Compliance Infrastructure
Compliance Infrastructure for Evidence-Based Governance.
SAC products and platforms help institutions organise, evidence, monitor, and improve their compliance posture across privacy, data protection, audit readiness, and board governance. These are operational instruments — not reference documents.
Select a product to explore the full specification.
Every product is built to the evidence standard the NDPC's inspection framework applies — not the standard that satisfies internal review. Click any card to see the full problem, contents, audience, and delivery format.
Privacy Compliance Toolkit
Organisations need a structured starting point for end-to-end NDPA compliance — not a single template but a coordinated suite.
Audit Evidence Tracker
Organisations cannot prove compliance because evidence is scattered, unmapped, and assembled under pressure — not maintained as a live system.
DPIA Builder
Most DPIAs are completed on inadequate templates that do not align with NDPA Section 28 or the NDPC's documentation standard — and would not withstand inspection.
RoPA Template Pack
Records of Processing Activities that most organisations have built are lists, not records — missing the lawful basis, retention, transfer, and security fields the NDPC requires.
Board Privacy Governance Dashboard
Boards acknowledge NDPA accountability but have no structured, visual, and regularly updated view of the organisation's privacy governance posture to govern against.
Vendor Privacy Due Diligence Pack
Organisations share personal data with vendors without DPAs, security assessments, or any structured framework for managing processor compliance obligations.
Breach Response Pack
Most organisations have no executable breach response — the 72-hour clock starts running the moment of discovery, and improvised responses produce incomplete or delayed NDPC notifications.
NDPC CAR Preparation Pack
Organisations that need to file a Compliance Audit Return lack the structured preparation framework to assemble the evidence, complete the assessment, and present it to their DPCO for certification.
Organisations attempting to build NDPA compliance from scratch encounter a coordination problem — the privacy policy, DSAR procedure, RoPA, DPIA template, and staff notice must work together as a system. Building them separately, from disparate templates, produces inconsistencies that NDPC inspectors identify immediately. The Privacy Compliance Toolkit provides a coordinated, internally consistent documentation suite structured to the NDPC's audit standard from the outset.
The Toolkit is used as the foundation layer of an organisation's NDPA compliance programme — either self-implemented by the DPO function or deployed with SAC advisory support. Each document is pre-formatted to the NDPC's documentation standard and pre-populated with Nigerian regulatory references, leaving the organisation to complete the organisation-specific fields rather than build from blank templates.
- Privacy Policy (NDPA-compliant, customisable)
- Privacy Notice templates (website, HR, clients)
- DSAR response procedure and log
- RoPA master template (NDPC format)
- DPIA trigger assessment checklist
- Breach response protocol and register
- Staff privacy awareness briefing
- Third-party data sharing log
DPOs, compliance officers, legal teams, and organisations beginning or restructuring their NDPA compliance programme. Suitable for all sectors. Available with SAC implementation support for accelerated deployment.
A complete NDPA documentation foundation — consistent, NDPC-formatted, and ready for use as the basis of the organisation's annual Compliance Audit Return.
Many organisations cannot prove compliance because evidence is scattered across email folders, SharePoint directories, and individual team members' hard drives — unmapped to any regulatory obligation and inaccessible under time pressure. The Audit Evidence Tracker maps every piece of compliance evidence to its specific NDPA/GAID obligation, records who is responsible, tracks status, and produces a consolidated view that survives an audit or inspection without a pre-inspection scramble.
The Tracker is used as the DPO's live compliance management instrument — updated continuously as evidence is generated, reviewed, and filed. It serves as the source document for the annual Compliance Audit Return, the input for board quarterly reporting, and the primary exhibit in an NDPC inspection response. It is designed to be maintained by the DPO function, reviewed quarterly, and presented annually to the board and to the DPCO who certifies the CAR filing.
- Evidence request list (all NDPA obligations)
- NDPA / GAID obligation-to-evidence mapping
- Responsible owner field per obligation
- Evidence status tracker (RAG: Complete / Partial / Missing)
- Evidence upload reference and location log
- Management action plan for gaps
- Audit readiness summary dashboard tab
- Board reporting extract format
DPOs, compliance officers, internal auditors, legal teams, and management. Delivered as Excel workbook and Google Sheets version. Compatible with all organisation sizes and sectors.
An organisation that is inspection-ready at any point — every compliance obligation tracked, every evidence item located, every gap identified and actioned before the NDPC asks.
Most DPIAs are completed on templates adapted from UK ICO or EU GDPR formats that do not align with NDPA Section 28 or the NDPC's GAID documentation requirements. The DPIA Builder is structured from the NDPC's own assessment framework — covering necessity and proportionality, risk identification and rating, risk mitigation design, and the sign-off and residual risk documentation that an NDPC inspection requires to see completed before high-risk processing commences.
The Builder guides the DPO or project team through each stage of the DPIA — from processing description and necessity assessment through risk scoring, mitigation design, and DPO/senior management sign-off. Each section contains instructional text explaining the NDPC's standard for that field, a worked example from a Nigerian regulatory context, and the input field for the organisation's own assessment. Completed DPIAs are stored in the DPIA Register tab.
- DPIA mandatory trigger assessment tool
- Processing description framework (NDPC format)
- Necessity and proportionality assessment
- Risk identification and scoring matrix
- Risk mitigation design section
- Residual risk documentation
- DPO and senior management sign-off fields
- DPIA Register (multi-DPIA tracking)
DPOs, project managers, IT leads, legal officers, and compliance teams managing high-risk processing activities. Works in conjunction with the RoPA Template Pack and Privacy Compliance Toolkit.
DPIAs that satisfy NDPA Section 28 and NDPC inspection criteria — completed before high-risk processing commences, documented to the regulatory standard, and stored in a retrievable register.
Records of Processing Activities built from generic privacy templates are missing the fields the NDPC requires — lawful basis documentation per activity, retention schedule, data subject categories, security measures, and transfer information. The RoPA Template Pack is built to NDPA Section 24 and the GAID's prescribed content standard, covering every field the NDPC expects to see completed when it requests the organisation's processing records.
The Pack is used by the DPO or compliance officer to conduct a structured processing inventory across the organisation — interviewing department heads, mapping data flows, and populating each activity record with the full required content. The master RoPA tab produces a submission-ready view for CAR filing and NDPC inspection. The department tabs enable distributed completion and review. A guidance sheet explains each field with reference to the relevant NDPA provision and NDPC interpretation.
- Master RoPA workbook (NDPA Section 24 fields)
- Processing activity inventory template
- Lawful basis selection guide (NDPA-specific)
- Data category classification framework
- Retention schedule builder
- Third-party and cross-border transfer fields
- Department-level completion tabs
- NDPC-format master export view
DPOs and compliance officers conducting processing inventories. Available in Excel and Google Sheets. Includes guidance notes with NDPC field-by-field explanations.
A complete, NDPC-format RoPA — submission-ready for CAR filing, inspection-ready for NDPC review, and maintainable by the DPO function without external advisory dependency.
Boards are accountable for NDPA privacy governance but receive compliance information in formats designed for operational teams — spreadsheet reports, email updates, and status lists that do not translate into board-level governance decisions. The Board Privacy Governance Dashboard provides a visual, structured, quarterly-cadence view of the organisation's privacy posture across the NDPA's principal obligations — designed for a board member who needs to understand the posture, identify the gaps, and discharge the governance accountability.
The DPO updates the Dashboard quarterly using data from the Audit Evidence Tracker and the organisation's compliance programme. The Dashboard produces a one-page board summary with RAG indicators per obligation domain, trend charts showing posture improvement or deterioration, and a management action summary. The board quarterly report appendix is generated directly from the Dashboard and formatted for Audit Committee presentation without further design work.
- NDPA obligation posture summary (RAG per domain)
- Compliance trend chart (quarterly)
- DPO function operational status panel
- Open management action items summary
- Incident and DSAR summary panel
- CAR filing status indicator
- Board report one-page export
- Audit Committee presentation template
DPOs producing board reports, Audit Committees, and board members receiving quarterly privacy governance updates. Delivered as Google Sheets / Excel with PowerPoint summary template.
A board that receives structured, visual, quarterly privacy governance reporting — able to identify posture trends, track management action, and evidence board-level oversight to the NDPC.
Organisations share personal data with vendors without structured data processing agreements, security assessments, or ongoing monitoring frameworks. Under the NDPA, controllers are accountable for what their processors do with data on their behalf — and a vendor breach or misuse becomes the controller's compliance failure. The Vendor Privacy Due Diligence Pack provides the complete framework for assessing, contracting, and monitoring data processors under NDPA Section 29 requirements.
Used by the DPO or procurement team to assess any vendor who will handle personal data before onboarding, at contract renewal, and on an annual review basis. The Pack includes a Vendor Register for tracking all data-sharing relationships, an Assessment Questionnaire for evaluating vendor privacy and security posture, DPA terms for insertion into vendor contracts, and a monitoring schedule for ongoing oversight.
- Vendor / data processor register
- Vendor privacy assessment questionnaire
- Data Processing Agreement (DPA) terms template
- Sub-processor notification procedure
- Security and breach notification requirements
- Vendor onboarding privacy checklist
- Annual review schedule and log
- Risk rating framework per vendor
DPOs, procurement teams, legal officers, and compliance managers managing vendor relationships involving personal data. Compatible with all sectors and organisation sizes.
A compliant vendor data governance framework — every processor assessed, every DPA in place, and every data-sharing relationship monitored against the NDPA's processor accountability standard.
When a data breach occurs, most organisations discover that their breach response exists only as a policy document — not as an executable playbook. The 72-hour NDPC notification window starts immediately upon discovery, and improvised responses produce late, incomplete, or non-compliant notifications that compound the original breach liability. The Breach Response Pack provides every tool, template, and procedure required to execute a complete NDPA-compliant breach response — before the clock starts.
The Pack is deployed at the point of incident detection — the Breach Assessment Tool determines severity and notification obligations within minutes; the 72-Hour Timeline Tracker manages the notification clock; the NDPC Notification Template is completed with the assessed breach details and submitted within the mandatory window. Post-breach, the Remediation Log captures all corrective actions for the NDPC follow-up and CAR filing.
- Breach assessment tool (severity and notification trigger)
- 72-hour timeline tracker with milestone alerts
- NDPC breach notification template (Section 40)
- Data subject notification decision framework
- Breach register (ongoing incident log)
- Evidence preservation checklist
- Remediation log and management action tracker
- Post-breach review report template
DPOs, IT security teams, legal counsel, and crisis response leads. Recommended for use alongside SAC's Breach Simulation Lab training for full operational readiness.
An organisation that can execute a complete NDPA-compliant breach response within 72 hours — with documented evidence of every step from discovery to NDPC notification to remediation.
Organisations preparing for their annual Compliance Audit Return filing — which must be certified and submitted by a licensed DPCO — lack the structured preparation framework to assemble the evidence, complete the self-assessment, and present it in a form that supports the DPCO's certification. Inadequate CAR preparation produces filings that the NDPC challenges or that the DPCO cannot certify without substantial rework. The CAR Preparation Pack structures the preparation process to the NDPC's submission standard.
Used by the DPO function in the weeks before the annual CAR filing cycle — working through the 32-point self-assessment, gathering and tagging evidence against each obligation, completing the management representation sections, and presenting the completed pack to the DPCO (SAC or another licensed DPCO) for review and certification. The Pack reduces the time required for DPCO certification review by ensuring all required components are present and correctly formatted before submission.
- 32-point NDPC self-assessment workbook
- Evidence assembly checklist per obligation
- Management representation statements
- DPO attestation form
- Gap identification and remediation log
- DPCO presentation pack (for certification review)
- Prior-year comparison tracker
- Post-filing improvement roadmap
DPOs and compliance officers preparing for CAR filing. To be used in conjunction with SAC's CAR Filing Service where SAC acts as the certifying and filing DPCO.
A CAR-ready evidence pack that supports DPCO certification and NDPC submission — assembled to the NDPC's standard before the filing deadline, not under it.
Products operate independently. Advisory support accelerates deployment.
Every SAC product is designed for self-implementation by a competent DPO or compliance officer. For organisations that want faster deployment, sectoral calibration, or external quality assurance, SAC advisory support is available as an add-on to any product.
| Capability | Toolkit Only | With SAC Advisory Support | Advisory Engagement Only |
|---|---|---|---|
| NDPA-standard documentation | ✓ Included | ✓ Included | ✓ Built by SAC |
| Sector calibration | ● Generic | ✓ Calibrated | ✓ Full calibration |
| Organisational data mapping | – Self-conducted | ✓ SAC-led | ✓ SAC-led |
| NDPC quality review | – Not included | ✓ SAC review | ✓ SAC certifies |
| DPCO certification for CAR | – Separate engagement | ● Add-on available | ✓ Included |
| Board reporting setup | ● Template included | ✓ SAC activates | ✓ Full setup |
| Deployment timeline | Depends on DPO capacity | Accelerated — 2–4 weeks | 30–60 days (full programme) |
| Appropriate for | Capable DPO with time | DPO with advisory support | Complex / regulated organisations |
✓ = Fully included ● = Partially included or available as add-on – = Not included in this option
Products are more powerful when deployed by practitioners.
SAC products are designed for self-implementation. For organisations that want the product deployed correctly, calibrated to their sector, and quality-assured by a licensed DPCO — SAC offers implementation support as an add-on to any product purchase.
Implementation support is priced separately from the product and is available as a fixed-scope engagement — ensuring the product is live, populated with the organisation's own data, and validated against the NDPC standard before the support engagement closes.
Request Implementation SupportBuild the compliance infrastructure your organisation needs to operate defensibly.
Request any product, request a bundle with advisory support, or enquire about a custom implementation. SAC responds to all product enquiries within one business day.