Answer a short set of questions about an incident to get an indicative severity rating and a plain-language read on your notification obligations under the Nigeria Data Protection Act 2023 (Section 40) and the NDPC's General Application and Implementation Directive (GAID) 2025.
Your assessment is never transmitted or stored — it's calculated entirely in your browser. This submission also adds one to an anonymous, aggregate count (industry, breach type and severity tier only) to help build a picture of breach trends in Nigeria — nothing about you, your organization, or the individuals affected is ever recorded.
NDPC notification applies once a breach is assessed as posing any risk to data subjects' rights and freedoms (Medium severity and above, per NDPA 2023 Section 40(2)). Data subject notification applies only where the breach is assessed as high risk — e.g. likely fraud, identity theft or exposure of sensitive data (High/Critical severity, per GAID 2025 Article 33(2)).
This tool provides an indicative, automated assessment for guidance only and does not constitute legal advice. It does not replace a full breach risk assessment or advice from qualified counsel. For a matter-specific assessment, book a consultation.