Skip to content
Izini
Enforcement

Nigeria's data regulator has collected over ₦7.2 billion in penalties and compliance revenue — fines now reach ₦10M or 2% of revenue, whichever is higher. NDPC fines reach ₦10M or 2% of revenue — over ₦7.2B collected.

See the record →
The platform

43 compliance modules. One platform. Built for Nigerian law.

Most privacy tools are GDPR products with Nigeria bolted on. Izini is built the other way round — every module maps to a section of the NDPA 2023, the GAID 2025 implementation directive, or the Compliance Audit Return you file with the NDPC each year.

43Modules
9Compliance areas
5Nigerian languages
Consent & CMP

Consent management built for Nigerian regulation

Consent under the NDPA is not a banner — it is a burden of proof. Izini captures consent across web, mobile and backend systems, then keeps the evidence you need to show the NDPC that every record was freely given, specific and revocable.

Explore Consent & CMP →

NDPA 2023 §26

Data Consent Register & Evidentiary Ledger

Section 26 places the burden of proof on you: if a data subject disputes that they consented, you have to show it. The register keeps a timestamped, immutable record of every opt-in, change and revocation.

IAB TCF compatible

Consent Banner Studio & Customizer

Design the banner to match your brand without touching code, and publish changes without a redeploy. Preview exactly what a visitor sees before it goes live.

Automated discovery

Cookie Scanner & Tracker Inventory

Non-transparent cookies are part of what cost Fidelity Bank ₦555.8 million in 2024. Izini scans your site, finds every cookie and tracker actually in use, and classifies each one, so your banner only ever declares the cookies you genuinely set.

5 Nigerian languages

Consent Translations

Consent is only valid if it is understood. Izini serves the banner in English, Yorùbá, Igbo, Hausa and Nigerian Pidgin, with translations generated for you and editable where you want a different phrasing.

Omnichannel

Universal Consent Topics

Consent does not stop at the website. Define topics once — marketing email, SMS, profiling, data sharing — and apply them consistently across every channel and product surface.

Web, iOS, Android

CMP Installation & Mobile SDKs

Three lines of script on the web, or a native SDK on mobile. Bundle-ID registration means only your own apps can pull your configuration.

HMAC-signed

Universal Webhooks & Backend Signals

A consent decision is useless if your CRM never hears about it. Every change fires a signed webhook to your own systems, with a delivery log so you can prove it arrived.

Evidence-grade

Consent Analytics & Intelligence

Opt-in rates by category, language and channel — so you can see where consent is being lost, and show an auditor how consent actually behaves across your estate.

Data Subject Rights

DSAR handling and grievances, on the statutory clock

A data subject request starts a clock you cannot pause. Izini registers every request, verifies the person behind it, and keeps a defensible record of exactly what you did and when — without your team touching raw personal data more than it has to.

Explore Data Subject Rights →

NDPA 2023 §34

Data Subject Rights (DSAR) Register

Every access, rectification, erasure and portability request in one register, with identity verification before anything is disclosed and a full event stream behind each case.

GAID Schedule 9

SNAG Grievances Desk

GAID expects a pre-complaint route: a data subject should be able to raise a grievance with you before escalating to the NDPC. The SNAG desk gives you that channel and records how each one was resolved.

Governance & Risk

RoPA, DPIAs and a risk register the regulator will recognise

Governance is where most Nigerian compliance programmes quietly fail — not because the controls are missing, but because nobody can produce the paperwork proving they exist. These modules are the paperwork, kept current as a by-product of doing the work.

Explore Governance & Risk →

NDPR · NDPA 2023

Privacy Policies

Generate a privacy notice that reflects what you actually do with personal data, published at your own URL and updated as your processing changes — rather than a PDF that went stale the week it was signed off.

Article 30 equivalent

RoPA Records of Processing

Your inventory of what personal data you hold, why, on what lawful basis and who you share it with. Upload a vendor contract and Izini drafts the RoPA entry for you to approve.

NDPA 2023 §28 · Schedule 4

Data Protection Impact Assessment (DPIA) Studio

Section 28 requires an impact assessment before high-risk processing. The studio walks the assessment, scores residual risk, and tells you whether the result crosses the threshold for prior consultation.

NDPA 2023 §28

NDPC Prior Consultation

When residual risk stays high after mitigation, section 28 requires you to consult the NDPC before proceeding. Izini assembles the consultation dossier from the DPIA rather than making you rewrite it.

GAID Schedule 6 · Form VI-06

Data Subject Vulnerability Indexes Matrix

GAID asks you to assess how vulnerable your data subjects are — minors, health status, financial exposure, literacy, power imbalance — and to weight your controls accordingly.

CAR-aligned · ISO 27701

Data Risk Assessment Register (DRAR)

A 5×5 risk register with inherent and residual scoring, treatment plans and CAPA tracking — so risk decisions are recorded rather than remembered.

NDPA 2023 §39 · CAR 2.3

Data Security System & MEM Schedule

Section 39 requires appropriate technical and organisational measures. The MEM schedule records them, along with the monitoring, evaluation and maintenance cycle that keeps them honest.

NDPA 2023 §25 · §30

Lawful Basis Register

Every processing operation needs a lawful basis, and you have to be able to say which one and why. The register is a ledger of those determinations, audit-ready for your CAR.

NDPA 2023 §25(1)(f)

Legitimate Interests Assessment (LIA)

Legitimate interests is the basis regulators probe hardest, because it is the one where you decide your own interests outweigh the data subject’s. The LIA records that balancing test against the specific processing activity.

Data residency

Data Mapping & Lineage

Where personal data actually lives and where it flows, including the parts most Nigerian organisations lose track of: which assets stay in-country, and which quietly leave.

NDPA 2023 · Schedule 4

Data Protection by Design & by Default

Privacy obligations enforced where engineering actually happens. Releases are gated on a DPIA where one is required, so a feature touching personal data cannot ship without the assessment.

Continuous

Regulatory Updates & Clause Revisions

Nigerian data protection guidance is still moving. When it does, Izini drafts the specific clause revisions your policies need and routes them to your DPO, with the regulator citation attached.

Scheduled

Regulatory Discovery Automation

Scheduled monitoring for regulatory change, so the first you hear of a new NDPC directive is not a client asking whether you have complied with it.

Audit & Reporting

File your Compliance Audit Return without the annual scramble

If you process the personal data of more than 2,000 people you are a data controller of major importance, and the annual return is not optional — it is filed with the NDPC through a licensed DPCO. Izini keeps your policies, consent logs, RoPA entries and risk decisions organised as you go, so filing is an export rather than six weeks of archaeology.

Explore Audit & Reporting →

GAID §14

DPO Designation & Statutory Register

A DCPMI must have a designated Data Protection Officer, and must be able to evidence it. The register holds the board appointment, the NDPC registration and the statutory deadlines in one place.

GAID Schedule 3

DPO Accreditation & Competency (ACA)

It is not enough to name a DPO — Schedule 3 asks whether they are actually qualified. The ACA workspace keeps the certifications, CPD and accreditation standing that answer that question.

CAR readiness

Compliance Audit Workbench

A live view of how ready you actually are, mapped to the sections of the Compliance Audit Return, with the gaps called out while there is still time to close them.

NDPC filing

CAR Master Evidence Pack Exporter

Assembles every artefact your DPCO or the NDPC will ask for into a single manifest-indexed archive, so nothing is missing and nothing has to be chased.

GAID Schedule 10

Statutory Regulatory Fee & Penalty Calculator

Works out what you actually owe under Schedule 10 — CAR fees, DCPMI, late surcharges — and produces the Remita reference so payment is not the thing that makes you late.

Third-Party Risk

Your processors are your exposure

Section 29 makes you responsible for the processors you appoint. If your payroll provider leaks, the NDPC comes to you. These modules make that relationship documented rather than assumed.

Explore Third-Party Risk →

NDPA 2023 §29

Vendor Due Diligence (DDQ)

A structured due diligence questionnaire per vendor, with their security posture captured and re-assessed rather than taken on trust at procurement and never revisited.

Processor agreements

Vendor DPAs

Every data processing agreement in one place, linked to the vendor and the processing activities it actually covers — so you can answer "is this covered?" in seconds.

NDPA 2023 §29

Sub-Processor Register

Your processors appoint their own processors, and you remain answerable for the whole chain. The register tracks it, including the substitutions that happen at short notice.

NDPA 2023 §41

Cross-Border Transfer Assessments (TIA)

This is what the NDPC fined MultiChoice Nigeria ₦766 million for in 2025 — transferring subscriber data abroad without adequate safeguards. Most Nigerian businesses run on infrastructure hosted elsewhere, and section 41 requires an adequacy basis or a documented assessment for each one.

Workforce

The obligations that point inward, not at your customers

Sections 24 and 25 are the obligations most organisations forget, because they are about your own staff rather than your customers. They are also among the easiest for an auditor to test — and the fastest to fail.

Explore Workforce →

NDPA 2023 §24 · CAR Schedule 2

Data Protection Training, Awareness & Sensitization

Run training campaigns across your workforce and keep the evidence that each person actually completed them — which is the part that matters when the CAR asks.

NDPA 2023 §24/§25

Employee Privacy Notices & Handbooks

Your staff are data subjects too. Generate the notices covering HR records, payroll, pension, CCTV and workplace monitoring, and record that they were issued.

GAID Article 30 · Form NDPC-BPC-30

Basic Privacy Checklist & Workforce Evaluation Studio

GAID's Basic Privacy Checklist is the plain-language do's and don'ts your workforce is measured against. The studio runs the evaluation and produces the form.

Incident Response

The 72-hour clock starts the moment you know

Under the NDPA you have 72 hours from becoming aware of a breach to notify the NDPC where it is likely to risk individuals’ rights. The hard part is rarely the notification — it is deciding whether the threshold was crossed, and proving afterwards that you decided properly.

Explore Incident Response →

NDPA 2023 §40

Incident Response Center & Remediation Desk

Starts the statutory clock automatically, walks the threshold assessment, and keeps a timestamped record of every decision and action taken from detection to closeout.

For Partners

See your whole client book in one place

If you resell or administer Izini for client organisations, the Partner Channel Portal is where you see your book: who is on which plan, how much of their allowance they have used, and who is about to lapse. Each client’s compliance work happens in their own workspace — this is the commercial layer over the top of it.

Explore For Partners →

Multi-client

Client Portfolio

Every organisation assigned to you in one list, searchable and filterable by standing, so you are not logging into accounts one at a time to find out where things stand.

Revenue protection

Renewal & Expiry Tracking

Which licences lapse when, so renewals are a pipeline you work rather than a client going quiet and later discovering they were suspended.

Monthly active users

Usage Across the Book

Consumption per client and across the whole portfolio, so you can see who is outgrowing their plan before the overage conversation happens.

Developers

A compliance API, not just a dashboard

Compliance fails at the integration boundary. Handling a DSAR properly means reaching into the systems that actually hold the data — your core banking platform, your CRM, your warehouse. These are the interfaces for doing that without exporting raw personal data into a spreadsheet.

Explore Developers →

Documented REST

DSAR API & Reference

Raise, track and fulfil data subject requests programmatically, so your own systems participate in the workflow rather than someone copying results between screens.

Per-project keys

Authentication & Key Management

Project-scoped API keys, hashed at rest and revocable without disturbing your other integrations.

Interactive testing

Integration Sandbox

A console for firing real requests at the gateway with a synthetic identifier, so you can watch your own handler respond to an erasure or access request before a live customer raises one.

HMAC SHA-256

Blueprints & Signed Webhooks

Reference patterns for common Nigerian stacks, plus signed webhooks so your backend hears about consent and DSAR events as they happen.

Book a demo

See it against your own compliance gaps.

We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.

  • A 30-minute walkthrough, no slides
  • A live cookie scan of your website, yours to keep
  • Straight answers on scope, timelines and pricing