Why Your Small Business Isn’t “Too Small” for the Nigeria Data Protection Act (NDPA)

Why Your Small Business Isn’t “Too Small” for the Nigeria Data Protection Act (NDPA)



​Most of the compliance advice targeted at Nigerian business owners reads like a boring law school textbook. You’ve probably seen the generic articles telling you to "protect customer privacy" and copy-pasting definitions from the Nigeria Data Protection Act (NDPA) 2023.

​Let’s be honest: if you run an online clothing store on Instagram, a beauty salon in Ikeja, or a small logistics outfit in Port Harcourt, your first instinct is to ignore it. You assume the Nigeria Data Protection Commission (NDPC) is only chasing banks, telcos, and multinational tech firms.

​That assumption is a highly expensive mistake.

​The NDPC has actively investigated hundreds of organizations, bringing in billions of Naira in designatory fees and enforcement actions. More importantly, the legal framework has changed. Under the General Application and Implementation Directive (GAID) 2025, the old rules under the 2019 NDPR are officially defunct. We are operating under a tighter, more structured system.

​If you think you are too small to care, you are likely sitting on a compliance landmine. Let's look at how the law actually applies to your daily operations.

​What is the "WhatsApp and Google Sheets" Trap?

​One of the biggest mistakes small business owners make is thinking "data protection" only applies if you have a custom database, an IT department, or a sophisticated website.

​Under the NDPA, "processing" refers to almost anything you do with personal information—including collecting, storing, retrieving, or sharing it. If you collect names, phone numbers, delivery addresses, or bank details, you are legally a Data Controller.

​Consider these everyday business activities:

  • The Shared Google Sheet: You keep your customer list, their phone numbers, and past purchase history on a Google Sheet so your three sales reps can access it.
  • The Unsecured WhatsApp Business Account: You use WhatsApp to take orders, meaning hundreds of customer addresses, chat histories, and bank payment screenshots sit on your personal or company phone.
  • The Delivery Dispatch Broadcast: You drop your daily delivery list (names, addresses, and phone numbers of 20 customers) into a WhatsApp group containing five different independent dispatch riders.

​Under Nigerian law, every single one of those examples constitutes "data processing".

​If one of your sales reps copies that Google Sheet before quitting to start their own business, that is a data breach. If a dispatch rider loses their phone and a stranger gains access to your unencrypted customer delivery list, that is a data breach. Under the law, you have exactly 72 hours from the moment you notice the leak to report it to the NDPC.

​If you cannot show that you took basic steps to secure that data—like restricting Google Sheet access, setting up two-factor authentication on WhatsApp, or masking customer details—you are liable.

​Am I Legally Required to Register with the NDPC?

​The short answer: it depends entirely on your numbers and the type of data you handle.

​You do not need to guess. The GAID 2025 outlines clear thresholds for who must register as a Data Controller or Processor of Major Importance (DCPMI).

​The NDPC categorizes major processors into three tiers: Ultra-High Level (UHL), Extra-High Level (EHL), and Ordinary-High Level (OHL). To see where your small business fits, ask yourself these three diagnostic questions:

​1. How many active customers do you interact with?

​If you process the personal data of more than 200 individuals within a six-month period, you are legally classified as an Ordinary-High Level (OHL) Data Controller.

Note: "Processing" includes simply keeping their phone numbers on your business phone for marketing. If you have 201 unique customers in half a year, you cross the OHL threshold.


​2. What kind of data are you collecting?

​If you process sensitive personal data of more than 200 people for commercial purposes, you automatically hit the OHL classification. Under the NDPA, "sensitive" data includes:

  • ​Financial records (like bank accounts or BVNs)
  • ​Health and medical information

  • ​Biometric data (fingerprints, facial recognition templates)
  • ​Information about children

​3. What is your registration tier and cost?

​The registration tiers and annual filing fees under the GAID baseline work as follows:


ClassificationActive Data Subjects (6-Month Window)NDPC Portal Registration Fee

Below ThresholdUnder 200 individualsExempt from registration (but must still obey the law)

Ordinary-High Level (OHL)200 to 999 individuals₦10,000 (Renews annually)

Extra-High Level (EHL)1,000 to 5,000 individuals₦100,000 (One-time registration, annual audit)

Ultra-High Level (UHL)Over 5,000 individuals₦250,000 (One-time registration, annual audit)



Tip: These represent the standard baseline fees. You should verify current portal fees directly on ndpc.gov.ng before processing payments.

​If I Outsource My Logistics, Who is Responsible for the Data?

​This is a massive point of confusion.

​Let's say you run an online boutique. A customer orders a dress. You collect their name, phone number, and home address. You then copy that information and hand it over to a third-party logistics company (e.g., GIG Go, Gokada, or an independent dispatch rider) to fulfill the delivery.

​If that dispatch rider leaks the customer's phone number, or uses it to harass them after the delivery, who gets in trouble with the NDPC?

​Under the NDPA:

  • You are the Data Controller: You collected the data and decided how and why it should be used.

  • The Logistics Company is the Data Processor: They are acting on your instructions to deliver the package.

​Most business owners assume that once they hand the package and the phone number to the delivery man, their responsibility ends. It does not.

​Section 29 of the NDPA states that a Data Controller is responsible for ensuring their third-party Data Processors have adequate security measures in place. If you hand customer data to an unregistered, unvetted delivery rider without a basic agreement (even a simple service level agreement stating they must keep customer details confidential), you share the liability for any breach.

​Case Study: Steps for a 40-Customer-a-Month Instagram Vendor

​Let’s look at a realistic scenario.

​Toke runs Toke's Glam, an Instagram store selling customized wig units. She averages 40 paying customers a month. She uses WhatsApp Business to close sales, receives bank transfers, and uses three local dispatch riders for delivery.

​Because she handles 40 customers a month, in a 6-month period she processes about 240 unique customer records. This puts her slightly over the 200-person limit, making her an Ordinary-High Level (OHL) Data Controller.

​Here is exactly what Toke needs to do to get compliant:

1. Map Your Customer Data (Days 1–5)

Toke starts by identifying everywhere she stores customer information. She discovers that customer data is scattered across:

  • WhatsApp chats on her iPhone
  • Her GTBank app (customer names on payment receipts)
  • An Excel spreadsheet used to track orders

By creating a complete inventory of where customer data is stored, she knows exactly what needs to be protected.

2. Create a Simple Privacy Notice (Days 6–10)

Instead of copying a lengthy privacy policy from another website, Toke writes a clear, one-page privacy notice in plain language. She adds the link to her Instagram bio and WhatsApp Business catalog.

Her privacy notice explains:

  • What information she collects (names, addresses, and payment details)
  • Why she collects it (to process orders and verify payments)
  • How long she keeps it (up to 12 months after a purchase)

3. Secure Customer Information (Days 11–15)

Next, Toke strengthens the security of her business.

She:

  • Enables two-factor authentication (2FA) on her WhatsApp and email accounts.
  • Password-protects her Excel order spreadsheet.
  • Stops sharing complete customer details in WhatsApp group chats with dispatch riders.

Instead, she shares only the information needed to complete each active delivery.

4. Register on the NDPC Portal (Days 16–20)

Finally, Toke registers her business on the NDPC portal at forms.ndpc.gov.ng.

As an Ordinary High-Level (OHL) data controller, she:

  • Pays the ₦10,000 OHL registration fee.
  • Updates her business information.
  • Does not need to hire a Data Protection Compliance Organisation (DPCO) or submit annual compliance audits.
  • Simply renews her registration each year.

The One Thing You Should Do Today

Data protection compliance doesn't require an expensive IT system. It begins with understanding what customer information you have and where you keep it.

Take a few minutes today to check your business phone, spreadsheets, notebooks, or any other records. Make a list of every place where you store customer names, phone numbers, addresses, or banking details.

Once you've identified those locations:

  • Protect important files with strong passwords.
  • Enable two-factor authentication (2FA) on your WhatsApp and email accounts.
  • Delete old customer records that you no longer need to keep.

Taking these simple steps will significantly improve your business's data security and put you on the right path toward NDPC compliance.

This article was researched with AI assistance and carefully reviewed for legal and technical accuracy against the current NDPC Guidelines and the General Application and Implementation Directive (GAID) 2025.



0 Comments