Clearance
← Back to All Blog Articles

Tech & data

If your app collects any personal data, NDPA already applies to you

5 min read · Last verified 2026-08-14

There's a common founder assumption that data protection law is something you deal with once you're large enough to attract regulatory attention. The Nigeria Data Protection Act 2023 doesn't work that way — it applies from the moment you collect, store, or process personal data belonging to a Nigerian, regardless of your company's size or revenue.

In practice that means almost every app qualifies immediately: a signup form with an email address, a delivery app storing addresses, a fintech app holding BVN and transaction history, an edtech platform storing a student's academic records. If your product has a database with a 'users' table, NDPA is already in scope.

What changes as you grow isn't whether NDPA applies — it's the intensity of what's expected of you. Early on, the baseline is: know what data you collect and why, have a lawful basis for collecting it, and give users a real privacy notice rather than boilerplate nobody reads. As you scale, or if your processing is higher-risk, you move into Data Protection Impact Assessments and potential registration as a data controller or processor.

There's a newer layer stacking on top of NDPA specifically for AI: if your product uses automated decision-making for anything considered high-risk — credit scoring, hiring decisions, health-related outputs — NITDA's emerging AI governance framework adds its own documentation and disclosure requirements. NDPA compliance alone doesn't cover this; it's an additional, separate obligation.

For founders building fintech, healthtech, or edtech products specifically, this is worth treating as core product work, not a legal afterthought bolted on before a funding round. A DPIA done during initial design is a much smaller task than one done retroactively across a live user base.

Take Action For Your Business

Verify your obligations with our free tools