Bonaventure OgetoBy Bonaventure Ogeto|

Nigeria Data Protection Act and Payment Data Storage

Under Nigeria's NDPA 2023, storing Paystack payment data (customer email, phone, amount, reference) is lawful under the "contractual necessity" basis — you need it to fulfill the transaction. You must: (1) only store what you need (data minimisation), (2) delete payment records after your retention period, (3) notify the NDPC and affected customers within 72 hours of a data breach, (4) register with the Nigeria Data Protection Commission (NDPC) if you process data for more than 2,000 persons annually, and (5) never store raw card numbers — Paystack prevents this by design.

How NDPA 2023 Applies to Paystack Payment Data

The Nigeria Data Protection Act 2023 covers any personal data — information that identifies or can identify a person. In your Paystack integration, this includes:

  • Customer email address and phone number
  • Customer name attached to a transaction
  • Transaction reference linked to a specific person
  • IP address captured during a transaction
  • Metadata you attach to transactions (e.g., customer ID, order details)

It does not include anonymised or aggregated data where no individual can be identified.

The lawful basis for storing this data is contractual necessity (NDPA Section 25(1)(b)) — you need to process the data to fulfill the payment contract with your customer. You do not need a separate consent form for storing payment records. However, your privacy policy must disclose that you collect and store this data.

Key NDPA Obligations for Payment Data Handlers

1. Data minimisation
Only store what you need. For a completed transaction, you need: reference, amount, status, customer email, and timestamp. You do not need to store the full webhook payload indefinitely.

2. Retention limits
Define and enforce a retention period. For financial records in Nigeria, 5-7 years aligns with FIRS (Federal Inland Revenue Service) requirements. After this period, delete or anonymise payment records.

3. Security measures
Encrypt sensitive fields at rest. Use TLS for all data in transit. Restrict access to payment tables — only staff who need transaction data for their role should be able to query it.

4. NDPC registration
If your business processes personal data of more than 2,000 Nigerians per year, register with the Nigeria Data Protection Commission (ndpc.gov.ng) and appoint a Data Protection Officer (DPO) or retain a licensed Data Protection Compliance Organisation (DPCO).

5. Breach notification
If your payment database is breached, you must:

  • Notify the NDPC within 72 hours of becoming aware
  • Notify affected customers without undue delay if the breach poses high risk to their rights
  • Document the breach, its scope, and remediation steps

Learn More

Key Takeaways

  • Nigeria's NDPA 2023 applies to all businesses processing personal data of Nigerian residents, regardless of where the business is registered.
  • Storing customer email, phone, name, and transaction reference for payment records is lawful under the "contractual necessity" basis — no separate consent form needed.
  • Never store card numbers, CVVs, or PINs. Paystack handles these by design — storing them yourself would violate both NDPA and PCI DSS.
  • If you process data for more than 2,000 people per year, you must register with the NDPC (Nigeria Data Protection Commission) and appoint a Data Protection Officer.
  • In a data breach affecting payment records, you must notify the NDPC within 72 hours and notify affected customers promptly.
  • Implement a data retention policy: delete customer payment records after your defined retention period (typically 5-7 years for financial records under Nigerian law).

Frequently Asked Questions

Does Paystack being PCI DSS compliant satisfy NDPA requirements?
No. PCI DSS covers card data security — it is a payment industry standard, not a national data protection law. The NDPA applies to all personal data you hold, not just card numbers. You need to comply with both: PCI DSS (via your Paystack integration) and NDPA (via your data handling practices).
Do I need a privacy policy to accept payments in Nigeria?
Yes. The NDPA requires you to inform customers about what data you collect, why, and how long you keep it. A privacy policy on your website or app that covers payment data is the minimum. It must be accessible before customers enter any personal information.
What is a DPCO and do I need one?
A Data Protection Compliance Organisation (DPCO) is a firm licensed by the NDPC to help companies with data protection compliance. If your business lacks the internal capacity to appoint a qualified Data Protection Officer, you can engage a DPCO instead. This is common for small to mid-size businesses.
Can I store Nigerian customer payment data on servers outside Nigeria?
The NDPA does not impose a blanket data localisation requirement (unlike some other jurisdictions). You may transfer data outside Nigeria, but you must ensure the recipient country or organisation provides adequate protection — comparable to NDPA standards. Using major cloud providers (AWS, GCP, Azure) with appropriate data processing agreements generally satisfies this.

Ready to build real-world apps?

Join the McTaba Labs full-stack marathon (4 months full-time · 6 months part-time). Learn M-Pesa, USSD, and WhatsApp engineering while shipping 8 production apps.

Apply to the McTaba Marathon