NDPC orders data controllers to harden security: certified DPOs, MFA, impact assessments
On 16 April 2026 the NDPC issued a data protection advisory directing all controllers and processors, government ministries included, to strengthen technical and organisational measures against escalating cyber threats: certified data protection officers, regular data protection impact assessments, multi-factor authentication and NDPA 2023-grade security controls. Advisories read as soft law until you place this one in its month. It followed the 1 April investigation notice and the CAC breach probe, and it preceded further enforcement moves. The NDPC was running a three-beat sequence: advise everyone, investigate the breached, then enforce against the non-compliant. The advisory converts general security expectations into specific, citable requirements, which is exactly what a regulator does before it starts penalising their absence. Nigeria-facing organisations that cannot evidence a certified DPO, MFA deployment and current DPIAs are carrying documented, self-inflicted exposure.
Spotted an error? Write to info@lawlab.africa and we will correct the record.