All articles
Compliance17 June 2026

NDPA & Your Cloud: What Nigerian CIOs Must Know in 2026

NDPA & Your Cloud: What Nigerian CIOs Must Know in 2026

If “NDPR compliance” is still the phrase sitting in your governance documents, your organisation is already working from an outdated playbook and that gap could be the most expensive item on your 2026 compliance budget.

The NDPR hasn’t existed as the primary law since 2023. It was replaced by the Nigeria Data Protection Act (NDPA), a far more enforceable piece of legislation with a dedicated regulator, real financial penalties, and as of the past year a detailed implementation framework that directly shapes how Nigerian enterprises should be thinking about cloud infrastructure. For CIOs, this is an infrastructure decision.

The NDPA (2023) is a full Act of the National Assembly, and it was created by the Nigeria Data Protection Commission (NDPC) as a standalone regulator with investigative powers, audit authority, and the ability to impose meaningful fines. In 2025, the NDPC went further, issuing the General Application and Implementation Directive (GAID) a detailed operational framework that clarifies exactly who needs to register, what “major importance” means in practice, and what organisations must demonstrate to prove they’re handling personal data responsibly. Under the NDPA and GAID, an organisation is classified as a Data Controller or Processor of Major Importance (DCPMI) and businesses are required to register with the NDPC if it meets any of several criteria. Two of those criteria should make every CIO sit up: (i) Processing personal data of more than 200 individuals within a six-month period (a threshold most mid-sized Nigerian businesses cross without realising it). (ii) Providing commercial ICT services on digital devices that store another individual’s personal data.

In other words, if your organisation runs customer databases, HR systems, transaction platforms, or hosts data on behalf of clients, you are very likely a DCPMI, whether you’ve registered or not. Certain sectors are automatically in scope regardless of size, financial services, healthcare, telecoms, energy, insurance, e-commerce, and public service, among others.

Important things every CIO should note

One of the most consequential and least discussed aspects of the NDPA is its position on moving Nigerian personal data outside the country. Data can only be transferred internationally if the destination jurisdiction offers a level of protection comparable to what Nigerian law guarantees. This has a direct implication for cloud architecture. If your infrastructure is hosted entirely outside Nigeria particularly with providers whose data residency, sub-processing, and jurisdictional arrangements you can’t fully map you may be creating compliance exposure without realising it.

This doesn’t mean every Nigerian business needs to abandon global cloud providers overnight. It does mean data residency has shifted from a “nice to have” to a documented compliance requirement that procurement and legal teams will increasingly ask IT to justify. Under the NDPA, organisations must notify the NDPC within 72 hours of becoming aware of a breach likely to pose a high risk to individuals and notify affected individuals “immediately” where that risk is high.

Seventy-two hours sounds like a long time until you consider what it actually requires; detection, investigation, impact assessment, internal escalation, and a defensible breach register all before the clock runs out. Organisations relying on manual monitoring, infrequent log reviews, or infrastructure without 24/7 oversight are taking on far more regulatory risk than they may realise. This is where infrastructure choices stop being an IT concern and start being a board-level risk question.

Organisations classified as DCPMIs are required to file an annual Compliance Audit Return (CAR), documenting how personal data was processed and protected over the prior year. The CAR for 2025 activity was originally due 31 March 2026, and has since been extended. If your organisation hasn’t yet mapped what a CAR submission would require a data flow documentation, technical and organisational safeguards, breach registers, and DPO sign-off

What non-compliance costs

The NDPC has shown it isn’t issuing warnings. Recent enforcement actions include a fine in the hundreds of millions of naira against a major broadcasting company, and a penalty in the hundreds of millions of dollars against a global technology platform. Under the NDPA, penalties can reach 2% of annual gross revenue or ₦10 million whichever is higher.

What Nigerian CIOs should do in 2026

A practical starting point is to confirm your DCPMI statusIf you haven’t formally assessed whether your organisation meets the registration criteria, that’s step one and it’s overdue for many businesses that assume they’re “too small” to be in scope. Map where your data actually livesand this includes backups, DR environments, and any third-party processors. Stress-test your 72-hour response and see if your team could detect, assess, and report a breach within that window today. If the honest answer is “not confidently,” that’s an infrastructure gap. CIOs review the cross-border data flows and understand exactly which providers, sub-processors, and jurisdictions touch Nigerian personal data and whether that arrangement is defensible under NDPA’s adequacy standard.

Local data residency, 24/7 monitored infrastructure, documented security controls, and a partner who understands Nigeria’s regulatory environment from the inside are the foundation of an infrastructure that holds up under scrutiny from regulators, from clients, and from your own board.

At inq., this is the environment we’ve built for; locally hosted, continuously monitored, and designed around the realities Nigerian enterprises actually operate in. If 2026 is the year your organisation closes its NDPA gaps, it’s worth having that conversation sooner rather than later.

inq.Nigeria

Simpler. Seamless. Solutions

🌐 https://ng.inq.inc

Next article

“Nothing has happened yet” is not a security strategy

More on Compliance

Ready to put this into practice?

Talk to our experts about connectivity, cloud, security and digital solutions for your business.