NDPA 2023: security awareness, training & human risk
If your organisation collects or processes personal data in Nigeria — as a bank, fintech, telco, insurer, hospital group or any business with Nigerian customers or staff — the Nigeria Data Protection Act 2023 (NDPA) applies to you, and the Nigeria Data Protection Commission (NDPC) supervises how well you comply. This page sets out what the NDPA expects on the human side of data security, and how AfriPhish turns those expectations into evidence you can hand to the Commission, an auditor or a customer.
What the NDPA requires on staff awareness and human risk
The NDPA replaced the earlier NDPR regime with a full statute and an empowered regulator. Several of its obligations land squarely on your workforce.
A duty of care over personal data. The Act places data controllers and processors under a duty of care towards data subjects, and requires that personal data be processed with appropriate regard for its security. A duty of care exercised by an organisation is, in the end, exercised by its employees — the people who open attachments, handle customer records and answer unexpected phone calls.
Security of processing (sections 39–40 area). Controllers and processors must implement appropriate technical and organisational measures to secure personal data — including safeguards against cyber-attacks and processes for periodically testing and evaluating the effectiveness of those measures. As under comparable laws worldwide, "organisational measures" is understood to include trained, tested people: an organisation whose staff have never seen a simulated phishing email has no basis for claiming its human safeguards are effective.
Breach notification within 72 hours. Where a personal data breach is likely to result in risk to data subjects, you must notify the NDPC within 72 hours of becoming aware of it, and inform affected data subjects where the risk is high. That deadline is only survivable if the employee who first notices something wrong recognises it and reports it immediately — internal detection and escalation are the first links in your notification chain.
Data Protection Officers (section 32). Data controllers of major importance must designate a Data Protection Officer with expert knowledge of data protection law and practice. Advising the organisation and monitoring compliance are core DPO functions — and a DPO cannot monitor an awareness programme that produces no records.
NDPC oversight and compliance audits. The Commission can request information, direct compliance audits and sanction non-compliance. Organisations of major importance also file compliance returns through accredited practitioners. In every one of these interactions, documented awareness activity is the difference between an assertion and an answer.
The obligations AfriPhish helps you evidence
| NDPA expectation | AfriPhish module | Evidence produced |
|---|---|---|
| Organisational security measures | Security awareness training (English, French, Arabic) | Per-user completion logs, quiz results, assignment history |
| Periodic testing of effectiveness | Phishing simulations across realistic scenario families | Click, credential-submission and report rates, trended over time |
| Duty of care over personal data | Human risk scoring | Individual and departmental risk scores that reflect real behaviour |
| Staff confidentiality and conduct | Policy management with e-signature attestation | Versioned, timestamped registers of who signed which policy |
| 72-hour breach readiness | Simulation report-rate tracking and security coaching | Proof staff recognise and escalate suspicious activity |
| DPO monitoring duties | Reports and analytics | Exportable programme reports for NDPC filings and audits |
Everything is tenant-scoped and exportable, so your DPO or compliance consultant can pull a complete human-risk evidence file in minutes rather than reconstructing it from spreadsheets and email threads.
What auditors and regulators typically ask for
Whether it is the NDPC, an accredited compliance practitioner preparing your audit filing, or a large customer's vendor-risk team, the evidence requests follow a pattern:
- Training records — assignments, completions, dates and assessment scores for every employee, including recent joiners.
- A policy acknowledgement register — who signed your data protection and acceptable-use policies, which version, and when.
- Simulation trend reports — proof that you test staff against realistic phishing and that the results feed back into training, not a one-off exercise from two years ago.
- Escalation and reporting records — evidence that employees know the internal channel for reporting suspected breaches, and use it.
- Programme continuity — evidence the awareness effort runs on a cycle, with measurable improvement over time.
Each of these is a standard AfriPhish export. No manual assembly, no gaps discovered mid-audit.
See where your organisation stands
Start with a measurement, not a purchase. Take the free 4-minute Human Risk Maturity Assessment — it benchmarks your current programme against what the NDPA's security and testing obligations imply, and shows you the gaps in plain language.
Want to see the platform against your own context? Book a demo and we will map your NDPA evidence requirements together.