Privacy Policy Sample

Publish an NDPA-compliant privacy policy for your Nigerian website or app - covering the data you collect, your lawful basis, data subject rights and your DPO

Premium
🇳🇬Nigeria

Preview

About this template

A Nigeria-ready, NDPA-compliant privacy policy you can customize and download in minutes

A privacy policy tells the people who use your website or app what personal data you collect, how you use and share it, how long you keep it, and what rights they have. This template is a standard, plain-English format built for Nigeria, drafted around the Nigeria Data Protection Act, 2023 (NDPA) and the Nigeria Data Protection Commission's General Application and Implementation Directive (GAID). It gives your business a clear, compliant policy that identifies you as the data controller, sets out your lawful basis for processing, explains cross-border transfers and data subject rights, and points users to your Data Protection Officer and the NDPC.

Just answer a few simple questions - your business name and RC number, your website, contact and DPO details, the third-party tools you use, and your retention period - and your personalized NDPA privacy policy is generated instantly (within five pages), ready to download as PDF or Word and publish on your platform.

What this privacy policy includes

- Introduction and identity - who you are as the data controller, your RC number and contact details, and a reference to the NDPA and GAID

- Categories of personal data collected - data you provide, data collected automatically, and how sensitive personal data is handled

- Purpose of collection - a clear, customizable list of why you process data

- Lawful basis for processing - the six bases under section 25 of the NDPA (consent, contract, legal obligation, vital interests, public interest, legitimate interests)

- Third-party disclosures - processors, legal/regulatory (including the NDPC), corporate transactions, and a "we do not sell your data" statement

- Cross-border transfers - aligned with sections 41–43 of the NDPA and the GAID (adequacy or a lawful safeguard)

- Data security measures and a breach-notification clause (NDPC within 72 hours; affected individuals for high-risk breaches)

- Data retention policy with a period you set

- Data subject rights under the NDPA — access, rectification, erasure, restriction/objection, portability, withdraw consent, automated-decision protection, and the right to complain to the NDPC

- Cookies, a children's privacy clause (under 18), a changes clause, and a contact & DPO section

How to create your privacy policy

1. Open the template and click Generate.

2. Answer the guided questions - your business, website, contact and DPO details, third-party tools and retention period.

3. Generate the document - your details are merged into the policy automatically.

4. Review and download as PDF or Word, then publish it on your website or app and keep it current.

Who is this privacy policy for?

Nigerian businesses, startups, online stores, fintechs and app developers - and any organization processing the personal data of people in Nigeria - that needs a clear, NDPA-compliant privacy policy. It is written as a strong compliance baseline; you fill in your specifics, including your DPO where you are a data controller of major importance.

Disclaimer: This template is provided for convenience and general information only and is not legal advice. The NDPA and the NDPC's GAID impose specific obligations - including registration of data controllers/processors of major importance, DPO appointment, DPIAs, breach reporting and cross-border transfer rules — that depend on your organization and the data you process. Confirm your obligations with the NDPC's current requirements, and for high-risk or large-scale processing have your policy reviewed by a qualified Nigerian data-protection lawyer.

---

What's included

- Professional formatting and layout, within 5 pages

- Easy customization with guided questions

- Multiple export formats: pdf, docx

- Core sections aligned with the NDPA 2023 and NDPC GAID

- Instant download after generation

What's included
  • Professional formatting and layout
  • Easy customization with guided questions
  • Multiple export formats: pdf, docx
  • Legally reviewed and compliant
  • Instant download after generation
Frequently asked questions
Does my Nigerian website or app need a privacy policy under the NDPA?

Yes. Under the Nigeria Data Protection Act, 2023 (NDPA), any business or organization that collects or processes the personal data of people in Nigeria must tell them, in a clear privacy notice, what data is collected, why, on what lawful basis, who it is shared with, and what rights they have. If your website or app collects names, emails, payment details, or even analytics and cookies, you need a compliant privacy policy — and the NDPC can enforce the rules.

Is this template compliant with the NDPA and the NDPC's GAID?

It is drafted around the NDPA 2023 and the NDPC's General Application and Implementation Directive (GAID), and includes the core sections they expect — identity of the data controller, categories of data, purpose, the six lawful bases under section 25, third-party disclosures, cross-border transfer rules, security and 72-hour breach notification, retention, data subject rights and DPO details. It is a strong standard baseline; because obligations depend on your organization, confirm the specifics with the NDPC's current requirements.

What lawful bases for processing does it cover?

It sets out the six lawful bases under section 25 of the NDPA: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, public interest or official authority, and legitimate interests. You should process personal data only where at least one applies, and where you rely on consent, the policy makes clear that users can withdraw it at any time.

What rights do data subjects have, and how do they exercise them?

Under the NDPA, individuals can be informed about processing, access their data, have it corrected, request erasure (the right to be forgotten), restrict or object to processing, receive their data in a portable format, withdraw consent, and not be subject to solely automated decisions. The policy tells users to contact you or your DPO to exercise these rights, and that they can lodge a complaint with the NDPC.

Do I need a Data Protection Officer (DPO)?

The NDPA and GAID require a DPO for data controllers or processors of major importance (and in some other cases). The template includes a DPO section with name and email fields. If you are not yet required to appoint one, you can name a responsible contact there for now, but check the NDPC's registration and DPO thresholds as your processing grows.

How does the policy handle sending data outside Nigeria?

Cross-border transfers are covered in line with sections 41–43 of the NDPA and the GAID: personal data may be transferred abroad only where the destination provides an adequate level of protection recognized by the NDPC, or where a lawful condition or safeguard applies — such as your consent, necessity for a contract, or binding contractual protections requiring the recipient to meet NDPA standards. List your overseas providers (e.g. hosting or analytics) so users know where data may go.

Premium plan required to use this template

Need help?

Our team is here to assist you with any questions about this template.

Contact Support