How to Avoid NDPC Fines: A Corporate Executive’s Data Breach Response Checklist (2026)
Under Section 40 of the NDPA 2023 and Article 7(p) of the GAID 2025, data controllers must notify the Nigeria Data Protection Commission within 72 hours of becoming aware of a personal data breach. Where the breach is likely to negatively affect the rights and freedoms of data subjects, those individuals must also be notified without undue delay. Failure to report within the 72-hour window is itself a separate compliance failure, in addition to any penalty arising from the underlying breach — meaning a poorly handled breach response can result in two distinct sets of penalties rather than one.
The NDPC has collected ₦7.2 billion in penalties since enforcement intensified, and cross-border data transfer violations and inadequate breach response have been among the largest contributors. Most Nigerian businesses do not have a documented breach response plan before a breach occurs — which means the 72-hour clock starts running while the organisation is still figuring out what to do. This checklist changes that.
What Actually Counts as a Reportable Breach
A personal data breach under the NDPA is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This is a broader definition than many business owners assume — it is not limited to a dramatic hack or external cyberattack.
Reportable breaches commonly include: a lost or stolen company laptop or phone containing customer data; an email containing personal data sent to the wrong recipient; a misconfigured database or cloud storage bucket left publicly accessible; a former employee retaining or misusing access to customer data after departure; a third-party vendor or processor experiencing a breach that exposes data you shared with them; and a ransomware attack affecting systems that store personal data.
The 72-Hour Clock: What Happens at Each Stage
| Time from awareness | What must happen | Who is responsible |
|---|---|---|
| Hour 0 | Breach is detected or reported internally. The clock starts from the moment the organisation becomes aware — not from when the breach actually occurred, which may be earlier. | Whoever discovers it — IT, an employee, a customer complaint, a third-party notification |
| Hours 0–4 | Immediate containment — stop the ongoing exposure where possible (revoke access, take a system offline, secure the affected data) | IT/security team, escalated immediately to the DPO |
| Hours 4–24 | Severity assessment — determine scope (how many data subjects, what categories of data, what risk level) and whether the reporting threshold is met | DPO, with input from IT and, where needed, legal counsel |
| Hours 24–60 | Prepare the NDPC notification — draft the required disclosure covering the nature of the breach, categories and approximate number of affected data subjects, likely consequences, and measures taken or proposed | DPO, supported by legal counsel for significant breaches |
| By Hour 72 | NDPC notification submitted | DPO or authorised representative |
| Without undue delay after NDPC notification | Where required, notify affected data subjects directly, in clear and plain language | DPO, coordinated with communications/customer service |
Notifying the NDPC: What the Notification Must Contain
- A description of the nature of the breach, including where possible the categories and approximate number of data subjects and personal data records affected
- The name and contact details of the DPO or other contact point for further information
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects
Where full details are not yet available within the 72-hour window, the NDPA framework contemplates that notification can be provided in phases — an initial notification with available information, followed by further details as the investigation into the breach’s scope continues. This is a materially better position than missing the 72-hour window entirely while waiting to have a complete picture.
When You Must Also Notify Affected Data Subjects
Beyond notifying the NDPC, organisations must notify affected data subjects directly where the breach is likely to result in a high risk to their rights and freedoms. This typically applies where the breach involves sensitive categories of data (financial information, health data, national identification numbers), where the exposed data could facilitate identity theft or fraud, or where the scale of exposure is significant.
Data subject notifications must be in clear, plain language — not legal or technical jargon — and should explain what happened, what data was affected, what the organisation is doing about it, and what steps the affected individual can take to protect themselves.
How to Actually Avoid NDPC Fines — Not Just Survive an Investigation
The businesses that avoid NDPC penalties entirely are not the ones with the best breach response — they are the ones that prevent reportable breaches from happening in the first place, and that respond so competently on the rare occasion something does happen that the NDPC’s assessment reflects genuine good-faith compliance rather than negligence.
- Build the breach response plan before you need it. Name specific roles, escalation paths, and decision-makers now, not during an active incident.
- Run a breach simulation at least annually. A tabletop exercise reveals gaps in the plan — unclear ownership, missing contact details, unrealistic timelines — while there is no real breach at stake.
- Maintain an up-to-date data inventory. You cannot assess a breach’s severity quickly if you do not already know what personal data you hold, where it lives, and how sensitive it is.
- Ensure every third-party processor has a Data Processing Agreement with breach notification obligations flowing back to you. A breach at your cloud provider or payroll vendor is still your responsibility to report — but only if they tell you about it promptly.
- Document every security decision, even the ones that seem obvious. When the NDPC evaluates a breach, a demonstrable pattern of reasonable security measures — even if imperfect — is treated very differently from an organisation that made no meaningful effort at all.
Data Breach Response Checklist — 72-Hour NDPC Protocol
A ready-to-use, timeline-based checklist covering the full 72-hour breach response process — immediate containment steps, severity assessment framework, NDPC notification template content, and data subject communication protocol.
Download Free →
The Mistakes That Turn a Breach Into a Bigger Penalty
- Waiting to have “complete” information before notifying the NDPC. This is the single most common way businesses blow the 72-hour deadline. Submit an initial notification with what you know at hour 60, and supplement it — do not wait until hour 90 for a complete picture and miss the window entirely.
- Internal debate about whether the breach is “serious enough” to report, without documenting the assessment. If your organisation decides not to report a borderline incident, document exactly why — the reasoning, who was involved, and what factors were weighed. An undocumented decision not to report looks, in hindsight, indistinguishable from simply failing to assess the situation at all.
- No one has clear authority to trigger the notification. If the DPO needs sign-off from three layers of management before submitting a notification, the 72-hour window can evaporate in internal approval processes. The DPO should have clear, pre-authorised authority to notify the NDPC once severity is assessed.
- Treating the breach as purely a technical/IT problem. A breach response that never involves legal counsel — particularly for anything beyond a minor, contained incident — misses the regulatory and litigation risk dimensions that a purely technical response won’t catch.
Frequently Asked Questions
What if we discover a breach that happened weeks ago but we are only becoming aware of it now?
The 72-hour clock runs from when the organisation becomes aware of the breach, not from when the breach actually occurred. If you have genuinely just discovered a historical breach, notify the NDPC within 72 hours of that discovery, and be prepared to explain in your notification why the delay in discovery occurred — this itself may be a relevant factor in how the incident is assessed, particularly if it reveals inadequate monitoring or detection capability that is a separate issue worth addressing regardless of the specific breach.
Does every data breach need to be reported to the NDPC, even minor ones?
No — the reporting obligation applies where the breach is likely to result in a risk to the rights and freedoms of data subjects. A trivial, fully contained internal incident with no realistic exposure risk may not meet this threshold. However, given the consequences of an incorrect judgment call, organisations should document their reasoning carefully whenever they conclude an incident does not require reporting, and when genuinely uncertain, the safer position is to report.
Can we be fined even if we notify the NDPC correctly and on time?
Yes — timely, correct notification of a breach does not automatically exempt the organisation from penalty for the underlying breach itself, particularly where the breach resulted from inadequate security measures or non-compliance with other NDPA obligations. However, a well-handled, transparent, and timely breach response is generally treated far more favourably in any penalty assessment than a breach discovered through late reporting, incomplete disclosure, or evidence of an inadequate security posture. Good breach response does not guarantee no penalty, but it materially improves the outcome.
Build Your Breach Response Plan Before You Need It
Lawberon Legals & Co. advises commercial clients across Lagos and Abuja on NDPA compliance, data breach response planning, and NDPC investigation defence.
Our team can build a tailored breach response plan for your organisation, or provide urgent support if you are currently managing an active data breach.
Contact our team at info@lawberonlegals.com or call +234 800 000 0000.
No. 12 Thomas Laniyan Street, Anthony, Lagos State.
