NDPR / Privacy Basics for Business Email in Nigeria
This guide is practical orientation, not legal advice. Nigeria’s data protection rules (commonly discussed as NDPR under NITDA’s framework and the newer Nigeria Data Protection Act (NDPA) administered with the Nigeria Data Protection Commission (NDPC)) expect you to handle people’s personal data carefully — and business email is full of it.
If you process customer or employee data via MailShrine, treat the mailbox as part of your privacy surface: access control, retention, and breach readiness. For formal compliance (DPO appointments, registration, DPIAs), speak with a qualified Nigerian privacy counsel or accredited practitioner.
Real-life example: Ember Atelier (Abuja)
Ifeoma runs a made-to-measure fashion label. Clients email measurements, IDs for pickup verification, and payment receipts to orders@emberatelier.ng. She asked whether “having Gmail forwarding forever” was fine under NDPR.
Her practical upgrades (still not a legal sign-off): move to a real business mailbox on her domain, enable 2FA, stop auto-forwarding everything to a personal Gmail, and keep a short privacy notice describing why they collect fittings data.
Why email shows up in privacy conversations
| Data often sitting in email | Risk if sloppy |
|---|---|
| Names, phones, addresses | Unauthorised staff access / shared passwords |
| Invoices & bank proofs | Fraud and identity misuse |
| CVs & ID scans | Sensitive personal data exposure |
| Health / school / finance notes | Higher sensitivity → tighter controls |
Mail is not anonymous just because it’s “in the cloud.”
Practical privacy controls for SMB email
None of these replace a legal review — they are operational hygiene most Nigerian SMEs can start this week:
- Know your mailboxes — list who can open what; retire shared passwords (password policy).
- Limit access — aliases over shared logins when one person owns the inbox.
- Secure login — 2FA on every human account.
- Prefer Nigerian-clear hosting contracts — read your provider’s privacy / DPA language; know where support staff may access mail for abuse cases.
- Minimise — don’t ask customers to email BVNs or full card numbers.
- Retention habit — archive or delete stale attachment dumps you no longer need.
- Breach readiness — know who to call if a mailbox is abused (incident guide) and when authorities or individuals may need notice under applicable law.
Step 1: Map personal data in your inboxes
For one week, note categories (orders, HR, support). That map feeds your privacy notice and access rules.
Step 2: Put a short privacy statement where customers see it
Website footer + order confirmation is enough to start: what you collect via email, why, how long you roughly keep it, and how to contact you. Have counsel review when you can.
Step 3: Lock the technical doors
- Unique passwords + manager.
- 2FA.
- DNS auth so scammers don’t spoof your brand (SPF/DMARC).
- Disable unused mailbox seats promptly when staff leave.
Step 4: Decide vendor roles carefully
If a marketer or VA needs inbox access, use least privilege and revoke quickly. Document processors you share mail content with (CRM sync tools, helpdesks).
Step 5: Know when to escalate beyond DIY
You likely need professional NDPA/NDPR advice if you:
- Process children’s data or special categories at volume
- Buy/sell large contact lists
- Operate as a significant data controller / processor under NDPC thresholds
- Suffer a confirmed large-scale breach
Checklist
- Mailbox access list written downCompleted
- 2FA + strong unique passwordsCompleted
- No routine forwarding of all mail to personal GmailCompleted
- Privacy notice reviewed by counsel (when budget allows)Not completed
- Incident contacts listed for suspected compromiseNot completed
Common mistakes
- Treating NDPR as “only for banks.” Many SMEs still process personal data.
- Dumping client IDs in unreplied threads forever.
- Shared
info@password with every intern. - Confusing spam filtering with privacy compliance.
Next steps
Citations & References
- Reference: Nigeria Data Protection Commission (NDPC)
- Reference: Nigeria Data Protection Act, 2023 (official overview / NDPC resources)
- Reference: NITDA: Nigeria Data Protection Regulation (historical NDPR materials)
Written by Ben A., Privacy Operations Writer. Ben helps Nigerian SMEs translate NDPA/NDPR ideas into mailbox hygiene — without pretending to be their lawyer.




