Demystifying NDPC compliance: a strategic guide to data protection impact assessments (DPIAs)

As businesses, government agencies, and innovative startups increasingly rely on personal information to drive growth, protecting people’s information has transitioned from being a mere legal obligation to a business need.

Data Protection Impact Assessments (DPIAs) is a rigorous safety inspection carried out before a processing activity commences instead of waiting for a system failure or, a data breach; data controllers/processors, through DPIAs proactively identify potential vulnerabilities and implement safeguards to prevent these risks from happening.

Introduction

A DPIA is simply a structured, risk-management exercise. This assessment goes the extra mile, rather than inquiring whether technical controls are in place to protect the user’s data. The whole essence of a DPIA is to systematically evaluate what data is being collected, why it is necessary, the risks posed to the data subjects, and the specific safeguards required to mitigate those risks.

The end goal of this assessment is not only protect individuals from data breaches/exposure but also, to build consumer trust and fortify their internal governance framework.

Key takeaways

  • The NDP Act requires a DPIA before processing that is likely to create a high risk to a data subject’s rights and freedoms.
  • Mandatory DPIA circumstances include profiling, automated decisions, systematic monitoring, sensitive data, new technologies, digital financial or healthcare services, CCTV, and cross-border transfers.
  • A DPIA must describe the proposed processing and its purpose, assess necessity and proportionality, evaluate risks, and identify safeguards.
  • A submitted DPIA must be vetted and signed by an NDPC accredited Data Protection Officer. The Commission must be consulted if high risk remains despite the proposed safeguards.
  • The DPIA outcome must be included in the annual Compliance Audit Returns, while failure to conduct a required DPIA may lead to enforcement action.

Section 28 of the Nigeria Data Protection Act, 2023 sets out the foundation for Data Privacy Impact Assessments. The NDP Act mandates that whenever a data processing activity by virtue of its nature, scope, context, and purposes is likely to result in a high risk to the rights and freedoms of a data subject, the data controller must conduct a DPIA prior to initiating the processing.

This is also to foster the principles of privacy by design (PbD) and privacy by default.

The above stated provision of the NDP Act is further operationalized by Article 28 of the NDP Act, General Application and Implementation Directive, (GAID) 2025, which explicitly outlines the triggers, methodologies, and consequences tied to DPIAs. When exactly does this high-risk threshold require a mandatory DPIA?

Article 28(3) of the NDP Act GAID outlines a comprehensive list of circumstances where an assessment must be conducted and filed with the Nigeria Data Protection Commission (NDPC). Controllers and Processors are legally required to conduct a DPIA in the following circumstance:

  1. Evaluation, scoring, or profiling of individuals.
  2. Automated decision-making that produces legal or significant effects.
  3. The systematic monitoring of data subjects.
  4. The processing of sensitive or highly personal data, or data relating to vulnerable subjects like children.
  5. The deployment of innovative processes, new technologies, or organizational solutions that pose significant privacy risks.
  6. The development of software designed to enable communication with data subjects
  7. Financial, healthcare, or e-commerce services processed through digital devices.
  8. The deployment of surveillance cameras (CCTV) in publicly accessible spaces.
  9. Cross-border data transfers.

The DPIA process explained

In conducting a DPIA, Section 28(4) of the NDP Act provides that your assessment must be thorough and strictly structured. It must comprise a systematic description of the envisaged processing and its legitimate purpose. It requires an objective assessment of the necessity and proportionality of the processing in relation to your goals.

Furthermore, it must include a detailed evaluation of the risks to the rights and freedoms of data subjects. This is to be followed by the specific safeguards, security measures, and mechanisms that will be implement to mitigate the identified risks.

The NDP Act GAID mandates a strict chain of accountability. This strongly suggests that every submitted DPIA to the Commission must be vetted and signed by a duly certified Data Protection Officer (DPO) who is officially accredited by the NDPC.

Additionally, in circumstances where, by your assessment, the processing activity will result in a high risk despite your proposed safeguards, the law requires you to consult the Commission before proceeding with the data processing. Ultimately, the outcome of your DPIA must be integrated into your annual Compliance Audit Returns (CAR) filed with the Commission.

The consequences of non-compliance are severe, and exposes your organization to immense regulatory risk. Under Article 28(6) of the NDP Act GAID, the failure, refusal, or negligence in conducting a required DPIA can trigger aggressive enforcement actions under Part X of the NDP Act.

Most notably, the Commission holds the power to impose direct restrictions on all platforms where data subjects interact with your organization, effectively halting your ability to carry out data-driven transactions.

Conclusion

Whether you are launching a new financial web app, integrating AI technologies, or transferring data across borders, conducting a DPIA is an obligation incumbent on you. The whole essence is not about avoiding sanctions; it is about engendering a privacy-first culture that respects the dignity and rights of every user.

Disclaimer: This publication is for general informational purposes only. It does not constitute legal advice. For specific guidance, contact a qualified lawyer.

Written by:

Ogheneyoma E. Ibuje LL.B, B.L, ACIS – Legal Associate
Abdulbaqi Suleiman – Team Lead
TCorporate Legal Advisory

Frequently asked questions (FAQs)

When should I file a DPIA?

Under the NDP Act, 2023, a DPIA must be filed whenever processing is likely to result in a high risk to data subject. Also, article 28(3) of the NDP Act GAID highlights in details these circumstances.

Do I need to file the DPIA with NDPC?

Under the NDP Act GAID, filing with NDPC is mandatory in circumstances where processing is likely to result in a high risk to the rights and freedoms of a data subject.

Is a new company required to conduct and file DPIA?

Yes, a new company is required to conduct and file DPIA if any of the circumstances that makes DPIA mandatory occurs.

Need help conducting a data protection impact assessment?

Whether you’re introducing new technologies, new processing techniques or cross boarder transfers, our Data Protection Department at TCorporate Legal Advisory is ready to assist you seamlessly.

Let us help you:

  • Conduct DPIA in accordance with the NDP Act, 2023 as well as the NDP Act GAID, 2025.
  • Submit your DPIA to the commission and consult on your behalf.

📞 Phone: 0806 234 8867, 0908 011 9975, 0908 011 9980
📧 Email: info@tcorporatelegaladvisory.com
🌐 Website: www.tcorporatelegaladvisory.com
📲 Click the WhatsApp button (bottom right) to chat with us now.

akujobinoble@gmail.com
akujobinoble@gmail.com
Articles: 3