NDPA and CBN Compliance for Nigerian Fintechs

Nigeria's fintech
regulators are not
waiting on you.

Blaecwood Systems Limited is a Data Protection Compliance Organisation licensed by the Nigeria Data Protection Commission. We work out which NDPA and CBN requirements reach you, document where you stand, and prepare the reports a licensed DPCO has to prepare.

Both regulators turn on the same thing: what you can show, in the form they expect to see it. Three services below, three different starting points. Find the one that describes your situation.

2023
Nigeria Data Protection Act in force
What applies to you depends on your NDPC classification
2026
CBN's active supervisory agenda
Open Banking · APP fraud rules at exposure draft
DPCO
A Compliance Audit Report has to be prepared with a licensed DPCO
Before it reaches the Commission
NDPC
Blaecwood is a licensed DPCO
Registered with the NDPC · Ref NDPC/DPCO/17469

Data Protection

NDPA & DPCO Compliance

Who this is for

Qualifying controllers and processors of major importance carry annual audit, registration and reporting obligations, and a Compliance Audit Report can only be prepared with a licensed DPCO. Whether any of it reaches you depends on how the NDPC classifies your organisation. That is the first question to settle.

NDPA & DPCO compliance in full

Where you sit
Not sure which tier you fall into?

The classification check is an indicative self-assessment. It is not an NDPA compliance audit and does not constitute a compliance opinion.

Financial Regulation

CBN Regulatory Readiness

Who this is for

CBN's 2026 supervisory agenda covers Open Banking participation and a proposed APP fraud liability regime still at exposure draft stage. We assess your controls against what CBN expects and document the gaps in the order they matter. Your team executes the changes, and we validate and record them.

CBN regulatory readiness in full

Start here

A Regulatory Readiness Review walks through your licensing stage and current controls, and maps what CBN will expect next.

Payments

Payments Partner Ready

Payment companies rarely face one requirement at a time. NDPA obligations, CBN expectations, partner security reviews, PCI DSS scope questions and SOC 2 requests can land in the same growth cycle. Payments Partner Ready starts from the approval you are trying to reach and works back from it.

Payments Partner Ready in full Request a Scoping Call

Why Blaecwood

Licensed to do
the part that counts.

Blaecwood Systems Limited is licensed by the Nigeria Data Protection Commission as a Data Protection Compliance Organisation, reference NDPC/DPCO/17469. That licence is what allows a Compliance Audit Report to be prepared and verified before it reaches the Commission, and it is verifiable with the NDPC.

Our work is assessment, documentation and validation. We do not implement your controls for you, and we would rather say so here than halfway through an engagement.

About Blaecwood

Assurance note

Readiness work does not guarantee a licence, certification, audit result or partner decision. Blaecwood's advisory and readiness work is separate from its DPCO assurance work.

The formal NDPA compliance audit, DPCO Verification Statement and Compliance Audit Return filing are contracted separately, with separate scope and review. SOC 2 examinations are performed by an eligible independent CPA or equivalent. PCI DSS validation follows the applicable SAQ, ASV or QSA route.

Start with what
actually applies.

Book a call and we will work through which NDPA and CBN requirements reach your business, and what is outstanding before your next filing or examination.

The classification check is an indicative self-assessment. It is not an NDPA compliance audit and does not constitute a compliance opinion.