Data protection basics for small Nigerian businesses
If you hold customer names, phone numbers or employee records, data protection obligations generally apply to you.
Sample article 5 min read

A common assumption among smaller businesses is that data protection is a concern for banks and technology companies. It is not. If you collect personal data about people in Nigeria, obligations generally apply regardless of size, although what is proportionate for a ten-person business differs from what is expected of a bank.
Nigeria's framework has developed considerably, with the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission. Detailed requirements continue to develop through regulations and guidance, so treat what follows as orientation rather than a checklist.
Know what you hold
You cannot protect data you have not catalogued. Write down what personal data you collect, where it came from, why you have it, where it is stored, who can access it, who you share it with, and how long you keep it.
This is uncomfortable for most businesses because it reveals spreadsheets on personal laptops, customer lists in WhatsApp, and CVs in an inbox from four years ago. That discovery is the point.
Have a reason for holding it
Processing personal data requires a lawful basis. Consent is one, but not the only one and often not the best: it must be freely given and can be withdrawn. Performing a contract, complying with a legal obligation and legitimate interests are others. For each category of data you hold, you should be able to state why you are entitled to hold it.
Tell people, readably
A privacy notice explains what you do with people's data. It should be available at the point of collection, and it should be readable. A notice only a lawyer can parse does not achieve its purpose.
Collect less
The cheapest and most effective measure available to a small business is to stop collecting what it does not need. Every optional field on a form is data you must secure, justify and eventually delete. Ask what each field is genuinely for.
Secure what you keep
Proportionate measures: access limited to those who need it, strong authentication, encrypted devices, care with removable media, and a plan for a lost laptop or compromised account. Consider your vendors too. If a third party processes data for you, there should be a written arrangement covering it.
Respect people's rights, and delete on schedule
Individuals have rights including access, correction and, in defined circumstances, deletion. You need a route for a request and a process for handling it in time. For a small business, a monitored email address and a simple procedure will do.
Retention is the obligation most often overlooked. Decide how long each category is kept and why, then actually delete when the period expires. Data you no longer hold cannot be breached.
A proportionate first step
If you do only three things: map what you hold, publish a readable privacy notice, and delete what you do not need. That is a meaningful improvement on where most small businesses start.
Found this useful? Share it.