The obligations that point inward, not at your customers
Sections 24 and 25 are the obligations most organisations forget, because they are about your own staff rather than your customers. They are also among the easiest for an auditor to test — and the fastest to fail.
Data Protection Training, Awareness & Sensitization
Run training campaigns across your workforce and keep the evidence that each person actually completed them — which is the part that matters when the CAR asks.
- Campaigns by department or cohort, with completion tracked per person
- Attestation and evidence records retained for audit
- Documented exceptions where someone genuinely could not attend
Employee Privacy Notices & Handbooks
Your staff are data subjects too. Generate the notices covering HR records, payroll, pension, CCTV and workplace monitoring, and record that they were issued.
- Notices covering HR, payroll, pension and workplace surveillance
- Handbook sections generated alongside, for onboarding packs
- Issue and acknowledgement records per employee
Basic Privacy Checklist & Workforce Evaluation Studio
GAID's Basic Privacy Checklist is the plain-language do's and don'ts your workforce is measured against. The studio runs the evaluation and produces the form.
- Workforce evaluation against the Article 30 checklist
- Cohort-level evidence for CAR items 1.10 and 1.11
- Form NDPC-BPC-30 generated from the completed evaluation
Explore the rest of the platform
Consent management built for Nigerian regulation
Banner, cookie scanning, mobile SDKs and an evidentiary consent register.
Data Subject RightsDSAR handling and grievances, on the statutory clock
A DSAR register under section 34 and a SNAG grievance desk under GAID Schedule 9.
Governance & RiskRoPA, DPIAs and a risk register the regulator will recognise
Records of processing, impact assessments, vulnerability indexes and a 5×5 risk register.
Audit & ReportingFile your Compliance Audit Return without the annual scramble
Audit workbench, CAR evidence pack exporter and the statutory fee calculator.
Third-Party RiskYour processors are your exposure
Vendor due diligence under §29, processor DPAs and cross-border transfer assessments.
For PartnersSee your whole client book in one place
Client portfolio, licence renewals and usage for channel partners and resellers.
DevelopersA compliance API, not just a dashboard
DSAR API, sandbox, integration blueprints and signed webhooks.
Incident ResponseThe 72-hour clock starts the moment you know
Breach assessment, NDPC notification and remediation through to root cause.
See it against your own compliance gaps.
We'll walk you through the modules that matter for how your organisation actually processes personal data — using your own site, not a canned demo.
- A 30-minute walkthrough, no slides
- A live cookie scan of your website, yours to keep
- Straight answers on scope, timelines and pricing