Understanding NDPR and What It Means for Your Online Store
NDPR applies to your online store if you collect customer names, emails, or phone numbers. Here is a practical compliance checklist for Nigerian SMEs.
The Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act (2023) establish rules for how businesses collect, use, store, and share personal data. If you run an online store โ even a small one โ you almost certainly process personal data every day.
Compliance is not only for banks and telcos. It protects your customers and reduces legal risk as your brand grows.
What counts as personal data for your store
- Customer name, phone number, email address
- Delivery addresses and billing details
- Order history and payment references (even if cards are tokenised by Paystack)
- IP addresses and device data in server logs
- Staff accounts with login credentials
- Newsletter signups and WhatsApp numbers you export to spreadsheets
If you can identify a person from the information, treat it as personal data.
Core principles (plain language)
- Lawful basis โ collect data for real business purposes (fulfil orders, support, receipts)
- Transparency โ tell people what you collect and why
- Minimisation โ do not ask for BVN on a t-shirt checkout
- Security โ protect admin access and do not leak customer exports
- Retention โ keep order records as long as tax/law requires; delete marketing lists when stale
- Rights โ customers may ask what you hold or request correction/deletion where applicable
Minimum viable compliance for SMEs
1. Publish a privacy policy
Oshop247 provides CMS pages you can adapt. State what you collect at checkout, how payments are processed by gateways, how long you keep orders, and how customers contact you about data requests.
2. Publish terms and cookie notice
Terms cover sales; privacy covers data. If you use analytics (Facebook Pixel, Google Analytics), disclose cookies and tracking in your cookie policy.
3. Secure your admin
- Strong unique passwords for admin users
- Remove access when staff leave
- Do not share one login across five people
- Use HTTPS storefront (Oshop247 provides this on platform domains)
4. Limit data exports
Customer CSV exports are powerful โ treat them like cash. Do not download to personal laptops without encryption. Do not paste customer lists into random bulk SMS apps without consent.
5. Marketing consent
Only email or WhatsApp marketing to people who opted in. Order confirmation emails are transactional; promotional blasts need separate consent where required.
Payment gateways and shared responsibility
Paystack, Flutterwave, and Stripe act as data processors for payment flows. Your privacy policy should mention that card processing is handled by licensed third parties โ you do not store full card numbers on Oshop247.
Data subject requests
Customers may email asking:
- What data you hold about them
- To correct their address
- To delete their account (balance against legal record-keeping for tax)
Respond within reasonable timeframes defined by current NDPA guidance. Document requests in a simple log.
Breach response basics
If admin credentials leak or a laptop with customer export is stolen:
- Rotate passwords and revoke sessions
- Assess what data was exposed
- Notify affected customers if risk is serious
- Seek legal advice for NDPC reporting obligations depending on scale
NDPR as competitive advantage
Professional policies signal maturity. Corporate buyers, diaspora customers, and partnership deals increasingly ask: "Where is your privacy policy?" before placing bulk orders.
Protecting customer data is part of good retail hygiene โ like accurate stock counts and honest delivery timelines.
Oshop247 continues to invest in platform security and legal page templates. Your job is honest collection, clear policies, and disciplined admin access. That is achievable this week โ not someday when you are "big enough."
Share this article: