NDPA Compliance on the Cloud: A Practical Checklist for Nigerian Businesses

The Nigeria Data Protection Act 2023 applies to almost every business that collects personal data, and the Nigeria Data Protection Commission has started enforcing it with audits and fines. Running on the cloud does not make you compliant, and it does not stop you being compliant either. It changes where the controls live. This checklist is the one we use when we build and operate platforms for regulated clients.
1. Know what you hold
- Map every place personal data lives: databases, object storage, backups, logs, analytics, support tools, spreadsheets exported by staff.
- Classify it. Names and emails are one thing; BVN, NIN, health and financial records are sensitive and need stricter handling.
- Record the purpose and lawful basis for each dataset. "We might need it" is not a purpose.
2. Collect less, keep it shorter
- Ask only for fields you use. Every extra field is liability.
- Set retention periods and automate deletion. Cloud lifecycle rules on storage buckets and database jobs make this cheap.
- Anonymise or aggregate analytics data; you rarely need the individual.
3. Secure it like the regulator expects
- Encryption in transit (TLS everywhere) and at rest (managed keys on AWS KMS, Google Cloud KMS or Azure Key Vault).
- Least-privilege access with named accounts, multi-factor authentication and no shared passwords; review access quarterly.
- Audit logs for who accessed what and when, kept separately from the systems they describe.
- Backups that are encrypted, tested and restorable within a stated time.
- Vulnerability scanning and patching on a schedule; automated where possible.
4. Cross-border transfers
Hosting in Europe or South Africa is a cross-border transfer. The NDPA permits it where the destination has adequate protection or appropriate safeguards exist. In practice: use the provider's data-processing terms, document the transfer and its safeguards, and give data subjects the information in your privacy notice. Sector regulators may add in-country requirements for specific data; check before you design.
5. People and process
- Appoint a Data Protection Officer if you are a data controller of major importance, and register with the NDPC.
- Publish a clear privacy notice and honour access, correction and deletion requests within the statutory time.
- Have a breach response plan: who decides, who notifies the NDPC within 72 hours, who tells affected users.
- Contracts with every processor (cloud, email, SMS, payments, support tools) that bind them to the same standards.
- Annual audit and a filed compliance audit return where required.
6. Build it in, do not bolt it on
The cheapest compliance is the kind designed into the platform: data classification tags on storage, encryption by default, automated retention, centralised logging and infrastructure defined as code so every change is reviewed. Retrofitting the same controls on a running system costs several times more and usually happens after an incident.
We build and run platforms for banks, insurers and health companies with these controls in place. Start with a security and compliance review.
Cloud security as a service

