Guide · NDPA s.40
Breach notification in 72 hours.
A personal data breach starts two clocks at once: the one running against your data subjects, and the statutory one running against you. Section 40 of the NDPA requires Commission notification within seventy-two hours of awareness when a breach is likely to pose a risk to individuals. This guide covers what triggers the clock, what the notification must contain, and the part most organisations get wrong: proving when they knew.
Estreat Limited · Reviewed August 2026 · General information, not legal advice. Confirm your obligations with the Commission, a qualified DPO, or a licensed DPCO.
The duty
Section 40 of the Nigeria Data Protection Act 2023 obliges a controller to notify the Nigeria Data Protection Commission of a personal data breach within seventy-two hours of becoming aware, where the breach is likely to result in a risk to the rights and freedoms of individuals. Where the breach is likely to result in high risk to those individuals, a second duty attaches: immediately informing the affected data subjects themselves under section 40(3). The Commission operates a dedicated breach reporting portal for exactly this purpose.
Processors sit inside the same machine: a processor that suffers or discovers a breach must notify the controller it processes for, because the controller’s seventy-two hours cannot start before the controller knows. Contractually, your vendor agreements should compress that handoff to hours, not days.
When the clock actually starts
“Aware” does not mean investigated, confirmed, or understood. It means a reasonable degree of certainty that a security compromise has occurred leading to personal data being lost, altered, accessed or disclosed. Three consequences follow:
- Weekend discovery counts. Awareness on Saturday evening gives you until roughly Tuesday evening.
- Processor awareness flows up. If your payroll vendor knew on Monday and told you Thursday, the Commission will ask why the vendor agreement allowed a three-day gap.
- Ambiguity must be logged. The period between a suspicious alert and confirmed compromise is exactly the window regulators examine. Your decision trail during those hours is evidence either way.
What the notification needs
A first notification should carry, at minimum:
- The nature of the breach: categories and approximate numbers of data subjects and records affected.
- The likely consequences for those people.
- The measures taken or proposed to address it, including containment done so far.
- Your contact point for follow-up.
- Where facts are incomplete: that they are, and a commitment to supplement.
The proof problem nobody plans for
The seventy-two hour duty is only half of section 40’s practical demand. The other half is evidencing compliance: demonstrating when you became aware and what you did each hour after. Email threads are not evidence of a clock; they are fragments of one. An auditor or the Commission in an enforcement review asks: when did the first person in your organisation know, who did they tell, when was the assessment made that this was notifiable, and where is that recorded? Keep the original communications alongside a structured record of awareness, risk assessment, notification and remediation; a register alone does not prove those actions occurred.
This is the reasoning behind treating breaches as a register rather than an incident: every breach entry holds the awareness timestamp, the assessment decision and its author, the notification made and its timing, and the remediation trail. Our platform overview shows how that register connects to the annual return, which asks about incidents and notification timing directly under Schedule 2.
Prepare now, decide later
You cannot write the breach plan during the breach. Before one happens: name the assessment team and their deputies, agree the severity criteria that trigger notification, template both notifications (Commission and data subjects), and make sure your processors’ contracts require breach notice to you within hours. Then rehearse once. Seventy-two hours is enough time to notify well, and almost never enough time to build the machinery mid-crisis.
This guide summarises section 40 of the NDPA 2023 for general information. Breach assessments are fact-specific and may carry legal privilege considerations; involve qualified counsel on live incidents. Reviewed August 2026.
Questions we are asked.
Short answers to the questions behind most searches about this topic. The body of the guide above carries the detail and the citations.
When does the 72-hour clock start?
From awareness: the moment your organisation becomes aware of a breach likely to result in a risk to the rights and freedoms of data subjects. A processor must notify its controller without undue delay under section 40(1). Record both the processor discovery time and the controller awareness time.
Do we notify data subjects too?
Where the breach is likely to result in a high risk to individuals, you must immediately inform affected data subjects, in clear and plain language. The Commission notification and the data subject notification are separate duties with different triggers.
What if we cannot investigate fully within 72 hours?
Notify within 72 hours with what is known, in phases. The duty is to notify without undue delay once aware; incomplete facts are expected in a first notification and can be supplemented. The failure regulators punish is silence while an organisation investigates quietly.
Continue with
RoPA in Nigeria
The record that tells you what data a breach touched.
Read the guideNDPA penalties and enforcement
What late or absent notification costs.
Read the guideCompliance Audit Return, explained
Where incidents and timing surface in the annual filing.
Read the guideGAID 2025 explained
The directive framing the evidentiary expectations.
Read the guideTurn this guidance into your next step.
Estreat keeps your processing registers, impact assessments, subject requests, breach clocks and evidence current all year, then assembles the Compliance Audit Return from that record for filing through a licensed DPCO. We are software, not a DPCO or a law firm, and we will introduce you to a licensed partner if you need one.