Skip to content
Izini
Enforcement

Nigeria's data regulator has collected over ₦7.2 billion in penalties and compliance revenue — fines now reach ₦10M or 2% of revenue, whichever is higher. NDPC fines reach ₦10M or 2% of revenue — over ₦7.2B collected.

See the record →
Product · Governance & Risk

RoPA, DPIAs and a risk register the regulator will recognise

Governance is where most Nigerian compliance programmes quietly fail — not because the controls are missing, but because nobody can produce the paperwork proving they exist. These modules are the paperwork, kept current as a by-product of doing the work.

01
NDPR · NDPA 2023

Privacy Policies

Generate a privacy notice that reflects what you actually do with personal data, published at your own URL and updated as your processing changes — rather than a PDF that went stale the week it was signed off.

  • Drafted from your RoPA entries, so the notice matches the processing you have recorded
  • Versioned with rollback, so you can show what the notice said on any given date
  • Published in your configured locales alongside the consent banner
02
Article 30 equivalent

RoPA Records of Processing

Your inventory of what personal data you hold, why, on what lawful basis and who you share it with. Upload a vendor contract and Izini drafts the RoPA entry for you to approve.

  • AI-assisted entry creation from contracts and data-sharing agreements
  • Lawful basis, retention period and recipient tracking per activity
  • Feeds directly into your CAR evidence pack
03
NDPA 2023 §28 · Schedule 4

Data Protection Impact Assessment (DPIA) Studio

Section 28 requires an impact assessment before high-risk processing. The studio walks the assessment, scores residual risk, and tells you whether the result crosses the threshold for prior consultation.

  • Guided assessment structured around the Schedule 4 criteria
  • Inherent and residual risk scoring with documented mitigations
  • Draft progress saved, so a DPIA can be built over weeks rather than one sitting
04
NDPA 2023 §28

NDPC Prior Consultation

When residual risk stays high after mitigation, section 28 requires you to consult the NDPC before proceeding. Izini assembles the consultation dossier from the DPIA rather than making you rewrite it.

  • Dossier assembled from the completed DPIA and risk register
  • Residual risk justification captured in the form the NDPC expects
  • Filing status tracked through to response
05
GAID Schedule 6 · Form VI-06

Data Subject Vulnerability Indexes Matrix

GAID asks you to assess how vulnerable your data subjects are — minors, health status, financial exposure, literacy, power imbalance — and to weight your controls accordingly.

  • Scoring across the Schedule 6 vulnerability dimensions
  • Feeds the DPIA, so high-vulnerability cohorts raise assessed risk automatically
  • Produces the Form VI-06 memo for your file
06
CAR-aligned · ISO 27701

Data Risk Assessment Register (DRAR)

A 5×5 risk register with inherent and residual scoring, treatment plans and CAPA tracking — so risk decisions are recorded rather than remembered.

  • 5×5 likelihood and impact heatmap across your processing activities
  • Inherent versus residual scoring, showing what your controls actually bought you
  • Corrective and preventive action tracking through to closure
07
NDPA 2023 §39 · CAR 2.3

Data Security System & MEM Schedule

Section 39 requires appropriate technical and organisational measures. The MEM schedule records them, along with the monitoring, evaluation and maintenance cycle that keeps them honest.

  • Technical and organisational measures documented against each system
  • Monitoring, evaluation and maintenance cadence with owners and dates
  • Disaster recovery and expert vetting records held alongside
08
NDPA 2023 §25 · §30

Lawful Basis Register

Every processing operation needs a lawful basis, and you have to be able to say which one and why. The register is a ledger of those determinations, audit-ready for your CAR.

  • Determinations across all six statutory bases under section 25(1)
  • Section 30 gating for sensitive personal data, which needs more than consent alone
  • Automatically flags where legitimate interests is claimed and an LIA is therefore required
09
NDPA 2023 §25(1)(f)

Legitimate Interests Assessment (LIA)

Legitimate interests is the basis regulators probe hardest, because it is the one where you decide your own interests outweigh the data subject’s. The LIA records that balancing test against the specific processing activity.

  • Purpose, necessity and balancing test recorded per activity
  • Attached to the RoPA entry it justifies, not filed separately
  • Surfaced from the lawful basis register whenever the basis is claimed
10
Data residency

Data Mapping & Lineage

Where personal data actually lives and where it flows, including the parts most Nigerian organisations lose track of: which assets stay in-country, and which quietly leave.

  • Assets classified by residency, including Tier-III in-country hosting
  • Special category data identified explicitly — BVN, biometrics and health
  • Cross-border lineage showing every point of international egress
11
NDPA 2023 · Schedule 4

Data Protection by Design & by Default

Privacy obligations enforced where engineering actually happens. Releases are gated on a DPIA where one is required, so a feature touching personal data cannot ship without the assessment.

  • Releases tracked per sprint with an approval gate in CI/CD
  • High-risk releases blocked pending the Schedule 4 assessment
  • Technical and organisational measures validated before sign-off
12
Continuous

Regulatory Updates & Clause Revisions

Nigerian data protection guidance is still moving. When it does, Izini drafts the specific clause revisions your policies need and routes them to your DPO, with the regulator citation attached.

  • Proposed revisions tied to the citation that prompted them
  • Target clause and replacement text drafted for review, not applied silently
  • DPO approval recorded before anything is published
13
Scheduled

Regulatory Discovery Automation

Scheduled monitoring for regulatory change, so the first you hear of a new NDPC directive is not a client asking whether you have complied with it.

  • Scheduled checks, or triggered manually when something breaks
  • Feeds the clause revision workflow directly
Book a demo

See it against your own compliance gaps.

We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.

  • A 30-minute walkthrough, no slides
  • A live cookie scan of your website, yours to keep
  • Straight answers on scope, timelines and pricing