SEPTEMBER 2026 · THE TOOL DESKPractical technology. No theatre.

Practical guide · verified against the real thing

Data security compliance in plain terms: GDPR, CCPA and Nigeria's NDPA, and what each actually asks of you

In one line: Compliance is not one rule — it depends on whose data you hold and where they are. Here is the honest plain-language map for the US, UK/EU and Nigeria, and the basics that satisfy most of it.

"Are we compliant?" is the wrong first question, because there is no single thing called compliance. Which rules bind you depends on whose personal data you hold and where those people are, not where your company is registered. A small business in Lagos with customers in London answers to different law than one serving only Lagos. This is the plain-language map, and the reassuring part is that the core discipline overlaps heavily across all three regimes.

The three regimes, and who they protect

The GDPR (UK and EU) protects the data of people in those regions and follows the data wherever it goes — so a Nigerian or American firm serving UK/EU customers is in scope. The CCPA/CPRA (California, and a growing patchwork of other US states) is consumer-rights law: disclosure, opt-out of sale, deletion on request. Nigeria's NDPA 2023 (with the NDPR that preceded it) is closer to the GDPR in shape — lawful basis, consent, data-subject rights — and applies to processing of Nigerian residents' data. The practical read: if you touch personal data of people in any of these places, assume that place's rules reach you.

What all three actually ask (the overlap)

Strip the jargon and the shared requirements are ordinary good practice: know what personal data you hold and why (a record of processing); have a lawful reason to hold it; keep it only as long as needed; secure it; let people see, correct or delete their data; and report a serious breach within the deadline (72 hours under GDPR, a defined window under the NDPA, and per-state rules in the US). None of that requires a legal team to start — it requires knowing your own data, which is the same hygiene as the security checklist applied to records rather than passwords.

Where the jurisdictions genuinely differ

Do not flatten these into one answer. Consent standards differ (GDPR's consent is stricter than much US practice). Breach-notification clocks and regulators differ. Cross-border transfer rules — moving EU/UK data to the US or Nigeria — carry extra conditions. Fines and enforcement differ sharply. So when a decision hinges on a specific obligation, name the jurisdiction and check the current text or a qualified adviser; this page is the map, not the legal advice. The security side of compliance — actually protecting the data — is the part this desk can help with directly, starting with patch management and the rest of this cluster.

Sources

Next

Related on this desk.