Understanding NDPR Compliance for Educational Institutions
In January 2025, a private secondary school in Lagos discovered that a former IT staff member had walked away with a USB drive containing the personal records of over 2,000 students — names, home addresses, parents' phone numbers, medical histories, and academic transcripts. The school had no data protection policy, no encryption on its databases, and no incident response plan. It took three weeks for the administration to even realise the data had been copied. By that point, the damage was done.
This is not a hypothetical scenario. It is the kind of data breach that happens quietly in Nigerian schools every year. And since the enactment of the Nigeria Data Protection Act (NDPA) in 2023 and the establishment of the Nigeria Data Protection Commission (NDPC), schools that fail to protect student data are not just taking a moral risk — they are breaking the law.
What Is the NDPA and How Does It Relate to NDPR?
Nigeria's data protection framework has evolved significantly over the past several years. The Nigeria Data Protection Regulation (NDPR) was issued in 2019 by the National Information Technology Development Agency (NITDA) as a regulatory instrument to protect the personal data of Nigerian citizens. In June 2023, the Nigeria Data Protection Act (NDPA) was signed into law, providing a stronger statutory foundation and creating the Nigeria Data Protection Commission (NDPC) as the independent body responsible for enforcement.
The NDPA builds on the NDPR's principles but carries the full force of legislation. It applies to every organisation that collects, stores, processes, or manages the personal data of individuals in Nigeria — and that includes schools, from large private institutions in Lekki to small community primary schools in Kano.
For the purpose of this article, we will use "NDPR compliance" as a practical shorthand for the full body of data protection obligations under both the NDPA and the NDPC's regulatory framework, as this is how most Nigerian professionals still reference the requirements.
Why Schools Are Data Processors
Many school administrators are surprised to learn just how much personal data their institution handles. Consider what a typical school collects and stores over the course of a single academic year:
Student data: full names, dates of birth, state of origin, passport photographs, home addresses, medical conditions, allergies, blood group, genotype, academic transcripts, disciplinary records, standardised test scores, and in some cases biometric data (fingerprints for attendance systems).
Parent/guardian data: names, phone numbers, email addresses, home and work addresses, occupations, and financial information related to fee payments.
Staff data: employment records, qualifications, salary details, bank account numbers, tax identification numbers, and next-of-kin information.
This is an extraordinary volume of sensitive personal information. Under the NDPA, schools are classified as data controllers (they determine why and how data is collected) and often also as data processors (they actively process the data through their systems). Both roles carry legal obligations.
When a school uses a digital platform to manage this data — whether it is a spreadsheet on a shared computer, a cloud-based school management system, or a WhatsApp group where teachers share student information — the school is processing personal data and must comply with the law.
The 6 Key NDPR Obligations for Schools
1. Lawful Basis for Processing
Schools must have a legitimate, lawful reason for every category of personal data they collect. For most educational data, the lawful basis is either contractual necessity (the data is needed to provide the educational service the parent enrolled the child for) or legal obligation (government reporting requirements). Schools cannot collect data simply because it seems useful or because "we've always done it this way." Every data point must be justifiable.
2. Consent
Where consent is the basis for processing, it must be freely given, specific, informed, and unambiguous. This means a generic sentence buried on page 14 of an admission form does not constitute valid consent. Schools need clear, plain-language consent forms that explain exactly what data is being collected, why it is being collected, how it will be used, who will have access to it, and how long it will be retained. Parents must have the right to withdraw consent without penalty.
For biometric data — such as fingerprint-based attendance systems — the consent requirements are even more stringent. Biometric data is classified as sensitive personal data, and schools must obtain explicit, specific consent before collecting it.
3. Data Minimisation
Schools should collect only the data that is strictly necessary for the purpose stated. If the school does not need a student's blood genotype to provide educational services, it should not collect it. If the parent's occupation is not relevant to any school process, it should not be on the admission form. Data minimisation reduces both the compliance burden and the potential damage from a breach.
4. Storage Limitation
Personal data should not be kept indefinitely. Schools must define retention periods for different categories of data and delete or anonymise data when it is no longer needed. A student who graduated eight years ago does not need their full medical history sitting in an active database. Schools should establish clear policies: academic transcripts may be retained for a defined period as required by regulation, but supplementary personal data should be purged according to a schedule.
5. Security Measures
The NDPA requires data controllers and processors to implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or damage. For schools, this means:
Technical measures: encrypted databases, password-protected systems, role-based access controls (not every teacher needs access to every student's medical records), regular software updates, secure Wi-Fi networks, and encrypted backup systems.
Organisational measures: data protection policies, staff training on data handling, visitor access controls for server rooms or offices where records are stored, and clear procedures for what happens when a staff member leaves.
6. Breach Notification
If a data breach occurs — whether through hacking, theft, accidental disclosure, or loss of a device containing personal data — the school must notify the NDPC within 72 hours. The notification must describe the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken to address the breach. If the breach is likely to result in a high risk to the rights and freedoms of the affected individuals, those individuals must also be notified directly.
The 72-hour window is tight. Schools that do not have an incident response plan will struggle to meet this requirement, which is why preparation is essential.
Practical Steps Schools Should Take Now
Appoint a Data Protection Officer (DPO). The NDPA requires organisations processing large volumes of personal data to designate a DPO. Even for smaller schools where a full-time DPO is not feasible, assigning responsibility for data protection to a specific senior staff member is critical. This person should receive training and serve as the point of contact for all data-related matters.
Conduct a data audit. Map every piece of personal data the school collects. Document where it comes from, where it is stored, who has access, and how long it is kept. This audit will almost certainly reveal data that the school does not need and practices that pose unnecessary risk.
Update consent forms. Replace vague, catch-all consent language with clear, specific disclosures. Create separate consent forms for sensitive data categories like health records and biometrics. Make consent withdrawal easy and penalty-free.
Secure digital systems. Audit all software, platforms, and devices used to store student data. Ensure databases are encrypted, access is role-based, passwords are strong and regularly changed, and software is up to date. If the school uses cloud services, verify that the provider offers data processing agreements compliant with Nigerian data protection law.
Train staff. The most sophisticated security system is undermined by a single staff member who shares a password on a sticky note or forwards student records via personal WhatsApp. Every staff member who handles personal data — teachers, administrators, accountants, IT staff — needs training on data protection basics.
Create an incident response plan. Document exactly what should happen when a breach is suspected: who to notify internally, how to assess the scope, how to contain the breach, and how to file the NDPC notification within 72 hours. Practice the plan with a tabletop exercise at least once a year.
Penalties for Non-Compliance
The enforcement regime under the NDPA is not symbolic. The NDPC has the authority to impose administrative fines of up to 2% of the organisation's annual gross revenue or ₦10 million, whichever is greater. For a school generating ₦200 million in annual fees, that is a potential fine of ₦4 million — significant enough to impact operations.
Beyond fines, non-compliance carries reputational risk. Parents are increasingly aware of data privacy issues, and a publicised breach can lead to loss of enrolment, legal action from affected families, and regulatory scrutiny that disrupts normal operations for months.
How HarmonyShield Helps Schools Achieve Compliance
At Harmony Digital Consults, we built HarmonyShield specifically to help educational institutions meet their NDPR obligations without needing a team of compliance lawyers or a dedicated IT security department.
Built-in compliance dashboard. HarmonyShield provides a visual overview of the school's compliance status across all six NDPR obligation areas. Administrators can see at a glance which areas are compliant, which need attention, and what specific actions are required.
Staff training modules. The platform includes interactive training courses on data protection tailored for school staff — not generic corporate training, but scenarios that reflect the daily realities of a Nigerian school. Modules cover topics like safe handling of student records, recognising phishing attempts, proper use of WhatsApp and other messaging platforms for school communication, and what to do when a laptop is lost or stolen.
Incident response workflow. When a breach is detected or suspected, HarmonyShield guides the response team through a structured process: containment, assessment, NDPC notification drafting, affected-individual communication templates, and post-incident review. The system tracks timelines to ensure the 72-hour notification deadline is met.
Threat monitoring. HarmonyShield continuously monitors the school's digital systems for signs of unauthorised access, unusual data transfers, and known vulnerability patterns. When a threat is detected, the system generates alerts with clear remediation steps — written for school administrators, not cybersecurity engineers.
Compliance Is Not Optional — and It Is Easier Than You Think
The most common reaction we hear from school administrators when we discuss NDPR compliance is some variation of: "This sounds complicated and expensive. We are a school, not a bank." The concern is understandable, but the reality is more encouraging.
Most of the foundational compliance steps — conducting a data audit, updating consent forms, establishing access controls, and training staff — are straightforward and low-cost. They require effort and attention, not large budgets. The NDPC has also signalled that it takes a proportionate approach to enforcement, focusing first on egregious non-compliance and organisations that handle very large volumes of data.
But proportionate enforcement is not the same as no enforcement. The regulatory environment is tightening, and schools that begin their compliance journey now will be far better positioned than those that wait until an incident forces their hand.
Nigerian schools are custodians of some of the most sensitive personal data in society — the information of children and their families. Protecting that data is not just a legal obligation. It is an ethical one. And with the right tools and a clear plan, it is entirely achievable.