Privacy and Data Protection Services
- Data Protection Regulation Compliance Implementation
- NDPR Compliance gap Analysis
- Data Protection Compliance audit
- Data Privacy Impact Assessment (DPIA) Preparation
- Facilitating and Vetting Data Privacy Agreements
- Development of Data Protection Policies and Supporting Procedures
- Development of Data Privacy and Protection Compliance Templates
- Data Protection Officer Outsourcing
- Data Management and Security Advisory
- Data Protection Awareness Training
- Advanced Data Protection Awareness Training
Nigeria Data Protection Regulation (NDPR) Implementation
The Nigeria Data Protection Regulation (NDPR) now the Nigeria Data Protection Act (2023), just like the EU General Data Protection Regulation (“GDPR”) is the Nigeria’s comprehensive privacy law. The NDPR applies to companies, individuals, corporations, public authorities and other entities – including small businesses, charities and nonprofit organizations – that collect and process the Personal Identifiable Information of Nigerian citizens are either based in Nigeria, offer goods or services (even for free) to people in Nigeria, either directly or as a third party. Data Controllers, Data Administrators/Processors, Private and Public organisations in Nigeria who process personal data of Nigerians have statutory obligations under the NDPR
There are many potential impacts of failure to comply with the Nigeria Data Protection Act (2023), including:
- Prosecution of or regulatory enforcement action against the Company, resulting in substantial penalties of up to 2% of an annual worldwide turnover of the preceding financial year or 10 million Naira (whichever is the greater),
- Adverse publicity, potentially leading to reputational damage and lost customer trust.Achieving NDPR Compliance can be a technical and logistical challenge for organisations. Computer Audit Control and Security Associates Limited, a licensed Data Protection Compliance Organisation (DPCO), is a full-service Nigeria Data Protection Act (NDPA) Compliance Assessor and Advisory company that is uniquely positioned to assist you in meeting the NDPA compliance requirements as well as honor data subject’s rights. At Computer Audit Control and Security Associates Limited, we are uniquely qualified to successfully guide your organisation through compliance with the NDPA 2023. Our primary goal is to assist businesses in complying with their data protection obligations under the Nigeria Data Protection Act (2023).
DATA PROTECTION COMPLIANCE AUDIT
In today’s current landscape, data reigns supreme. Collecting data can be responsible for a great deal of business advantages. However, it also comes with a considerable amount of responsibility, particularly when it comes to safeguarding the sensitive information entrusted to you. Navigating the intricate web of data protection regulations, like the Nigeria Data Protection Act (2023), General Data Protection Regulation (GDPR), etc., can be daunting. That’s where a Data Protection Compliance Audit from Computer Audit Control and Security (CACSS) Associates Limited comes in, empowering you to proactively assess your data practices and confidently take charge of your compliance strategy.Our comprehensive Data Protection Compliance Review is a meticulous, high-level assessment designed to provide you with a transparent snapshot of your data governance posture. Our data protection experts delve deep into your organisation’s practices, scrutinising key areas such as:
Uncover the types of personal data you collect, store, and process, across all departments and systems.
Assess your adherence to relevant data protection regulations, including NDPR, GDPR, etc., and relevant industry-specific requirements
Evaluate the effectiveness of your existing policies, identifying potential gaps and inconsistencies.
Analyse the robustness of your data security measures, from access controls to encryption protocols.
Assess your processes for handling data subject requests, including access, rectification, and erasure.
Evaluate your readiness to detect, contain, and report data breaches effectively.
At Computer Audit Control and Security (CACS) Associates Limited, we believe compliance is a journey, not a destination. Our Data Protection Compliance audit is just the first step. We partner with you to translate insights into actionable recommendations, offering invaluable support through:
We pinpoint areas requiring improvement and prioritise potential risks, providing a clear roadmap for remediation.
We collaborate with your team to craft robust, practical policies and procedures that align with regulatory requirements and your unique business needs.
We equip your workforce with the knowledge and skills to handle data responsibly and securely.
We help you assess and manage data protection risks associated with your third-party vendors and service providers.
We assist you in establishing efficient processes for handling data subject requests, ensuring prompt and compliant responses.
We refine your preparedness and response strategies for potential data breaches, minimizing risks and downtime.
We offer ongoing support to track progress, address evolving regulations, and ensure sustained compliance over time.
DATA PRIVACY IMPACT ASSESSMENT SERVICE
Data Privacy Impact Assessments (DPIAs) under the Nigeria Data Protection Regulation (NDPR) are mandatory for any new personal data processing operations that are likely to result in a high risk to the rights and freedoms of individuals. The Nigeria Data Protection Regulation requires that organizations conduct data Privacy Impact Assessment (DPIA) before undertaking any new Information Technology Project. A Data Privacy Impact Assessment (DPIA) is a type of risk assessment. It helps you identify and minimize risks relating to personal data processing activities. DPIAs are sometimes known simply as Privacy Impact Assessment (PIA). It is also good practice to do a DPIA for any other major project which requires the processing of personal data. A DPIA should begin early in the life of a project, before you start your processing, and run alongside the planning and development process.
You should also think carefully about doing a DPIA for any other processing that is large scale, involves profiling or monitoring, decides on access to services or opportunities, or involves sensitive data or vulnerable individuals.
Even if there is no specific indication of likely high risk, it is good practice to do a Data Protection Impact Assessment (DPIA) when you are introducing new data processing processes, systems or technologies.
A good DPIA helps you to evidence that:
- you have considered the risks related to your intended processing; and
- you have met your broader data protection obligations.
Our DPIA service provides an on-site assessment of the data protection risks associated with a new or existing data processing operation within your organisation and recommendations on the appropriate controls to mitigate these risks.Our Data Security Consultants can assist you in carrying out a Data Protection Impact Assessment for any new project that you want to undertake.At the end, we will provide you with a written response advising you whether the project risks are acceptable, or whether you need to take further action. The DPIA report will detail the data protection risks identified and prioritise them according to severity, including a statement of the likely impact on the rights of individuals should those risks occur, and recommend appropriate controls to mitigate the risks and reduce them to an acceptable level.In some cases, we may advise you not to carry out the processing because we consider it would be in breach of the NDPR. In appropriate cases we may issue a formal warning or take actions to ban the processing altogether.The report will be delivered within ten working days of completing the data-gathering phase of the DPIA.
DEVELOPMENT OF DATA PROTECTION POLICIES AND PROCEDURES
Policy development is a key consideration for any organisation looking to comply with data protection laws. Data protection policies are a set of principles, rules and guidelines that define the goals of an organisation in terms of privacy compliance. They provide guidance on how to achieve compliance objectives. Apart from guidance, a sound privacy policy framework ensures consistency in data protection across your organisation, offers clarity on data protection obligations and promotes accountability within the business.The accountability principle of data protection laws (e.g. the Nigeria Data Protection Act, the EU General Data Protection Regulation, etc.) requires data controllers to be able to demonstrate compliance with the laws /regulations by showing the regulatory authority (the Nigeria Data Protection Commission – NDPC) and individuals how the data controller complies, on an ongoing basis, through evidence of:
- Internal policies and processes that comply with the NDPR's requirements.
- The implementation of the policies and processes into the organization's activities.
- Effective internal compliance measures.
- External controls.
Some of the policies that the Nigeria Data Protection Act (2023) requires companies to have in place include the privacy policy, Data Protection Impact Assessment (DPIA) Policy, Data Protection Policy, IT Security Policy, Data Retention Policy, Personal Data Quality Review Policy, etc.An organisation cannot comply to data protection laws and regulations without an appropriate data protection policy framework. Policies not only outline your organisations overall attitude towards privacy but they also offer specific guidelines for compliance.Creating data protection policies and supporting procedures is essential for businesses but this can seem like a daunting task. Computer Audit Control and Security (CACS) Associates Limited can assist your company with the development of the relevant data privacy and Protection policies and supporting procedures that will demonstrate to the regulatory authorities and individuals, how your company is complying with the data protection laws and regulations
FACILITATING THE DEVELOPMENT AND VETTING OF DATA PROTECTION AGREEMENTS
Modern businesses collect and process personal information about their customers and employees for the benefit of their business. these benefits include identifying opportunities to enhance their products or services, streamlining operations, reducing costs or maximizing profits. Processing such data is often outsourced to a third-party data processing service provider. For example, third parties may be retained to perform payroll activities, store data in a centralized location, or send targeted advertisements to consumers.Data protection agreements (DPAs) are vital instruments that form part of a service agreement. A data protection agreement is a legal document between an organization and a customer that establishes the terms of how personal data will be used. This agreement includes who has access to the information, what can happen with it, and if it needs to be removed from their system at any point in time. They allow the business (the data controller) to impose privacy obligations on the third-party service provider (the data processor). DPAs ensure compliance with privacy laws by creating obligations for the data processor to maintain the same level of data protection for the controller and the data subjects. DPAs can also be expanded to protect proprietary or confidential information of the business (not just personal information).Our Legal team can help you in the development and vetting of your Data Privacy Agreements that are legally binding on all the contracting parties.
DEVELOPMENT OF PRIVACY AND DATA PROTECTION COMPLIANCE TEMPLATES
As a summary of your requirements to comply with Privacy and Data Protection regulations such as the EU GDPR, Nigeria DNDPR, etc., your organization is expected to be able prove that both cybersecurity and privacy principles are designed and implemented by design and by default. The reality with compliance assessments is that if something is not documented, you cannot prove it exists. Given that reality, you need to ensure your company has appropriate cybersecurity & privacy documentation. This ranges from policies and standards, to program-level guidance (e.g., risk and vulnerability management), all the way down to risk assessments and procedures.We have developed Privacy and Data Protection compliance solution templates that can help you provide both the evidence of due care and due diligence in getting and staying compliant with the Privacy and Data Protection legislations. We developed our products with the concept of Cybersecurity for Privacy by Design to address the People, Process & Technology (PPT) components that together build secure and compliant applications, systems, and processes.Our documentation is designed to address common cybersecurity and privacy needs, so that you can demonstrate compliance with your specific requirements. Regardless of the regulatory framework, you need to have evidence of how both cybersecurity and privacy principles are designed and implemented. Our privacy bundles are uniquely designed to help you comply with leading privacy practices.
DATA PROTECTION OFFICER (DPO) OUTSOURCING
In today’s business landscape, data reigns supreme. Collecting data can be responsible for a great deal of business advantages. However, this comes with a considerable amount of responsibility, particularly when it comes to safeguarding the sensitive information entrusted to you. Navigating the intricate web of data protection regulations, like the EU GDPR, Nigeria NDPR, etc., can be daunting.Having access to an experienced and knowledgeable outsourced DPO is a cost-effective solution for improving information security and compliance with data protection laws. Failing to protect personal data can not only lead to significant financial penalties from regulators, but also risks reputational damage to your organisation. By following tested and established best practices, an outsourced DPO helps to protect the data your organisation processes on your customers, suppliers and employees keep your organisation informed and advised about data protection and where necessary, cooperate with regulators on your behalf. The Computer Audit Control and Security (CACSS) Associates outsourced Data Protection Officer (DPO) service delivers flexible, tailored data protection support, advice and expertise to your organisation. Our outsource service provides you with a highly experienced Data Protection Officer (DPO) who works on your site or remotely as an integral member of your team. You benefit from a knowledgeable, hands-on data protection professional who undertakes the DPO’s responsibilities in an extremely cost-effective way, and is backed by the support, shared best practice and model documentation developed from our company’s experience of working with several organisations. Unlike other outsourced providers, our DPOs work with you, either at your offices or remotely, as an integral member of your team. They become immersed in your culture and take a proactive, rather than reactive approach to your requirements.Our DPO Outsourcing service will benefit your company in the following ways:
- Highly cost effective
- Experience and shared best practice gained from working with over 900 clients
- Designated Data Protection Officer working on site with your team
- Pre-existing model documentation tested and validated across varied industry sectors
- Pragmatic, straightforward, solution-driven advice
DATA MANAGEMENT AND SECURITY ADVISORY
The age of digital technology proliferation means the biggest businesses are collecting and storing massive amounts of sensitive data, including personal information about customers and employees. At the same time, cyberattacks, data breaches, and phishing scams impact more people than ever and are costlier to deal with.Organizations must protect sensitive data to reduce business risk, maintain stakeholder and customer trust, avoid illegal practices, and prevent incurring massive costs in today’s era of cybercrime and breaches.Data security now ranks as the most important aspect of data management. Digital transformation encouraged capturing everything that an individual or application does while connected to the Internet in tremendous detail. People working from home, using various devices that fall outside of corporate oversight or monitoring tools, further complicates sound data security management. More startling is how easy a personal device can affect an entire organization with a computer virus or open the door to a hacker. Government regulations for data control, such as the Nigeria Data Protection regulation (NDPR), the European Union General Data Protection Regulation (GDPR) or the Health Insurance Portability and Accountability Act (HIPAA), provide guidance and fines to force organizations to improve data security management. Still, there is little regulation of personal security management.Companies failing to adequately protect personal information from vulnerabilities can expect damage to their financial health. Additionally, organizations run the risk of suffering long-term reputational damage and a loss of customer trust. As such, a strong Data Security Management program is a crucial aspect of managing business risk.When it comes to Data Security Management and protection, companies find it challenging to secure sensitive data all on their own. Implementing a company-wide Data Security Management program is important, but not always easy or straightforward.Our Data management and security advisory solutions will help you gain greater visibility and insights into potential data issues and allow for comprehensive regulatory compliance management. Our data security experts provide you with insights that will help you understand your current business operations, technical requirements, and regulatory mandates to form a foundation for your information security environment. By conducting data security assessments, we will help you create and continually update an over-arching enterprise security architecture that:
- Utilizes your existing technologies
- Effectively satisfies your organization’s regulatory requirements
- Leverages the technical innovation needed to create a more secure and efficient information technology environment
DATA PTOTECTION AWARENESS TRAINING
The training of your staff on their data protection responsibilities is one of the most important parts of any data protection compliance project or data governance structure in an organisation. Having policies and procedures in place is of no use if your staff are not aware of them or their meaning. Having data subject access requests or a data beach if your staff do not know how to recognize them will put you at serious risk of being in breach of the law. Your staff are always your front line of defence when it comes to compliance with the requirement of the data protection law. It is part of the data protection legislation to make your staff aware of their responsibilities and aware of the law. This forms part of the Accountability principle. Our NDPR awareness training will educate your employees on the most the current NDPR legislation and keeps your business compliant and reduces the risk of an internal data breach. At the end of the data protection awareness training, attendees should be able to:
- Explain the reasoning behind the Nigeria Data Protection Regulation and how to adopt the right approach when confronted to a question in the course of your daily activities
- Discuss the scope and geographical reach of the NDPR.
- Explain the impact that the regulation has on the way that they handle the data of clients, prospect and employees.
Course Duration: 3 hours
Course Content
- Overview of the Nigeria Data Protection Regulation (NDPR)
- Objectives of the NDPR,
- What personal data is and special categories of personal data
- The principles of Data Protection
- The lawful basis for data processing
- The role of the data protection Officer,
- what subject access request is and what it could look like
- They are also taught what a data incident or breach is and how to report them to a manager.
- Steps to achieve the Nigeria Data Protection Regulation Compliance
ADVANCED DATA PROTECTION AWARENESS TRAINING
The Nigeria Data Protection Regulation (NDPR) places several complex requirements on organisations regarding their role as a data controller. These include requiring them to have a data processing agreement with third-party services, host a privacy policy on their website and perform data protection impact assessments for new projects. To ensure NDPR compliance, your staff must understand a range of topics. These include the purpose of the Nigeria Data Protection Regulation, what the regulation considers as ‘personal data,’ the 7 principles of the NDPR, and the role of a data protection officer This advanced NDPR training course covers the basics mentioned above as well as exploring additional key considerations. These include the NDPR privacy rights you need to uphold as a data controller and the definition of a ‘lawful basis for processing personal data. The Advanced NDPR Awareness training course will help individuals and organisations to understand and follow these requirements, allowing them to meet their legal obligations and avoid the penalties that come with non-compliance. It will provide participants with an awareness of the requirements of the Nigeria Data Protection Regulations and the privacy rights of individuals outlined in the NDPR. At the end of the training, participants should be able to:
- Explain the aim and scope of the Nigeria Data Protection Regulation and data protection law.
- Discuss the penalties for breaching the NDPR.
- Explain the lawful bases for processing personal data set out by the NDPR
- List the data privacy rights under the NDPR
- List the data protection principles
- Discuss some measures that can be used to demonstrate compliance and ensure data security
- Explain when international data transfers can be carried out
Course Duration: 3 hours
Course Content
1. Introduction to NDPR
- What is NDPR
- What counts as ‘personal data’
- The roles that individuals and organisations have under the NDPR
- When international transfers can be carried out
2. Principles of Data Processing
- The seven data protection principles of the NDPR
- What these principles mean for the way an organisation must handle personal data
3. Lawful bases for processing personal data
- Lawful bases for processing personal data
- The lawful basis for processing personal data set out by the NDPR
- Lawful bases for processing special category and criminal offence data
4. Data Subject rights
- The rights that the NDPR grants to data subjects
- When these rights apply
- What these rights mean for organisations and how they process data
5. Data Security
- What is data security
- Objectives of data security
- Threats to data security
- Some example data security measures
- Data breaches and bad practices
6. Data Protection: Accountability and Governance
- The concept of Accountability
- Some examples of measures that organisations can implement to demonstrate accountability in Data Protection.
Why Choose Computer Audit Control and Security (CACS) Associates Limited?
There are many licensed Data Protection Compliance Organisations (DPCOs) and providers offering data protection services. But the following qualities set us apart?
Our team boasts seasoned data protection professionals who possess in-depth knowledge of complex regulations and practical implementation strategies. Our mission is ‘Data Protection Made Easy’ our experts are not only knowledgeable but they are skilled at simplifying complex areas of data protection making it easy to understand and easy to implement.
We recognise that every organisation is unique, and we customise our reviews and support to fit your specific needs, industry, and risk profile.
We go beyond ticking regulatory boxes, focusing on building a sustainable data protection culture within your organisation, empowering responsible data governance practices.
We maintain open communication throughout the process, sharing insights and recommendations clearly and effectively, ensuring you stay informed and empowered.
We have a history of helping organisations of all sizes achieve and maintain data protection compliance, minimising risks and building trust with stakeholders.
Investing in a Data Protection Compliance audit from Computer Audit Control and Security (CACS) Associates Limited is an investment in your future. It’s a proactive step towards safeguarding your reputation, minimising financial and legal risks, and building a foundation of trust with your customers, employees, and regulators.