Skip to content
Izini
Enforcement

Nigeria's data regulator has collected over ₦7.2 billion in penalties and compliance revenue — fines now reach ₦10M or 2% of revenue, whichever is higher.

See the record →

Stop worrying about fines.
Put your compliance on autopilot.

Izini is the compliance toolkit built specifically for Nigerian businesses. Consent, privacy policies, DSARs and breach response run on autopilot — so your team spends less time on paperwork and more time on the business.

50% off your first year  ·  Free white-glove setup  ·  Only 10 founder spots

40%Less manual compliance work
5Nigerian languages in one widget
72-hrBreach countdown, tracked automatically
10Founder spots — no rolling admissions
Why now

Nigeria is enforcing data protection like never before.

The Nigeria Data Protection Commission has moved from registration drives to active enforcement. Fines now reach ₦10 million or 2% of a company's annual gross revenue — whichever is higher — and the regulator has already used that power against some of the country's largest brands.

A directive issued in March 2025 and fully in effect since September 2025 widened the net further, and the NDPC's own leadership has described 2026 as its "full enforcement" era. Waiting for a warning letter is no longer a safe strategy.

Figures and dates verified against Techmoonshot's enforcement report, DataGuidance, TechAfrica News and Connecting Africa.

₦7.2B+

Total collected in registrations, compliance revenue and fines by the NDPC as of early 2026. Techmoonshot

$220M

Meta — fined for data misuse and consent failures; upheld on appeal in 2025. Connecting Africa

₦766M

MultiChoice Nigeria — fined July 2025 for privacy violations and unlawful cross-border data transfer. DataGuidance

₦555.8M

Fidelity Bank — fined August 2024 for processing data without informed consent. TechAfrica News

The toolkit

Everything a Nigerian compliance program actually needs.

Not a GDPR template with the logo swapped out. Every workflow below is built around how NDPR, the NDPA 2023 and CBN guidelines actually work in Nigeria.

The wedge no one else has

The only Nigerian consent banner that speaks the language your customers do.

One line of code puts a consent widget on your site or app that greets visitors in the language they're most comfortable in — and logs a timestamped record of every response. When your customers in Aba, Kano or Port Harcourt understand exactly what they're agreeing to, trust follows.

English Yorùbá Igbo Hausa Pidgin
01 — Privacy Policies

Deploy-and-forget policies that update themselves.

When Nigerian regulation changes, your privacy policy changes with it — automatically, without a lawyer's invoice or a developer ticket.

  • Written for NDPR & the NDPA 2023, not translated from GDPR
  • Auto-republishes when regulatory guidance shifts
  • Version history for every audit trail

Privacy Policy — v4.2

Up to date
Regulatory source: NDPC guidance, GAID directiveSynced
Last auto-update3 days ago
Published languages5
02 — Cookie & Tracker Scanning

Your banner only ever shows the cookies you actually use.

Izini scans your website and automatically identifies every tracker in play — no manual audits, no guesswork, no banner that lists trackers you dropped a year ago.

  • Automatic monthly re-scans catch new trackers
  • Categorised by purpose: necessary, analytics, marketing

Tracker Scan Results

12 found
03 — DSAR Automation

Find every customer record. Delete it correctly. Never touch the raw data.

Izini maps where customer information lives across your systems and generates an exact deletion plan for your team to execute — without Izini ever storing or accessing the underlying data itself.

  • Auto-discovers systems holding personal data
  • Zero-PII architecture — Izini never stores the data itself

DSAR Request #4471

In progress
CRM (HubSpot)Located
Billing (Stripe)Located
Support inboxLocated
04 — Incident Response

The 72-hour clock starts the moment you know.

Manage data breaches internally with a live countdown against Nigeria's 72-hour notification window, built-in thresholds to assess reporting obligations, and a documented trail of every corrective action you take.

  • Automatic countdown against the 72-hour window
  • Guided threshold assessment for reporting obligations

Incident #INC-081

Reporting window open
52Hours
18Minutes
07Seconds
05 — AI Vendor Review

Upload a vendor contract. Get a finished RoPA entry.

Izini's AI reads vendor and processor agreements, extracts how data is actually processed, and adds it to your Record of Processing Activities with suggested retention periods and risk flags — ready for your next Compliance Audit Return.

  • Cross-border transfer flags for offshore processors
  • CAR-ready export, ready for your DPCO to review

RoPA Entry — Payment Processor

Risk flagged
PurposePayment processing
Data usedName, card token, transaction history
RetentionSuggested: 7 years
RiskCross-border transfer
06 — Mobile SDK

Three lines of code. Every platform.

The Izini SDK integrates with iOS, Android and React Native, so your app checks for consent before loading any third-party tool — not after.

// React Native
import { Izini } from '@izini/consent-sdk';

await Izini.init({ appId: 'yourbusiness-ng' });
if (Izini.hasConsent('analytics')) { loadAnalytics(); }
How it works

Live in an afternoon. Covered for the long run.

01

Connect

Drop in one line of code on your site or three lines in your app. Your consent widget goes live immediately.

02

Configure

Upload your vendor contracts and let Izini's AI build your first RoPA, policies and cookie inventory automatically.

03

Stay covered

Izini tracks regulatory changes, republishes your policies, and keeps the 72-hour breach clock running whenever you need it.

Founder pricing

Simple for startups. Flexible for enterprise.

Izini is fully operational. We're opening early access to a carefully selected group of Nigerian businesses before we scale — only 10 spots, no rolling admissions.

Enterprise & DPO Teams

For teams with a dedicated DPO

Custom workflows for CBN-regulated entities, multi-entity RoPA management, and audit support tailored to your existing legal and compliance team.

  • CBN-aligned workflows for regulated financial services
  • Multi-entity & multi-brand support
  • DPCO- and audit-ready exports
  • Dedicated support & custom SLAs
Talk to us on WhatsApp
FAQ

Compliance questions, answered plainly.

Under the Nigeria Data Protection Act 2023, any organisation that processes the personal data of Nigerian residents falls within scope — startups, SMEs and enterprises alike. There's no employee or revenue threshold that exempts a business. As of early 2026, more than 38,677 data controllers and processors have registered with the NDPC. Source

Depending on the volume and sensitivity of personal data you process, the NDPC may require you to engage a licensed Data Protection Compliance Organisation (DPCO) to review your practices and file your annual Compliance Audit Return. As of early 2026, the NDPC has licensed 317 DPCOs nationwide. Izini doesn't replace your DPCO — it gives your team, or theirs, the tools to generate policies, manage consent and prepare audit evidence faster. Source

Fines now reach ₦10 million or 2% of a company's annual gross revenue, whichever is higher. The NDPC has already used this power: Meta was fined $220 million (upheld on appeal in 2025), MultiChoice Nigeria was fined ₦766 million in July 2025, and Fidelity Bank was fined ₦555.8 million in August 2024. Total penalties and compliance revenue collected by the NDPC have surpassed ₦7.2 billion.

Controllers must notify the NDPC within 72 hours of becoming aware of a breach likely to result in a risk to individuals' rights. Izini's incident workflow starts the 72-hour clock automatically, helps you assess whether the breach crosses the reporting threshold, and keeps a timestamped record of every step you take.

The CAR is the annual filing every registered data controller or processor submits to the NDPC, documenting how personal data is collected, processed and protected. As of early 2026, more than 8,155 CARs have been filed nationwide. Izini's audit workflow keeps your policies, consent logs and vendor RoPA entries organised year-round, so filing your CAR is a formality rather than a scramble. Source

Under the NDPA 2023 and NDPR, consent must be freely given, specific, informed, and unambiguous. A generic "We use cookies" banner that only offers an "OK" button does not meet this standard. Nigerian law requires that users are given clear information about what data is collected, the purpose of collection, and a genuine choice to accept or decline before any non-essential trackers are loaded. Furthermore, you must maintain a verifiable, timestamped audit trail of that consent.

No. Izini automates the repetitive, time-consuming parts of compliance — policy generation, consent capture, cookie scanning, DSAR routing and breach documentation — so your legal counsel or DPCO can focus on judgment calls instead of paperwork.

Only 10 founder spots

Get compliant before your next audit — not after.

We're onboarding Nigeria's first 10 founding customers personally, so every account is configured to fit exactly how you work. No rolling admissions once the spots are gone.

  • 50% off your entire first year
  • A dedicated setup session with our team
  • Direct access to the product team
Thanks for believing in Izini, we shall get back to you as quickly as possible.

Or skip the form — chat with us directly.