RoPA, DPIAs and a risk register the regulator will recognise
Governance is where most Nigerian compliance programmes quietly fail — not because the controls are missing, but because nobody can produce the paperwork proving they exist. These modules are the paperwork, kept current as a by-product of doing the work.
Privacy Policies
Generate a privacy notice that reflects what you actually do with personal data, published at your own URL and updated as your processing changes — rather than a PDF that went stale the week it was signed off.
- Drafted from your RoPA entries, so the notice matches the processing you have recorded
- Versioned with rollback, so you can show what the notice said on any given date
- Published in your configured locales alongside the consent banner
RoPA Records of Processing
Your inventory of what personal data you hold, why, on what lawful basis and who you share it with. Upload a vendor contract and Izini drafts the RoPA entry for you to approve.
- AI-assisted entry creation from contracts and data-sharing agreements
- Lawful basis, retention period and recipient tracking per activity
- Feeds directly into your CAR evidence pack
Data Protection Impact Assessment (DPIA) Studio
Section 28 requires an impact assessment before high-risk processing. The studio walks the assessment, scores residual risk, and tells you whether the result crosses the threshold for prior consultation.
- Guided assessment structured around the Schedule 4 criteria
- Inherent and residual risk scoring with documented mitigations
- Draft progress saved, so a DPIA can be built over weeks rather than one sitting
NDPC Prior Consultation
When residual risk stays high after mitigation, section 28 requires you to consult the NDPC before proceeding. Izini assembles the consultation dossier from the DPIA rather than making you rewrite it.
- Dossier assembled from the completed DPIA and risk register
- Residual risk justification captured in the form the NDPC expects
- Filing status tracked through to response
Data Subject Vulnerability Indexes Matrix
GAID asks you to assess how vulnerable your data subjects are — minors, health status, financial exposure, literacy, power imbalance — and to weight your controls accordingly.
- Scoring across the Schedule 6 vulnerability dimensions
- Feeds the DPIA, so high-vulnerability cohorts raise assessed risk automatically
- Produces the Form VI-06 memo for your file
Data Risk Assessment Register (DRAR)
A 5×5 risk register with inherent and residual scoring, treatment plans and CAPA tracking — so risk decisions are recorded rather than remembered.
- 5×5 likelihood and impact heatmap across your processing activities
- Inherent versus residual scoring, showing what your controls actually bought you
- Corrective and preventive action tracking through to closure
Data Security System & MEM Schedule
Section 39 requires appropriate technical and organisational measures. The MEM schedule records them, along with the monitoring, evaluation and maintenance cycle that keeps them honest.
- Technical and organisational measures documented against each system
- Monitoring, evaluation and maintenance cadence with owners and dates
- Disaster recovery and expert vetting records held alongside
Lawful Basis Register
Every processing operation needs a lawful basis, and you have to be able to say which one and why. The register is a ledger of those determinations, audit-ready for your CAR.
- Determinations across all six statutory bases under section 25(1)
- Section 30 gating for sensitive personal data, which needs more than consent alone
- Automatically flags where legitimate interests is claimed and an LIA is therefore required
Legitimate Interests Assessment (LIA)
Legitimate interests is the basis regulators probe hardest, because it is the one where you decide your own interests outweigh the data subject’s. The LIA records that balancing test against the specific processing activity.
- Purpose, necessity and balancing test recorded per activity
- Attached to the RoPA entry it justifies, not filed separately
- Surfaced from the lawful basis register whenever the basis is claimed
Data Mapping & Lineage
Where personal data actually lives and where it flows, including the parts most Nigerian organisations lose track of: which assets stay in-country, and which quietly leave.
- Assets classified by residency, including Tier-III in-country hosting
- Special category data identified explicitly — BVN, biometrics and health
- Cross-border lineage showing every point of international egress
Data Protection by Design & by Default
Privacy obligations enforced where engineering actually happens. Releases are gated on a DPIA where one is required, so a feature touching personal data cannot ship without the assessment.
- Releases tracked per sprint with an approval gate in CI/CD
- High-risk releases blocked pending the Schedule 4 assessment
- Technical and organisational measures validated before sign-off
Regulatory Updates & Clause Revisions
Nigerian data protection guidance is still moving. When it does, Izini drafts the specific clause revisions your policies need and routes them to your DPO, with the regulator citation attached.
- Proposed revisions tied to the citation that prompted them
- Target clause and replacement text drafted for review, not applied silently
- DPO approval recorded before anything is published
Regulatory Discovery Automation
Scheduled monitoring for regulatory change, so the first you hear of a new NDPC directive is not a client asking whether you have complied with it.
- Scheduled checks, or triggered manually when something breaks
- Feeds the clause revision workflow directly
Explore the rest of the platform
Consent management built for Nigerian regulation
Banner, cookie scanning, mobile SDKs and an evidentiary consent register.
Data Subject RightsDSAR handling and grievances, on the statutory clock
A DSAR register under section 34 and a SNAG grievance desk under GAID Schedule 9.
Audit & ReportingFile your Compliance Audit Return without the annual scramble
Audit workbench, CAR evidence pack exporter and the statutory fee calculator.
Third-Party RiskYour processors are your exposure
Vendor due diligence under §29, processor DPAs and cross-border transfer assessments.
WorkforceThe obligations that point inward, not at your customers
Staff training under §24, employee privacy notices and the Basic Privacy Checklist.
For PartnersSee your whole client book in one place
Client portfolio, licence renewals and usage for channel partners and resellers.
DevelopersA compliance API, not just a dashboard
DSAR API, sandbox, integration blueprints and signed webhooks.
Incident ResponseThe 72-hour clock starts the moment you know
Breach assessment, NDPC notification and remediation through to root cause.
See it against your own compliance gaps.
We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.
- A 30-minute walkthrough, no slides
- A live cookie scan of your website, yours to keep
- Straight answers on scope, timelines and pricing