Your processors are your exposure
Section 29 makes you responsible for the processors you appoint. If your payroll provider leaks, the NDPC comes to you. These modules make that relationship documented rather than assumed.
Vendor Due Diligence (DDQ)
A structured due diligence questionnaire per vendor, with their security posture captured and re-assessed rather than taken on trust at procurement and never revisited.
- Standardised DDQ covering security, retention, sub-processing and breach handling
- Certification tracking for SOC 2, ISO 27001 and equivalents, with expiry dates
- Scored outcomes feeding your risk register
Vendor DPAs
Every data processing agreement in one place, linked to the vendor and the processing activities it actually covers — so you can answer "is this covered?" in seconds.
- DPAs linked to the RoPA entries they authorise
- Renewal and expiry tracking
- Gaps surfaced where a processor is in use without an agreement
Sub-Processor Register
Your processors appoint their own processors, and you remain answerable for the whole chain. The register tracks it, including the substitutions that happen at short notice.
- The full processing chain, not just your direct contracts
- DPO review with an objection window before a new sub-processor goes live
- Emergency substitutions recorded under a temporary 30-day scope rather than slipping through unlogged
Cross-Border Transfer Assessments (TIA)
This is what the NDPC fined MultiChoice Nigeria ₦766 million for in 2025 — transferring subscriber data abroad without adequate safeguards. Most Nigerian businesses run on infrastructure hosted elsewhere, and section 41 requires an adequacy basis or a documented assessment for each one.
- Assessment per destination country and provider
- Adequacy basis recorded, or the safeguards relied on where there is none
- Surveillance-risk considerations documented for the destination jurisdiction
Explore the rest of the platform
Consent management built for Nigerian regulation
Banner, cookie scanning, mobile SDKs and an evidentiary consent register.
Data Subject RightsDSAR handling and grievances, on the statutory clock
A DSAR register under section 34 and a SNAG grievance desk under GAID Schedule 9.
Governance & RiskRoPA, DPIAs and a risk register the regulator will recognise
Records of processing, impact assessments, vulnerability indexes and a 5×5 risk register.
Audit & ReportingFile your Compliance Audit Return without the annual scramble
Audit workbench, CAR evidence pack exporter and the statutory fee calculator.
WorkforceThe obligations that point inward, not at your customers
Staff training under §24, employee privacy notices and the Basic Privacy Checklist.
For PartnersSee your whole client book in one place
Client portfolio, licence renewals and usage for channel partners and resellers.
DevelopersA compliance API, not just a dashboard
DSAR API, sandbox, integration blueprints and signed webhooks.
Incident ResponseThe 72-hour clock starts the moment you know
Breach assessment, NDPC notification and remediation through to root cause.
See it against your own compliance gaps.
We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.
- A 30-minute walkthrough, no slides
- A live cookie scan of your website, yours to keep
- Straight answers on scope, timelines and pricing