Core data-protection documents for Nigerian organizations: a privacy policy, RoPA register, DPIA template, consent notice, and a 72-hour breach-notification procedure.
These terms are key components of modern data privacy and protection laws like the Nigeria Data Protection Act (NDPA):
- NDPA (Nigeria Data Protection Act): The principal legislation that regulates how public and private entities collect, store, and process personal data in Nigeria. It gives individuals control over their personal information and is enforced by the Nigeria Data Protection Commission (NDPC).
- RoPA (Record of Processing Activities): An internal document or live register maintained by organizations. It details exactly what personal data is being processed, why it is collected, who it is shared with, and how long it is kept.
- DPIA (Data Protection Impact Assessment): A systematic evaluation process used to identify and minimize privacy risks before beginning any "high-risk" data processing project. It is often triggered by the use of new technologies, sensitive data, or systematic monitoring.