Skip to main content

Compliance Infrastructure

Compliance Infrastructure for Evidence-Based Governance.

SAC products and platforms help institutions organise, evidence, monitor, and improve their compliance posture across privacy, data protection, audit readiness, and board governance. These are operational instruments — not reference documents.

Excel / Google Sheets Word Templates PDF Checklists Dashboard Frameworks SOPs & Playbooks
Eight Products

Select a product to explore the full specification.

Every product is built to the evidence standard the NDPC's inspection framework applies — not the standard that satisfies internal review. Click any card to see the full problem, contents, audience, and delivery format.

Problem Solved

Organisations attempting to build NDPA compliance from scratch encounter a coordination problem — the privacy policy, DSAR procedure, RoPA, DPIA template, and staff notice must work together as a system. Building them separately, from disparate templates, produces inconsistencies that NDPC inspectors identify immediately. The Privacy Compliance Toolkit provides a coordinated, internally consistent documentation suite structured to the NDPC's audit standard from the outset.

How It Is Used

The Toolkit is used as the foundation layer of an organisation's NDPA compliance programme — either self-implemented by the DPO function or deployed with SAC advisory support. Each document is pre-formatted to the NDPC's documentation standard and pre-populated with Nigerian regulatory references, leaving the organisation to complete the organisation-specific fields rather than build from blank templates.

What It Includes
  • Privacy Policy (NDPA-compliant, customisable)
  • Privacy Notice templates (website, HR, clients)
  • DSAR response procedure and log
  • RoPA master template (NDPC format)
  • DPIA trigger assessment checklist
  • Breach response protocol and register
  • Staff privacy awareness briefing
  • Third-party data sharing log
Who It Is For

DPOs, compliance officers, legal teams, and organisations beginning or restructuring their NDPA compliance programme. Suitable for all sectors. Available with SAC implementation support for accelerated deployment.

Outcome

A complete NDPA documentation foundation — consistent, NDPC-formatted, and ready for use as the basis of the organisation's annual Compliance Audit Return.

Problem Solved

Many organisations cannot prove compliance because evidence is scattered across email folders, SharePoint directories, and individual team members' hard drives — unmapped to any regulatory obligation and inaccessible under time pressure. The Audit Evidence Tracker maps every piece of compliance evidence to its specific NDPA/GAID obligation, records who is responsible, tracks status, and produces a consolidated view that survives an audit or inspection without a pre-inspection scramble.

How It Is Used

The Tracker is used as the DPO's live compliance management instrument — updated continuously as evidence is generated, reviewed, and filed. It serves as the source document for the annual Compliance Audit Return, the input for board quarterly reporting, and the primary exhibit in an NDPC inspection response. It is designed to be maintained by the DPO function, reviewed quarterly, and presented annually to the board and to the DPCO who certifies the CAR filing.

What It Includes
  • Evidence request list (all NDPA obligations)
  • NDPA / GAID obligation-to-evidence mapping
  • Responsible owner field per obligation
  • Evidence status tracker (RAG: Complete / Partial / Missing)
  • Evidence upload reference and location log
  • Management action plan for gaps
  • Audit readiness summary dashboard tab
  • Board reporting extract format
Who It Is For

DPOs, compliance officers, internal auditors, legal teams, and management. Delivered as Excel workbook and Google Sheets version. Compatible with all organisation sizes and sectors.

Outcome

An organisation that is inspection-ready at any point — every compliance obligation tracked, every evidence item located, every gap identified and actioned before the NDPC asks.

Problem Solved

Most DPIAs are completed on templates adapted from UK ICO or EU GDPR formats that do not align with NDPA Section 28 or the NDPC's GAID documentation requirements. The DPIA Builder is structured from the NDPC's own assessment framework — covering necessity and proportionality, risk identification and rating, risk mitigation design, and the sign-off and residual risk documentation that an NDPC inspection requires to see completed before high-risk processing commences.

How It Is Used

The Builder guides the DPO or project team through each stage of the DPIA — from processing description and necessity assessment through risk scoring, mitigation design, and DPO/senior management sign-off. Each section contains instructional text explaining the NDPC's standard for that field, a worked example from a Nigerian regulatory context, and the input field for the organisation's own assessment. Completed DPIAs are stored in the DPIA Register tab.

What It Includes
  • DPIA mandatory trigger assessment tool
  • Processing description framework (NDPC format)
  • Necessity and proportionality assessment
  • Risk identification and scoring matrix
  • Risk mitigation design section
  • Residual risk documentation
  • DPO and senior management sign-off fields
  • DPIA Register (multi-DPIA tracking)
Who It Is For

DPOs, project managers, IT leads, legal officers, and compliance teams managing high-risk processing activities. Works in conjunction with the RoPA Template Pack and Privacy Compliance Toolkit.

Outcome

DPIAs that satisfy NDPA Section 28 and NDPC inspection criteria — completed before high-risk processing commences, documented to the regulatory standard, and stored in a retrievable register.

Problem Solved

Records of Processing Activities built from generic privacy templates are missing the fields the NDPC requires — lawful basis documentation per activity, retention schedule, data subject categories, security measures, and transfer information. The RoPA Template Pack is built to NDPA Section 24 and the GAID's prescribed content standard, covering every field the NDPC expects to see completed when it requests the organisation's processing records.

How It Is Used

The Pack is used by the DPO or compliance officer to conduct a structured processing inventory across the organisation — interviewing department heads, mapping data flows, and populating each activity record with the full required content. The master RoPA tab produces a submission-ready view for CAR filing and NDPC inspection. The department tabs enable distributed completion and review. A guidance sheet explains each field with reference to the relevant NDPA provision and NDPC interpretation.

What It Includes
  • Master RoPA workbook (NDPA Section 24 fields)
  • Processing activity inventory template
  • Lawful basis selection guide (NDPA-specific)
  • Data category classification framework
  • Retention schedule builder
  • Third-party and cross-border transfer fields
  • Department-level completion tabs
  • NDPC-format master export view
Who It Is For

DPOs and compliance officers conducting processing inventories. Available in Excel and Google Sheets. Includes guidance notes with NDPC field-by-field explanations.

Outcome

A complete, NDPC-format RoPA — submission-ready for CAR filing, inspection-ready for NDPC review, and maintainable by the DPO function without external advisory dependency.

Problem Solved

Boards are accountable for NDPA privacy governance but receive compliance information in formats designed for operational teams — spreadsheet reports, email updates, and status lists that do not translate into board-level governance decisions. The Board Privacy Governance Dashboard provides a visual, structured, quarterly-cadence view of the organisation's privacy posture across the NDPA's principal obligations — designed for a board member who needs to understand the posture, identify the gaps, and discharge the governance accountability.

How It Is Used

The DPO updates the Dashboard quarterly using data from the Audit Evidence Tracker and the organisation's compliance programme. The Dashboard produces a one-page board summary with RAG indicators per obligation domain, trend charts showing posture improvement or deterioration, and a management action summary. The board quarterly report appendix is generated directly from the Dashboard and formatted for Audit Committee presentation without further design work.

What It Includes
  • NDPA obligation posture summary (RAG per domain)
  • Compliance trend chart (quarterly)
  • DPO function operational status panel
  • Open management action items summary
  • Incident and DSAR summary panel
  • CAR filing status indicator
  • Board report one-page export
  • Audit Committee presentation template
Who It Is For

DPOs producing board reports, Audit Committees, and board members receiving quarterly privacy governance updates. Delivered as Google Sheets / Excel with PowerPoint summary template.

Outcome

A board that receives structured, visual, quarterly privacy governance reporting — able to identify posture trends, track management action, and evidence board-level oversight to the NDPC.

Problem Solved

Organisations share personal data with vendors without structured data processing agreements, security assessments, or ongoing monitoring frameworks. Under the NDPA, controllers are accountable for what their processors do with data on their behalf — and a vendor breach or misuse becomes the controller's compliance failure. The Vendor Privacy Due Diligence Pack provides the complete framework for assessing, contracting, and monitoring data processors under NDPA Section 29 requirements.

How It Is Used

Used by the DPO or procurement team to assess any vendor who will handle personal data before onboarding, at contract renewal, and on an annual review basis. The Pack includes a Vendor Register for tracking all data-sharing relationships, an Assessment Questionnaire for evaluating vendor privacy and security posture, DPA terms for insertion into vendor contracts, and a monitoring schedule for ongoing oversight.

What It Includes
  • Vendor / data processor register
  • Vendor privacy assessment questionnaire
  • Data Processing Agreement (DPA) terms template
  • Sub-processor notification procedure
  • Security and breach notification requirements
  • Vendor onboarding privacy checklist
  • Annual review schedule and log
  • Risk rating framework per vendor
Who It Is For

DPOs, procurement teams, legal officers, and compliance managers managing vendor relationships involving personal data. Compatible with all sectors and organisation sizes.

Outcome

A compliant vendor data governance framework — every processor assessed, every DPA in place, and every data-sharing relationship monitored against the NDPA's processor accountability standard.

Problem Solved

When a data breach occurs, most organisations discover that their breach response exists only as a policy document — not as an executable playbook. The 72-hour NDPC notification window starts immediately upon discovery, and improvised responses produce late, incomplete, or non-compliant notifications that compound the original breach liability. The Breach Response Pack provides every tool, template, and procedure required to execute a complete NDPA-compliant breach response — before the clock starts.

How It Is Used

The Pack is deployed at the point of incident detection — the Breach Assessment Tool determines severity and notification obligations within minutes; the 72-Hour Timeline Tracker manages the notification clock; the NDPC Notification Template is completed with the assessed breach details and submitted within the mandatory window. Post-breach, the Remediation Log captures all corrective actions for the NDPC follow-up and CAR filing.

What It Includes
  • Breach assessment tool (severity and notification trigger)
  • 72-hour timeline tracker with milestone alerts
  • NDPC breach notification template (Section 40)
  • Data subject notification decision framework
  • Breach register (ongoing incident log)
  • Evidence preservation checklist
  • Remediation log and management action tracker
  • Post-breach review report template
Who It Is For

DPOs, IT security teams, legal counsel, and crisis response leads. Recommended for use alongside SAC's Breach Simulation Lab training for full operational readiness.

Outcome

An organisation that can execute a complete NDPA-compliant breach response within 72 hours — with documented evidence of every step from discovery to NDPC notification to remediation.

Problem Solved

Organisations preparing for their annual Compliance Audit Return filing — which must be certified and submitted by a licensed DPCO — lack the structured preparation framework to assemble the evidence, complete the self-assessment, and present it in a form that supports the DPCO's certification. Inadequate CAR preparation produces filings that the NDPC challenges or that the DPCO cannot certify without substantial rework. The CAR Preparation Pack structures the preparation process to the NDPC's submission standard.

How It Is Used

Used by the DPO function in the weeks before the annual CAR filing cycle — working through the 32-point self-assessment, gathering and tagging evidence against each obligation, completing the management representation sections, and presenting the completed pack to the DPCO (SAC or another licensed DPCO) for review and certification. The Pack reduces the time required for DPCO certification review by ensuring all required components are present and correctly formatted before submission.

What It Includes
  • 32-point NDPC self-assessment workbook
  • Evidence assembly checklist per obligation
  • Management representation statements
  • DPO attestation form
  • Gap identification and remediation log
  • DPCO presentation pack (for certification review)
  • Prior-year comparison tracker
  • Post-filing improvement roadmap
Who It Is For

DPOs and compliance officers preparing for CAR filing. To be used in conjunction with SAC's CAR Filing Service where SAC acts as the certifying and filing DPCO.

Outcome

A CAR-ready evidence pack that supports DPCO certification and NDPC submission — assembled to the NDPC's standard before the filing deadline, not under it.

Toolkit vs Advisory Support

Products operate independently. Advisory support accelerates deployment.

Every SAC product is designed for self-implementation by a competent DPO or compliance officer. For organisations that want faster deployment, sectoral calibration, or external quality assurance, SAC advisory support is available as an add-on to any product.

Capability Toolkit Only With SAC Advisory Support Advisory Engagement Only
NDPA-standard documentation✓ Included✓ Included✓ Built by SAC
Sector calibration● Generic✓ Calibrated✓ Full calibration
Organisational data mapping– Self-conducted✓ SAC-led✓ SAC-led
NDPC quality review– Not included✓ SAC review✓ SAC certifies
DPCO certification for CAR– Separate engagement● Add-on available✓ Included
Board reporting setup● Template included✓ SAC activates✓ Full setup
Deployment timelineDepends on DPO capacityAccelerated — 2–4 weeks30–60 days (full programme)
Appropriate forCapable DPO with timeDPO with advisory supportComplex / regulated organisations

✓ = Fully included   ● = Partially included or available as add-on   – = Not included in this option

Implementation Support

Products are more powerful when deployed by practitioners.

SAC products are designed for self-implementation. For organisations that want the product deployed correctly, calibrated to their sector, and quality-assured by a licensed DPCO — SAC offers implementation support as an add-on to any product purchase.

Implementation support is priced separately from the product and is available as a fixed-scope engagement — ensuring the product is live, populated with the organisation's own data, and validated against the NDPC standard before the support engagement closes.

Request Implementation Support
01
Product setup and population

SAC deploys the product for the organisation — mapping existing data into the templates, calibrating fields to the sector, and validating the output against NDPC requirements. Available for all eight products.

02
Sector calibration

Generic templates adapted to the specific regulatory obligations of the organisation's sector — financial services, public sector, technology, NGO, or healthcare — with sector-specific examples, lawful bases, and retention schedules.

03
DPCO quality review

A licensed DPCO reviews self-completed products before submission or use — identifying gaps, errors, or non-conformities against the NDPC standard and providing a written review report.

04
Bundle: Products + CAR Filing

Products combined with SAC's DPCO-certified CAR filing service — the toolkit is implemented, the DPO is supported through the self-assessment, and SAC certifies and files the CAR with the NDPC as the licensed DPCO of record.

Request Products

Build the compliance infrastructure your organisation needs to operate defensibly.

Request any product, request a bundle with advisory support, or enquire about a custom implementation. SAC responds to all product enquiries within one business day.

NDPC-Licensed DPCO · NDPC/DCP/01784 IIM ATO #d193ed82f32a4eb64 ISACA DTEF Certified Facilitator products@sac.ng