# Data Controller or Data Processor? Getting the NDPA Split Right With Your Technology Vendor
TL;DR: Under Nigeria's Data Protection Act (NDPA) 2023 and the Commission's 2025 General Application and Implementation Directive (GAID), "controller" and "processor" are legal roles with different obligations, not interchangeable labels. Getting the split wrong in a vendor contract leaves gaps in exactly the documents the NDPC asks for, such as data processing agreements and registration.
This article is general information, not legal advice.
Why this distinction suddenly matters
For years, Nigerian companies treated data protection as a checkbox: paste a privacy policy on the website, get an NDPR audit certificate, move on. That era is over. On 20 March 2025, the Nigeria Data Protection Commission (NDPC) issued the General Application and Implementation Directive (GAID), which became effective 19 September 2025. Article 3(3) of the GAID states that the Commission ceased to apply the older Nigeria Data Protection Regulation (NDPR) 2019 as a legal instrument once the GAID was issued, without affecting anything already done under it. The GAID and the NDPA 2023 are now the two instruments that govern how personal data is handled in Nigeria, and together they spell out — in far more operational detail than before — who is responsible for what when a business hands customer or employee data to a software vendor, a cloud host, a payments processor, or an AI tool.
The Commission is not treating this as theoretical. On 25 August 2025, the NDPC published a notice naming 1,368 organisations in banking, insurance, pensions and gaming and giving them 21 days to submit evidence of compliance, including compliance audit returns, the appointment of a Data Protection Officer and registration as a data controller or processor of major importance (Premium Times). If your business was one of the 1,368, or expects to be swept up in the next round, knowing exactly which role you occupy (and which role your technology vendor occupies) is the difference between a clean audit and a costly one.
The core definitions, in plain terms
The NDPA borrows its structure from the GDPR, so if you've seen "controller" and "processor" in a European context, the logic will feel familiar — but the Nigerian penalties and registration mechanics are distinctly local.
- Data Controller (Section 65 of the NDPA): any individual, private entity, public authority, agency or other body that determines — alone or jointly with others — the purposes and means of processing personal data. In practice: the business that decides why customer data is collected and how it will be used.
- Data Processor (Section 65): any individual, private entity, public authority or other body that processes personal data on behalf of or at the direction of a controller or another processor. In practice: the vendor executing tasks — hosting, running analytics, sending SMS/email, processing payments — strictly as directed.
Because both definitions turn on who determines purposes and means, the sensible reading is functional, not contractual: what matters is who actually makes the decisions, not what a services agreement claims. Calling your CRM vendor a "processor" in a contract doesn't hold up if that vendor is quietly repurposing your customer list for its own marketing — at that point, it has stepped into controller territory for that specific activity, regardless of the label.
Where it gets genuinely confusing
Common vendor relationships tend to follow one of these patterns, and each carries a different answer:
| Scenario | Who is the Controller | Who is the Processor |
|---|---|---|
| You hire an agency to build and host a customer-facing app that only you operate | You (the business) | The agency/hosting provider, for hosting/maintenance only |
| Your fintech app routes transactions through a third-party payment gateway using its own risk and fraud rules | You, for your app's user data | Gateway is typically a processor for the transaction data, but often a joint/independent controller for its own fraud-scoring data |
| You use a shared SaaS HR or payroll platform that also benchmarks anonymised salary data across its client base for its own product | You, for your employees' data | The SaaS vendor is your processor and a controller for its own benchmarking use — a dual role |
| Two companies co-run a marketing campaign and pool customer lists | Both are controllers — likely joint controllers | N/A unless a separate execution vendor is involved |
The third row is the easy one to miss: a vendor can be your processor for one activity and an independent controller for another, inside the same contract. Because the definitions attach to who decides the purpose and means of each processing activity, a single blanket clause labelling the vendor a "processor" doesn't settle it.
What each role actually owes under the NDPA and GAID
If you're the controller, you carry the heavier weight:
- Establishing a lawful basis for processing (Section 25: consent, contract, legal obligation, vital interest, public interest or legitimate interest)
- Data Privacy Impact Assessments (DPIAs) for high-risk processing (Section 28; Article 28(3) of the GAID lists cases where a DPIA is mandatory and must be filed with the NDPC)
- Notifying the NDPC of a breach within 72 hours where it is likely to create a risk to people's rights, and notifying affected people immediately where the risk is high (Section 40(2)-(3))
- Designating a Data Protection Officer if you are a controller of major importance (Section 32)
- Ensuring any processor you engage meets the Section 29 obligations, including through a written agreement
- Registering as a data controller of major importance (Section 44) if you meet the NDPC's designation criteria. Under the Guidance Notice now reproduced as Schedule 7 of the GAID, the entry threshold is keeping a filing system and processing the personal data of more than 200 data subjects in six months, or operating in a listed sector
If you're the processor, your obligations are narrower but still real:
- Complying with the Act's principles and obligations as they apply to the controller, and helping the controller honour data subject rights (Section 29(1)(a)-(b))
- Implementing appropriate technical and organisational security measures (Section 29(1)(c))
- Giving the controller the information it needs to demonstrate compliance (Section 29(1)(d))
- Notifying the controller when it engages another processor (Section 29(1)(e)); your contract can go further and require prior authorisation
- Notifying the controller of a breach on becoming aware of it and answering its information requests (Section 40(1)); the controller owns the regulator and data-subject notifications
- Registering as a data processor of major importance where the same designation criteria apply
Penalties are tiered and apply to both roles. Under the NDPA, controllers/processors of "major importance" face a maximum fine of the greater of ₦10,000,000 or 2% of the entity's annual gross revenue for the preceding financial year; other organisations face the greater of ₦2,000,000 or 2% of annual gross revenue. Those caps are set by Section 48, which also lets the NDPC order a remedy, compensation to affected data subjects, or an account of profits realised from the violation. Failing to comply with a compliance order under Section 47 is an offence under Section 49, punishable by a fine up to the same caps, imprisonment of up to one year, or both.
The one document that actually protects you: the Data Processing Agreement
Neither the NDPA nor the GAID lets a controller off the hook by simply outsourcing processing to a vendor. Section 29(2) of the Act says the measures a controller takes to bind its processor include a written agreement, and Article 34 of the GAID lists what a data processing agreement (DPA) must contain. It is not a boilerplate NDA. Among other things, it must cover:
- The parties' obligations under Section 29 of the NDPA
- The purpose, scope and lawful basis of the processing
- The location of processing, taking the cross-border transfer rules into account
- The technical and organisational security measures (in a schedule if they are technical)
- The outcome of any DPIA and the potential risks
- Evidence of NDPA compliance, including the other party's registration with the Commission
- Confidentiality, tenure, specific restrictions, indemnity, insurance, force majeure and dispute resolution
It is also sensible to add breach-notification timelines back to the controller and audit rights, even though the GAID list doesn't name them.
If your current vendor contracts predate 2023, or were drafted against the old NDPR, check them against the Article 34 list, since several of those items (location of processing, DPIA outcome, registration evidence) were not standard clauses before the GAID.
A practical checklist before your next vendor engagement
1. Map the data flow first, then assign roles. Don't start with "we'll call them the processor" — start with who decides purpose and means for each specific data activity.
2. Assume dual roles are possible. A vendor can be a processor for one function and a controller for another within the same engagement.
3. Check the 200-data-subject threshold. If your organisation keeps a filing system and processes more than 200 individuals' data in a six-month window, or operates in a listed sector, budget for registration as a controller or processor of major importance (unless you fall in an exempt category such as faith-based organisations).
4. Get the DPA in writing before data flows, not after. Retrofitting a compliant agreement after a breach is the worst possible time to discover it doesn't exist.
5. Build security and access controls into the architecture, not just the contract. A DPA that promises "appropriate technical measures" is only as good as what's actually implemented in the codebase and infrastructure.
That last point is where a development partner's engineering choices and a client's legal exposure intersect. A software agency that builds and hosts a platform handling a client's customer data (a client portal, a fintech dashboard, a health record system) is normally acting as that client's processor, which means access controls, encryption at rest and in transit, audit logging and breach-notification readiness need to be designed in from day one, not bolted on before an audit. Our data protection page describes the technical practices we apply in that processor role.
FAQ
Q: Can a small business avoid NDPA obligations entirely if it's not a "controller of major importance"?
No. The major-importance threshold (a filing system plus more than 200 data subjects in six months, or operating in a listed sector) triggers registration with the NDPC and the DPO requirement, but the core NDPA obligations (lawful basis, security safeguards, breach notification, a written agreement with any processor) apply to controllers and processors of any size. Major-importance status adds registration and heavier scrutiny; it isn't the line at which the law starts applying.
Q: Our vendor is based outside Nigeria (e.g., a cloud provider or offshore dev team). Does the NDPA still apply?
Yes. Section 2 of the NDPA applies the Act where the controller or processor is in Nigeria, where processing happens in Nigeria, or where a foreign controller or processor processes the personal data of a data subject in Nigeria. Sending data to an offshore vendor is also a cross-border transfer, which Section 41 only allows with adequate protection (for example contractual clauses) or under a Section 43 condition, and which Article 28(3)(o) of the GAID lists as a mandatory DPIA trigger. Your DPA needs an explicit transfer clause, not just a generic confidentiality clause.
Q: What happened to the old NDPR — do we still need to comply with it?
No longer as a separate legal instrument. Article 3(3) of the GAID says the Commission ceased to apply the NDPR 2019 once the GAID was issued (things done under the NDPR before then are unaffected). The NDPA 2023 and the GAID 2025 are now the operative framework, so any policy or contract still referencing only the NDPR should be updated.
Q: If our processor causes a data breach, are we (the controller) still liable?
Generally yes, in terms of regulatory and data-subject-facing responsibility. Under Section 40 the processor must tell the controller, but it is the controller that must notify the NDPC and affected individuals, even when the breach originated at the processor, and Article 34(3) of the GAID makes every controller accountable for the actions or inactions of third parties it engages. This is precisely why the DPA's breach-notification-to-controller timeline, and the processor's actual security posture, matter as much as the paperwork.
---
Sources
- NDPC Issues GAID – Key Compliance Insights — DLA Piper Privacy Matters
- Data Protection Commission's General Application and Implementation Directive enters into force — Digital Policy Alert
- NDPC Issues Guidance Notice on Registration of Data Controllers and Processors of Major Importance — Mondaq
- Nigeria Data Protection Act, 2023 — NDPC
- NDP Act General Application and Implementation Directive (GAID) 2025 — NDPC
- NDPC issues compliance notices to banks, insurers, pension and gaming firms — Premium Times
- An Overview of Nigeria's Data Protection Act, 2023 — Securiti
- Introducing the Nigeria Data Protection Act 2023 — Aluko & Oyebode