On discovering a data breach, which regulators or other government agencies should be notified?
In Nigeria, the Nigeria Data Protection Bureau (NDPB) is the agency to notify for a data breach. The National Information Technology Development Agency (NITDA) is an agency created for the sole purpose of coordinating Information Technology practices and activities in Nigeria which then created the Nigeria Data Protection Regulation (NDPR) 2019 as a comprehensive regulation on data protection in Nigeria. The NDPB was then further created to implement the objectives of the NDPR 2019.
The Nigeria Data Protection Bureau is an office, set up for the purpose of protecting the rights of data subjects, the obligations of data controllers and data processors, and the transfer of data to a foreign territory. The Bureau, through its website allows individuals to directly notify them of a data breach. Data Controllers have a duty of self-reporting of data breaches to NDPB within 72 (seventy-two) hours of becoming aware of the breach. A Data Controller is also required to immediately notify the Data Subject of a Personal Data breach where the breach will likely result in high risks to the rights of the data subject. The Bureau also has the option to collaborate with other security agencies for data related crimes beyond its capacity.