HomeAboutResourcesGET IN TOUCH
Cybersecurity

Cybersecurity Compliance in 2025–2026: NDPC, GDPR, and What African Businesses Must Know

AD

Adewale

Network Engineer

January 20269 min read

With Nigeria's Data Protection Commission actively enforcing the NDPA and UK/EU-based operations subject to GDPR, the compliance landscape is increasingly complex. We break it down into actionable steps.

01

A New Enforcement Reality

The Nigeria Data Protection Act 2023 (NDPA) came into force with the establishment of the Nigeria Data Protection Commission (NDPC), which has since moved from awareness-raising to active enforcement. Organisations processing personal data of Nigerian residents — whether based in Lagos or London — are subject to its requirements. The NDPC has made clear that cross-border data transfers, consent mechanisms, and data breach notification are priority areas for investigation.

Simultaneously, African enterprises with UK or EU operations remain subject to GDPR and the UK GDPR (now codified in the UK Data Protection Act 2018). For a pan-African business with offices in Nigeria, Cameroon, Rwanda, and the UK, the compliance picture is genuinely complex — multiple regulators, overlapping obligations, and different enforcement timelines.

02

NDPA: What Organisations Must Have in Place

At its core, the NDPA requires a lawful basis for every processing activity, meaningful consent mechanisms where applicable, and data subject rights that must be fulfilled within defined timeframes. Organisations processing significant volumes of personal data must appoint a Data Protection Officer (DPO) and register with the NDPC.

Data Protection Impact Assessments (DPIAs) are mandatory before commencing high-risk processing activities — including the use of AI-driven profiling, large-scale employee monitoring, and systematic processing of sensitive data categories such as health or biometric information. Many organisations have not yet performed DPIAs for their existing processing activities, which represents immediate risk.

Breach notification is the area where enforcement is most likely to create headlines. Under the NDPA, a personal data breach must be reported to the NDPC within 72 hours of discovery — matching the GDPR timeline. Organisations without a documented incident response plan and a tested breach notification procedure are not compliant with this requirement.

03

GDPR Obligations That Are Frequently Missed

Despite GDPR being in force since 2018, several obligations remain routinely unaddressed. Records of Processing Activities (ROPA) — a documented inventory of every data processing activity — are required under Article 30 for organisations with 250 or more employees, but also recommended for smaller organisations. The ROPA is often the first document a regulator requests after an incident.

Legitimate interests assessments (LIAs) are frequently relied upon as a lawful basis without the requisite three-part balancing test being documented. Organisations using legitimate interests for marketing, analytics, or fraud prevention need a formal LIA for each use case. Without it, the lawful basis cannot be substantiated if challenged.

Vendor management is another gap. Under GDPR Article 28, every third party that processes personal data on your behalf must be covered by a Data Processing Agreement (DPA). Many organisations have not audited their vendor lists recently enough to ensure all new SaaS tools, analytics platforms, and cloud services are covered.

04

Practical Steps for 2026

Start with a data mapping exercise — understand what personal data you hold, where it flows, what lawful basis applies, and who has access. This foundation supports every other compliance activity. Many organisations skip this step and then struggle to respond to subject access requests or breach notifications because they cannot locate the relevant data quickly.

Implement technical controls that support your compliance obligations: encryption at rest and in transit, access controls aligned to least privilege, audit logging for all sensitive data access, and automated data retention policies. These controls satisfy both NDPA and GDPR technical requirements and will be reviewed by any competent regulator.

Document everything. Regulators under both the NDPA and GDPR can request documentation of your compliance programme at any time. An organisation that has solid controls but poor documentation is in almost as weak a position as one that has neither. Policies, procedures, training records, DPIA reports, and ROPA entries should all be current and accessible.

Work with Limesoft

Need help applying these insights to your organisation?

Our certified engineers have delivered projects across Africa and the UK. Let's talk about your specific situation.