FREE TOOL

NDPA Data Breach Severity Assessor

Answer a short set of questions about an incident to get an indicative severity rating and a plain-language read on your notification obligations under the Nigeria Data Protection Act 2023.

Section A

Incident details

Section B

Impact assessment

How badly could this affect the people whose data was involved.

B1. Type of personal data involved
B2. Potential consequences to individuals
B3. Volume of data involved
B4. Are children's data or vulnerable persons involved?
Section C

Likelihood assessment

How likely this type of incident is to recur or escalate. Rate each area Low, Medium or High.

C1. Network & technical
How likely is it that the underlying vulnerability could be exploited again (e.g. missing multi-factor authentication, unpatched systems, a successful phishing attempt)?
C2. Processes & procedures
Were there gaps in data protection policy or practice (e.g. no access controls, no designated DPO, no encryption)?
C3. People & parties
Insider threat, third-party vendor involvement, or general staff training level.
C4. Sector & scale
Higher-risk sectors (e.g. financial services, telecoms, health, education) and degree of public exposure.
Result

Final severity:

Impact level
Likelihood level
Final severity

Recommended next steps

    This tool provides an indicative, automated assessment for guidance only and does not constitute legal advice. It does not replace a full breach risk assessment or advice from qualified counsel. For a matter-specific assessment, book a consultation.