43 compliance modules. One platform. Built for Nigerian law.
Most privacy tools are GDPR products with Nigeria bolted on. Izini is built the other way round — every module maps to a section of the NDPA 2023, the GAID 2025 implementation directive, or the Compliance Audit Return you file with the NDPC each year.
Consent management built for Nigerian regulation
Consent under the NDPA is not a banner — it is a burden of proof. Izini captures consent across web, mobile and backend systems, then keeps the evidence you need to show the NDPC that every record was freely given, specific and revocable.
Data Consent Register & Evidentiary Ledger
Section 26 places the burden of proof on you: if a data subject disputes that they consented, you have to show it. The register keeps a timestamped, immutable record of every opt-in, change and revocation.
Consent Banner Studio & Customizer
Design the banner to match your brand without touching code, and publish changes without a redeploy. Preview exactly what a visitor sees before it goes live.
Cookie Scanner & Tracker Inventory
Non-transparent cookies are part of what cost Fidelity Bank ₦555.8 million in 2024. Izini scans your site, finds every cookie and tracker actually in use, and classifies each one, so your banner only ever declares the cookies you genuinely set.
Consent Translations
Consent is only valid if it is understood. Izini serves the banner in English, Yorùbá, Igbo, Hausa and Nigerian Pidgin, with translations generated for you and editable where you want a different phrasing.
Universal Consent Topics
Consent does not stop at the website. Define topics once — marketing email, SMS, profiling, data sharing — and apply them consistently across every channel and product surface.
CMP Installation & Mobile SDKs
Three lines of script on the web, or a native SDK on mobile. Bundle-ID registration means only your own apps can pull your configuration.
Universal Webhooks & Backend Signals
A consent decision is useless if your CRM never hears about it. Every change fires a signed webhook to your own systems, with a delivery log so you can prove it arrived.
Consent Analytics & Intelligence
Opt-in rates by category, language and channel — so you can see where consent is being lost, and show an auditor how consent actually behaves across your estate.
DSAR handling and grievances, on the statutory clock
A data subject request starts a clock you cannot pause. Izini registers every request, verifies the person behind it, and keeps a defensible record of exactly what you did and when — without your team touching raw personal data more than it has to.
Data Subject Rights (DSAR) Register
Every access, rectification, erasure and portability request in one register, with identity verification before anything is disclosed and a full event stream behind each case.
SNAG Grievances Desk
GAID expects a pre-complaint route: a data subject should be able to raise a grievance with you before escalating to the NDPC. The SNAG desk gives you that channel and records how each one was resolved.
RoPA, DPIAs and a risk register the regulator will recognise
Governance is where most Nigerian compliance programmes quietly fail — not because the controls are missing, but because nobody can produce the paperwork proving they exist. These modules are the paperwork, kept current as a by-product of doing the work.
Privacy Policies
Generate a privacy notice that reflects what you actually do with personal data, published at your own URL and updated as your processing changes — rather than a PDF that went stale the week it was signed off.
RoPA Records of Processing
Your inventory of what personal data you hold, why, on what lawful basis and who you share it with. Upload a vendor contract and Izini drafts the RoPA entry for you to approve.
Data Protection Impact Assessment (DPIA) Studio
Section 28 requires an impact assessment before high-risk processing. The studio walks the assessment, scores residual risk, and tells you whether the result crosses the threshold for prior consultation.
NDPC Prior Consultation
When residual risk stays high after mitigation, section 28 requires you to consult the NDPC before proceeding. Izini assembles the consultation dossier from the DPIA rather than making you rewrite it.
Data Subject Vulnerability Indexes Matrix
GAID asks you to assess how vulnerable your data subjects are — minors, health status, financial exposure, literacy, power imbalance — and to weight your controls accordingly.
Data Risk Assessment Register (DRAR)
A 5×5 risk register with inherent and residual scoring, treatment plans and CAPA tracking — so risk decisions are recorded rather than remembered.
Data Security System & MEM Schedule
Section 39 requires appropriate technical and organisational measures. The MEM schedule records them, along with the monitoring, evaluation and maintenance cycle that keeps them honest.
Lawful Basis Register
Every processing operation needs a lawful basis, and you have to be able to say which one and why. The register is a ledger of those determinations, audit-ready for your CAR.
Legitimate Interests Assessment (LIA)
Legitimate interests is the basis regulators probe hardest, because it is the one where you decide your own interests outweigh the data subject’s. The LIA records that balancing test against the specific processing activity.
Data Mapping & Lineage
Where personal data actually lives and where it flows, including the parts most Nigerian organisations lose track of: which assets stay in-country, and which quietly leave.
Data Protection by Design & by Default
Privacy obligations enforced where engineering actually happens. Releases are gated on a DPIA where one is required, so a feature touching personal data cannot ship without the assessment.
Regulatory Updates & Clause Revisions
Nigerian data protection guidance is still moving. When it does, Izini drafts the specific clause revisions your policies need and routes them to your DPO, with the regulator citation attached.
Regulatory Discovery Automation
Scheduled monitoring for regulatory change, so the first you hear of a new NDPC directive is not a client asking whether you have complied with it.
File your Compliance Audit Return without the annual scramble
If you process the personal data of more than 2,000 people you are a data controller of major importance, and the annual return is not optional — it is filed with the NDPC through a licensed DPCO. Izini keeps your policies, consent logs, RoPA entries and risk decisions organised as you go, so filing is an export rather than six weeks of archaeology.
DPO Designation & Statutory Register
A DCPMI must have a designated Data Protection Officer, and must be able to evidence it. The register holds the board appointment, the NDPC registration and the statutory deadlines in one place.
DPO Accreditation & Competency (ACA)
It is not enough to name a DPO — Schedule 3 asks whether they are actually qualified. The ACA workspace keeps the certifications, CPD and accreditation standing that answer that question.
Compliance Audit Workbench
A live view of how ready you actually are, mapped to the sections of the Compliance Audit Return, with the gaps called out while there is still time to close them.
CAR Master Evidence Pack Exporter
Assembles every artefact your DPCO or the NDPC will ask for into a single manifest-indexed archive, so nothing is missing and nothing has to be chased.
Statutory Regulatory Fee & Penalty Calculator
Works out what you actually owe under Schedule 10 — CAR fees, DCPMI, late surcharges — and produces the Remita reference so payment is not the thing that makes you late.
Your processors are your exposure
Section 29 makes you responsible for the processors you appoint. If your payroll provider leaks, the NDPC comes to you. These modules make that relationship documented rather than assumed.
Vendor Due Diligence (DDQ)
A structured due diligence questionnaire per vendor, with their security posture captured and re-assessed rather than taken on trust at procurement and never revisited.
Vendor DPAs
Every data processing agreement in one place, linked to the vendor and the processing activities it actually covers — so you can answer "is this covered?" in seconds.
Sub-Processor Register
Your processors appoint their own processors, and you remain answerable for the whole chain. The register tracks it, including the substitutions that happen at short notice.
Cross-Border Transfer Assessments (TIA)
This is what the NDPC fined MultiChoice Nigeria ₦766 million for in 2025 — transferring subscriber data abroad without adequate safeguards. Most Nigerian businesses run on infrastructure hosted elsewhere, and section 41 requires an adequacy basis or a documented assessment for each one.
The obligations that point inward, not at your customers
Sections 24 and 25 are the obligations most organisations forget, because they are about your own staff rather than your customers. They are also among the easiest for an auditor to test — and the fastest to fail.
Data Protection Training, Awareness & Sensitization
Run training campaigns across your workforce and keep the evidence that each person actually completed them — which is the part that matters when the CAR asks.
Employee Privacy Notices & Handbooks
Your staff are data subjects too. Generate the notices covering HR records, payroll, pension, CCTV and workplace monitoring, and record that they were issued.
Basic Privacy Checklist & Workforce Evaluation Studio
GAID's Basic Privacy Checklist is the plain-language do's and don'ts your workforce is measured against. The studio runs the evaluation and produces the form.
The 72-hour clock starts the moment you know
Under the NDPA you have 72 hours from becoming aware of a breach to notify the NDPC where it is likely to risk individuals’ rights. The hard part is rarely the notification — it is deciding whether the threshold was crossed, and proving afterwards that you decided properly.
Incident Response Center & Remediation Desk
Starts the statutory clock automatically, walks the threshold assessment, and keeps a timestamped record of every decision and action taken from detection to closeout.
See your whole client book in one place
If you resell or administer Izini for client organisations, the Partner Channel Portal is where you see your book: who is on which plan, how much of their allowance they have used, and who is about to lapse. Each client’s compliance work happens in their own workspace — this is the commercial layer over the top of it.
Client Portfolio
Every organisation assigned to you in one list, searchable and filterable by standing, so you are not logging into accounts one at a time to find out where things stand.
Renewal & Expiry Tracking
Which licences lapse when, so renewals are a pipeline you work rather than a client going quiet and later discovering they were suspended.
Usage Across the Book
Consumption per client and across the whole portfolio, so you can see who is outgrowing their plan before the overage conversation happens.
A compliance API, not just a dashboard
Compliance fails at the integration boundary. Handling a DSAR properly means reaching into the systems that actually hold the data — your core banking platform, your CRM, your warehouse. These are the interfaces for doing that without exporting raw personal data into a spreadsheet.
DSAR API & Reference
Raise, track and fulfil data subject requests programmatically, so your own systems participate in the workflow rather than someone copying results between screens.
Authentication & Key Management
Project-scoped API keys, hashed at rest and revocable without disturbing your other integrations.
Integration Sandbox
A console for firing real requests at the gateway with a synthetic identifier, so you can watch your own handler respond to an erasure or access request before a live customer raises one.
Blueprints & Signed Webhooks
Reference patterns for common Nigerian stacks, plus signed webhooks so your backend hears about consent and DSAR events as they happen.
See it against your own compliance gaps.
We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.
- A 30-minute walkthrough, no slides
- A live cookie scan of your website, yours to keep
- Straight answers on scope, timelines and pricing