Nigeria data protection
How we meet the Nigeria Data Protection Act 2023, and what you can require of us under it.
Last updated 13 September 2026
Contents
The law that applies
The Nigeria Data Protection Act 2023 is the law that now governs personal data in Nigeria. It created the Nigeria Data Protection Commission and replaced the Nigeria Data Protection Regulation 2019 as the operative framework. The Commission’s General Application and Implementation Directive, made in March 2025, has applied in full since 19 September 2025 and sets out how the Act works in practice.
People still call this “NDPR compliance”, and this page is where you will land if you go looking for it. What is described here is compliance with the Act and the Directive, which is the higher standard and the one that is actually enforced.
Our role
For the personal data described in our privacy policy, Greencrest Integrated Services Limited (RC 1797334) is the data controller: we decide what is collected and what happens to it.
On client projects we are usually a data processor instead. There, the client decides, and we act only on their documented instructions under a written agreement.
The principles we work to
Section 24 of the Act requires that personal data is:
- processed fairly, lawfully and transparently;
- collected for a specified, explicit and legitimate purpose, and not used for an incompatible one;
- adequate, relevant and limited to what that purpose needs;
- kept accurate, and corrected or erased without delay when it is not;
- kept no longer than is necessary;
- kept secure against loss, destruction and unauthorised access.
We are accountable for demonstrating all of that, not merely for asserting it. That is why the retention periods in the privacy policy are written down with actual numbers.
Lawful bases
We must have a lawful basis before processing anything. Ours are: your consent; the performance of a contract with you, or steps taken at your request before one; compliance with a legal obligation; and our legitimate interests, where those are not overridden by your rights. The Act also allows processing for a vital interest or a public interest task; we do not rely on either.
Where we rely on consent, it is asked for separately, in plain words, and you can take it back at any time without penalty. We do not treat silence or a pre-ticked box as consent, and we do not make service conditional on consent we do not need.
Your rights under the Act
- To be told what we are doing with your data, before we do it.
- To get access to the data we hold about you, and a copy of it.
- To have inaccurate or incomplete data corrected.
- To have data erased, where the Act allows it.
- To restrict what we do with it while a dispute about it is resolved.
- To object to processing we base on legitimate interests, and to direct marketing at any time.
- To receive your data in a portable, machine-readable form, or have it sent to another controller.
- Not to be subject to a decision with legal or similarly significant effect made solely by automated means. We make no such decisions.
- To withdraw consent, and to lodge a complaint with the Commission.
How to make a request
Email info@greencrestisl.com with the word “data request” in the subject line, and tell us what you want. There is no form to fill in and no fee.
We reply within 30 days. If a request is complex enough to need longer, we will tell you so, and why, before those 30 days are up. We may need to confirm your identity first; we ask for the least that will do the job. If we decide we cannot do what you asked, we will tell you the reason and how to challenge it.
Who is responsible here
Data protection is owned by the Managing Director, who is the point of contact for anything on this page. Reach that role at info@greencrestisl.com or by writing to Plot 536, J.K Zaphaniah Street, Zone ‘A’ Extension, Apo Resettlement, Abuja, FCT, Nigeria.
If our processing grows to the point where the Act requires a designated data protection officer, we will appoint one and name them on this page.
If something goes wrong
If personal data we hold is lost, exposed or accessed by somebody who should not have it, and that is likely to risk your rights and freedoms, we notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it. Where the risk to you is high, we tell you directly and without undue delay, in plain language: what happened, what it means for you, and what we are doing about it.
We keep a record of every breach, including ones that do not meet the reporting threshold, so that the pattern is visible to us and to a regulator who asks.
Sending data out of Nigeria
Our website and email are hosted outside Nigeria, in the United States, so data does leave the country. Section 41 of the Act allows this where an adequate level of protection is ensured, and we rely on contractual safeguards with our host together with the commitments in our privacy policy. We check before adding a supplier that would move personal data somewhere new, and we will not use one that cannot meet this standard.
Data we handle for clients
Much of our work is building and running systems that hold other organisations’ data. In those engagements we are the processor and the client is the controller. We act only on their written instructions, we do not use their data for our own purposes, we do not bring in a sub-processor without their agreement, we impose the same duties on anyone we do bring in, and at the end of the engagement we return or delete what we hold as they direct.
If you are one of our clients’ users and you want to exercise a right over data held in a system we built, ask that organisation. If you write to us instead, we will pass it on and tell you we have.
Registration and audit
The Directive requires organisations that meet the thresholds for a data controller or processor of major importance to register with the Commission, and requires a compliance audit within 15 months of starting business and every year after that. We keep our position under review against those thresholds, and we file what is required of us when it is required.
Complaining to the Commission
If you are not satisfied with how we have handled your data or your request, you can complain to the Nigeria Data Protection Commission at ndpc.gov.ng. You do not need our permission and you do not have to come to us first, though we would rather you did, because most things are quicker to fix directly.
