NDPA 2023 · GAID 2025 · NDPC Major Importance

NDPA compliance, done properly.

Klari is a system of record for in-house DPOs at Nigerian banks, fintechs and insurers classified by the NDPC as Data Controllers and Processors of Major Importance. Records of Processing, DPIAs, and an append-only audit trail — in one place, in Frankfurt, hash-verified and exportable.

Request access

Annual contracts · Naira billing · Invoiced by bank transfer

Firms under formal NDPC investigation

1,368

Aug 2025 enforcement sweep · banks, fintechs, insurers, gaming, pensions

Collected by the NDPC

₦7.2bn

Cumulative registration fees and penalties reported to August 2025

Maximum fine, Major Importance

₦10m or 2%

Whichever is higher — of annual gross revenue, per NDPA

NDPC figures as reported at August 2025. Verify against ndpc.gov.ng before relying on them.

NDPC Major Importance · 13 named sectors, plus the 2025 sweep

The August 2025 sweep covered financial services, insurance, gaming and pensions. Enforcement is broadening. If you’re here, you already know.

The 13 sectors named by the NDPC · swept sectors highlighted

  • Aviation
  • Communication
  • Education
  • Electric power
  • Financial services
  • Health
  • Hospitality
  • Insurance
  • Oil and gas
  • Tourism
  • E-commerce
  • Export and import
  • Public service

Also covered by the 2025 sweep, but not among the NDPC’s 13 named sectors. Klari does not yet support these two as a workspace sector:

  • Gaming
  • Pension

V1

The core three. Each one a thing the NDPC asks for.

Records, assessments, evidence — built to the standard a DPO would accept. An NDPC registration helper, a Compliance Audit Return dossier generator and billing sit alongside them.

Records of Processing

RoPA Builder

A guided wizard for NDPA s.28 records, aligned to the GAID 2025 schema. Multi-step, save-and-resume, PDF export.

  • NDPA s.28 + GAID 2025 fields out of the box
  • One lawful basis per record, with an audit trail
  • PDF export carrying a SHA-256 verification hash

Impact assessments

DPIA Workflow

Structured Data Protection Impact Assessments with likelihood x severity risk scoring, residual-risk banding, and a two-stage sign-off chain.

  • Likelihood × severity scoring, inherent and residual
  • Two-stage sign-off: reviewer, then DPO countersignature
  • Closed NDPA s.28(2) + GAID 2025 trigger list, not free text

Append-only

Audit Log + Evidence Locker

Every state change is a semantic, append-only event. Evidence uploads via signed URLs, short download TTLs, nightly hash verification.

  • Append-only at the database layer — not just policy
  • Signed-URL uploads, 15-minute download TTLs
  • A nightly SHA-256 re-verification pass over stored files
Why Klari

Built the way an auditor would build it.

Data resident in Frankfurt

Supabase Postgres + Storage in eu-central-1 only. Audit-defensible cross-border transfer posture out of the box — no US CDN holding your tenant data.

Append-only by construction

INSERT-only audit events at the database layer; the service-role key can’t mutate them. Every stored file carries a SHA-256 that a nightly job re-verifies.

Documents you can hand to the NDPC

Every PDF carries the organisation name, ISO timestamp and a document hash. Cover pages on DPIAs. No screenshots-as-evidence.

Design partners

Request access.

Klari is pre-general-availability and we are looking for our first design partners. Tell us who you are and what you’re preparing for — we read every submission.

Submissions go to a single inbox, not a tenant database. We reply from a klari.ng address within one business day.

We reply within one business day. Submissions are stored in our inbox only — not in any tenant database.