Integrated Digital Trust Enablement & Professional Services — Nigeria

Digital Trust.
Privacy & Data Protection.
Assurance & Financial Intelligence.

NDPC-Licensed DPCO IIM Accredited ATO ISACA DTEF Certified FCA · CISA · CDPSE
01 / 03
0
Core Service Lines
0days
NDPA Delivery Timeline
0hr
Breach Response SLA
0
DTEF Governance Domains
SAC team in professional consultation
Our Position
"Integration is not a claim. It is the structure."

Compliance is Our Main Goal

We do it for institutions that cannot afford to get compliance wrong.

Stephen Alaekwe & Co (SAC) is Nigeria's integrated Digital Trust, Privacy & Data Protection, Financial Advisory & Assurance Firm. We hold NDPC License NDPC-Licensed DPCO, IIM ATO Accreditation, and ISACA DTEF Certification, operating at the convergence of five disciplines where each reinforces the others. The integration is structural, not aspirational.

Our Focus Areas

We Do It for Institutions That Matter.

Addressing the real compliance and governance needs of Nigerian organizations through targeted, credential-backed programmes.

01

Privacy & Data Protection

End-to-end NDPA 2023 compliance: RoPA, DPIA, DPO enablement, DCPMI registration, and annual CAR filing as a licensed DPCO.

02

Digital Trust & Cybersecurity

ISACA DTEF maturity assessments and board governance structures across all seven digital trust domains, Nigeria's only DTEF-certified facilitator.

03

Independent Assurance

Credible, objective assurance over governance, privacy, cybersecurity, risk, and financial controls, structured for external scrutiny, not internal comfort.

04

Financial Advisory

Seasoned professional accountants (FCAs) delivering capital structuring, financial modelling, transaction advisory, tax advisory, and financial governance to investor, lender, and regulator standards.

05

Regulatory Filing & CAR

Annual Compliance Audit Return preparation, certification, and filing, mandatory for all DCPMI-classified organizations under NDPA Section 33.

06

Professional Training, CDPO

IIM-accredited Certified Data Protection Officer training, delivering NDPC-recognised qualifications for compliance professionals across Nigeria.

Make a Difference

Move from Documentation
to Demonstrable Compliance.

Our mission is to enable Nigerian institutions to meet regulatory expectations, withstand scrutiny, and operate with confidence through audit-defensible, regulator-aligned, and board-visible delivery. SAC works across privacy, digital trust, assurance, and financial advisory, not as separate silos, but as an integrated model where each discipline reinforces the others.

Core Services

What SAC Delivers.

Six service areas, each with a specific problem it resolves, a specific credential that authorizes delivery, and a specific audit-defensible output.

NDPC-Licensed DPCO · NDPC-Licensed DPCO

Privacy & Data Protection Compliance

Problem: Organizations face NDPC enforcement risk with no documented processing records or operational DPO function.

SAC designs and implements end-to-end NDPA compliance programs, including RoPA, DPIA execution, DPO enablement, and annual CAR filing as a licensed DPCO.

Explore service
NDPC Licensed · Annual Filing

NDPC Compliance Audit Returns

Problem: CAR filing is mandatory annually for DCPMI-classified organizations, most have not filed.

As a licensed DPCO, SAC prepares, certifies, and files Compliance Audit Returns with the NDPC on behalf of data controllers and processors.

Explore service
NDPA Section 30 · GAID Compliant

DCPMI Registration Advisory

Problem: Data Controllers of Major Importance must register with the NDPC, most haven't confirmed their threshold status.

SAC assesses DCPMI classification thresholds, prepares and submits NDPC registration applications, and manages the annual renewal cycle.

Explore service
ISACA DTEF Certified Facilitator

Digital Trust & Cybersecurity

Problem: Boards acknowledge digital trust accountability but have no governance framework to discharge it.

SAC conducts DTEF maturity assessments across all seven trust domains and builds board governance structures, KPIs, and reporting dashboards.

Explore service
CISA · CRISC · CDPSE

Independent Assurance

Problem: Internal assurance functions lack the independence or multi-discipline scope that regulators and boards require.

SAC provides independent assurance over governance, privacy, cybersecurity, risk, and financial controls, co-sourced internal audit and governance reviews.

Explore service
Professional Accountants (FCA) · FRCN Registered

Financial Advisory

Problem: Financial governance decisions require chartered-accountant oversight to satisfy investor and regulatory scrutiny.

SAC delivers capital structuring, financial modelling, transaction due diligence, accounting systems advisory, tax consulting, and financial governance — led by seasoned professional accountants (FCAs).

Explore service
Solutions by Outcome

Commission an Outcome, Not a Process.

Every SAC solution is defined by what it produces, scoped deliverables, named timelines, audit-defensible outputs.

01

Achieve NDPA/GAID Compliance

Full NDPA compliance lifecycle, DCPMI registration, RoPA, DPIA, DPO designation, annual CAR filing, delivered in 60 days by a licensed DPCO.

Commission this
02

Prepare for NDPC Audit & CAR Filing

Audit readiness assessment, evidence pack preparation, and Compliance Audit Return filing submitted in SAC's name as a licensed DPCO.

Commission this
03

Build Board-Level Privacy Governance

Board accountability frameworks, privacy governance policies, DPO reporting structures, and DTEF-aligned digital trust KPIs for Audit Committee reporting.

Commission this
04

Respond to Data Breaches

72-hour NDPC breach notification, evidence preservation, regulatory liaison, and post-breach remediation, led by a licensed DPCO with 24-hour response SLA.

Commission this
05

Manage Third-Party Data Risk

Data processor due diligence, contract review, data sharing agreements, and transfer risk assessments structured to NDPA transfer restriction requirements.

Commission this
+

View All Solutions

Ten packaged solutions across privacy, digital trust, cybersecurity, assurance, and financial advisory, each with fixed scope and defined deliverables.

See all solutions
Industries Served

Sector-Native. Not Generic.

SAC applies the specific regulatory obligations of each sector, NDPA, CBN, NHIS, NCC, NUPRC, BPP, not a standard framework adapted for every context.

Client Perspectives

What Clients Say About SAC

3+ Verified Engagements

SAC's NDPA compliance engagement was thorough, structured, and board-ready. Our DCPMI registration was completed in under 30 days with full documentation our auditors accepted without question.

A
Aisha M.
Chief Compliance Officer · FinTech Firm

The DTEF assessment gave our board something they'd never had, a structured, evidence-based view of our digital trust posture that we could actually report to regulators and present to investors.

O
Oluwaseun B.
Head of IT Governance · Insurance Group

SAC filed our CAR and we passed the NDPC inspection. What set them apart was that they explained every obligation, what we owed as evidence, and why. That level of transparency builds real trust.

C
Chidi N.
General Counsel · Public Agency
Institutional Credentials

Recognised. Certified. Trusted.

Every credential is verifiable with its issuing body. SAC publishes reference numbers because claims without verifiable anchors are not evidence, and evidence is what this firm is built to produce.

NDPC · Nigeria
Licensed Data Protection Compliance Organization
NDPC-Licensed DPCO

Authorizes delivery of data protection advisory, audit, and CAR filing under Section 33 of the NDPA 2023.

IIM Africa · NDPC
NDPC / IIM Accredited Training Organization

Accredited to deliver and certify the IIM Certified Data Protection Officer (CDPO) programme. Graduates verifiable with IIM Africa.

ISACA · International
ISACA DTEF Certified Facilitator
Nigeria's Only DTEF Certified Facilitator

Authorized to assess digital trust maturity across all seven DTEF domains, the only such certified facilitator in Nigeria.

ICAN · Nigeria
FCA, Fellow, Institute of Chartered Accountants of Nigeria
ICAN · FRCN Registered

Financial advisory practice led by FCA principals registered with the Financial Reporting Council of Nigeria.

ISACA · International
CISA, Certified Information Systems Auditor
ISACA Certified

Principal-level CISA credential authorizing IS audit, assurance, and governance engagements, verifiable with ISACA International.

ISACA · International
CDPSE, Certified Data Privacy Solutions Engineer
ISACA Certified

Privacy solutions engineering credential applied to NDPA technical compliance architecture and data protection system design.

Verify all credentials →
Free Resource

Assess Your Compliance Readiness.

Download the NDPA/GAID Compliance Readiness Checklist, a structured, NDPC-aligned framework covering all principal compliance obligations for data controllers and processors in Nigeria.

Free Download · PDF
NDPA/GAID Compliance Readiness Checklist

All principal NDPA and GAID obligations mapped against the NDPC audit framework, DCPMI registration, RoPA, DPIA, DPO designation, breach response, CAR filing, and board governance. Formatted for DPO functions and compliance teams.

PDF · 2 pages · Free · NDPC-aligned · Updated April 2026
Get your free checklist.

Your data is handled in accordance with the SAC Privacy Policy. It will not be shared with third parties.

Book a Consultation

Ready to Begin Your
Compliance Journey?

A 20-minute conversation with a named SAC principal, not a sales call. Substantive diagnostic expertise on your compliance position and what it requires.

20 minutes · No screening Named SAC principal No obligation · Genuine diagnostic
NDPC-Licensed DPCO · NDPC-Licensed DPCO IIM Accredited ATO · ISACA DTEF Certified Facilitator