Back to Resources & Guides
Data Privacy

NDPA Basics: What Every Startup Needs to Know

Under the Nigeria Data Protection Act (NDPA) 2023, data protection is an immediate legal obligation from the moment you collect personal data even for pre-revenue and seed-stage startups.

Published July 30, 2026


If you collect a customer's name, email address, or phone number, the NDPA already applies to you. It doesn't matter if you're pre-revenue, pre-launch, or running your entire operation out of WhatsApp. Most founders treat data protection as a "later" problem, something to worry about once they scale or attract regulatory scrutiny. That assumption is exactly what catches early-stage teams off guard, usually at the worst possible moment: in the middle of investor due diligence.

This is the complete breakdown: what the NDPA actually is, what counts as personal data, your real obligations, what the GAID adds on top, and a practical baseline checklist for where you are right now.

What the NDPA actually is

The Nigeria Data Protection Act (NDPA) 2023 is the primary statutory framework regulating how businesses collect, store, process, and share personal information in Nigeria. It replaced the older NDPR 2019 as the governing law, and established the Nigeria Data Protection Commission (NDPC) as the regulator responsible for enforcement. It applies to any individual or corporate entity processing the personal data of people in Nigeria, regardless of team size, legal structure, or annual turnover.

What counts as personal data?

"Personal data" is broader than most founders assume. It covers:

  • Names, email addresses, and phone numbers

  • Bank verification numbers (BVN), payment records, and transaction histories

  • Location data, physical addresses, and device or IP identifiers

  • Biometric information

  • Any identifier that can distinguish a specific person, directly or indirectly

If your landing page form, waitlist, WhatsApp intake, or CRM stores any of this, your business is a Data Controller or Data Processor under the Act with binding obligations attached.

Your core obligations under the NDPA

You need a lawful basis for processing data: You can't collect personal data arbitrarily. Common lawful grounds include consent, necessity to perform a contract, legal obligation, or legitimate business interest that doesn't override the individual's rights.

You should only collect what you actually need: This is the principle of data minimisation. If your signup only needs an email, asking for more without justification creates unnecessary compliance exposure.

You must protect the data you hold: Reasonable security measures, encryption, access controls, secure authentication are expected.

You must respect data subject rights: People can request access to their data, ask you to correct it, request deletion, object to processing, or withdraw consent. You need a way to actually respond to these requests.

You must be ready to respond to breaches: If a breach is likely to pose a risk to affected individuals, you're required to notify the NDPC - within 72 hours of becoming aware of it - and inform affected users where the risk is high.

Cross-border data transfers: If you use cloud infrastructure, payment processors, or analytics tools hosted outside Nigeria, you're likely transferring personal data across borders.

The NDPA permits this, but only where the receiving country has adequate protections or contractual safeguards are in place.

What the GAID adds to the NDPA

In 2025, the NDPC issued the General Application and Implementation Directive (GAID), which spells out more specific compliance obligations.

Key additions that matter even at early stage:

  • DPO designation: Organisations are required to designate a Data Protection Officer (or equivalent contact), publish their details, and notify the NDPC.

  • Privacy policy and cookie notice standards: Your privacy policy needs to be specific to your actual practices and cookie notices need to be genuinely visible, not buried at the bottom of the page.

  • Data retention limits. Where no other legal timeline applies, personal data generally shouldn't be retained longer than six months after its original purpose is fulfilled.

  • Registration as a Data Controller/Processor of Major Importance (DCPMI): This applies once you cross certain thresholds, larger or higher-risk processors face annual Compliance Audit Report filing requirements.

Why this matters earlier than founders think

Due diligence readiness: Investors, accelerators, and enterprise partners increasingly audit privacy practices before signing term sheets. Missing basics doesn't just look bad, it slows down a raise at the exact moment speed matters most.

Real regulatory enforcement: The NDPC actively investigates complaints. For Data Controllers of Major Importance, statutory fines can reach up to ₦10,000,000 or 2% of annual gross revenue, whichever is greater.

Trust : A clear privacy notice and genuine opt-in practices build credibility from day one, not just protection from penalties.

The early-stage compliance package

You don't need an enterprise data governance program on day one. At early stage, this is the floor:

  1. A real privacy policy : scoped to your actual data practices, not a copy-pasted template

  2. Clear, explicit consent : at every intake point  sign-up forms, WhatsApp onboarding, contact forms

  3. A basic data map : knowing which tools hold customer data (e.g. your CRM, email platform, hosting), who has access, and whether vendors have signed data processing agreements

  4. A simple breach response plan : what you'd actually do, and who you'd notify, within the 72-hour window

Common challenges startups run into

  • Limited awareness that these obligations exist pre-revenue

  • Fast product cycles that skip privacy considerations entirely

  • Third-party tools and vendors used without any data processing agreement

  • No internal owner responsible for data governance

Frequently Asked Questions

1. Does NDPA apply to my startup if I'm pre-revenue? Yes. The Act applies based on whether you process personal data, not based on revenue or company size.

2. What counts as personal data under the NDPA? Any information that can identify a specific person - names, emails, phone numbers, BVNs, IP addresses, location data, and biometric data all qualify.

3. Do I need a Data Protection Officer as an early-stage startup? The GAID requires DPO designation for organisations processing personal data, the scale of the role depends on your size and risk level. 

4. What happens if I don't comply? Regulatory investigation, statutory fines, and a due diligence red flag that can slow down or complicate fundraising.

5. How long can I keep customer data? Generally no longer than six months after the original purpose is fulfilled, unless another legal basis applies.

6. Do I need a lawyer to become compliant? Not necessarily at an early stage. Basic compliance, privacy policy, consent flows, a data map, and a breach plan  is achievable without a full legal engagement. More complex situations (cross-border transfers, DCPMI registration) may need specialist input  like a DPO (Data Protection Officer).

7. What's the difference between the NDPA and the GAID? The NDPA is the law. The GAID is the NDPC's directive spelling out how to actually implement compliance under that law .

8. Is a generic privacy policy template enough? No. It needs to reflect your actual data collection and processing practices, not generic language copied from elsewhere.

Get your baseline in place

We've put together a simple compliance checklist you can work through this week - privacy policy, consent flows, data mapping, and breach response, mapped to what actually applies at your stage. Access the Checklist

Conclusion

The cost of waiting isn't hypothetical. Founders build fast, integrate third-party tools, and defer governance until a partner or investor asks for a compliance answer they don't have. Fixing this mid-transaction is far more expensive and disruptive than putting the basics in place at launch.


Want to check where your startup actually stands? Message us on WhatsApp using the button on this page, send a quick overview of what you collect and the tools you use, and we'll outline your baseline requirements.

Share this guide:

Discussion & Founder Questions

No comments yet. Be the first to start the discussion!

Read Next: Other Founder Guides

View all