News
Nigeria's data regulator has collected ₦7.2bn. What that means
The NDPC has concluded 246 investigations and says it will intensify enforcement through 2026. Registration is no longer a formality for Nigerian businesses.
Prem Kumar Dvivedi · 2026 оны есдүгээр сарын 12
The Nigeria Data Protection Commission has concluded 246 breach investigations and collected ₦7.2 billion in penalties, with 38,677 organisations registered. Eleven enforcement actions have followed those investigations, including a ₦766.2 million fine against MultiChoice Nigeria in July 2025 over data practices the Commission found intrusive and disproportionate.
Source: BusinessDay — NDPC concludes 246 investigations, generates ₦5.2bn revenue
What is coming
The Commission has said it intends to intensify enforcement against non-compliant organisations through 2026, with more investigations and more penalties. Fines under the Nigeria Data Protection Act reach ₦10 million or 2% of annual revenue, whichever is greater for the category of controller concerned. Reporting in early 2026 put more than a thousand firms under scrutiny for registration and audit obligations.
Source: AllAfrica — Nigeria targets 1,368 firms in landmark data protection crackdown
The practical reading
Two things have changed for a Nigerian business. Registration as a data controller is now the first thing a regulator checks rather than a formality, and the audit obligation that follows it is enforced. And the penalties are large enough, relative to the cost of compliance, that the arithmetic no longer favours waiting.
What an organisation needs is unglamorous: a record of what personal data it holds and why, a lawful basis recorded against each use, a retention schedule that is followed, a breach procedure with named responsibilities, and evidence that somebody reviews all of it. ISO/IEC 27701 packages exactly that and produces a certificate a regulator recognises as evidence of intent.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- ISO/IEC 27001:2022: documentation and compliance requirements
Everything ISO/IEC 27001:2022 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
2026 оны есдүгээр сарын 12
- ISO/IEC 27701:2025: documentation and compliance requirements
Everything ISO/IEC 27701:2025 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
2026 оны есдүгээр сарын 12
- India's DPDP consent manager rules bite in November 2026
Rule 4 of the DPDP Rules comes into force on 13 November 2026, with full compliance due by May 2027. What Indian businesses have to have ready.
2026 оны есдүгээр сарын 12
