Data breach reporting under the NDPA
The main NDPA breach obligations, how the risk assessment works, and a response sequence and record template to prepare in advance.
Data protection law, sector rules, client contracts and cyber insurers all expect you to protect information properly and prove it. We help organisations understand the technical and operational side of those expectations, close the gaps and prepare the evidence. We work alongside your legal adviser; we do not give legal advice or certify compliance.
Compliance readiness means getting your privacy and security practices to the point where they meet the requirements that apply to you, and being able to show it. Promatics handles the technical and operational side: what data you hold, how it is protected, how breaches are handled, and what evidence exists. Your legal adviser interprets the law; independent bodies certify. We sit between the two and do the practical work.
These summaries are general and not legal advice. Your adviser should confirm what applies to you.
Many organisations need to satisfy someone other than a regulator. We prepare you for:
The first days after a breach are stressful, and decisions made then are hard to undo. A breach response plan sets out how an incident is contained, who assesses the risk to individuals, who decides on notification of the NDPC and of affected people, who speaks to your insurer and legal adviser, and how the breach record is kept. With a 72-hour window to notify the NDPC where a breach is likely to risk individuals' rights and freedoms, roles need to be clear before anything happens. We build the plan with you and rehearse it in a tabletop exercise.
Readiness work goes faster when roles are clear. Your legal adviser decides which obligations apply and how to read them. Your auditor or certification body decides whether you meet a standard. We translate their requirements into systems, procedures and evidence, flag questions that need a legal answer instead of guessing, and keep a traceable list showing each requirement, the control that meets it, its owner and where the evidence lives. That list becomes the working document for everyone involved, and it stays with you after we finish.
Readiness often reveals technical work. Security assessments measure your controls in depth, and our wider cybersecurity services close the gaps, including EDR, email security and awareness training.
The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.
Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.
Each stage ends with something you can review before the next one starts.
Identify which laws, sector rules, contracts and frameworks are likely to apply, and confirm them with your legal adviser.
Output: Requirements map.
Inventory what personal data you collect, why, where it lives, who can see it and how long it is kept.
Output: Data inventory and flow diagram.
Compare your technical and organisational safeguards with the requirements and rank the gaps by risk.
Output: Gap report and remediation plan.
Update controls, procedures, contracts and training, and build the breach response plan and register.
Output: Updated safeguards and breach plan.
Assemble the documents and records an auditor, insurer or regulator would ask for, and rehearse a breach scenario.
Output: Evidence pack and tabletop results.
We do not publish package prices. Each estimate is based on an agreed scope, in naira, with taxes shown separately. These are the things that move the number most:
No. We explain the technical and operational side of data protection and security requirements and help you put them into practice. Your legal adviser should confirm which obligations apply and how to interpret them, and we are happy to work with them.
In general terms, under the Nigeria Data Protection Act 2023 a controller must notify the NDPC within 72 hours of becoming aware of a breach likely to risk the rights and freedoms of individuals, and must tell affected people without undue delay where the risk is high. Operators of critical national information infrastructure have further incident-reporting duties. Read more in our breach reporting overview.
No. Certification and attestation, such as SOC 2 reports or ISO/IEC 27001 certificates, are issued by independent, accredited bodies. We help you get ready for them and gather the evidence they will ask for.
Not on its own. There is no major public cloud region in Nigeria, so the choice is usually a local data centre in Lagos or Abuja or a region abroad. Either can be appropriate, but compliance also depends on the NDPA's transfer rules, any sector rules, access controls, contracts, support access and how data is backed up and transferred. We review the whole picture.
Data protection obligations generally apply regardless of size when you handle personal data. The work scales down, and a small organisation usually needs a focused data inventory, a breach plan and a handful of well-run controls.
The main NDPA breach obligations, how the risk assessment works, and a response sequence and record template to prepare in advance.
A clear look at your security: what could go wrong, how likely it is, and what to fix first, explained in plain language.
Practical cybersecurity: assessments, endpoint protection, email security, training, incident readiness and 24/7 monitoring for managed-service clients.
Tell us what has been asked and what information you handle. We will reply to arrange a conversation about getting ready.