Nigerian users · Legal notice · effective September 25, 2026

Nigeria NDPR / NDPA Addendum

Nigerian Data Protection Regulation (NDPR 2019) and Nigeria Data Protection Act 2027 compliance disclosures, DPO details and breach notification protocol.

This Nigeria NDPR / NDPA Addendum applies to every data subject located in the Federal Republic of Nigeria, to every data subject who is a Nigerian citizen wherever resident, and to every processing operation performed by Invozaa in respect of personal data transmitted from Nigeria or originating from an individual in Nigeria. This Addendum implements the Nigeria Information Technology Development Agency (NITDA) Nigeria Data Protection Regulation, 2019 (the “NDPR 2019”), and the Nigeria Data Protection Act, 2027 (the “NDPA 2027”).


1. Controller, Processor, and DPO
Data Controller: Invozaa — the organisation that alone or jointly with others determines the purposes and means of the processing of personal data in the course of providing the invoice and receipt platform.
Data Processor: where Invozaa processes personal data strictly on the written instructions of an enterprise customer who is the Data Controller (for example, B2B customers using our API or white-label account feature), Invozaa acts strictly as a Data Processor in accordance with NDPA 2027 Section 16 obligations.
Data Protection Officer (DPO): Invozaa has registered a DPO with the Nigeria Data Protection Commission (“NDPC”) in line with NDPA 2027 Section 11. The DPO may be contacted directly for all data-protection related enquiries, rights requests, breach alerts, and DPIA review at support@invozaa.com. Correspondence may be submitted in English or any major language of Nigeria; response turnaround is acknowledged within 7 business days.


2. Lawful bases for processing (NDPA 2027 Sections 9–13)
All processing of Nigerian personal data by Invozaa is grounded in one or more of the following lawful bases, recorded on our processing inventory for each data stream:
(a) Explicit, freely-given, specific, informed, and unambiguous consent of the Data Subject (e.g. marketing consent, opt-in to non-essential cookies);
(b) Necessary for the performance of a contract to which the Data Subject is party (your paid invoice/receipt service);
(c) Necessary for compliance with a legal obligation to which the Controller is subject (7-year tax record retention, FIRS reporting, compelled disclosure by lawful warrant or court order);
(d) Necessary to protect the vital interests of the Data Subject or another natural person;
(e) Necessary for the performance of a task carried out in the public interest;
(f) Necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the fundamental rights and freedoms of the Data Subject (balancing test documented in our ROPA).
Where processing is based on consent, the Data Subject has the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.


3. Transparency & Privacy notices (NDPA 2027 Section 17)
All personal data processing operations are described in our global Privacy Policy, supplemented by this NDPR/NDPA-specific notice, available at the public URL of this page. The notice is issued in plain-language English and, where processing is directed to a particular ethnic or language group, may be translated. No discriminatory unfair contract terms are used to waive Data Subject rights.


4. Fair & lawful processing principles (NDPR 2019 Principles 1–7)
Every processing operation performed by Invozaa conforms to the NDPR 2019 seven core principles: Lawfulness, Fairness & Transparency; Purpose Limitation; Data Minimisation; Accuracy; Storage Limitation; Integrity & Confidentiality; Accountability. A copy of our Principle Compliance Attestation is available on written request to the DPO.


5. Rights of Data Subjects (NDPA 2027 Chapter 4 & Chapter 6)
Each Nigerian Data Subject may, without undue delay and without payment of any fee, exercise the following rights against the Controller by signed written request to support@invozaa.com:
(a) Right to confirmation that processing concerning the Data Subject is being or has been carried out, and, in the affirmative case, access to personal data (including a copy of the categories processed and the technical organisation);
(b) Right to obtain, without constraint and at an affordable cost, the personal data undergoing processing in an intelligible form, with knowledge of the logic involved in any automated processing;
(c) Right to request rectification or update of inaccurate, incomplete, or misleading personal data;
(d) Right to erasure of personal data where processing is no longer justified or where consent was withdrawn (Right to be Forgotten, subject to NDPA 2027 Section 33 exceptions for legal-retention data);
(e) Right to restrict or object to processing for direct marketing, automated decision-making, or for processing based on legitimate interest;
(f) Right to receive personal data in a structured, commonly-used, machine-readable format, including the right to have that ported to another controller without hindrance;
(g) Right to compensation for damage caused by a breach of any provision of the NDPA 2027 or NDPR 2019 on the part of the Controller or Processor, and the right to report an infringement to the NDPC.
All requests acknowledged in writing within 7 (seven) business days and substantively completed within 30 calendar days. Where processing is complex, we may extend this by an additional 60 (sixty) days, with written notification of the delay during the first 30-day window.


6. Cross-border data transfers (NDPR 2019 Part VI, NDPA 2027 Sections 46–53)
Invozaa does NOT transfer, whether directly or through onward processing, Nigerian personal data to any country outside the Federal Republic of Nigeria unless one of the following safeguards is in place, in strict order of precedence:
(a) The destination country is listed on a published adequacy decision issued by the Nigeria Data Protection Commission;
(b) The Controller or Processor in the destination country provides legally binding and enforceable commitments, including duly-executed Standard Contractual Clauses in a form approved by the NDPC, or Binding Corporate Rules approved by the NDPC;
(c) The transfer is necessary by reason of public interest, for the conclusion or performance of a contract, to protect the vital interests of the Data Subject, or for the establishment, exercise or defence of legal claims;
(d) An Impact Assessment report submitted to, and approved by, the NDPC confirms adequate level of protection in the destination country.
Nigerian personal data is, by default, stored in the Lagos Region AWS af-south-1 zone, with encrypted, integrity-verified backups written to the same region first, and cross-region disaster-recovery replicas only where Section 52(c)–(d) conditions apply.


7. Data Protection Impact Assessments (NDPA 2027 Section 44)
Where processing is likely to result in a high risk to the rights and freedoms of Data Subjects — including large-scale processing of PHI, processing of biometric data, processing for the purpose of scoring/creditworthiness, use of video / audio monitoring, or novel AI-based decision making — Invozaa will conduct, or procure from a third-party auditor, a full Data Protection Impact Assessment (“DPIA”) and submit a copy to the NDPC for prior consultation if the residual risk remains high after mitigation design.


8. Record of Processing Activities / ROPA (NDPA 2027 Section 15)
A living, versioned Record of Processing Activities is maintained under the authority of the DPO and includes for each processing operation: the controller identity, joint-controller identities (if any), processor identities, DPO contact, purposes of processing, categories of Data Subjects, categories of personal data, lawful basis, retention periods, safeguards, categories of recipients with categories of transfer, and cross-border transfer route with applicable adequacy clause / SCC / BCR reference. The ROPA is available for on-site audit by the NDPC during any scheduled or unscheduled inspection visit.


9. Breach reporting to NDPC (NDPA 2027 Sections 56–57)
Controller is obliged to notify the NDPC within 72 HOURS of awareness of a personal data breach, where the breach is not unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk, the affected Data Subject(s) are individually notified without undue delay, including the likely consequences, and the contact details of the DPO. A post-incident remediation report is delivered to the NDPC no later than 30 (thirty) calendar days after the initial 72-hour alert.


10. Penalties & enforcement
We are aware that the NDPA 2027 provides for maximum administrative penalties of up to N10,000,000 (Ten Million Naira) or 2% of annual gross revenue, whichever is higher, for a contravention; a maximum criminal fine of N20,000,000 (Twenty Million Naira) or imprisonment for a term of 3 years or both for a Director or officer who knew or ought to have known; and unlimited civil damages for negligence-based claims by affected Data Subjects at the Federal High Court. It is therefore our policy to immediately report, investigate, and close every confirmed data-security incident, with copies of the completed incident report published internally and shared with affected individuals.


11. DPO / NDPC contact
Data Protection Officer: support@invozaa.com
Nigeria Data Protection Commission (NDPC): contact the NDPC via ndpc.gov.ng should you wish to escalate any privacy complaint directly to the national regulator.