The NDPA 2023 for the CDPO Exam: The Law the Exam Actually Tests
The CDPO exam is anchored to the Nigeria Data Protection Act 2023. Candidates should be able to apply its processing principles, lawful bases, consent rules, data subject rights, controller/process...
The CDPO exam is anchored to the Nigeria Data Protection Act 2023. Candidates should be able to apply its processing principles, lawful bases, consent rules, data subject rights, controller/processor duties, DPIA requirements, DPO responsibilities, breach-notification rules and cross-border transfer framework. The exam turns those obligations into decisions rather than asking for abstract legal commentary.
The NDPA is not a long statute by the standards of major regulatory frameworks. It is still easy to study badly.
One weak method is to memorise section numbers in order. Another is to read explanatory articles until the language feels familiar. Both can create recognition without decision-making ability.
The CDPO exam sits in the gap between those two things.
You need enough statutory knowledge to know the rule, then enough operational judgement to know what the rule requires when a scenario gives you incomplete facts, competing interests and several plausible actions.
Which parts of the NDPA 2023 matter most for the CDPO exam?
The official IIM blueprint does not publish a section-by-section exam list, so no independent prep provider should pretend to know a hidden weighting by statutory section.
What we can do is map the Act's core obligations to IIM's five published domains.
| NDPA area | Key provision | Why it matters in exam scenarios |
|---|---|---|
| Processing principles | Section 24 | Tests fairness, purpose limitation, minimisation, retention, accuracy, security and accountability |
| Lawful bases | Section 25 | Tests whether the organisation has the correct legal ground for processing |
| Consent | Section 26 | Tests whether consent is valid, informed, affirmative and withdrawable |
| Transparency | Section 27 | Tests what the data subject must be told before direct collection |
| DPIA | Section 28 | Tests high-risk processing, timing, necessity, proportionality and residual risk |
| Controller/processor duties | Section 29 | Tests processor governance, written agreements and accountability |
| DPO | Section 32 | Tests who must appoint a DPO and what the DPO does |
| Data subject rights | Sections 34-38 | Tests access, rectification, erasure/restriction, objection/automated decisions and portability |
| Personal data breaches | Section 40 | Tests processor-to-controller notice, 72-hour NDPC notification and high-risk communication |
| Cross-border transfers | Sections 41-43 | Tests transfer bases, adequacy and permitted conditions |
You do not need to recite that table from memory to answer every question. You do need to understand the logic behind it.
What does Section 24 of the NDPA test?
Section 24 sets the principles that govern personal data processing.
The practical version is straightforward: even if you have a lawful basis, you can still process data badly.
A company may have a legitimate reason to collect customer data and still violate the Act if it collects far more information than needed, retains it indefinitely, uses it for an incompatible purpose or fails to protect it properly.
For exam purposes, learn to spot the principle from the facts.
If the scenario says an employer collects personal information "just in case it becomes useful later," think purpose limitation and data minimisation.
If a company keeps former-customer identity documents with no defined need or retention rule, think storage limitation and accountability.
If a database contains known inaccuracies that the organisation does not correct, think accuracy.
The exam is unlikely to help you by naming the principle in the question stem.
What lawful bases should you know under Section 25?
The NDPA recognises six lawful bases:
- consent;
- contract;
- legal obligation;
- vital interests;
- public interest or official authority; and
- legitimate interests.
The common exam error is treating consent as the default.
It is not.
If processing is necessary to perform a contract with the data subject, contract may be the correct basis. If a law requires the processing, legal obligation may be the correct basis. If the controller relies on legitimate interests, the rights and reasonable expectations of the data subject become part of the analysis.
The useful question is always: why is this processing necessary?
What does the NDPA require for valid consent?
Section 26 is more exacting than "the data subject clicked agree."
The controller bears the burden of proving consent. Silence or inactivity does not constitute consent. A request must use clear and simple language. Consent must be affirmative rather than based on a pre-selected confirmation, and a person should be told of the right to withdraw consent before giving it.
This produces obvious scenario traps.
A pre-ticked marketing box is not rescued by the fact that the customer failed to untick it.
A company should not make a service conditional on consent to unrelated processing merely because it wants a convenient legal basis.
And withdrawal does not retroactively make earlier lawful processing unlawful; it changes what happens going forward where consent was the basis.
When is a DPIA required under Section 28?
Before processing that is likely to create high risk to the rights and freedoms of a data subject.
The statutory trigger turns on the nature, scope, context and purposes of the processing.
The DPIA should include:
- a systematic description of the proposed processing and purpose;
- an assessment of necessity and proportionality;
- an assessment of risks to individuals; and
- the measures, safeguards and security controls intended to address those risks.
If high risk remains despite the proposed measures, the controller should consult the Commission before processing.
The timing is exam-relevant: the DPIA comes before the high-risk processing. A privacy assessment completed after launch may be useful remediation, but it does not satisfy the logic of prior risk assessment.
The NDPC's General Application and Implementation Directive 2025 adds more operational detail, including Schedule 4 guidance on DPIAs.
What should you know about controllers and processors?
Section 29 makes outsourcing a poor excuse for losing control of compliance.
Where a controller engages a processor, or a processor engages another processor, the engaging party must ensure the processor meets applicable obligations, supports data subject rights, implements appropriate security and provides information needed to demonstrate compliance.
The measures include a written agreement.
A classic scenario therefore asks what happens when a vendor processes customer data "on behalf of" a company. The answer is not that the vendor now owns the privacy risk. Controller accountability continues.
What does the NDPA say about Data Protection Officers?
Section 32 requires a data controller of major importance to designate a Data Protection Officer with expert knowledge of data protection law and practice.
The DPO may be an employee or engaged under a service contract.
The statutory tasks include:
- advising the controller or processor and staff;
- monitoring compliance with the Act and related policies; and
- acting as a contact point for the NDPC on processing issues.
Do not confuse the DPO with the person who owns every business decision involving personal data. The DPO advises, monitors and provides oversight. Accountability remains organisational.
Which data subject rights matter for the exam?
Sections 34-38 cover a substantial rights framework.
Candidates should understand, at a practical level, rights relating to:
- information and access;
- rectification;
- erasure in applicable circumstances;
- restriction and objection;
- automated decision-making protections;
- withdrawal of consent; and
- data portability.
A rights question often turns on the response the controller should make, not on naming the right.
If a data subject asks what data is being processed, why, who receives it and how long it is kept, recognise the access and transparency framework rather than treating the request as a customer-service complaint.
What are the breach-notification rules under Section 40?
Section 40 separates processor and controller obligations.
A processor that becomes aware of a personal data breach must notify the controller or processor that engaged it and provide relevant information.
A controller must notify the NDPC within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals.
Where the breach is likely to result in a high risk to a data subject, the controller must also communicate the breach to the affected data subject, subject to the statutory framework.
Do not reduce the topic to "72 hours." The threshold and the party responsible are equally examinable.
How do cross-border transfers work under the NDPA?
Section 41 begins with a prohibition: personal data should not be transferred from Nigeria to another country unless the statutory conditions are met.
The recipient may be protected by mechanisms such as an applicable law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism that provides adequate protection. Section 43 also provides conditions that can support a transfer in specified circumstances.
The controller or processor must record the basis for the transfer and the adequacy of protection.
The GAID 2025 provides further guidance around adequacy and cross-border transfer instruments.
For exam purposes, avoid the oversimplified rule that "using a foreign cloud provider is illegal." The legal question is whether the transfer has a valid basis and adequate safeguards.
Does the CDPO exam test the GAID 2025 as well as the NDPA?
IIM's public certification page identifies the NDPA 2023 as a core study resource and does not, on the page reviewed for this article, publish a separate GAID exam weighting.
However, the legal environment candidates now operate in includes the NDP Act General Application and Implementation Directive 2025, issued by the NDPC to operationalise the Act. The NDPC states that the GAID took effect on 19 September 2025.
So the sensible preparation position in 2026 is:
- know the Act as the legal foundation;
- use the GAID to understand how the NDPC operationalises key obligations; and
- check the current IIM training and candidate materials for the exact scope of your sitting.
That is stronger than assuming the exam froze in 2023.
How should you study the NDPA for scenario questions?
Use a three-layer method.
Layer 1: Know the rule
Read the actual statutory provision, not only a summary.
Layer 2: Translate it into an operational question
For Section 28: "Would this processing likely create high risk, and have we assessed it before launch?"
For Section 40: "Who discovered the breach, what is the risk threshold, and who must be told by when?"
Layer 3: Test it with facts that change
Change one fact in the scenario and see whether the answer changes.
If a transfer recipient has approved contractual safeguards, does your conclusion change? If consent is withdrawn, what happens to future processing? If a breach is unlikely to create risk, does the 72-hour NDPC notification rule operate the same way?
That is how statutory knowledge becomes exam judgement.
See NDPA-mapped CDPO questions.
Continue in this guide
- the complete guide to the IIM CDPO certification
- the CDPO exam domains D1-D5
- how to prepare for the CDPO exam
Frequently Asked Questions
Is the NDPA 2023 the main law for the IIM CDPO exam?
Yes. IIM states that its CDPO certification is designed around compliance with the Nigeria Data Protection Act 2023 and lists the Act among its recommended study resources.
What are the six lawful bases under the NDPA?
Consent, contract, legal obligation, vital interests, public interest or official authority, and legitimate interests.
What is the NDPA breach-notification deadline?
A controller must notify the NDPC within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals.
When is a DPIA required in Nigeria?
Section 28 requires a DPIA before processing likely to result in high risk to a data subject's rights and freedoms because of the processing's nature, scope, context or purposes.
Does the NDPA allow cross-border data transfers?
Yes, where the statutory conditions and safeguards are satisfied. The Act requires a valid basis for transfer and documentation of the protection available to the recipient.
Should I memorise every NDPA section number for CDPO?
Section numbers are useful anchors, but applied understanding is more important. You should be able to identify the obligation from a scenario even when the question does not name the section.
Sources checked
- Nigeria Data Protection Commission, Nigeria Data Protection Act 2023.
- Nigeria Data Protection Commission, NDP Act — General Application and Implementation Directive 2025.
- Nigeria Data Protection Commission, 2026 journal explanation of the GAID and its 19 September 2025 effective date.
- Institute of Information Management, IIM CDPO Certification.
This article is exam-preparation guidance, not legal advice. For live compliance decisions, use the current Act, NDPC instruments and professional advice appropriate to the facts.
Frequently Asked Questions
Is the NDPA 2023 the main law for the IIM CDPO exam?
Yes. IIM states that its CDPO certification is designed around compliance with the Nigeria Data Protection Act 2023 and lists the Act among its recommended study resources.
What are the six lawful bases under the NDPA?
Consent, contract, legal obligation, vital interests, public interest or official authority, and legitimate interests.
What is the NDPA breach-notification deadline?
A controller must notify the NDPC within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals.
When is a DPIA required in Nigeria?
Section 28 requires a DPIA before processing likely to result in high risk to a data subject's rights and freedoms because of the processing's nature, scope, context or purposes.
Does the NDPA allow cross-border data transfers?
Yes, where the statutory conditions and safeguards are satisfied. The Act requires a valid basis for transfer and documentation of the protection available to the recipient.
Should I memorise every NDPA section number for CDPO?
Section numbers are useful anchors, but applied understanding is more important. You should be able to identify the obligation from a scenario even when the question does not name the section.
Keep building exam readiness
If this article helped clarify the path, the next step is to turn insight into practice. Explore the platform, choose your exam track, and start preparing with structure.
