Privacy & Data Protection Compliance
SAC designs and implements end-to-end NDPA compliance programs, including RoPA, DPIA execution, DPO enablement, and annual CAR filing as a licensed DPCO.
Explore service
We do it for institutions that cannot afford to get compliance wrong.
Stephen Alaekwe & Co (SAC) is Nigeria's integrated Digital Trust, Privacy & Data Protection, Financial Advisory & Assurance Firm. We hold NDPC License NDPC-Licensed DPCO, IIM ATO Accreditation, and ISACA DTEF Certification, operating at the convergence of five disciplines where each reinforces the others. The integration is structural, not aspirational.
Addressing the real compliance and governance needs of Nigerian organizations through targeted, credential-backed programmes.
End-to-end NDPA 2023 compliance: RoPA, DPIA, DPO enablement, DCPMI registration, and annual CAR filing as a licensed DPCO.
ISACA DTEF maturity assessments and board governance structures across all seven digital trust domains, Nigeria's only DTEF-certified facilitator.
Credible, objective assurance over governance, privacy, cybersecurity, risk, and financial controls, structured for external scrutiny, not internal comfort.
Seasoned professional accountants (FCAs) delivering capital structuring, financial modelling, transaction advisory, tax advisory, and financial governance to investor, lender, and regulator standards.
Annual Compliance Audit Return preparation, certification, and filing, mandatory for all DCPMI-classified organizations under NDPA Section 33.
IIM-accredited Certified Data Protection Officer training, delivering NDPC-recognised qualifications for compliance professionals across Nigeria.
Our mission is to enable Nigerian institutions to meet regulatory expectations, withstand scrutiny, and operate with confidence through audit-defensible, regulator-aligned, and board-visible delivery. SAC works across privacy, digital trust, assurance, and financial advisory, not as separate silos, but as an integrated model where each discipline reinforces the others.
Six service areas, each with a specific problem it resolves, a specific credential that authorizes delivery, and a specific audit-defensible output.
SAC designs and implements end-to-end NDPA compliance programs, including RoPA, DPIA execution, DPO enablement, and annual CAR filing as a licensed DPCO.
Explore serviceAs a licensed DPCO, SAC prepares, certifies, and files Compliance Audit Returns with the NDPC on behalf of data controllers and processors.
Explore serviceSAC assesses DCPMI classification thresholds, prepares and submits NDPC registration applications, and manages the annual renewal cycle.
Explore serviceSAC conducts DTEF maturity assessments across all seven trust domains and builds board governance structures, KPIs, and reporting dashboards.
Explore serviceSAC provides independent assurance over governance, privacy, cybersecurity, risk, and financial controls, co-sourced internal audit and governance reviews.
Explore serviceSAC delivers capital structuring, financial modelling, transaction due diligence, accounting systems advisory, tax consulting, and financial governance — led by seasoned professional accountants (FCAs).
Explore serviceEvery SAC solution is defined by what it produces, scoped deliverables, named timelines, audit-defensible outputs.
Full NDPA compliance lifecycle, DCPMI registration, RoPA, DPIA, DPO designation, annual CAR filing, delivered in 60 days by a licensed DPCO.
Commission thisAudit readiness assessment, evidence pack preparation, and Compliance Audit Return filing submitted in SAC's name as a licensed DPCO.
Commission thisBoard accountability frameworks, privacy governance policies, DPO reporting structures, and DTEF-aligned digital trust KPIs for Audit Committee reporting.
Commission this72-hour NDPC breach notification, evidence preservation, regulatory liaison, and post-breach remediation, led by a licensed DPCO with 24-hour response SLA.
Commission thisData processor due diligence, contract review, data sharing agreements, and transfer risk assessments structured to NDPA transfer restriction requirements.
Commission thisTen packaged solutions across privacy, digital trust, cybersecurity, assurance, and financial advisory, each with fixed scope and defined deliverables.
See all solutionsSAC applies the specific regulatory obligations of each sector, NDPA, CBN, NHIS, NCC, NUPRC, BPP, not a standard framework adapted for every context.
SAC's NDPA compliance engagement was thorough, structured, and board-ready. Our DCPMI registration was completed in under 30 days with full documentation our auditors accepted without question.
The DTEF assessment gave our board something they'd never had, a structured, evidence-based view of our digital trust posture that we could actually report to regulators and present to investors.
SAC filed our CAR and we passed the NDPC inspection. What set them apart was that they explained every obligation, what we owed as evidence, and why. That level of transparency builds real trust.
Every credential is verifiable with its issuing body. SAC publishes reference numbers because claims without verifiable anchors are not evidence, and evidence is what this firm is built to produce.
Authorizes delivery of data protection advisory, audit, and CAR filing under Section 33 of the NDPA 2023.
Accredited to deliver and certify the IIM Certified Data Protection Officer (CDPO) programme. Graduates verifiable with IIM Africa.
Authorized to assess digital trust maturity across all seven DTEF domains, the only such certified facilitator in Nigeria.
Financial advisory practice led by FCA principals registered with the Financial Reporting Council of Nigeria.
Principal-level CISA credential authorizing IS audit, assurance, and governance engagements, verifiable with ISACA International.
Privacy solutions engineering credential applied to NDPA technical compliance architecture and data protection system design.





Download the NDPA/GAID Compliance Readiness Checklist, a structured, NDPC-aligned framework covering all principal compliance obligations for data controllers and processors in Nigeria.
All principal NDPA and GAID obligations mapped against the NDPC audit framework, DCPMI registration, RoPA, DPIA, DPO designation, breach response, CAR filing, and board governance. Formatted for DPO functions and compliance teams.
A 20-minute conversation with a named SAC principal, not a sales call. Substantive diagnostic expertise on your compliance position and what it requires.