Platform

One record, not six spreadsheets.

Most Nigerian compliance programmes are six disconnected documents that disagree with each other. Estreat holds a single record of how your organisation processes personal data, and every obligation is answered as a view of that record.

Designed for data protection officers, general counsel and heads of risk at controllers and processors of major importance.

What sits underneath

Four primitives carry the whole system: the entity, the processing activity, the obligation and the artefact. Every module reads and writes those four, which is why an answer given once is never asked for twice.

EntityYour company, its group members, tier and NDPC registration
ActivityA purpose, its data, systems, people, processors and transfers
ObligationA statutory or audit requirement with an owner and a due date
ArtefactThe dated evidence that an obligation was met

One record

Nothing is re-keyed, because nothing is stored twice.

A processing activity captured during onboarding becomes a RoPA entry, a candidate for DPIA screening, a scope item for transfer analysis, a target for a subject request search, and a line in your annual return. It is one object with one owner and one history, viewed six ways.

Module, output, and the obligation it answers
ModuleWhat it producesObligation answered
Record of processingA versioned inventory of processing activities, systems, purposes, lawful bases, retention periods and transfersNDPA s.29 record-keeping; GAID Schedule 2 questions on processing and lawful basis
Impact assessmentsA scored DPIA per high-risk activity, with identified risks, mitigations, residual risk and named sign-offNDPA s.28 impact assessment duty for processing likely to result in high risk
Data subject requestsA request register with identity checks, statutory clocks, response letters and the decision trailData subject rights under NDPA Part V, and the audit question on how rights are honoured
Breach registerAn incident record dated from awareness, with the 72-hour clock, assessment, notification and remediationNDPA s.40 notification to the Commission within 72 hours, and notice to affected data subjects
Evidence vaultDated artefacts — policies, training logs, processor agreements, configuration screenshots — bound to controlsEvidence expected by a licensed DPCO during audit, and by the Commission on enquiry
CARPathA continuously assembled Compliance Audit Return package with per-question coverage and attached evidenceAnnual CAR obligation for Ultra-High and Extra-High Level entities under GAID 2025, article 10

Statutory references are to the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025, published by the Nigeria Data Protection Commission. The directive text is available as GAID 2025. Estreat is not a law firm and this page is not legal advice.

Module one

Record of processing and data map

The RoPA is built by interview, not by template. Estreat asks about the business in plain language — what the department does, which systems it uses, who receives the data — and derives the record from the answers. Lawful basis is proposed with the reasoning shown, and challenged where the stated basis does not fit the purpose. Consent-based activities are flagged for proof of consent, because a consent you cannot evidence is not a lawful basis.

Each activity carries its retention period, its recipients, and its cross-border position. Where data leaves Nigeria, the record states the destination, the mechanism relied on under Part VIII of the Act, and the date that mechanism was last reviewed. Changes are versioned, so you can show an auditor what the record said in any prior month rather than only what it says today.

In the module

  • Department-led capture with review and approval by the DPO
  • Lawful basis assistant with the reasoning recorded against each activity
  • System and processor register linked to each activity that relies on it
  • Retention schedule per activity, with review dates and owners
  • Cross-border transfer register naming destination and mechanism
  • Full version history and an exportable point-in-time RoPA

In the module

  • Screening test applied automatically to every new or changed activity
  • Assessment scored against the risk criteria set out in GAID 2025
  • Mitigation register with owners, target dates and residual risk
  • Consultation notes, including where a DPCO or counsel was engaged
  • Named sign-off, dated, with the version of the activity it approved
  • Re-assessment triggered when the underlying activity materially changes

Module two

Impact assessments and risk

Screening comes first. Most activities do not require a full assessment, and the record should say why. Estreat applies the screening test to every activity as it is created or amended, records the outcome, and opens a full DPIA only where the threshold is met. That leaves a defensible answer to the question auditors ask most often, which is not whether you did a DPIA but how you decided you did not need one.

Where an assessment is required, the workflow moves from description of processing through necessity and proportionality to risk to data subjects, mitigation and residual risk. Risk is scored consistently so that assessments can be compared across departments, and each mitigation becomes a task with an owner rather than a sentence in a document nobody reads again.

Module three

Data subject requests

Rights requests arrive by every channel: a web form, a support ticket, a message to a branch, a letter from a lawyer. Estreat gives you one register for all of them. Each request is logged with the date received, the identity verification performed, the rights invoked, and the clock that follows from it. The register is the single place a regulator or auditor is directed to.

Because the RoPA already describes which systems hold which categories of data, the search scope for a request is proposed rather than reconstructed. Response letters are drafted from templates that cite the basis for any refusal or partial refusal, and exemptions are recorded with reasons. Requests that turn out to be manifestly unfounded or excessive are closed on the record with the analysis attached.

In the module

  • Single register for access, rectification, erasure, restriction, objection and portability
  • Identity verification steps recorded before disclosure
  • Search scope proposed from the RoPA, with per-system confirmation
  • Statutory clock per request, with escalation before it expires
  • Response templates with recorded grounds for refusal or redaction
  • Reporting on volumes, outcomes and time to close

The clock

72 hours from awareness

A personal data breach must be notified to the Commission within 72 hours of the controller becoming aware of it. The clock starts at awareness, not at confirmation, and the record must be able to show when awareness occurred.

  1. 0hIncident opened, awareness timestamped, owner assigned
  2. 0 to 24hContainment, categories and volumes of affected data established
  3. 24 to 60hRisk to data subjects assessed, notification decision recorded
  4. By 72hNotification to the Commission packaged and dispatched
  5. AfterData subject notice where required, remediation tasks, closure review

Module four

Breach register and the 72-hour clock

Under section 40 of the Act, notification to the Commission is due within 72 hours of the controller becoming aware of a personal data breach. In practice the failure is rarely the notification itself. It is that no one can say when awareness began, who assessed the risk, or on what basis it was decided that data subjects did not need to be told.

Estreat holds the incident as a record with an explicit awareness timestamp and a running clock. The assessment fields correspond to the facts the Commission expects to receive, so the notification is assembled from the register rather than drafted from scratch under pressure. Where a processor reports an incident to you, that report is attached, and the interval between their notice and your awareness is visible.

Near misses and incidents assessed as non-notifiable are kept on the same register with the reasoning recorded, because the pattern of what you decided not to report is itself evidence of how the programme operates.

Module five

Evidence vault

An audit is an evidence exercise. The vault holds each artefact once, with the date it was produced, the person who produced it, and the control or audit question it proves. Policies carry approval dates and version numbers. Training records carry completion dates per person. Processor agreements carry their signature dates and the activities that rely on them.

Evidence has a shelf life, and the vault treats staleness as a live condition rather than a discovery made in March. Each artefact type has a review interval; when an artefact passes it, a task opens for its owner. The result is that the evidence pack requested by a DPCO is a report you run, not a folder you assemble.

In the module

  • Artefacts bound to the control and audit question they satisfy
  • Versioning, approval dates and named approvers on every policy
  • Training completion tracked per person and per role
  • Processor agreement register with signature and review dates
  • Freshness rules that raise a task when evidence ages out
  • One-click evidence pack export for an auditor or a DPCO

In the module

  • Coverage tracked question by question against GAID Schedule 2
  • Readiness view by month, so the gap is visible in July rather than March
  • Gaps issued as owned tasks with due dates, not as a year-end report
  • Evidence attached to each answer before the auditor sees it
  • Deadline tracking against 31 March, with the 2026 extension to 30 May noted
  • Packaged return shared with your licensed DPCO partner for audit and filing

Module six

CARPath and the annual return

Ultra-High Level and Extra-High Level controllers and processors of major importance must file an annual Compliance Audit Return. Ordinary-High Level entities renew their NDPC registration each year and do not file a return. CARPath begins by establishing which of those applies to you, because the wrong tier assumption is an expensive mistake in both directions.

From there the return is assembled continuously. Each Schedule 2 question is mapped to the part of your record that answers it, and the coverage view shows what is complete, what is thin, and what is missing. The standing deadline is 31 March each year under article 10 of GAID 2025, moved forward from 15 March under the former NDPR. For the 2026 cycle only, the Commission extended filing to 30 May 2026. Late filing attracts a surcharge.

A Compliance Audit Return is filed through a Data Protection Compliance Organisation licensed by the Commission. Estreat prepares and packages the return and works alongside licensed DPCO partners. Estreat is not a licensed DPCO and does not file on a client’s behalf.

Read the CARPath detail

Who the product is for

Built for the person who actually does the work.

In most Nigerian organisations the data protection officer is one person with another full job. The programme succeeds or fails on whether that person can spread the work across a year and hold other departments to their part of it.

  1. 01

    Open the queue, not a blank document

    The console opens on what is due: subject requests approaching their deadline, breach clocks running, evidence that has aged out, DPIA sign-offs waiting. Everything is a discrete item with an owner and a date, so a spare hour is productive rather than daunting.

  2. 02

    Delegate without losing the thread

    Business owners are asked narrow questions about their own processing and can answer them without training in data protection law. The DPO reviews and approves. Ownership is recorded on the item, so accountability does not quietly return to the DPO by default.

  3. 03

    Report upward in the language of the board

    Readiness, open risks, overdue items and the position on the annual return are summarised for an audit committee without a week of preparation. The same view is what an auditor or a licensed DPCO is given at the start of an engagement.

  4. 04

    Leave a defensible trail

    Every material action is attributable and dated: who approved a lawful basis, who signed a DPIA, when awareness of a breach began, when a policy was last reviewed. The trail is the product of ordinary use rather than a separate documentation exercise.

Deployment

Your data stays where you decide.

Estreat runs with Nigerian data residency by default. An EU region is available where a group parent or a customer contract requires it, and the region is named in the order form rather than left to inference. Single-tenant deployment is offered for organisations whose own policies or regulators require logical and physical separation from other customers.

Your record is yours. Structured export of the RoPA, DPIA set, request register, breach register and evidence index is available at any time, in formats you can open without Estreat. There is no contractual or technical barrier to leaving, and on termination we delete or return your data on your instruction. A compliance record that cannot be taken out of the system it lives in is a liability, not an asset.

Details of the controls behind these statements, and our honest current position on certifications, are set out on the trust page.

Trust and security
Deployment options
Default residencyNigeria
Alternative regionEuropean Union, on request
TenancyMulti-tenant with logical isolation, or single-tenant
AccessRole-based, with multi-factor authentication required
ExportStructured export of the full record at any time
On terminationDeletion or return of data on your instruction

Bring one process and we will map it.

In twenty minutes we will take a single business process, put it on the record, and show you the Schedule 2 questions it answers and the evidence it still needs.

Book a demo View plans