The NDPA and Customer Data: What Nigerian SME Websites Should Get Right
The Nigeria Data Protection Act applies to ordinary business websites, not just big tech. Here is what an SME site should get right about enquiries, cookies, and storage.
By FASS Admin
The Nigeria Data Protection Act is often assumed to be a concern for banks and telecoms. In practice, any website that collects a name, phone number, email address, or order history is processing personal data, which brings ordinary Nigerian SMEs inside the NDPA’s reach. The obligations for a small business are lighter than for a large data broker, but they are not zero, and the basics cost almost nothing to implement properly.
Begin with honesty at the point of collection. An enquiry form should say what will happen to the details submitted: who receives them, whether marketing may follow, and how to request deletion. This is usually one sentence under the submit button. Hidden collection is the fastest way to turn a routine form into a complaint.
Minimise what you gather. Every field on a form is a liability as well as a convenience. A catering business rarely needs a date of birth to quote for an event, and a retailer does not need an ID number to ship an order. Collecting less means storing less, and storing less shrinks both the risk and the compliance burden.
Storage and access come next. Enquiry emails sitting in a shared inbox that every former employee can still open are a common weak point. Remove access when people leave, use a password manager instead of a group chat for credentials, and know where customer records physically live: your hosting provider, your developer’s laptop, or a third-party tool. Backups should exist, but so should a way to delete a person’s data from them when requested.
Third parties deserve attention. Payment gateways, analytics tools, messaging services, and email providers all process something on your behalf. Two practical rules cover most of it: use reputable providers configured sensibly, and disclose in your privacy policy that these processors are involved. Card details themselves should never be stored on your own servers; that is precisely what gateways like Paystack handle under their own compliance.
Documents close the loop. A readable privacy policy and terms of service, aligned to the NDPA, are expected on professional websites, and drafting them is available as a focused add-on at ₦50,000, with legal review remaining the client’s responsibility. What matters is that the documents describe what the site truly does, not what a template guessed it might do.
None of this requires a lawyer on retainer to start. An afternoon spent listing what your website collects, where it goes, and who can reach it will put you ahead of most competitors. FASS builds these defaults into new sites and can review an existing one; send the URL through /contact to begin.