← Back to Insights

Nigeria

Cross-Border Data Transfers Nigeria: NDPA Rules for Cloud, AI & SaaS

Michael K. Onyekwere··7 min read

If you use AWS, Google Cloud, OpenAI, Slack, HubSpot, or basically any modern SaaS tool from Nigeria, your data is leaving the country. Every API call, every cloud database query, every email through Google Workspace.

Most Nigerian businesses do this without thinking about it. Under the NDPA, every one of those transfers needs documented safeguards. And almost nobody has them.

I've audited the data flows of Nigerian fintechs and found 10-15 undocumented international transfers in the first hour. Nobody told them cloud infrastructure means cross-border transfers, so the paperwork never got done.

What counts as a transfer

Any time personal data moves from Nigeria to another country. Data processed on servers outside Nigeria counts, even when no file is ever emailed. Which means:

Cloud hosting. Your app runs on AWS Ireland, Google Cloud US, or Azure Frankfurt. Every piece of customer data stored there has been transferred out of Nigeria.

AI APIs. Every call to OpenAI, Anthropic, Google AI, or any external AI provider sends customer data to servers outside Nigeria. Usually the US. If your chatbot processes customer conversations through Claude or GPT-4, that's a cross-border transfer on every single interaction.

SaaS tools. HubSpot, Salesforce, Slack, Google Workspace, Mailchimp, Mixpanel: your CRM, email, analytics, and communication tools all store data outside Nigeria.

Payment processors. Paystack and Flutterwave handle some data locally, but international payment flows route through external servers.

Group companies. Sharing employee or customer data with a parent company or subsidiary abroad.

If you're a Nigerian business using modern technology (and you are) you're transferring data internationally. The question is whether you've documented it.

What the NDPA requires

The NDPA restricts cross-border transfers to ensure Nigerian residents' data stays protected when it leaves the country. Three lawful mechanisms:

Adequacy determination. The NDPC can certify that a receiving country has adequate data protection. In practice, this framework is still developing. The NDPC had published no formal adequacy decisions when we last checked (August 2026), and the old NDPR-era whitelist no longer has legal effect. Don't wait for this.

Appropriate safeguards. This is the practical route, and since the NDPC's GAID 2025 took effect it has a Nigerian shape of its own. Schedule 5 frames the recognised ground as a Cross-Border Data Transfer Instrument (CBDTI) approved by the Commission, which can take the form of codes of conduct, certification mechanisms, binding corporate rules, or standard contractual clauses. In practice the documentation is still a Data Processing Agreement with transfer clauses in it, and GDPR-style SCCs are the common starting point, but under the GAID the instrument route runs through NDPC approval, and the Commission can take your audit and filing record into account when it considers one. Building the paperwork now and following the NDPC's instrument process as it matures is the defensible position.

Derogations. Limited exceptions: explicit consent (the person understands the transfer risks), contractual necessity, legal claims, vital interests. Don't rely on consent for routine transfers; getting and managing consent for every data flow to every cloud service is impractical.

What to actually do, by scenario

Cloud hosting (AWS, Google Cloud, Azure)

Your customer data lives on servers in Ireland, Virginia, Frankfurt, wherever your cloud region is. That's a transfer.

What you need: a DPA with your cloud provider (AWS, Google, and Microsoft all offer them, but most businesses just haven't signed them), a record in your processing register documenting the transfer and safeguards, and a privacy notice that tells users their data goes to [country] under [safeguard].

Worth considering: AWS has an Africa (Cape Town) region. It's not Nigeria, but keeping data on the continent reduces transfer complexity and improves latency.

AI APIs (OpenAI, Anthropic, Google AI)

Every customer query sent to an AI API is personal data leaving Nigeria. Usually going to the US.

What you need: a DPA with the AI provider (most offer them), data minimisation before the API call (strip names, emails, and account numbers if the query doesn't need them), confirmation the provider doesn't retain your data for training (most API tiers offer zero-retention; verify it), a DPIA covering the combined risk of AI processing and international transfer, and documentation of the full data flow.

The AI provider piece is where I see the most gaps. Fintechs build chatbots, connect them to OpenAI, and never sign the DPA. The DPA exists. It's usually a few clicks on the provider's website. But nobody does it because nobody told them to.

SaaS platforms

HubSpot, Salesforce, Slack, Google Workspace, Mailchimp: each one is a cross-border transfer.

Audit your entire SaaS stack. List every tool that touches personal data. For each: check if you've signed a DPA (free-tier accounts often don't come with one by default; you need to actively request it), document what data the platform holds and where, and include each platform in your privacy notice.

You probably use more SaaS tools with personal data than you think. Spend an hour listing them. You'll find 15-20 minimum.

Group companies

Sharing data with a parent company or subsidiary abroad needs a formal agreement: binding corporate rules or an intra-group DPA covering what data is shared, why, who has access, and what protections apply. Nigerian employees must be told their data goes abroad.

Building your transfer framework

Step 1: Map every data flow. List every service, platform, partner, and group company that receives personal data from your Nigerian operations. For each: what data, which country, why, and what safeguards. This takes 2-3 days for an SME. It's tedious but it's the foundation of everything else.

Step 2: Sign DPAs. For every processor receiving Nigerian personal data. Check that each DPA covers cross-border transfer obligations, sub-processors, and breach notification. Most major providers have DPAs ready. The gap is usually that nobody at the company has executed them. If the processor is an AI vendor, see what to check on any AI vendor's DPA before signing.

Step 3: Update privacy notices. Users must know their data leaves Nigeria, which countries it goes to, and what safeguards are in place. Name the country and the safeguard. "Your conversation data is processed by Anthropic (US) under Standard Contractual Clauses."

Step 4: Include in your DPIA. Cross-border transfers are a specific risk factor in your impact assessment. What additional risks does the transfer create? What mitigations are in place? Is the transfer proportionate?

Step 5: Document for your CAR filing. When your DPCO files the Compliance Audit Return, cross-border transfers are part of it. NDPC wants to know where Nigerian personal data goes.

What I keep seeing go wrong

"We don't send data abroad." Yes you do. You use Gmail, AWS, and HubSpot. That's three cross-border transfers before you've written a line of code.

No DPAs with SaaS providers. The free tier doesn't come with one. You need to go find it and sign it. Takes 10 minutes per provider but nobody does it.

Privacy notices that don't mention transfers. Even if you have DPAs in place, your customers still need to know about the transfers. Leaving the transfers out of your privacy notice is itself a transparency failure under the NDPA.

No documentation at all. The transfers happen daily but nobody's written down where, why, and under what safeguards. When the NDPC asks (and they will, through your CAR filing at minimum) you need answers, not guesses.

Relying on consent for routine transfers. Getting explicit consent for every data flow to every cloud service is impractical. Use contractual safeguards as your primary mechanism and keep consent as a fallback for edge cases.

What happens if you get it wrong

Undocumented transfers surface through the CAR filing, through a breach investigation, or through a complaint. Under section 48 of the NDPA, a controller of major importance faces whichever is higher of ₦10 million or 2% of annual gross revenue for the preceding year (₦2 million or 2% for everyone else), and the NDPC publishes its enforcement actions, so the finding is public. The more common first-round outcome is a remediation order with a deadline, which means doing all of the work above anyway, under scrutiny, on the regulator's timetable.


Need help mapping your data flows and documenting transfers? Our NDPA Fintech Compliance Programme includes full data flow mapping, DPA review, and transfer documentation, from ₦3,500,000. Not sure where you stand? Start with an NDPA Readiness Diagnostic, ₦500,000.

Start with an NDPA Readiness Diagnostic

If you need NDPA compliance advice or a compliant AI build, the first step is a written diagnostic. You get a written assessment with priced next steps.

Cross-Border TransfersNDPANigeriaData ProtectionCloud