Compliance · · 11 min read · By Hackrowd Team
NDPA Compliance Audit: Technical Evidence Checklist for 2026
Prepare technical evidence for a Nigerian data protection compliance audit under the NDPA 2023 and GAID 2025, with statutory duties separated from audit practice.
## What Governs a Nigerian Data Protection Audit in 2026?
The **Nigeria Data Protection Act 2023** is the primary statute. The Nigeria Data Protection Commission's **General Application and Implementation Directive 2025**, or GAID 2025, provides current implementation direction.
The older Nigeria Data Protection Regulation 2019 is no longer the operative instrument: GAID 2025 cancelled its application while preserving actions already taken under it. This distinction matters because many online checklists still present NDPR procedures as current law.
Use the [official NDPC GAID 2025 publication](https://ndpc.gov.ng/wp-content/uploads/2025/03/NDP-ACT-GAID-2025-MARCH-20TH.pdf) and the [Nigeria Data Protection Act 2023 text](https://ncc.gov.ng/sites/default/files/2024-11/Nigeria_Data_Protection_Act_2023.pdf) as primary references. Confirm filing status and deadlines with a licensed Data Protection Compliance Organisation, because classification and Commission guidance can change.
## Statutory Duties Versus Practical Technical Evidence
The law and Directive establish duties such as lawful processing, data-subject rights, appropriate security, accountability, Data Protection Impact Assessments for high-risk processing, Data Protection Officer responsibilities, registration where applicable and compliance audit returns.
They do not prescribe a universal pentest frequency or a single technology stack. Items such as configuration screenshots, access logs and penetration-test reports are **practical evidence** used to demonstrate that controls operate; they are not each standalone statutory commands.
Keeping that distinction clear prevents two errors: claiming that one report proves compliance, or dismissing technical evidence because the Act does not name a particular tool.
## Core Governance Evidence
Prepare a controlled evidence index containing:
- Your data controller or processor classification and registration evidence
- DPO appointment, responsibilities, competence records and internal reports
- Records of processing activities and data-flow maps
- Applicable Compliance Audit Return and licensed DPCO correspondence
- Approved privacy, retention, access-control and incident-response policies
- DPIAs for high-risk processing
- Data subject request procedures and completed request records
- Processor agreements and international-transfer assessments
- Training records and management review minutes
Only include personal data needed for the audit. Redact or securely transfer samples so the evidence exercise does not create a new privacy incident.
## Technical Evidence Auditors Commonly Request
### Identity and access management
Provide approved role definitions, joiner-mover-leaver samples, privileged-access reviews, multi-factor authentication settings and access logs. The evidence should show that access is granted for a purpose and removed when no longer required.
### Encryption and key management
Show how sensitive personal data is protected in transit and at rest, where keys are held, who can use them and how they rotate. A policy statement without configuration evidence is incomplete.
### Logging, monitoring and incident response
Retain security alert examples, log coverage, escalation records, incident exercises and the breach register. Where an incident occurred, preserve the decision trail for notification and remediation.
### Secure development and vulnerability management
Keep code-review controls, dependency checks, vulnerability records, penetration-test reports, remediation tickets and retest evidence. These demonstrate reasonable security; they do not by themselves certify NDPA compliance.
### Retention, deletion and backup
Map retention rules to systems, show completed deletion or anonymisation jobs, and demonstrate that backups are protected and expire consistently with policy.
### Vendor assurance
Maintain due-diligence records, processing agreements, subprocessor lists, security reviews and exit arrangements for vendors that handle personal data.
## DPIA Evidence for High-Risk Processing
A useful DPIA identifies the purpose and legal basis, categories of people and data, data flows, necessity and proportionality, risks to individuals, safeguards, residual risk, consultations and approval. Revisit it when the purpose, technology, recipients or risk changes.
A generic template with no system-specific data flow is unlikely to show that the assessment influenced a real decision.
## Build an Audit-Ready Evidence Pack
1. Confirm entity classification, registration and filing obligations.
2. Assign an owner to every evidence request.
3. Map each duty to a policy, operating record and accountable approver.
4. Sample evidence across the audit period instead of taking one current screenshot.
5. Record gaps with remediation owners and dates.
6. Use a licensed DPCO for the formal filing process where required.
7. Keep legal conclusions with qualified privacy counsel or the DPCO; keep technical findings factual.
## Common Audit Gaps
- Calling the engagement an NDPR audit in 2026 without addressing GAID 2025
- No complete data inventory or system-level flow map
- Policies that cannot be connected to operating records
- Excessive standing privileges and weak access reviews
- DPIAs completed after a high-risk product launched
- Vendor contracts with no evidence of ongoing oversight
- Vulnerabilities marked closed without proof or retesting
- Retention schedules that are not implemented in production systems
## NDPA Technical Evidence Checklist
- Confirm current registration and audit-return obligations
- Appoint and support a competent DPO
- Maintain processing records and data-flow diagrams
- Complete DPIAs before high-risk processing
- Evidence access control, encryption, logging and monitoring
- Test incident response and maintain a breach register
- Track vulnerabilities through remediation and verification
- Evidence retention, deletion and protected backups
- Review processors and keep appropriate agreements
- File through a licensed DPCO where required
## Frequently Asked Questions
### Does the NDPA require a penetration test?
The Act requires appropriate security and accountability but does not set one universal pentest cadence for every organisation. A risk-based penetration test can be strong technical evidence for internet-facing or high-risk systems.
### Is an NDPR audit still the current process?
The NDPA 2023 and GAID 2025 are the current starting points. Older NDPR filings remain relevant historically, but current advice should not treat NDPR 2019 as the operative instrument.
### Can Hackrowd file our Compliance Audit Return?
Formal filing should be handled through a licensed DPCO. Hackrowd can assess technical controls and assemble remediation evidence, while your DPCO and counsel handle the formal compliance determination.
## Strengthen the Technical Evidence
Hackrowd's [penetration testing](/penetration-testing), [cloud security assessment](/cloud-security-assessment) and [third-party risk](/third-party-risk) services can help validate the security controls supporting your audit. These services provide technical evidence, not legal certification.