Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity and Compliance in Nigeria

Security audits, penetration testing, and regulatory compliance for organizations operating in Nigeria, aligned with the NDPC, NITDA, and CBN frameworks.

Last updatedAugust 22, 2026

The local regulatory framework

Nigeria has one of the more developed regulatory frameworks in Sub-Saharan Africa. Personal data protection is governed by the Nigeria Data Protection Act 2023 (NDPA), overseen by the Nigeria Data Protection Commission (NDPC). Information systems security is further addressed by the NITDA Framework, issued by the National Information Technology Development Agency. Financial institutions are additionally subject to the Central Bank of Nigeria's (CBN) Risk-Based Cybersecurity Framework, which imposes specific cyber risk management requirements.

Concrete obligations

Registration and compliance with the NDPC for organizations processing personal data at scale

Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing under the NDPA 2023

Notifying the NDPC of data breaches within the timelines set by the NDPA 2023

Implementing the CBN Risk-Based Cybersecurity Framework for regulated financial institutions

Complying with NITDA Framework requirements for information systems security

Priority sectors

Financial services and fintechTelecommunicationsEnergy and oil & gas

Delivery modalities

Engagement mode

On-site missions in Lagos and Abuja, remote delivery elsewhere in the country

Working language

English, with deliverables available in French on request

Regulatory coordination

Dedicated contact for interactions with the NDPC, NITDA, and CBN

Local FAQ

What is the main data protection law in Nigeria?

The Nigeria Data Protection Act 2023 (NDPA), enforced by the Nigeria Data Protection Commission (NDPC).

Do financial institutions have specific obligations?

Yes, they must comply with the Central Bank of Nigeria's (CBN) Risk-Based Cybersecurity Framework, in addition to the NDPA.

Is a DPIA always mandatory?

It is required for processing activities that present a high risk to data subjects, as defined under the NDPA 2023.

What is the difference between the NITDA Framework and the NDPA?

The NDPA governs personal data protection; the NITDA Framework addresses information systems security more broadly, regardless of the type of data processed.

Do you work with Nigerian banks and fintechs?

Yes, this sector is a priority given the requirements of the CBN Risk-Based Cybersecurity Framework and its associated risk level.

How much time is allowed to notify the NDPC of a data breach?

The NDPA 2023 sets specific notification timelines; we help you meet these deadlines from the moment an incident is detected.

Do you support registration with the NDPC?

Yes, as part of our governance, risk and compliance service, covering diagnosis and operational compliance.

Do you operate outside Lagos and Abuja?

Yes, technical engagements can be delivered remotely nationwide, with on-site visits as required by the mission.

Get in touch