NDPR
Market regime · Nigeria Data Protection Regulation 2019
NITDA (now administered under the NDPC regime)
Nigeria
Issued 2019; NDPA 2023 now leads the regime
NDPC (originally NITDA), with audits filed through DPCOs
Organisations with obligations or filings that still reference the 2019 regulation
Curated, versioned & cross-mapped
The obligation, plainly.
The NDPR was Nigeria's first broadly enforced data-protection regime, and years of audit filings, contracts and policies were built against it. The NDPA 2023 now leads, but NDPR references have not vanished from diligence questionnaires or legacy obligations.
We curate both, cross-mapped to the same controls, so organisations can answer legacy NDPR questions and current NDPA obligations from one implementation, and retire the old mapping deliberately rather than by accident.
Where programmes are tested.
The 2019 obligations
Consent and lawful processing, data-subject rights, and the audit-filing regime built around DPCOs.
Continuity to the NDPA
Knowing which legacy commitments still bind, and where the Act has superseded them.
Curated once, evidenced continuously.
- NDPR and NDPA are curated side by side and resolve to one shared privacy control set, so the transition is a mapping change, not a rebuild.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
NDPR, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Is the NDPR still in force?
The NDPA 2023 now leads Nigeria's data-protection regime, but the NDPR and its implementation framework did not vanish: filings, contracts and diligence questionnaires built on it persist, and the GAID 2025 directive is consolidating the transition. Treat it as legacy that still gets cited.
What was the DPCO audit regime?
Organisations above processing thresholds filed annual data-protection audit returns through licensed Data Protection Compliance Organisations. Years of those filings exist, and legacy commitments made in them still surface in due diligence.
What is the difference between the NDPR and the NDPA?
The NDPR is a 2019 regulation issued by NITDA; the NDPA is a 2023 Act of the National Assembly that created the NDPC and put the regime on statutory footing with clearer duties and penalties. The Act supersedes, but the regulation's vocabulary lingers.
Why keep NDPR mapped if the NDPA supersedes it?
Because questionnaires, contracts and old commitments still reference it. Curating both against one shared control set lets you answer legacy NDPR questions and current NDPA obligations from a single implementation, and retire the old mapping deliberately.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.