Too many programmes treat the Nigeria Data Protection Regulation as a privacy-policy page and a checkbox in a vendor’s proposal. That is how you discover, after go-live, that customer data is sitting in a region nobody can name, accessible to a support team nobody has met, retained for a period nobody chose.
NDPR, records law, and ordinary prudence are architectural. They decide hosting, identity, logging, retention, and the right to be left alone — before they decide the colour of a button.
Sovereign enough
Not every workload must live in a Nigerian data centre. Some must. The work is to classify, not to slogan. Payment data, health records, security logs, and the contents of a registry are not in the same class as a marketing site. An architecture that cannot say so in writing is not finished.
Related practices
