access, rectification, deletion, portability).

3. DPIAs for high-risk processing

Required for large-scale credit scoring, behavioral profiling, biometric verification, and real-time transaction monitoring. A completed DPIA is your primary evidence of proactive compliance. Fintechs that skip DPIAs consistently fail audits.

4. 72-hour breach notification

NDPA Section 40 requires a controller to notify the NDPC within 72 hours of awareness when a breach is likely to risk people's rights and freedoms. A high-risk breach also requires an immediate, plain-language notice to affected people. Your plan needs detection steps, escalation owners, risk checks, an NDPC notice template, and customer messages. Test the plan. See our after a breach guide.

Need a structured NDPR privacy audit for your fintech?

Get a Privacy Audit

Cross-border data transfers

Nigerian fintechs handling EU resident data cannot rely on Nigeria's domestic framework to satisfy GDPR. You need Standard Contractual Clauses or another GDPR-compliant mechanism. Fintechs using international processors (AWS, Google Cloud, Stripe) must contractually document transfer arrangements. Note: NDPR does not include "legitimate interests" as a lawful processing basis, unlike GDPR. See the EU adequacy framework.

Preparing for an NDPC audit

The NDPC audits three areas: people (DPO qualifications, training records), processes (policies, consent records, breach logs, DPIAs), and technology (encryption, access controls, data retention). The CAR requires a complete data processing inventory, security measures documentation, privacy policies, the DPO appointment letter, and NDPC registration confirmation. Fintechs using AI for credit scoring or fraud detection must also document those processing activities.

Compliance calendar

Start here

Start with the data map

Map every collection point, every processor, every retention period. Then appoint your DPO, register with the NDPC, implement consent controls, complete DPIAs, and test your breach response plan. If you're not sure where your gaps are, a structured privacy audit is the fastest way to find them.

Related reading

Blog: Nigeria data protection guide · Security audit before launch · Top Nigerian vulnerabilities

Guides: NDPR/NDPA compliance · CBN compliance · After a breach

Services: Penetration testing · Vulnerability assessment