← Back to Insights

Nigeria

NDPA vs GDPR: Key Differences for Nigerian Businesses

Michael K. Onyekwere··8 min read

I work across both frameworks daily. The NDPA and GDPR look similar on paper: both protect personal data, both give individuals rights, both impose obligations on organisations. But the practical differences trip up every Nigerian business that tries to treat them as interchangeable.

Here's what actually differs and why it matters for compliance.

Where they agree

Both frameworks share the same foundational principles: lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability. If you understand one, the other isn't alien.

Both require privacy notices. Both require a lawful basis for every processing activity. Both impose breach notification obligations. Both give individuals the right to access, correct, and delete their data.

If you're already GDPR-compliant, maybe 80% of your work transfers to the NDPA. But the remaining 20% is where Nigerian businesses get caught.

The differences that matter

You can't self-audit under the NDPA

The biggest structural difference and the one that surprises people most.

Under GDPR, you assess your own compliance. You can hire a consultant if you want, but there's no mandatory external audit for most businesses.

Under the NDPA, the higher tiers of Data Controllers and Processors of Major Importance (Extra-High and Ultra-High Level, which includes every fintech) must file a Compliance Audit Return (CAR) every year through a licensed DPCO; Ordinary-High Level entities renew their NDPC registration annually instead. The official filing fees under the GAID's fee schedule run from ₦100,000 to ₦1,000,000 depending on tier and size, and the DPCO's professional fees for the audit work come on top at market rates. Neither cost exists under GDPR.

The DPO threshold is lower in Nigeria

GDPR requires a Data Protection Officer for public authorities, organisations doing large-scale systematic monitoring, or those processing special category data at scale. Many SMEs don't technically need one.

The NDPA requires a DPO for every data controller or processor of major importance, and the entry bar is low: under the GAID's classification, processing the data of just 200 data subjects within six months puts you in the Ordinary-High Level tier, 1,000 makes you Extra-High Level, and 5,000 or a named sector makes you Ultra-High Level. Fintechs, banks, insurers, telcos and payment gateways are Ultra-High Level by sector regardless of user count. If you run a fintech app in Nigeria, you need a DPO from day one. Under GDPR, the same sized company might not.

Legitimate interest is less settled in Nigeria

Under GDPR, legitimate interest is a well-established lawful basis with extensive case law and regulatory guidance. The ICO's legitimate interest assessment provides a clear three-part test. Fraud detection, direct marketing to existing customers, employee monitoring within limits: all commonly rely on legitimate interest.

Under the NDPA, legitimate interest exists as a lawful basis, and the GAID now prescribes how to use it: a Legitimate Interest Assessment on the NDPC's own template, completed before you rely on the basis. That is arguably more formal than the ICO's approach. There's less precedent, fewer published decisions, and less certainty about where the boundaries are. If you rely heavily on legitimate interest under GDPR for things like analytics or fraud detection, you should document your reasoning more thoroughly for NDPA purposes, and be prepared to fall back on consent if NDPC interprets it more narrowly.

Cross-border transfers are handled differently

GDPR has a mature transfer framework. Standard Contractual Clauses, adequacy decisions, Binding Corporate Rules: the mechanisms are well-established and widely used. When you sign a DPA with OpenAI or AWS, the SCCs are usually built in.

The NDPA transfer framework now has its operating rules: the GAID recognises an adequacy decision by the Commission, a Commission-approved transfer instrument (codes of conduct, certifications, binding corporate rules, standard contractual clauses), and the Act's derogations. The genuinely practical gap is different: Most Nigerian businesses send data internationally (every cloud provider, every AI API, every SaaS tool), but few have formally documented these transfers under the NDPA.

This is one of the biggest compliance gaps I see. A Nigerian fintech using AWS, calling OpenAI's API, and running Google Analytics has three undocumented international data transfers. Under GDPR, the SCCs in those providers' DPAs cover it. Under the NDPA, you need to document the safeguards separately.

How NDPC enforcement actually works

GDPR fines go up to €20 million or 4% of global annual turnover. The enforcement record is extensive: billions in fines issued across the EU since 2018.

NDPA fines for a controller of major importance run to whichever is higher of ₦10 million or 2% of annual gross revenue for the preceding year (₦2 million or 2% for everyone else). The ceilings are lower than GDPR's, but for a Nigerian SME, a ₦10 million fine is serious money. And NDPC enforcement is real and growing. They have political backing, they're hiring investigators, and the CAR filing system gives them visibility into who's compliant and who's not.

Don't assume Nigerian enforcement is slack because the fines are lower than GDPR. The trajectory is clear.

Breach notification timelines differ

GDPR gives you 72 hours to notify the relevant supervisory authority of a breach likely to result in risk to individuals. The clock starts when you become "aware" of the breach.

The NDPA runs on the same clock. Section 40(2) requires notification to the NDPC within 72 hours of becoming aware of a breach likely to cause significant harm, and the GAID adds that affected individuals must be told immediately where the breach poses a high risk to them, with phased reporting permitted where the full detail is not yet available. The real difference between the regimes is maturity of enforcement practice, and that gap is closing.

If a breach affects both Nigerian and EU data subjects, you may need to notify both NDPC and the relevant EU DPA, under different rules. Your breach response plan should account for this.

Data subject rights overlap but aren't identical

Both frameworks give individuals the right to access, rectify, and delete their data, and to object to processing. GDPR additionally provides a well-established right to data portability and specific rights around automated decision-making under Article 22.

The NDPA's rights framework is similar in scope but the practical complaint and enforcement mechanisms are still maturing. Building one data subject rights process that satisfies both frameworks is possible; just make sure it meets the stricter of the two requirements for each right.

If you operate under both

This is common for Nigerian businesses that serve diaspora customers, use EU/US cloud infrastructure, have European partners, or process employee data across multiple countries.

The practical approach:

Build to GDPR standard first. It's the more mature and more demanding framework. If you meet GDPR, you meet most NDPA requirements automatically. The reverse isn't true.

Layer NDPA-specific requirements on top. The DPCO engagement, the lower DPO threshold, the CAR filing, and any NDPC-specific guidance. The DPCO engagement, the lower DPO bar and the CAR filing come on top of your GDPR work. These are additions, not replacements.

Document transfers in both directions. Data leaving Nigeria needs NDPA transfer documentation. Data entering the EU needs GDPR transfer mechanisms. They're separate obligations, even if the data flows are the same.

One DPO can cover both. If your DPO understands both frameworks, you don't need separate officers. But make sure they're registered with NDPC specifically; GDPR DPO registration is a different process.

We've written a detailed guide on NDPA compliance for Nigerian fintechs using AI that covers the framework integration in one programme.

Mistakes I keep seeing

Assuming GDPR compliance means NDPA compliance. It doesn't. The DPCO requirement alone means you have a Nigeria-specific obligation that no amount of GDPR work covers.

Ignoring NDPA because "nobody enforces." NDPC is enforcing. The CAR filing system means they know exactly who's filing and who isn't. The businesses that aren't filing are the ones that get investigated first.

Copy-pasting GDPR templates for Nigeria. Your privacy notice, policies, and DPIAs need to reference the NDPA specifically, cite the relevant NDPC guidance, and use Nigerian legal terminology. Regulators notice when you've done a find-and-replace on a GDPR template.

Treating cross-border transfers as a GDPR-only problem. If data leaves Nigeria, and it does every time you use a cloud provider or AI API, you have an NDPA obligation to document it.


Stuck on NDPA plus GDPR dual-compliance? The NDPA Readiness Diagnostic below is the first step for any Nigerian business running both regimes. Fintechs wanting the whole function run for them can get a written fractional-DPO proposal. Tell us your stage, NDPC status, monthly active users, and what is driving the compliance need. Michael writes a proposal within 24 hours, recommended tier and what the first three months would cover. Free to request.

Prefer to read the offer first? Janus Compliance offers a fractional Data Protection Officer service for Nigerian fintechs serving diaspora customers, accepting international cards, or partnering with European processors. One DPO covers both regimes in a single engagement: NDPA Section 32 designation, GDPR Article 28-equivalent processor agreements, cross-border transfer documentation. Outsourced DPO for Nigerian fintechs, fixed monthly Naira retainer from ₦600,000/month.

Start with an NDPA Readiness Diagnostic

If you need NDPA compliance advice or a compliant AI build, the first step is a written diagnostic. You get a written assessment with priced next steps.

NDPAGDPRNigeriaData ProtectionCompliance