Prove NDPA compliance on any day of the year.
Document once. Elbamp creates the evidence requests, tasks, reminders, and register entries that keep you ready.
Built for the Nigeria Data Protection Act 2023 and GAID 2025.
Vendor added: payment processor
- EVR-0231EVIDENCE REQUEST
Signed data processing agreement
c4314a - TSK-0114TASK
Complete vendor due diligence
51a951 - RMD-0088REMINDER
Data processing agreement renewal
3cfde3 - REG-0412REGISTER ENTRY
Vendor register updated
38aaaf
The obligations, in figures.
- 31 MarchCompliance Audit Return deadline, UHL and EHL
- ₦10M or 2%Maximum penalty, whichever is greater
- Licensed DPCOWho UHL and EHL must file through
- 9 practitionersOne DPCO owner, three auditors, five DPOs
Compliance today lives in spreadsheets, inboxes, and the last three weeks of March.
For most Nigerian organizations the compliance year is a scramble. Evidence sits with HR, IT, procurement, and legal, in versions nobody agrees on. The pre-audit questionnaire stalls for weeks. The record of processing activities gets rebuilt from memory. Then the return is due, and twelve months of work compresses into three.
If you are a data controller or processor of major importance at UHL or EHL level, your Compliance Audit Return is due by 31 March each year, filed through a licensed DPCO. The NDPC has moved from warnings to enforcement, and for a controller of major importance the penalty can reach the higher of ₦10,000,000 or 2% of annual gross revenue.
| Item | Owner | State |
|---|---|---|
| Retention schedule | HR | |
| Vendor DPA, payments | Procurement | |
| Access review, Q4 | IT |
Documenting triggers action.
A document repository stores what you wrote. Elbamp acts on it. Answer a questionnaire, add a system, register a vendor, and the platform creates the evidence request, assigns the owner, sets the reminder, and writes the register entry. You review. You do not chase.
| The old way | With Elbamp |
|---|---|
| A folder of policies nobody reads | Every control tied to an owner, a due date, and evidence |
| You remember to follow up | The system follows up |
| Readiness is a guess in March | Readiness is a status today |
| Your audit trail is your email | An append-only record of every action |
Four steps, and the platform does the chasing.
- 01
Classify
Confirm your DCPMI tier.
Answer a short set of questions about your sector and size, and Elbamp confirms whether you are UHL, EHL, or OHL, and which obligations attach to you.
- 02
Generate
Your checklist is built for you.
Elbamp generates your compliance checklist, questionnaires, and registers from your sector and tier. You start from a filled template, not a blank page.
- 03
Collect
Assign it once, and the system chases.
Send evidence requests to the people who actually hold the evidence. Reminders, overdue flags, and departmental accountability are handled for you.
EVR-0198Access review, Q4 - 04
Prove
Export the proof, or file.
Produce a readiness report, an evidence pack, or your semi-annual DPO report to management. If you file a Compliance Audit Return, your DPCO reviews inside the platform.
One engine, three ways of working.
- For the in-house DPO
Organizations
Run the whole program in one place: controls, evidence, registers, Data Champions, reports. Built for DPOs who do this alongside another job.
- For licensed compliance organizations
DPCO firms
Manage a portfolio of clients from one workspace, white-labelled to your firm. Scoped, revocable, review-only access keeps your independence intact.
- For DPO-as-a-Service
Outsourced DPOs
Operate compliance for many clients, including clients who never log in. A portfolio view on top, full operational depth per client.
Small organizations at OHL level get OHL Lite: the same engine, a lighter surface, self-serve.
The platform has to pass your privacy review, not just talk about ours.
- 01
Nigeria data residency by design
Elbamp is built to run on Nigeria-resident infrastructure, with the hosting region confirmed in writing before any real data is processed.
- 02
We never store your raw personal data
Elbamp holds compliance metadata and the evidence you upload. It does not import, mirror, or store your customers' or employees' personal records. Less of your risk sits with us.
- 03
A tamper-evident audit trail
Every action is written to an append-only log, hash-chained so each entry seals the one before it. Alter a record after the fact and the chain breaks. Exportable for your own audit.
- 04
Independent DPCO review, built in
External reviewers work in a separate, time-boxed, revocable scope. They can raise findings and request evidence. They cannot silently alter your records.
- 05
Encryption and access control
Encrypted in transit and at rest. Role-based access scoped to workspace and department, evaluated on every request.
- Reviewer
- Scope
- Expires
- ALLOWRaise findings
- ALLOWRequest evidence
- DENYAlter records
What changes.
Prove readiness continuously
Answer “are we compliant today?” with evidence, not a promise.
Pass your own privacy review
Give your IT and security teams what they ask for, the first time.
Meet your obligations on time
File when you should, with the evidence behind it.
Replace the spreadsheet scramble
Get March back.
Designed with the people who do this work.
Elbamp was designed with a DPCO owner, three DPCO auditors, and five DPOs, across banking, government, research, oil and gas, and consulting. Every requirement traces to a named obligation in the NDPA or GAID, or to something one of them told us.
One of our auditors carries about fifty clients between January and March. The part that costs us months is not the judgement, it is the chasing.
Organizations we are speaking with
- Banking
- Health
- Education
- Hospitality
- Telecoms
- Compliance
Priced annually, by your DCPMI tier.
You pay for the obligations that actually apply to you. UHL, EHL, and OHL carry different requirements, so they carry different prices. DPCO and partner firms are priced by portfolio. We quote after a short conversation about your sector, size, and tier.
OHL Lite
Small organizations at OHL level
- Guided DCPMI classification
- Sector checklist and registers
- Evidence requests and reminders
- Self-serve, no implementation needed
EHL
Controllers and processors at EHL level
- Everything in OHL Lite
- Full Compliance Audit Return workflow
- Data Champions across departments
- DPCO review access, scoped and revocable
- Semi-annual DPO report to management
UHL
Controllers and processors at UHL level
- Everything in EHL
- Group and multi-entity oversight
- Dedicated database isolation
- Priority support through your compliance year
Partner
DPCO firms and outsourced DPOs
- Portfolio across all your clients
- White-labelled to your firm
- Managed clients who never log in
- Team assignment and cross-client chasing
- Priced by portfolio, not per seat
See it against your own compliance year.
Thirty minutes, walked through with your sector and tier in mind. No preparation needed.