How to implement NDPR data protection policies in a small company?
Small businesses in Lagos, Abuja, and across Nigeria often operate under the dangerous assumption that data protection is a burden reserved for Tier-1 banks and multinational telecommunications firms. I have seen situations where leaders dismissed the Nigeria Data Protection Act (NDPA) 2023 as a mere 'suggestion' for SMEs. This is a costly mistake. If you handle the Personal Identifiable Information (PII) of even ten Nigerian citizens, you are within the crosshairs of the Nigeria Data Protection Commission (NDPC). Compliance is not a luxury; it is a statutory requirement under the laws of the Federal Republic of Nigeria.
Transition from the 2019 NDPR to the more robust NDPA 2023 is not just about changing nomenclature. It is about shifting your corporate culture from data hoarding to data minimisation. As a Data Protection Officer, I tell my clients that the first step to compliance is acknowledging that every piece of data you hold is a liability until it is proven to be an asset held legally. Here is how you can implement these policies effectively without breaking your operational budget.
1. Conduct a Comprehensive Data Inventory
You cannot protect what you do not know you have. I recommend starting with a 'Data Map'. For a small company, this means looking at every department. Look at HR. You likely hold staff names, home addresses, Next of Kin details, Bank Verification Numbers (BVN), and National Identification Numbers (NIN). This is highly sensitive PII. Look at your Sales and Marketing teams. They have customer phone numbers, email addresses, and perhaps physical delivery addresses.
We must document where this data lives. Is it in an Excel sheet on a personal laptop? Is it in a physical filing cabinet in your Ikeja office? Is it on a cloud server hosted in the US? Under the NDPA 2023, you must know the location of your data. I suggest creating a 'Record of Processing Activities' (ROPA). This document lists what data you collect, why you collect it, where it is stored, and who has access to it. This forms the bedrock of your audit trail.
2. Define Your Lawful Basis for Processing
In the past, Nigerian firms relied almost exclusively on 'Consent'. They would put a tiny checkbox on a form and assume they were safe. The NDPA 2023 is more nuanced. I advise small companies to identify which of the six lawful bases applies to their specific activities. These include:
- Consent: The individual has given clear permission.
- Contract: You need the data to fulfil a contract (e.g., delivering a product).
- Legal Obligation: You need the data to comply with the law (e.g., FIRS tax filings or pension remittances).
- Vital Interests: To save someone's life.
- Public Task: Performing a task in the public interest.
- Legitimate Interests: Your company has a valid reason to use the data, provided it does not override the individual's rights.
I often find that small businesses can rely on 'Contract' or 'Legal Obligation' more often than 'Consent'. This reduces the administrative burden of managing consent withdrawal requests, which can be a nightmare for a small team.
3. Drafting Your Internal and External Policies
A policy is not just a document you copy and paste from the internet. I have seen companies use policies that mention the UK GDPR but ignore the Nigerian NDPC. Your policies must be 'fit for purpose'. You need two primary documents. First, an External Privacy Policy. This is the public-facing document on your website that tells the world how you treat their data. It must be written in plain, clear language. No legalese. No 'AI slop'.
Second, you need an Internal Data Handling Policy. This is for your staff. It should dictate how they handle passwords, whether they can use personal USB drives, and how they should report a data breach. I have witnessed small firms crumble because an employee lost a laptop containing an unencrypted database. Your policy must forbid the storage of PII on unencrypted local drives.
4. The March 15th Audit Deadline
Every small company needs to be aware of the annual compliance cycle. The NDPC requires 'Data Controllers and Processors of Major Importance' to file their annual audit reports. However, even if you do not meet the threshold of a 'Major Controller', the principle of accountability remains. The deadline for filing your annual audit report is March 15th of every year. This audit must be conducted by a licensed Data Protection Compliance Organisation (DPCO).
I recommend starting your internal review in January. Do not wait until March 10th to look for a DPCO. By then, the fees will be higher, and the quality of the audit will be lower. Filing this audit is your shield. If the NDPC ever investigates a complaint against you, the first thing they will ask for is your previous audit filings. If you have them, you are seen as a 'compliant entity'. If you do not, you are seen as negligent.
5. Implement Technical and Organisational Measures (TOMs)
Compliance is not just paperwork. It is also about locks and keys. For a small Nigerian company, I suggest the following 'quick wins':
- Encryption: Ensure all company laptops use full-disk encryption. If a laptop is stolen in traffic, the data remains safe.
- Two-Factor Authentication (2FA): Force 2FA on all company emails and cloud storage (Google Workspace, Microsoft 365). This stops 99% of basic hacking attempts.
- Physical Security: If you keep physical files, they must be in a locked room with restricted access. I have seen offices where the cleaner has more access to PII than the Managing Director. This must stop.
- Data Minimisation: Stop asking for data you do not need. Do you really need a customer's date of birth to sell them a pair of shoes? If not, do not collect it.
6. Managing Third-Party Risks
Small companies often outsource their IT, payroll, or marketing. Under the NDPA 2023, you are responsible for the data even when it is in the hands of a vendor. I advise my clients to sign a Data Processing Agreement (DPA) with every vendor. This agreement must state that the vendor will only use the data as instructed by you and that they have their own security measures in place. If your payroll provider has a breach and you do not have a DPA, the NDPC will hold YOU liable for the lack of 'due diligence'.
7. Staff Training and Culture
The weakest link in your security chain is likely the person sitting at the front desk. I have seen well-secured systems bypassed simply because a staff member clicked on a phishing link in a 'FIRS Tax Refund' email. You must conduct regular training sessions. These do not need to be expensive. A monthly 30-minute brief on how to spot suspicious emails and how to dispose of sensitive documents (use a shredder, not a bin) can save you millions in potential fines.
8. The Importance of Self-Assessment
Before you hire an expensive consultant or a DPCO, you should know where you stand. I strongly encourage all small business owners and compliance officers to perform a self-assessment. It gives you a clear picture of your gaps and prevents you from being overcharged by service providers. You can access a tailored self-assessment tool for small companies here: https://ndpr-gdpr-complianceassess.9jaoncloud.com/. Use this tool to generate a baseline report. It will help you prioritise your spending on the most critical risks first.
Conclusion
Implementing data protection policies in a small company is about building trust. In the Nigerian market, customers are becoming more aware of their rights. When you can prove that you handle data according to the NDPA 2023, you gain a competitive advantage. You are telling your clients that their privacy is safe with you. Compliance is not a 'once-a-year' event for the March 15th deadline; it is a daily commitment to integrity. Start with the data map, fix your policies, train your staff, and use the self-assessment tool to stay ahead of the regulators. We are moving into an era where data is the new currency, but only if you have the right vault to keep it in.