The Nigeria Data Protection Act 2023 made one thing unambiguous: handing personal data to a vendor does not hand off your responsibility for it. If your processor mishandles data, the obligation, and the exposure, is still yours. Here's how to manage third parties so that's a position you can defend.
Controller, processor, and where liability sits
Most regulated organisations are data controllers: you decide why and how personal data is processed. The vendors who process it on your behalf, your cloud provider, your KYC partner, your HR or payroll system, are data processors. Under the NDPA, a controller must only use processors that provide sufficient guarantees to meet the Act's requirements, and must hold them to those guarantees in a contract.
In practice this means you cannot simply trust a vendor's marketing. You have to assess them, bind them contractually, and keep evidence that you did.
Due diligence: assess before you onboard
Before a vendor touches personal data, you should understand:
- What personal data they'll process, for what purpose, and where it will be stored.
- Their security posture, access controls, encryption, breach history, certifications.
- Any onward transfers, including cross-border, and the safeguards in place.
- Their own sub-processors, and whether you're notified of changes.
A questionnaire-based assessment, scored into a risk tier, is the standard mechanism, but it only protects you if it's on the record and repeated on a cadence, not filed once and forgotten.
The breach clock runs through your vendors
The NDPA's breach-notification timelines don't pause because the breach happened at a processor. If your vendor is breached, your obligation to assess and notify can be triggered, often on a tight clock. That makes two things essential: a contractual duty on the vendor to tell youfast, and your own ability to act on that notice without scrambling.
Ongoing monitoring, not one-and-done
Vendor risk is not a point-in-time event. Tiers should drive a reassessment cadence; contracts and certifications (a current SOC 2 report, for example) have expiry dates worth tracking; and a vendor that materially changes what it does with your data should trigger a fresh look. The goal is that at any moment you can show who processes your data, under what terms, and when you last checked.
What “defensible” looks like
When the regulator, or a customer's security team, asks about a third party, you want to produce:
- The completed assessment and the risk tier it produced.
- The executed data-processing terms.
- The evidence on file (certifications, attestations) and its validity dates.
- The date of the last review and when the next one is due.
The NDPA didn't make vendor management harder so much as it made the consequences explicit. Treat third parties as an extension of your own control environment, assessed, contracted, monitored, and evidenced, and the obligation you can't outsource becomes one you can stand behind.