Skip to content
Izini
Enforcement

Nigeria's data regulator has collected over ₦7.2 billion in penalties and compliance revenue — fines now reach ₦10M or 2% of revenue, whichever is higher. NDPC fines reach ₦10M or 2% of revenue — over ₦7.2B collected.

See the record →
Product · Third-Party Risk

Your processors are your exposure

Section 29 makes you responsible for the processors you appoint. If your payroll provider leaks, the NDPC comes to you. These modules make that relationship documented rather than assumed.

01
NDPA 2023 §29

Vendor Due Diligence (DDQ)

A structured due diligence questionnaire per vendor, with their security posture captured and re-assessed rather than taken on trust at procurement and never revisited.

  • Standardised DDQ covering security, retention, sub-processing and breach handling
  • Certification tracking for SOC 2, ISO 27001 and equivalents, with expiry dates
  • Scored outcomes feeding your risk register
02
Processor agreements

Vendor DPAs

Every data processing agreement in one place, linked to the vendor and the processing activities it actually covers — so you can answer "is this covered?" in seconds.

  • DPAs linked to the RoPA entries they authorise
  • Renewal and expiry tracking
  • Gaps surfaced where a processor is in use without an agreement
03
NDPA 2023 §29

Sub-Processor Register

Your processors appoint their own processors, and you remain answerable for the whole chain. The register tracks it, including the substitutions that happen at short notice.

  • The full processing chain, not just your direct contracts
  • DPO review with an objection window before a new sub-processor goes live
  • Emergency substitutions recorded under a temporary 30-day scope rather than slipping through unlogged
04
NDPA 2023 §41

Cross-Border Transfer Assessments (TIA)

This is what the NDPC fined MultiChoice Nigeria ₦766 million for in 2025 — transferring subscriber data abroad without adequate safeguards. Most Nigerian businesses run on infrastructure hosted elsewhere, and section 41 requires an adequacy basis or a documented assessment for each one.

  • Assessment per destination country and provider
  • Adequacy basis recorded, or the safeguards relied on where there is none
  • Surveillance-risk considerations documented for the destination jurisdiction
Book a demo

See it against your own compliance gaps.

We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.

  • A 30-minute walkthrough, no slides
  • A live cookie scan of your website, yours to keep
  • Straight answers on scope, timelines and pricing