ARTICLE
19 June 2026

Did You Know? Doing Nothing About A Data Breach Can Be More 'Expensive' Than The Breach!

UU
Udo Udoma & Belo-Osagie

Contributor

Founded in 1983, Udo Udoma & Belo-Osagie is a multi-specialisation full service corporate and commercial law firm with offices in Nigeria’s key commercial centres. The firm’s corporate practice is supported by a company secretarial department, Alsec Nominees Limited, which provides a full range of company secretarial services and our sub-firm, U-Law which caters exclusively to entrepreneurs, MSMEs, startups, and growth businesses across several industries, including the FinTech industry. It is designed as a one-stop-shop for all basic business-related legal needs, providing high-quality support in a simplified and straightforward manner at super competitive prices. We are privileged to work with diverse local and international clients to create and implement innovative practical solutions that facilitate business in Nigeria and beyond. When required, we are well-placed to work across Africa with a select network of leading African and international law firms with whom we enjoy established relationships.
In today’s digital environment, data breaches are an operational reality. It could be the result of a sophisticated cyber-attack or an email sent to the wrong person. It is important to note, however, that our data privacy law does not penalise organisations simply for being victims of a personal data breach.
Nigeria Privacy
Udo Udoma & Belo-Osagie are most popular:
  • within Privacy, Strategy and Technology topic(s)
  • in United States

Under the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025, the greatest regulatory risk often isn’t the breach itself, but how you respond to it.

In today’s digital environment, data breaches are an operational reality. It could be the result of a sophisticated cyber-attack or an email sent to the wrong person. It is important to note, however, that our data privacy law does not penalise organisations simply for being victims of a personal data breach.

The Real Risk

Regulatory exposure typically arises from a failure in accountability. If you cannot demonstrate robust technical and organisational safeguards, a proactive response, and compliance with reporting obligations, the Nigeria Data Protection cOMMISSION (“NDPC”) may view the incident as a broader governance failure.

To build resilience, the response should be:

Transparent: A notification to the NDPC should move beyond the ‘what’ to address the impact and your remediation plan.

Documented: A Personal Data Breach Register should be maintained to record the facts and rationale for all incidents, whether they are deemed reportable or not.

Structured: Clear escalation lines and incident management protocols must be established before a breach occurs.

You should treat breaches as a test of your organisation's integrity. Do not allow a lack of documentation to turn a manageable incident into a significant regulatory failure.

For data privacy-related support, please contact dpteam@uubo.org

UUBO is a licensed Data Protection Compliance Organisation. We can assist you with your audit compliance obligations, preparation and filing of audit returns, or provision of general information on data protection.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More