[codicts-css-switcher id=”346″]

Global Law Experts Logo
how to conduct a DPIA in Nigeria

How to Conduct a DPIA in Nigeria: NDPA & GAID Step-by-step Checklist (2026)

By Global Law Experts
– posted 48 minutes ago

Understanding how to conduct a DPIA in Nigeria is now a pressing compliance priority for every organisation that processes personal data in or from the country. A Data Protection Impact Assessment (DPIA) is the structured process by which a data controller identifies, evaluates and mitigates privacy risks before commencing high-risk processing activities. Since the Nigeria Data Protection Commission (NDPC) General Administrative Implementation Directive (GAID) took effect on 19 September 2025, DPIAs have moved from best-practice recommendation to enforceable regulatory expectation, and 2026 audit activity by the NDPC is reinforcing that shift.

Overview of the DPIA Process and Who It Applies To

A data protection impact assessment in Nigeria is a systematic evaluation required under the Nigeria Data Protection Act 2023 (NDPA) and operationalised by the GAID. Its purpose is to identify the likely impact of proposed data processing on the rights and freedoms of data subjects, and to document the measures adopted to reduce that impact to an acceptable level.

The obligation falls primarily on data controllers, the entities that determine the purposes and means of processing personal data. However, the GAID also extends practical responsibility to data processors acting on delegated tasks, particularly where a processor designs or implements a processing system on behalf of the controller. Public-sector bodies, financial institutions, healthcare organisations, telecommunications companies and technology firms deploying AI, biometric identification or large-scale profiling are among the entities most frequently required to complete a DPIA in Nigeria.

Under Article 28 of the GAID, the NDPC may require a controller to conduct and file a DPIA with the Commission in specified circumstances. The DPIA must follow the format set out in Schedule 4 of the GAID, which prescribes content headings, risk-scoring expectations and sign-off requirements. Failure to produce a compliant DPIA when requested during an NDPC audit can expose the controller to enforcement action, including an order to cease processing until the assessment is completed.

Eligibility and Prerequisites: When Is a DPIA Required?

Not every processing activity requires a full DPIA. The legal threshold under the NDPA and the GAID is whether the processing is likely to result in a high risk to the rights and freedoms of data subjects. The GAID identifies several categories of processing that will ordinarily meet this threshold:

  • Large-scale processing of sensitive personal data. This includes health records, biometric data, genetic data, financial records, and data revealing ethnic origin or political opinions.
  • Systematic monitoring of publicly accessible areas. CCTV networks, location tracking, and behavioural profiling systems fall within this category.
  • Novel technology deployments. Artificial intelligence, machine-learning models, automated decision-making systems and blockchain-based identity systems trigger the DPIA requirement.
  • Cross-border transfers of personal data. Where data is transferred outside Nigeria, particularly to jurisdictions without an NDPC adequacy determination, a DPIA is expected.
  • Processing that combines datasets or involves vulnerable data subjects. Projects involving children, employees, patients or other categories where the power imbalance between controller and subject is significant.

Before initiating the DPIA steps, the organisation should confirm that the following prerequisites are in place: a designated Data Protection Officer (DPO) or DPIA lead; access to the project’s technical and business stakeholders; senior management awareness and commitment to sign-off; and a current data inventory or processing register from which to draw baseline information.

Step-by-Step: How to Conduct a DPIA in Nigeria

The following seven-step procedure aligns with the NDPA DPIA requirements, the GAID Schedule 4 format, and internationally recognised methodology drawn from the EU GDPR Article 35 framework and ICO DPIA guidance. Each step produces a defined deliverable that forms part of the final, NDPC-ready DPIA report.

Step 1, Screen the Project and Decide Whether a Full DPIA Is Required

Begin with a DPIA screening checklist. The DPIA lead, typically the DPO or a senior compliance officer, applies the high-risk criteria from the GAID to the proposed processing activity. If any trigger is met, proceed to a full assessment. If no trigger is met, record the screening outcome and the reasons for concluding that a DPIA is not required. This screening record must be retained, as NDPC auditors may ask to see it.

  • Run the screening questionnaire against GAID high-risk triggers
  • Document the decision rationale in a formal screening form
  • Store the signed screening form in the compliance folder

Deliverable: Signed DPIA screening form and decision log.

Step 2, Appoint the DPIA Lead and Assemble the Assessment Team

Appoint the DPO or a nominated project lead to manage the assessment. The DPIA team should include representatives from information security, legal or compliance, the business unit sponsoring the project, and any external vendors whose systems will process personal data. Assign clear roles, who drafts the processing description, who identifies risks, who designs mitigations, and record these in a team roster.

  • Formally appoint the DPIA lead (document the appointment)
  • Identify team members from security, legal, business and vendor organisations
  • Prepare a roles and responsibilities matrix

Deliverable: DPIA team roster and roles matrix.

Step 3, Describe the Processing Activities and Their Legal Basis

This is the foundational step. Document every processing activity within the project’s scope, including the categories of personal data collected, the categories of data subjects, the purposes of processing, the retention periods, and any intended transfers to third parties or across borders. For each processing activity, identify the lawful basis relied upon under the NDPA, whether consent, contractual necessity, legal obligation, vital interest, public interest, or legitimate interest.

  • Map data flows from collection to deletion (internal systems, processors, sub-processors)
  • Record the legal basis for each category of processing
  • Note retention periods and deletion mechanisms
  • Identify cross-border transfers and the transfer mechanism relied upon

Deliverable: Processing description table aligned with GAID Schedule 4 headings.

Step 4, Identify Privacy Risks and Score Likelihood and Severity

Convene a risk workshop with the DPIA team. For each processing activity, identify threats (unauthorised access, data loss, re-identification, function creep), vulnerabilities (weak encryption, inadequate access controls, poorly drafted processor contracts), and harm scenarios (financial loss, discrimination, reputational damage, physical harm to data subjects). Score each risk using a likelihood-times-severity matrix to produce a residual risk rating. Record all identified risks in a risk register.

  • List threats, vulnerabilities and harm scenarios for each processing activity
  • Apply a consistent scoring methodology (e.g., 5×5 likelihood/impact grid)
  • Produce a risk heatmap showing high, medium and low residual risks

Deliverable: Risk register with scored risks and heatmap visualisation.

Step 5, Design Mitigations and Assign Owners

For every risk rated medium or high, design a mitigation measure. Mitigations should be a blend of technical controls (encryption at rest and in transit, pseudonymisation, automated deletion), organisational controls (access-control policies, staff training, incident-response plans), and contractual safeguards (processor agreements with audit rights, data-breach notification clauses, sub-processor approval mechanisms). Each mitigation must have a named owner and an implementation deadline.

  • Draft technical, organisational and contractual mitigations for each risk
  • Assign a responsible owner and target completion date for each measure
  • Re-score residual risk after mitigations are factored in

Deliverable: Mitigation plan with owners, deadlines and revised risk scores.

Step 6, Consult Stakeholders and Test Residual Risk

Circulate the draft DPIA report to internal stakeholders, including senior management, the legal team and the information-security function, for review. Where the GAID or the NDPA requires external consultation (for example, where residual risk remains high despite mitigations), engage the NDPC or seek independent expert advice. Vendor assessments should be completed at this stage if third-party processors are involved. Record all consultation responses and update the risk register accordingly.

  • Distribute the draft DPIA for internal review and comment
  • Consult the NDPC where residual risk remains high
  • Complete vendor due-diligence assessments
  • Log all consultation evidence (meeting minutes, email responses, expert reports)

Deliverable: Consultation log and updated risk register.

Step 7, Obtain Senior Management Sign-Off, File with the NDPC (If Required), and Set Up Monitoring

Present the final DPIA report to senior management for formal sign-off. The sign-off page should include the signatory’s name, title and date. Under Article 28 of the GAID, DPIAs must be filed with the NDPC in certain mandatory circumstances, the DPIA shall be prepared in accordance with Schedule 4 of the GAID and submitted via the NDPC’s designated channel. Even where filing is not mandatory, the completed DPIA must be retained and produced on request during an NDPC audit. Schedule a periodic review, industry observers recommend every 6 to 12 months, or sooner if the processing activity changes materially.

  • Secure executive sign-off with a dated signature page
  • File with the NDPC where GAID mandates submission
  • Store the DPIA in the compliance archive with version control
  • Set calendar reminders for periodic review

Deliverable: Signed DPIA report, NDPC filing confirmation (if applicable), and monitoring schedule.

Documents Needed for an NDPC-Ready DPIA Report

An NDPC-ready DPIA is only as strong as its supporting evidence. Auditors expect a self-contained compliance pack that demonstrates each stage of the assessment was completed with rigour. The following table sets out the documents that should accompany every completed DPIA in Nigeria.

Document Notes
DPIA screening form Completed by the DPIA lead; signed and dated; stored as PDF in the compliance folder
Full DPIA report Narrative covering all seven steps, plus embedded risk register, mitigation plan and sign-off pages; PDF with version history
Processing map Diagram or table showing data flows between internal systems, processors and sub-processors; exported as PDF or PNG
Data inventory List of systems, data categories and retention schedules; exported CSV with a signed declaration of completeness
Vendor / processor contracts Current contracts containing data-processing clauses, security annexes and sub-processor approval terms; PDF, signed and dated
Security assessment evidence Penetration-test reports, vulnerability scan outputs and encryption configuration records; dated and signed by the assessor
Consent or lawful-basis documentation Sample consent forms, records of lawful-basis assessments and any legitimate-interest balancing tests; PDF or log format
Consultation evidence Minutes, stakeholder emails, NDPC correspondence and external expert reports; dated transcripts
Senior management sign-off Executive approval page with signatory name, title and date; PDF with wet or electronic signature
Monitoring plan and review log Review schedule and subsequent review entries; living document maintained as PDF with change log

Maintain the full pack in a single compliance archive. If the NDPC requests evidence during an audit, the organisation should be able to produce the entire set within the timeframe specified in the audit notice.

DPIA Timeline and Key Deadlines

The elapsed time for a DPIA depends on the complexity of the processing activity. The table below provides realistic durations for a medium-complexity project, such as launching a digital lending platform or deploying a customer-profiling system.

Step Who does it Typical duration
DPIA screening and decision Project lead + DPO 1–3 business days
Team appointment and scoping DPO / Project lead 2–5 business days
Processing description and mapping Business owner + IT + Legal 3–10 business days
Risk identification and scoring DPIA team (workshop) 3–7 business days
Mitigation design and owner allocation IT / Security + Legal 5–14 business days
Consultation and residual risk check DPO + stakeholders (+ external consult if needed) 7–21 business days
Sign-off, filing and monitoring setup Senior management + DPO 3–7 business days
Total (medium-complexity project) , 4–8 weeks from screening to sign-off

For straightforward processing activities with limited data categories, a DPIA can be completed in 2 to 3 weeks. Complex projects involving multiple vendors, cross-border transfers or novel technologies may require 10 to 14 weeks. Regardless of complexity, the DPIA should be reviewed at least every 6 to 12 months, or immediately when there is a material change to the processing activity, such as a new data-sharing arrangement or a technology migration.

Costs, Fees and Practical Budget Considerations

The cost of conducting a DPIA in Nigeria varies according to whether the assessment is handled in-house or with external advisory support, and the complexity of the processing activity. The following table provides indicative market estimates.

Item Typical amount (NGN / USD) Notes
In-house DPIA (staff time) NGN 150,000–900,000 (≈ USD 200–1,200) Dependent on staff rates and project complexity
External legal / compliance advisor (DPIA drafting) NGN 600,000–4,500,000 (≈ USD 800–6,000) For a lawyer-led, NDPC-ready DPIA with sign-off
Penetration test / security review NGN 250,000–2,500,000 (≈ USD 350–3,300) One-off engagement; scope-dependent
Vendor / processor due diligence NGN 100,000–800,000 per vendor Varies with vendor count and geographic complexity
NDPC filing fee No published fixed filing fee as at August 2026 Confirm current position on the NDPC portal before filing

The cost estimates above are industry approximations and will vary by firm, sector and project scope. Organisations should confirm current NDPC fee schedules directly with the Commission before budgeting for a filing.

What Changes in 2026: GAID DPIA Guidance and NDPC Enforcement

The GAID, which took effect on 19 September 2025, introduced the most significant operational change to the DPIA landscape in Nigeria since the NDPA was enacted in 2023. Schedule 4 of the GAID prescribes the content, format and risk-assessment methodology that a compliant DPIA must follow. Article 28 of the GAID sets out the circumstances in which a controller must conduct and file a DPIA with the NDPC, including where processing involves large-scale sensitive data, systematic monitoring, or novel technology.

Early indications suggest that the NDPC has increased its audit and compliance-monitoring activity through 2026, with a particular focus on fintech platforms, health-technology companies and public-sector digital identity systems. The NDPC’s Privacy by Design white paper reinforces the expectation that DPIAs will be treated as a core component of any privacy-by-design framework, not an afterthought. Organisations that have not yet aligned their DPIA processes with the GAID Schedule 4 format should treat this as an immediate priority.

Common Pitfalls and How to Avoid Them

  • Superficial screening. Recording that no DPIA is required without documenting the reasoning. Always complete a formal screening form and retain it, NDPC auditors will ask for it.
  • Missing sign-offs. Completing the assessment but failing to obtain senior management approval. An unsigned DPIA is incomplete and will not satisfy the GAID requirements.
  • Weak vendor clauses. Relying on generic processor contracts that lack data-protection clauses, audit rights or breach-notification obligations. Ensure every processor agreement is reviewed against NDPA standards.
  • No evidence trail. Conducting consultations and risk workshops without recording minutes, attendee lists or follow-up actions. Maintain a dated consultation log for every stakeholder interaction.
  • Failure to monitor and review. Treating the DPIA as a one-off document rather than a living assessment. Set a review cadence of 6 to 12 months and trigger an immediate review when processing changes materially.
  • Ignoring cross-border transfer risks. Omitting international data transfers from the risk register. Map all transfer destinations and document the transfer mechanism relied upon under the NDPA.

Conclusion

Knowing how to conduct a DPIA in Nigeria, and executing the process to GAID and NDPA standards, is no longer optional for organisations handling personal data at scale. The seven-step procedure outlined in this guide provides a practical, NDPC-audit-ready framework: from initial screening through risk assessment, mitigation design and senior sign-off to ongoing monitoring. With the NDPC intensifying enforcement activity through 2026, the cost of delay significantly outweighs the cost of compliance. Organisations should begin with a formal screening of their current and planned processing activities and engage experienced data protection counsel where processing involves sensitive data, cross-border transfers or novel technology.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Paul Mgbeoma at Tayo Oyetibo LP, a member of the Global Law Experts network.

Sources

  1. Nigeria Data Protection Commission, GAID (NDP-ACT GAID 2025)
  2. Nigeria Data Protection Commission, NDPC Homepage
  3. NDPC, DIAL White Paper: Privacy by Design in Early-Stage Innovation
  4. EU General Data Protection Regulation (GDPR), Article 35
  5. ICO (UK), Data Protection Impact Assessments (DPIAs) Guidance

FAQs

When is a DPIA required under the NDPA and the GAID?
A DPIA is required whenever processing is likely to result in a high risk to data subjects. The GAID identifies specific triggers, including large-scale sensitive data processing, systematic monitoring, novel technology deployments and cross-border transfers. The eligibility criteria are detailed in the eligibility section above.
The process follows seven stages: project screening, team appointment, processing description, risk identification and scoring, mitigation design, stakeholder consultation, and sign-off with filing and monitoring. The full procedure, including deliverables for each stage, is set out in the step-by-step section above.
An NDPC-ready report should include the screening form, full DPIA narrative with risk register, processing map, data inventory, vendor contracts, security assessment evidence, lawful-basis documentation, consultation evidence, senior management sign-off and a monitoring plan. The complete checklist is in the required documents section above.
Under Article 28 of the GAID, filing with the NDPC is mandatory in certain circumstances, particularly where processing involves high-risk activities specified in the GAID. The DPIA must follow the format prescribed by Schedule 4 of the GAID. A medium-complexity DPIA typically takes 4 to 8 weeks from screening to sign-off, as detailed in the timeline section above.
Yes. The NDPA applies to any controller or processor that processes the personal data of data subjects in Nigeria, regardless of where the controller is established. A non-Nigerian entity processing Nigerian personal data must comply with NDPA DPIA requirements and should engage Nigerian legal counsel to ensure the assessment meets GAID standards. Find a data protection lawyer in Nigeria for jurisdiction-specific guidance.
The NDPC has enforcement powers under the NDPA that include the ability to restrict processing, issue compliance directions and impose administrative penalties. If a controller fails to produce a DPIA when required during an audit, the NDPC may order the suspension of the relevant processing activities until a compliant DPIA is completed. Organisations that receive an audit notice should engage qualified data protection counsel immediately and prioritise remediation.
what are the requirements for a pledge to be valid?
By Global Law Experts

posted 4 hours ago

Company vs Sole Trader Cyprus

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Conduct a DPIA in Nigeria: NDPA & GAID Step-by-step Checklist (2026)

Send welcome message

Custom Message