FREE TOOL

NDPA Data Breach Severity Assessor

Answer a short set of questions about an incident to get an indicative severity rating and a plain-language read on your notification obligations under the Nigeria Data Protection Act 2023 (Section 40) and the NDPC's General Application and Implementation Directive (GAID) 2025.

Your assessment is never transmitted or stored — it's calculated entirely in your browser. This submission also adds one to an anonymous, aggregate count (industry, breach type and severity tier only) to help build a picture of breach trends in Nigeria — nothing about you, your organization, or the individuals affected is ever recorded.

Section A

Incident details

Used only to add one to an anonymous, aggregate count (e.g. "Fintech, Q3 2026: 6 breaches reported") — never stored or transmitted alongside your organization name or any other answer.
Section B

Impact assessment

How badly could this affect the people whose data was involved.

B1. Type of personal data involved
B2. Potential consequences to individuals
B3. Volume of data involved
B4. Are children's data or vulnerable persons involved?
"Vulnerable persons" (per GAID 2025 Schedule 6) means individuals who, due to age (elderly or minor), health, financial difficulty, physical disability, or lack of capacity, education, digital literacy, or access to support, are less able to protect their own interests.
Section C

Likelihood assessment

How likely this type of incident is to recur or escalate. Rate each area Low, Medium or High.

C1. Network & technical
How likely is it that the underlying vulnerability could be exploited again (e.g. missing multi-factor authentication, unpatched systems, a successful phishing attempt)?
C2. Processes & procedures
Were there gaps in data protection policy or practice (e.g. no access controls, no designated DPO or in-house privacy expertise, no encryption)?
C3a. Insider threat
Low = no known history and strong access controls. Medium = some access control gaps but no known prior misuse. High = a known or suspected prior incident of internal misuse.
C3b. Third-party vendor involvement
Low = no third party involved, or a vetted vendor with a signed Data Processing Agreement. Medium = a vendor involved without a full DPA or recent audit. High = a vendor involved with no due diligence, DPA, or oversight in place.
C3c. Staff training level
Low = regular, documented data protection training for relevant staff. Medium = some training but not regular or comprehensive. High = no data protection training in place.
C4. Sector & scale
Higher-risk sectors (e.g. financial services, telecoms, health, education) and degree of public exposure.
Result

Final severity:

Impact level
Likelihood level
Final severity

Notification obligations

NDPC Notification (72 hours)
Data Subject Notification

NDPC notification applies once a breach is assessed as posing any risk to data subjects' rights and freedoms (Medium severity and above, per NDPA 2023 Section 40(2)). Data subject notification applies only where the breach is assessed as high risk — e.g. likely fraud, identity theft or exposure of sensitive data (High/Critical severity, per GAID 2025 Article 33(2)).

Recommended next steps

    This tool provides an indicative, automated assessment for guidance only and does not constitute legal advice. It does not replace a full breach risk assessment or advice from qualified counsel. For a matter-specific assessment, book a consultation.