Our Expert in Nigeria
No results available
Understanding how to conduct a DPIA in Nigeria is now a pressing compliance priority for every organisation that processes personal data in or from the country. A Data Protection Impact Assessment (DPIA) is the structured process by which a data controller identifies, evaluates and mitigates privacy risks before commencing high-risk processing activities. Since the Nigeria Data Protection Commission (NDPC) General Administrative Implementation Directive (GAID) took effect on 19 September 2025, DPIAs have moved from best-practice recommendation to enforceable regulatory expectation, and 2026 audit activity by the NDPC is reinforcing that shift.
A data protection impact assessment in Nigeria is a systematic evaluation required under the Nigeria Data Protection Act 2023 (NDPA) and operationalised by the GAID. Its purpose is to identify the likely impact of proposed data processing on the rights and freedoms of data subjects, and to document the measures adopted to reduce that impact to an acceptable level.
The obligation falls primarily on data controllers, the entities that determine the purposes and means of processing personal data. However, the GAID also extends practical responsibility to data processors acting on delegated tasks, particularly where a processor designs or implements a processing system on behalf of the controller. Public-sector bodies, financial institutions, healthcare organisations, telecommunications companies and technology firms deploying AI, biometric identification or large-scale profiling are among the entities most frequently required to complete a DPIA in Nigeria.
Under Article 28 of the GAID, the NDPC may require a controller to conduct and file a DPIA with the Commission in specified circumstances. The DPIA must follow the format set out in Schedule 4 of the GAID, which prescribes content headings, risk-scoring expectations and sign-off requirements. Failure to produce a compliant DPIA when requested during an NDPC audit can expose the controller to enforcement action, including an order to cease processing until the assessment is completed.
Not every processing activity requires a full DPIA. The legal threshold under the NDPA and the GAID is whether the processing is likely to result in a high risk to the rights and freedoms of data subjects. The GAID identifies several categories of processing that will ordinarily meet this threshold:
Before initiating the DPIA steps, the organisation should confirm that the following prerequisites are in place: a designated Data Protection Officer (DPO) or DPIA lead; access to the project’s technical and business stakeholders; senior management awareness and commitment to sign-off; and a current data inventory or processing register from which to draw baseline information.
The following seven-step procedure aligns with the NDPA DPIA requirements, the GAID Schedule 4 format, and internationally recognised methodology drawn from the EU GDPR Article 35 framework and ICO DPIA guidance. Each step produces a defined deliverable that forms part of the final, NDPC-ready DPIA report.
Begin with a DPIA screening checklist. The DPIA lead, typically the DPO or a senior compliance officer, applies the high-risk criteria from the GAID to the proposed processing activity. If any trigger is met, proceed to a full assessment. If no trigger is met, record the screening outcome and the reasons for concluding that a DPIA is not required. This screening record must be retained, as NDPC auditors may ask to see it.
Deliverable: Signed DPIA screening form and decision log.
Appoint the DPO or a nominated project lead to manage the assessment. The DPIA team should include representatives from information security, legal or compliance, the business unit sponsoring the project, and any external vendors whose systems will process personal data. Assign clear roles, who drafts the processing description, who identifies risks, who designs mitigations, and record these in a team roster.
Deliverable: DPIA team roster and roles matrix.
This is the foundational step. Document every processing activity within the project’s scope, including the categories of personal data collected, the categories of data subjects, the purposes of processing, the retention periods, and any intended transfers to third parties or across borders. For each processing activity, identify the lawful basis relied upon under the NDPA, whether consent, contractual necessity, legal obligation, vital interest, public interest, or legitimate interest.
Deliverable: Processing description table aligned with GAID Schedule 4 headings.
Convene a risk workshop with the DPIA team. For each processing activity, identify threats (unauthorised access, data loss, re-identification, function creep), vulnerabilities (weak encryption, inadequate access controls, poorly drafted processor contracts), and harm scenarios (financial loss, discrimination, reputational damage, physical harm to data subjects). Score each risk using a likelihood-times-severity matrix to produce a residual risk rating. Record all identified risks in a risk register.
Deliverable: Risk register with scored risks and heatmap visualisation.
For every risk rated medium or high, design a mitigation measure. Mitigations should be a blend of technical controls (encryption at rest and in transit, pseudonymisation, automated deletion), organisational controls (access-control policies, staff training, incident-response plans), and contractual safeguards (processor agreements with audit rights, data-breach notification clauses, sub-processor approval mechanisms). Each mitigation must have a named owner and an implementation deadline.
Deliverable: Mitigation plan with owners, deadlines and revised risk scores.
Circulate the draft DPIA report to internal stakeholders, including senior management, the legal team and the information-security function, for review. Where the GAID or the NDPA requires external consultation (for example, where residual risk remains high despite mitigations), engage the NDPC or seek independent expert advice. Vendor assessments should be completed at this stage if third-party processors are involved. Record all consultation responses and update the risk register accordingly.
Deliverable: Consultation log and updated risk register.
Present the final DPIA report to senior management for formal sign-off. The sign-off page should include the signatory’s name, title and date. Under Article 28 of the GAID, DPIAs must be filed with the NDPC in certain mandatory circumstances, the DPIA shall be prepared in accordance with Schedule 4 of the GAID and submitted via the NDPC’s designated channel. Even where filing is not mandatory, the completed DPIA must be retained and produced on request during an NDPC audit. Schedule a periodic review, industry observers recommend every 6 to 12 months, or sooner if the processing activity changes materially.
Deliverable: Signed DPIA report, NDPC filing confirmation (if applicable), and monitoring schedule.
An NDPC-ready DPIA is only as strong as its supporting evidence. Auditors expect a self-contained compliance pack that demonstrates each stage of the assessment was completed with rigour. The following table sets out the documents that should accompany every completed DPIA in Nigeria.
| Document | Notes |
|---|---|
| DPIA screening form | Completed by the DPIA lead; signed and dated; stored as PDF in the compliance folder |
| Full DPIA report | Narrative covering all seven steps, plus embedded risk register, mitigation plan and sign-off pages; PDF with version history |
| Processing map | Diagram or table showing data flows between internal systems, processors and sub-processors; exported as PDF or PNG |
| Data inventory | List of systems, data categories and retention schedules; exported CSV with a signed declaration of completeness |
| Vendor / processor contracts | Current contracts containing data-processing clauses, security annexes and sub-processor approval terms; PDF, signed and dated |
| Security assessment evidence | Penetration-test reports, vulnerability scan outputs and encryption configuration records; dated and signed by the assessor |
| Consent or lawful-basis documentation | Sample consent forms, records of lawful-basis assessments and any legitimate-interest balancing tests; PDF or log format |
| Consultation evidence | Minutes, stakeholder emails, NDPC correspondence and external expert reports; dated transcripts |
| Senior management sign-off | Executive approval page with signatory name, title and date; PDF with wet or electronic signature |
| Monitoring plan and review log | Review schedule and subsequent review entries; living document maintained as PDF with change log |
Maintain the full pack in a single compliance archive. If the NDPC requests evidence during an audit, the organisation should be able to produce the entire set within the timeframe specified in the audit notice.
The elapsed time for a DPIA depends on the complexity of the processing activity. The table below provides realistic durations for a medium-complexity project, such as launching a digital lending platform or deploying a customer-profiling system.
| Step | Who does it | Typical duration |
|---|---|---|
| DPIA screening and decision | Project lead + DPO | 1–3 business days |
| Team appointment and scoping | DPO / Project lead | 2–5 business days |
| Processing description and mapping | Business owner + IT + Legal | 3–10 business days |
| Risk identification and scoring | DPIA team (workshop) | 3–7 business days |
| Mitigation design and owner allocation | IT / Security + Legal | 5–14 business days |
| Consultation and residual risk check | DPO + stakeholders (+ external consult if needed) | 7–21 business days |
| Sign-off, filing and monitoring setup | Senior management + DPO | 3–7 business days |
| Total (medium-complexity project) | , | 4–8 weeks from screening to sign-off |
For straightforward processing activities with limited data categories, a DPIA can be completed in 2 to 3 weeks. Complex projects involving multiple vendors, cross-border transfers or novel technologies may require 10 to 14 weeks. Regardless of complexity, the DPIA should be reviewed at least every 6 to 12 months, or immediately when there is a material change to the processing activity, such as a new data-sharing arrangement or a technology migration.
The cost of conducting a DPIA in Nigeria varies according to whether the assessment is handled in-house or with external advisory support, and the complexity of the processing activity. The following table provides indicative market estimates.
| Item | Typical amount (NGN / USD) | Notes |
|---|---|---|
| In-house DPIA (staff time) | NGN 150,000–900,000 (≈ USD 200–1,200) | Dependent on staff rates and project complexity |
| External legal / compliance advisor (DPIA drafting) | NGN 600,000–4,500,000 (≈ USD 800–6,000) | For a lawyer-led, NDPC-ready DPIA with sign-off |
| Penetration test / security review | NGN 250,000–2,500,000 (≈ USD 350–3,300) | One-off engagement; scope-dependent |
| Vendor / processor due diligence | NGN 100,000–800,000 per vendor | Varies with vendor count and geographic complexity |
| NDPC filing fee | No published fixed filing fee as at August 2026 | Confirm current position on the NDPC portal before filing |
The cost estimates above are industry approximations and will vary by firm, sector and project scope. Organisations should confirm current NDPC fee schedules directly with the Commission before budgeting for a filing.
The GAID, which took effect on 19 September 2025, introduced the most significant operational change to the DPIA landscape in Nigeria since the NDPA was enacted in 2023. Schedule 4 of the GAID prescribes the content, format and risk-assessment methodology that a compliant DPIA must follow. Article 28 of the GAID sets out the circumstances in which a controller must conduct and file a DPIA with the NDPC, including where processing involves large-scale sensitive data, systematic monitoring, or novel technology.
Early indications suggest that the NDPC has increased its audit and compliance-monitoring activity through 2026, with a particular focus on fintech platforms, health-technology companies and public-sector digital identity systems. The NDPC’s Privacy by Design white paper reinforces the expectation that DPIAs will be treated as a core component of any privacy-by-design framework, not an afterthought. Organisations that have not yet aligned their DPIA processes with the GAID Schedule 4 format should treat this as an immediate priority.
Knowing how to conduct a DPIA in Nigeria, and executing the process to GAID and NDPA standards, is no longer optional for organisations handling personal data at scale. The seven-step procedure outlined in this guide provides a practical, NDPC-audit-ready framework: from initial screening through risk assessment, mitigation design and senior sign-off to ongoing monitoring. With the NDPC intensifying enforcement activity through 2026, the cost of delay significantly outweighs the cost of compliance. Organisations should begin with a formal screening of their current and planned processing activities and engage experienced data protection counsel where processing involves sensitive data, cross-border transfers or novel technology.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Paul Mgbeoma at Tayo Oyetibo LP, a member of the Global Law Experts network.
posted 25 minutes ago
posted 49 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 9 hours ago
posted 9 hours ago
posted 19 hours ago
No results available
Find the right Advisory Expert for your business
Sign up for the latest advisor briefings and news within Global Advisory Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Advisory Experts is dedicated to providing exceptional advisory services to clients around the world. With a vast network of highly skilled and experienced advisors, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message