Skip to content
NDPA / NDPC compliance

Prove NDPA compliance on any day of the year.

Document once. Elbamp creates the evidence requests, tasks, reminders, and register entries that keep you ready.

Built for the Nigeria Data Protection Act 2023 and GAID 2025.

Each entry seals the one before it.
RECORDVEN-0117

Vendor added: payment processor

DOCUMENTEDda2563
14 Jan 2026, 09:42
  • EVR-0231EVIDENCE REQUEST

    Signed data processing agreement

    Requested from procurementc4314a
  • TSK-0114TASK

    Complete vendor due diligence

    Due in 5 days51a951
  • RMD-0088REMINDER

    Data processing agreement renewal

    Set3cfde3
  • REG-0412REGISTER ENTRY

    Vendor register updated

    Recorded38aaaf

The obligations, in figures.

  • 31 MarchCompliance Audit Return deadline, UHL and EHL
  • ₦10M or 2%Maximum penalty, whichever is greater
  • Licensed DPCOWho UHL and EHL must file through
  • 9 practitionersOne DPCO owner, three auditors, five DPOs
THE REALITY

Compliance today lives in spreadsheets, inboxes, and the last three weeks of March.

For most Nigerian organizations the compliance year is a scramble. Evidence sits with HR, IT, procurement, and legal, in versions nobody agrees on. The pre-audit questionnaire stalls for weeks. The record of processing activities gets rebuilt from memory. Then the return is due, and twelve months of work compresses into three.

If you are a data controller or processor of major importance at UHL or EHL level, your Compliance Audit Return is due by 31 March each year, filed through a licensed DPCO. The NDPC has moved from warnings to enforcement, and for a controller of major importance the penalty can reach the higher of ₦10,000,000 or 2% of annual gross revenue.

NDPA_evidence_tracker_v7_FINAL_v2.xlsx
A typical evidence tracker spreadsheet, with unresolved owners and one overdue item
ItemOwnerState
Retention scheduleHRAsk Tayo?
Vendor DPA, paymentsProcurementChased 3x
Access review, Q4ITOverdue
THE SHIFT

Documenting triggers action.

A document repository stores what you wrote. Elbamp acts on it. Answer a questionnaire, add a system, register a vendor, and the platform creates the evidence request, assigns the owner, sets the reminder, and writes the register entry. You review. You do not chase.

How compliance work changes with Elbamp, four points of comparison
The old wayWith Elbamp
A folder of policies nobody readsEvery control tied to an owner, a due date, and evidence
You remember to follow upThe system follows up
Readiness is a guess in MarchReadiness is a status today
Your audit trail is your emailAn append-only record of every action
HOW IT WORKS

Four steps, and the platform does the chasing.

  1. 01

    Classify

    Confirm your DCPMI tier.

    Answer a short set of questions about your sector and size, and Elbamp confirms whether you are UHL, EHL, or OHL, and which obligations attach to you.

  2. 02

    Generate

    Your checklist is built for you.

    Elbamp generates your compliance checklist, questionnaires, and registers from your sector and tier. You start from a filled template, not a blank page.

  3. 03

    Collect

    Assign it once, and the system chases.

    Send evidence requests to the people who actually hold the evidence. Reminders, overdue flags, and departmental accountability are handled for you.

    EVR-0198Access review, Q4Overdue, 3 reminders sent
  4. 04

    Prove

    Export the proof, or file.

    Produce a readiness report, an evidence pack, or your semi-annual DPO report to management. If you file a Compliance Audit Return, your DPCO reviews inside the platform.

WHO IT'S FOR

One engine, three ways of working.

  • For the in-house DPO

    Organizations

    Run the whole program in one place: controls, evidence, registers, Data Champions, reports. Built for DPOs who do this alongside another job.

  • For licensed compliance organizations

    DPCO firms

    Manage a portfolio of clients from one workspace, white-labelled to your firm. Scoped, revocable, review-only access keeps your independence intact.

  • For DPO-as-a-Service

    Outsourced DPOs

    Operate compliance for many clients, including clients who never log in. A portfolio view on top, full operational depth per client.

Small organizations at OHL level get OHL Lite: the same engine, a lighter surface, self-serve.

SECURITY AND TRUST

The platform has to pass your privacy review, not just talk about ours.

  1. 01

    Nigeria data residency by design

    Elbamp is built to run on Nigeria-resident infrastructure, with the hosting region confirmed in writing before any real data is processed.

  2. 02

    We never store your raw personal data

    Elbamp holds compliance metadata and the evidence you upload. It does not import, mirror, or store your customers' or employees' personal records. Less of your risk sits with us.

  3. 03

    A tamper-evident audit trail

    Every action is written to an append-only log, hash-chained so each entry seals the one before it. Alter a record after the fact and the chain breaks. Exportable for your own audit.

  4. 04

    Independent DPCO review, built in

    External reviewers work in a separate, time-boxed, revocable scope. They can raise findings and request evidence. They cannot silently alter your records.

  5. 05

    Encryption and access control

    Encrypted in transit and at rest. Role-based access scoped to workspace and department, evaluated on every request.

Access grantRevoke
Reviewer
[Placeholder] External DPCO reviewer
Scope
Review workspace, separate
Expires
31 Mar 2026, 23:59
  • ALLOWRaise findings
  • ALLOWRequest evidence
  • DENYAlter records
OUTCOMES

What changes.

  • Prove readiness continuously

    Answer “are we compliant today?” with evidence, not a promise.

  • Pass your own privacy review

    Give your IT and security teams what they ask for, the first time.

  • Meet your obligations on time

    File when you should, with the evidence behind it.

  • Replace the spreadsheet scramble

    Get March back.

HOW IT WAS BUILT

Designed with the people who do this work.

Elbamp was designed with a DPCO owner, three DPCO auditors, and five DPOs, across banking, government, research, oil and gas, and consulting. Every requirement traces to a named obligation in the NDPA or GAID, or to something one of them told us.

One of our auditors carries about fifty clients between January and March. The part that costs us months is not the judgement, it is the chasing.
[Placeholder] Partner, DPCO firm, Lagos

Organizations we are speaking with

  • [Placeholder] Commercial bankBanking
  • [Placeholder] Teaching hospitalHealth
  • [Placeholder] Private universityEducation
  • [Placeholder] Hotel groupHospitality
  • [Placeholder] Telecoms operatorTelecoms
  • [Placeholder] DPCO consultancyCompliance
PRICING

Priced annually, by your DCPMI tier.

You pay for the obligations that actually apply to you. UHL, EHL, and OHL carry different requirements, so they carry different prices. DPCO and partner firms are priced by portfolio. We quote after a short conversation about your sector, size, and tier.

  • OHL Lite

    Small organizations at OHL level

    • Guided DCPMI classification
    • Sector checklist and registers
    • Evidence requests and reminders
    • Self-serve, no implementation needed
    Talk to us
  • EHL

    Controllers and processors at EHL level

    • Everything in OHL Lite
    • Full Compliance Audit Return workflow
    • Data Champions across departments
    • DPCO review access, scoped and revocable
    • Semi-annual DPO report to management
    Talk to us
  • UHL

    Controllers and processors at UHL level

    • Everything in EHL
    • Group and multi-entity oversight
    • Dedicated database isolation
    • Priority support through your compliance year
    Talk to us
  • Partner

    DPCO firms and outsourced DPOs

    • Portfolio across all your clients
    • White-labelled to your firm
    • Managed clients who never log in
    • Team assignment and cross-client chasing
    • Priced by portfolio, not per seat
    Talk to us
REQUEST A DEMO

See it against your own compliance year.

Thirty minutes, walked through with your sector and tier in mind. No preparation needed.