Nigeria's Data Protection Regulation, first introduced in 2019 and updated in the National Data Protection Act (now referred to as NDPA in regulatory guidance), has moved from theoretical concern to practical requirement. The National Information Technology Development Agency (NITDA) now actively enforces it, particularly against fintech, healthtech, and e-commerce platforms handling personal data at scale.
For startups, the reality is straightforward: if you collect, process, or store any personal data—names, phone numbers, email addresses, transaction history, location data—you are subject to NDPA provisions. This includes informal customer lists, WhatsApp groups with client contacts, and backend databases. Ignorance of the regulation no longer protects you. The fine for non-compliance runs up to ₦50 million or 2% of annual turnover, whichever is higher, plus potential criminal prosecution for executives.
Compliance begins with documentation. Most startups cannot accurately answer: What personal data do we hold? Where is it stored? Who has access to it? How long do we keep it?
You need a data mapping exercise. Walk through each system—your CRM, payment processor, customer support database, Google Sheets with client lists, even email threads. Record:
— What data categories are collected (names, emails, phone numbers, transaction amounts, IP addresses, device identifiers) — The legal basis for processing each category (customer consent, contract performance, legal obligation) — Where data physically resides (local servers, AWS Lagos region, third-party SaaS platforms) — Data retention periods (why you keep customer records for 12 months, then delete; or why longer) — Who internally accesses this data (engineering team, customer support, finance)
This sounds administrative. It is. It is also required. During a NITDA inspection or audit, the absence of documented data flows is itself a violation. A Lagos-based logistics startup we've worked with discovered—only during this exercise—that their developer had exported 18 months of customer location data to a personal laptop for performance analysis. That's a breach waiting to be discovered.
Start with a simple spreadsheet. If you process data for payment processing, compliance, or regulatory reporting, invest in data governance tools like OneTrust or local alternatives. Most startups can begin with a structured audit.
Consent is not a checkbox. The NDPA requires clear, specific, informed consent before processing personal data. A vague app privacy policy updated three years ago does not meet this standard.
You need:
— Transparent communication before data collection. Users should understand what data you collect, why, and how you use it. Burying this in a 40-page terms of service fails the transparency test. — Affirmative opt-in, not opt-out. A pre-checked box saying "I agree to marketing emails" does not constitute consent under NDPA. Users must actively choose. — A lawful basis beyond consent. If processing data for contractual performance (billing, order fulfillment), you don't need consent for that specific transaction. But if you want to use customer emails for marketing campaigns, you need separate consent. — The right to withdraw consent easily. If a customer opts into SMS marketing, they must be able to unsubscribe without friction.
For fintech startups in particular: KYC data (identification, proof of address) is often collected under regulatory obligation, not consent. You still need to document this legal basis in your privacy notice. The CBN's Know Your Customer requirements are a lawful basis for processing—make this explicit to users.
A common mistake: startups assume that because they are regulated by the CBN or FIRS for other purposes, they are automatically compliant with NDPA. They are not. Banking regulation and data protection regulation are separate. You need both.
The NDPA requires a Data Protection Officer (DPO) for organizations processing data at a certain scale or in sensitive sectors. You are not exempt just because you are a startup.
The regulation broadly covers: public authorities, organizations whose core activity involves systematic large-scale monitoring, and processors handling sensitive personal data (health, genetic data, biometric information). For early-stage startups with small customer bases processing non-sensitive data, a formal DPO may not be legally mandated—but NITDA guidance increasingly expects documented accountability measures.
In practice, this means:
— Identify who owns data protection responsibility within your team. This person is your de facto DPO, even if you do not formally title them as such. — That person should understand NDPA requirements, lead your data inventory, review third-party integrations for data privacy, and handle user access requests. — Document this role. When audited, you need to show that someone was explicitly responsible.
If you process health data (healthtech), genetic data, or operate a platform with systematic user monitoring, a formal DPO or external compliance officer becomes essential. The cost—typically ₦1-3 million annually for a consultant-led service—is justified by reduced regulatory risk.
For most early-stage fintech or e-commerce startups, this is one founder or early employee wearing the hat alongside their regular role. As you scale, formalize it.
You are responsible for how third parties handle your customer data. If you use AWS, Stripe, Interswitch, or a payment aggregator, you inherit their data handling practices.
REQUIRED:
— Data Processing Agreements (DPAs) with every third party that touches customer data. These are contracts specifying that the processor only handles data as you direct, maintains security, and doesn't use data for their own purposes. — Due diligence on processor security. You do not need to audit their servers, but you should verify they have published security certifications or compliance statements. — Notification of breach obligations. If a processor suffers a data breach, they must notify you within a specific timeframe so you can assess impact and notify affected users.
Many startups use payment processors or SMS gateways without any formal DPA. When NITDA asks for processor agreements, nothing exists. This is a compliance gap.
Reality check: Stripe, AWS, and major platforms offer standard DPAs. Request them. Smaller local processors may not—negotiate one, or reconsider the vendor. A Naira-denominated payment processor should be able to provide basic data handling commitments in writing.
NDPA grants users several explicit rights. You must be able to fulfill these requests within 30 days:
— Right of access: A user requests a copy of their personal data. You provide it in a structured, portable format. This requires you to know how to extract individual data from your systems. — Right to rectification: Users correct outdated or inaccurate information. Your system should allow users to update their own data without support tickets. — Right to erasure ("right to be forgotten"): Users request deletion. You must delete their data, except where legal obligations require retention (tax records, fraud investigation, CBN compliance holds). You need a documented retention policy explaining these exceptions. — Right to data portability: Users request their data in machine-readable format. They want to move their profile to a competitor's platform. You must facilitate this without penalty.
Implications: You need an engineering capability to execute these requests systematically. A manual process of searching spreadsheets and databases fails the 30-day requirement. If you cannot fulfill access requests easily, that is a red flag for your overall data governance.
For fintech startups, CBN regulations often require you hold transaction records for seven years. This is a legitimate legal basis for not deleting transaction history, but you must be clear about this in your privacy policy. You can delete associated profile data while retaining anonymized transaction records for audit purposes.
NITDA has moved from guidance to enforcement. The agency has issued compliance notices to fintech and e-commerce platforms, conducted inspections, and published investigation outcomes. The enforcement trend is accelerating as the agency builds capacity.
What triggers attention: Complaints from users (reported through NITDA's portal), media coverage of data breaches, or routine sector audits. Fintech and healthtech startups face higher scrutiny. Social platforms and data brokers face mandatory audits.
The pragmatic approach for startups: Compliance is not about perfection. It is about demonstrating good faith effort and documented accountability. NITDA does not expect startups to match enterprise-grade data infrastructure immediately. It does expect:
— Evidence that you understand what data you hold and why — A privacy policy that accurately describes your practices (not marketing copy) — User consent mechanisms that work as documented — A named person responsible for compliance — Response to user rights requests (even if imperfect initially) — Incident response procedures in case of breach
If an inspection finds gaps, you have time to remediate if you cooperate. Startups that acknowledge issues and commit to fixing them face lower penalties than those that deny problems or misrepresent their practices.
At KorabTech, we have helped early-stage fintech and e-commerce platforms conduct NDPA audits, document data flows, and build compliance-ready systems before regulatory scrutiny arrives. This typically costs ₦2-5 million depending on complexity, but prevents far costlier enforcement actions later.
Why work with KorabTech? We're a Lagos-based team that builds and ships real, production systems for Nigerian and West African businesses — not pilots, not proof-of-concepts. If what you just read sounds like a problem your business is facing, we'd genuinely like to talk it through with you.