What data processing agreement means
A data processing agreement is the contract between a data controller and a data processor.
The controller decides why and how personal data is processed. It is the business whose customers, employees or users the data belongs to.
The processor handles the data on the controller's behalf and on its instructions. A payroll bureau, a cloud hosting provider, a customer support platform, an email marketing service, a debt collection agency, an outsourced IT provider.
The Nigeria Data Protection Act 2023 requires that relationship to be governed by a written contract. It is not optional, and it is not satisfied by the provider's standard terms of service unless those terms actually contain what the Act requires.
The purpose is accountability. Personal data leaves the controller's hands and goes to somebody else, and the agreement is what ensures the obligations travel with it.
How it is used
A data processing agreement should cover a defined list, and the list is broadly consistent internationally.
The subject matter and duration of the processing.
The nature and purpose of it: what the processor is actually doing with the data.
The types of personal data and the categories of data subjects.
An obligation to process only on the controller's documented instructions.
Confidentiality obligations on the processor's personnel.
Appropriate security measures.
Terms governing sub processors: whether they are permitted, whether the controller must be notified or must consent, and that they are bound by equivalent obligations.
Assistance to the controller with data subject requests and with breach notification.
What happens at the end: deletion or return of the data.
And audit or information rights allowing the controller to verify compliance.
In practice, most large providers offer their own data processing addendum, and the exercise for a Nigerian business is to obtain it, read it against the Act, and keep it with the contract.
Key features
- Governs a processor handling personal data on a controller's behalf
- Required in writing by the Nigeria Data Protection Act 2023
- Must define subject matter, duration, nature, purpose and data types
- Processing only on the controller's documented instructions
- Must address security, sub processors, assistance and deletion
- The controller remains accountable to data subjects and the regulator
How this works in Nigeria
The Nigeria Data Protection Act 2023 replaced the earlier regulation with primary legislation and established the Nigeria Data Protection Commission, and enforcement has been increasing.
The practical exposure for a Nigerian business is that it is a controller for far more processing than it realises. Employee records, customer contact details, delivery addresses, identification documents collected for onboarding, CCTV footage, and marketing lists are all personal data.
Every provider touching that data is a processor, and each relationship needs a written agreement.
The list for a typical Nigerian SME is longer than expected: the payroll provider, the accounting software, the CRM, the email marketing tool, the cloud storage, the website host, the customer support platform, the logistics partner receiving delivery addresses, and the recruitment agency receiving CVs.
The second point is accountability. Outsourcing the processing does not outsource the responsibility. Where a processor suffers a breach, the controller remains accountable to the data subjects and to the Commission, and it will be asked what agreement was in place and what due diligence was done.
The third is breach notification. A personal data breach carries notification obligations to the Commission within a defined period, and to affected individuals where the risk is high. A controller that finds out about a breach late, because the processor had no obligation to tell it promptly, has a problem the agreement should have prevented.
The practical starting point is an inventory: list every provider that touches personal data, and obtain a processing agreement from each.
Controller vs processor vs joint controllers
Three roles under data protection law, and the label decides the obligations.
A controller determines why and how personal data is processed. It bears the primary obligations: lawful basis, transparency, data subject rights, security and breach notification.
A processor acts on the controller's instructions and does not decide the purposes. Its obligations flow largely from the agreement, though the legislation imposes direct duties too, including security and assisting the controller.
Joint controllers determine the purposes and means together. They must allocate responsibilities between them transparently, and data subjects can exercise rights against either.
The classification follows the reality rather than the contract label. A provider that decides what to do with the data, rather than following instructions, is a controller for that processing regardless of what the agreement calls it, and it carries the obligations that go with it.
Limits and risks
An agreement does not create security. A processor with weak controls and an excellent contract is still a breach waiting to happen, which is why due diligence matters alongside the paperwork.
Bargaining power is also limited. A small Nigerian business cannot negotiate the terms of a global cloud provider's addendum, and its practical choice is to accept it or use a different provider.
Enforcement of an agreement against a foreign processor raises jurisdiction and practical difficulties.
And the agreement does not shift accountability. The controller answers to data subjects and to the Commission whatever the contract says between the parties.
Worth knowing
List every provider that touches personal data and obtain a processing agreement from each, including the payroll bureau and the logistics partner. Nigerian businesses sign one with their cloud provider and none with the six other services that hold their customers' details.
Questions people ask
What is a data processing agreement?
The written contract required between a data controller and a data processor handling personal data on its behalf, governing what the processor may do with the data and on what terms.
Is it required in Nigeria?
Yes. The Nigeria Data Protection Act 2023 requires the controller and processor relationship to be governed by a written contract, and a provider's standard terms satisfy it only if they contain what the Act requires.
What must it contain?
The subject matter, duration, nature and purpose of processing, the data types and categories of data subjects, processing only on documented instructions, confidentiality, security, sub processor terms, assistance with requests and breaches, deletion or return, and audit rights.
Who is liable if the processor has a breach?
The controller remains accountable to data subjects and to the Commission. Outsourcing the processing does not outsource the responsibility, and the controller will be asked what agreement and due diligence were in place.
Which providers count as processors?
Any that handle personal data on your behalf: payroll bureaux, accounting and CRM software, email marketing tools, cloud storage, website hosts, support platforms, logistics partners receiving addresses and recruitment agencies receiving CVs.
What if a provider decides what to do with the data?
Then it is a controller for that processing, not a processor, and it carries controller obligations regardless of what the agreement calls it. Classification follows the reality rather than the label.