Cybersecurity

Privacy and compliance readiness

Data protection law, sector rules, client contracts and cyber insurers all expect you to protect information properly and prove it. We help organisations understand the technical and operational side of those expectations, close the gaps and prepare the evidence. We work alongside your legal adviser; we do not give legal advice or certify compliance.

Who this service is for

A good fit if

  • You collect personal data and are not confident your practices would stand up to a complaint, an NDPC enquiry or a breach investigation.
  • You may need to register with the Nigeria Data Protection Commission (NDPC) as a data controller or processor of major importance, or need to appoint and support a data protection officer.
  • You handle health records or other sensitive personal data, for example as a clinic, laboratory, hospital or health-tech provider.
  • You are a bank, payment service provider, insurer, pension operator or capital-market operator, or you supply one, and need to meet CBN, NAICOM, PenCom or SEC Nigeria technology and cyber expectations.
  • A client, insurer or auditor has sent a security questionnaire, or you are preparing for SOC 2 or ISO/IEC 27001 certification.

Another approach may suit you better if

  • You need a legal opinion on your obligations. That must come from a lawyer; we can work with yours.
  • You need someone to certify or attest that you comply. That is done by independent, accredited bodies; we prepare you for them.
  • You want policies written only to file away. We focus on practices that actually operate.

What this service is

Compliance readiness means getting your privacy and security practices to the point where they meet the requirements that apply to you, and being able to show it. Promatics handles the technical and operational side: what data you hold, how it is protected, how breaches are handled, and what evidence exists. Your legal adviser interprets the law; independent bodies certify. We sit between the two and do the practical work.

Nigerian requirements we commonly prepare for

  • The Nigeria Data Protection Act 2023 (NDPA), the main data protection law, enforced by the Nigeria Data Protection Commission (NDPC). It covers lawful basis and consent, data subject rights, data protection officers, data protection impact assessments for high-risk processing, rules for transfers outside Nigeria, and breach notification.
  • The NDPC's General Application and Implementation Directive (GAID) 2025, which sets out how the NDPA applies in practice, including registration of data controllers and processors of major importance.
  • Health data, which the NDPA treats as sensitive personal data, together with the confidentiality duties in the National Health Act 2014, for clinics, laboratories, hospitals and health-tech providers.
  • Central Bank of Nigeria (CBN) cybersecurity framework and guidelines, for banks and payment service providers, and the requirements of SEC Nigeria, NAICOM and PenCom for capital-market operators, insurers and pension operators, together with the vendors that serve them.
  • Direct marketing rules, where email and SMS marketing and consent practices are part of the review: the NDPA's consent rules and the Nigerian Communications Commission's rules on unsolicited messages.

These summaries are general and not legal advice. Your adviser should confirm what applies to you.

Frameworks, audits and insurers

Many organisations need to satisfy someone other than a regulator. We prepare you for:

  • ISO/IEC 27001 and SOC 2, often requested by enterprise and international clients. Reports and certificates come from independent auditors and registrars.
  • Sector cybersecurity assessments, such as those a bank, insurer or other regulated client may require of its suppliers.
  • Cyber insurance questionnaires, which commonly ask about MFA, EDR, backups, email security and training.
  • Client security questionnaires and contract clauses on data location, breach notification and subcontractors.

Breach readiness

The first days after a breach are stressful, and decisions made then are hard to undo. A breach response plan sets out how an incident is contained, who assesses the risk to individuals, who decides on notification of the NDPC and of affected people, who speaks to your insurer and legal adviser, and how the breach record is kept. With a 72-hour window to notify the NDPC where a breach is likely to risk individuals' rights and freedoms, roles need to be clear before anything happens. We build the plan with you and rehearse it in a tabletop exercise.

Readiness work goes faster when roles are clear. Your legal adviser decides which obligations apply and how to read them. Your auditor or certification body decides whether you meet a standard. We translate their requirements into systems, procedures and evidence, flag questions that need a legal answer instead of guessing, and keep a traceable list showing each requirement, the control that meets it, its owner and where the evidence lives. That list becomes the working document for everyone involved, and it stays with you after we finish.

Connected services

Readiness often reveals technical work. Security assessments measure your controls in depth, and our wider cybersecurity services close the gaps, including EDR, email security and awareness training.

What is included

The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.

Typical deliverables

  • A map of the laws, rules, contracts and frameworks that likely apply, confirmed with your legal adviser.
  • An inventory of the personal data you hold, where it is stored, who can access it and how long it is kept.
  • A gap review of technical and organisational safeguards against the applicable requirements.
  • A prioritised remediation plan, with owners and effort estimates.
  • A breach response plan, including how breaches are assessed for risk to individuals' rights and freedoms, who decides on notification, how the 72-hour NDPC window is managed, and how records are kept.
  • A breach record register that shows how each incident was assessed and handled.
  • Review of vendor and cloud contracts for security, data location, cross-border transfer and breach notification terms.
  • Support for data protection impact assessments, including for transfers of personal data outside Nigeria.
  • Evidence packs and help answering client, insurer and auditor questionnaires.

Not included unless agreed separately

  • Legal advice or legal opinions.
  • Certification, attestation or audit reports.
  • Filing breach reports or notifying individuals on your behalf.
  • Fixing technical findings, unless included in the scope or delivered under a separate agreement.

What we will need from you

Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.

  • A named person accountable for data protection in your organisation (often required by law in any case).
  • Access to your legal adviser for questions of interpretation.
  • Existing policies, contracts, insurer questionnaires and past incident records.
  • Time with the people who manage IT, HR, finance and client records.
Delivery

How the work is delivered

Each stage ends with something you can review before the next one starts.

  1. Scope the requirements

    Identify which laws, sector rules, contracts and frameworks are likely to apply, and confirm them with your legal adviser.

    Output: Requirements map.

  2. Understand your data

    Inventory what personal data you collect, why, where it lives, who can see it and how long it is kept.

    Output: Data inventory and flow diagram.

  3. Review the gaps

    Compare your technical and organisational safeguards with the requirements and rank the gaps by risk.

    Output: Gap report and remediation plan.

  4. Close the gaps

    Update controls, procedures, contracts and training, and build the breach response plan and register.

    Output: Updated safeguards and breach plan.

  5. Prepare the evidence

    Assemble the documents and records an auditor, insurer or regulator would ask for, and rehearse a breach scenario.

    Output: Evidence pack and tabletop results.

Testing and handover

  • Every requirement in scope is traced to a control, an owner and evidence.
  • Gaps that remain open are listed with an owner and target date, not hidden.
  • The breach response plan is rehearsed with the people who would use it.
  • Legal interpretations are marked as questions for your legal adviser, not answered by us.
  • Documents are written for your staff to maintain after we finish.

What affects the cost

We do not publish package prices. Each estimate is based on an agreed scope, in naira, with taxes shown separately. These are the things that move the number most:

  • The number of laws, rules and frameworks in scope.
  • The amount and sensitivity of personal data you hold.
  • The number of systems, vendors and locations.
  • How much evidence and documentation already exists.
  • Whether remediation is included or handled separately.

Questions buyers usually ask

Is this legal advice?

No. We explain the technical and operational side of data protection and security requirements and help you put them into practice. Your legal adviser should confirm which obligations apply and how to interpret them, and we are happy to work with them.

What does the NDPA require after a breach?

In general terms, under the Nigeria Data Protection Act 2023 a controller must notify the NDPC within 72 hours of becoming aware of a breach likely to risk the rights and freedoms of individuals, and must tell affected people without undue delay where the risk is high. Operators of critical national information infrastructure have further incident-reporting duties. Read more in our breach reporting overview.

Can you certify that we comply?

No. Certification and attestation, such as SOC 2 reports or ISO/IEC 27001 certificates, are issued by independent, accredited bodies. We help you get ready for them and gather the evidence they will ask for.

Does hosting our data in a particular country or data centre make us compliant?

Not on its own. There is no major public cloud region in Nigeria, so the choice is usually a local data centre in Lagos or Abuja or a region abroad. Either can be appropriate, but compliance also depends on the NDPA's transfer rules, any sector rules, access controls, contracts, support access and how data is backed up and transferred. We review the whole picture.

We are a small organisation. Does this apply to us?

Data protection obligations generally apply regardless of size when you handle personal data. The work scales down, and a small organisation usually needs a focused data inventory, a breach plan and a handful of well-run controls.

Has a client, insurer or regulator started asking questions?

Tell us what has been asked and what information you handle. We will reply to arrange a conversation about getting ready.