A recent cyberattack on Kido International, a private nursery group operating 18 branches across Greater London, has raised alarm in the UK and beyond. The personal data of around 8,000 children — including names, photos, addresses, and family contact details — was stolen by a notorious ransomware group. This incident highlights the growing risks of […]
Cybersecurity threats are increasing globally, and Nigerian companies are not exempt. From ransomware attacks on banks to data breaches in fintech and e-commerce, organizations need structured approaches to protect sensitive data. One of the most widely respected global standards is the NIST Cybersecurity Framework (NIST CSF). Developed by the U.S. National Institute of Standards and […]
Data privacy is no longer just a legal checkbox—it’s a global business necessity. As regulations like the General Data Protection Regulation (GDPR) in Europe, the Nigeria Data Protection Act (NDPA 2023/2025), and the California Consumer Privacy Act (CCPA) reshape corporate responsibilities, one international standard stands out as the backbone of trust: ISO 27001. This article […]
Welcome to the definitive, up-to-date guide on Nigeria’s NDPA Act 2025, incorporating the recently issued General Application & Implementation Directive (GAID) 2025. If you are a business, compliance officer, startup, law firm, or simply interested in data privacy, this article walks you through everything: scope, definitions, obligations, rights, compliance steps, and real-world examples. We aim […]
Why Definitions Matter Under the NDPA If you’re new to the Nigeria Data Protection Act (NDPA), one of the first hurdles is the legal jargon. Words like “data subject,” “controller,” and “processing” may sound abstract but they matter. Legal clarity: Compliance obligations depend on exact definitions. Roles & scope: Whether you’re a controller or processor […]