Open Access iconOpen Access

ARTICLE

crossmark

Evaluating the Level of Compliance with the Nigeria Data Protection Regulation (NDPR): Insights from Organizations across Key Sectors

Asere Gbenga Femi1,*, Monday Osagie Adenomon1, Gilbert Imuetinyan Osaze Aimufua1, Umar Ibrahim2

1 Centre for Cyberspace Studies, Nasarawa State University, Keffi, 911019, Nigeria
2 Department of Physics, Nasarawa State University, Keffi, 911019, Nigeria

* Corresponding Author: Asere Gbenga Femi. Email: email

Journal of Cyber Security 2025, 7, 377-394. https://doi.org/10.32604/jcs.2025.069185

Abstract

Effective data protection frameworks are vital for safeguarding personal information, fostering digital trust, and ensuring alignment with global standards. In Nigeria, the Nigeria Data Protection Regulation (NDPR), administered by the National Information Technology Development Agency (NITDA), constitutes the nation’s primary privacy framework, harmonized with principles of the European Union’s GDPR. This study evaluates NDPR compliance across six strategic sectors; finance, telecommunications, education, health, Small and Medium-sized Enterprises (SMEs), and the public sector using a mixed-methods design. Data from 615 respondents in 30 organizations were collected through surveys, interviews, and document analysis. Findings reveal notable sectoral disparities: finance and telecommunications demonstrate high compliance due to regulatory pressure and strong technical capacity, while SMEs and public institutions exhibit lower adherence. Compliance, monitoring, and awareness were assessed against NDPR benchmarks, including lawful processing, consent protocols, and breach response procedures. Regression results indicate that NDPR compliance, staff training, and cybersecurity investment significantly predict enhanced cybersecurity outcomes, though perfect correlations raise concerns about instrument validity. Weak enforcement, with limited penalties or legal actions, undermines the regulation’s deterrent effect. Drawing on Institutional and Deterrence Theories, the study identifies legal and structural gaps in the NDPR and proposes reforms, stronger oversight, and sector-specific interventions. These findings contribute to debates on regulatory effectiveness and offer actionable strategies for improving data governance and cybersecurity resilience in Nigeria.

Keywords

NDPR compliance; data privacy; cybersecurity; Nigerian organizations; sectoral analysis

Cite This Article

APA Style
Femi, A.G., Adenomon, M.O., Aimufua, G.I.O., Ibrahim, U. (2025). Evaluating the Level of Compliance with the Nigeria Data Protection Regulation (NDPR): Insights from Organizations across Key Sectors. Journal of Cyber Security, 7(1), 377–394. https://doi.org/10.32604/jcs.2025.069185
Vancouver Style
Femi AG, Adenomon MO, Aimufua GIO, Ibrahim U. Evaluating the Level of Compliance with the Nigeria Data Protection Regulation (NDPR): Insights from Organizations across Key Sectors. J Cyber Secur. 2025;7(1):377–394. https://doi.org/10.32604/jcs.2025.069185
IEEE Style
A. G. Femi, M. O. Adenomon, G. I. O. Aimufua, and U. Ibrahim, “Evaluating the Level of Compliance with the Nigeria Data Protection Regulation (NDPR): Insights from Organizations across Key Sectors,” J. Cyber Secur., vol. 7, no. 1, pp. 377–394, 2025. https://doi.org/10.32604/jcs.2025.069185



cc Copyright © 2025 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 393

    View

  • 193

    Download

  • 0

    Like

Share Link