Consent management built for Nigerian regulation
Consent under the NDPA is not a banner — it is a burden of proof. Izini captures consent across web, mobile and backend systems, then keeps the evidence you need to show the NDPC that every record was freely given, specific and revocable.
Data Consent Register & Evidentiary Ledger
Section 26 places the burden of proof on you: if a data subject disputes that they consented, you have to show it. The register keeps a timestamped, immutable record of every opt-in, change and revocation.
- Consent receipts capturing what was shown, in which language, and what was agreed
- Full revocation history — consent is only valid while it can be withdrawn as easily as it was given
- Exportable as evidence for a Compliance Audit Return or an NDPC enquiry
Consent Banner Studio & Customizer
Design the banner to match your brand without touching code, and publish changes without a redeploy. Preview exactly what a visitor sees before it goes live.
- Full control of colours, copy, layout and placement
- Draft and published versions, so edits are never live until you say so
- Works alongside the IAB Transparency & Consent Framework for ad-tech vendors
Cookie Scanner & Tracker Inventory
Non-transparent cookies are part of what cost Fidelity Bank ₦555.8 million in 2024. Izini scans your site, finds every cookie and tracker actually in use, and classifies each one, so your banner only ever declares the cookies you genuinely set.
- Automatic classification into necessary, analytics, marketing, functional and security
- Enriched against the IAB Global Vendor List and the Open Cookie Database
- Script blocking until the visitor has given consent for that category
Consent Translations
Consent is only valid if it is understood. Izini serves the banner in English, Yorùbá, Igbo, Hausa and Nigerian Pidgin, with translations generated for you and editable where you want a different phrasing.
- Machine translation with a shared cache, so repeated phrases stay consistent
- Manual overrides that are never overwritten by a later automatic pass
- Per-project locale configuration
Universal Consent Topics
Consent does not stop at the website. Define topics once — marketing email, SMS, profiling, data sharing — and apply them consistently across every channel and product surface.
- One topic definition reused across web, mobile and backend systems
- Per-topic revocability, so mandatory processing is never presented as a choice
- Category mapping that keeps topics aligned with your banner
CMP Installation & Mobile SDKs
Three lines of script on the web, or a native SDK on mobile. Bundle-ID registration means only your own apps can pull your configuration.
- Direct script embed or Google Tag Manager
- Native iOS, Android and Flutter integration
- Registered bundle IDs per project, so configuration cannot be scraped by another app
Universal Webhooks & Backend Signals
A consent decision is useless if your CRM never hears about it. Every change fires a signed webhook to your own systems, with a delivery log so you can prove it arrived.
- HMAC SHA-256 signatures on every delivery, so your endpoint can verify authenticity
- Delivery logs with response status and duration for every attempt
- Subscribe per event type, or to everything
Consent Analytics & Intelligence
Opt-in rates by category, language and channel — so you can see where consent is being lost, and show an auditor how consent actually behaves across your estate.
- Acceptance and rejection rates broken down by category and locale
- Trends over time, to evidence that consent rates are not being manufactured
- Per-project and per-organisation views
Explore the rest of the platform
DSAR handling and grievances, on the statutory clock
A DSAR register under section 34 and a SNAG grievance desk under GAID Schedule 9.
Governance & RiskRoPA, DPIAs and a risk register the regulator will recognise
Records of processing, impact assessments, vulnerability indexes and a 5×5 risk register.
Audit & ReportingFile your Compliance Audit Return without the annual scramble
Audit workbench, CAR evidence pack exporter and the statutory fee calculator.
Third-Party RiskYour processors are your exposure
Vendor due diligence under §29, processor DPAs and cross-border transfer assessments.
WorkforceThe obligations that point inward, not at your customers
Staff training under §24, employee privacy notices and the Basic Privacy Checklist.
For PartnersSee your whole client book in one place
Client portfolio, licence renewals and usage for channel partners and resellers.
DevelopersA compliance API, not just a dashboard
DSAR API, sandbox, integration blueprints and signed webhooks.
Incident ResponseThe 72-hour clock starts the moment you know
Breach assessment, NDPC notification and remediation through to root cause.
See it against your own compliance gaps.
We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.
- A 30-minute walkthrough, no slides
- A live cookie scan of your website, yours to keep
- Straight answers on scope, timelines and pricing