Skip to content

Architecture-first platforms for startups and growing organisations

Estimate a programme

Governance · 18 July 2026 · 7 min

NDPR is not a footer. It is an architectural constraint.

Data protection for Nigerian organisations has to show up in where systems live, who can query them, and how long a record remains a record.

Too many programmes treat the Nigeria Data Protection Regulation as a privacy-policy page and a checkbox in a vendor’s proposal. That is how you discover, after go-live, that customer data is sitting in a region nobody can name, accessible to a support team nobody has met, retained for a period nobody chose.

NDPR, records law, and ordinary prudence are architectural. They decide hosting, identity, logging, retention, and the right to be left alone — before they decide the colour of a button.

Sovereign enough

Not every workload must live in a Nigerian data centre. Some must. The work is to classify, not to slogan. Payment data, health records, security logs, and the contents of a registry are not in the same class as a marketing site. An architecture that cannot say so in writing is not finished.

More notes

Next step

Bring us the hard programme.

If the work needs architecture, security, and a team that will still be there at go-live, we should talk. Discovery conversations are with a senior architect — not a queue.