FREE LEARNING PATH · DATA PROTECTION

Become a stronger data protection professional.

A complete 30-day study path through the Nigeria Data Protection Act—practical lessons, scenarios and self-checks, open to everyone.

TrustStack Academy CDPO study badge: free 30-day data protection learning pathA study-path badge, not a professional certification
30complete study days
Freeno sign-in or payment
Practicediagnostics and model answers
Self-pacedprogress saved in this browser
ABOUT THIS FREE COURSE

Learn the law. Practise the decisions.

This free course adapts the supplied 30-day CDPO tutor handbook into a readable, interactive learning path. Work through each day, try the questions before revealing the model responses, and apply the ideas to realistic Nigerian workplace scenarios.

How to use the handbook and view the full roadmap

This handbook converts the uploaded 30-day plan into a structured tutor programme. Each study day begins with diagnostics, supplies model responses for advance learning, explains the assigned provisions, and ends with revision and workplace application activities.

Read the assigned provisions before the lesson.

Attempt each question before consulting its model response.

Cite the relevant section in every legal answer.

Record weak topics and revisit them through spaced repetition.

Complete the cumulative assessment after every five days.

Treat the Act as primary authority. The Guide organises study and professional practice. Tutor explanations are labelled as interpretations or practical inferences.

SOURCE LIMITATION: Where the two uploaded PDFs do not resolve a detail, this handbook identifies the limitation. It does not invent legal requirements, regulatory directions or authorities.

Source and Citation Convention

LabelMeaningHow it is used
ActNigeria Data Protection Act 2023Primary legal requirements, conditions, powers, rights and definitions.
GuideComprehensive CDPO Study GuideStudy sequence, summaries, workflows, templates and professional-practice guidance.
Tutor explanationReasoned explanation grounded in the two sourcesHelps apply provisions to facts. It is not represented as additional law.

Complete 30-Day Roadmap

DayTopicActExpected outcome
1Orientation and Act MapLong title, arrangement of sections and s.1Explain and apply purpose, 12 Parts and 66 sections, objectives, Act navigation, source hierarchy.
2Scope and Exemptionsss.2-3Explain and apply territorial application, controllers and processors, processing in Nigeria, data subjects in Nigeria, precise exemptions.
3The Regulatorss.4-7Explain and apply establishment of the Commission, functions, powers, independence, regulatory authority.
4Governance of the Commissionss.8-18Explain and apply Governing Council, appointments and tenure, conflicts of interest, National Commissioner, staff and pension.
5Finance, Audit and Reviewss.19-23Explain and apply funds and expenditure, borrowing and gifts, accounts and audit, annual reports, institutional accountability.
6Processing Principless.24Explain and apply lawfulness fairness transparency, purpose limitation, data minimisation, accuracy and storage limitation, security accountability and duty of care.
7Lawful Basess.25Explain and apply consent, contract, legal obligation, vital interests, public task and legitimate interests.
8Consents.26Explain and apply proof of consent, freely given choice, affirmative action, clear language, withdrawal and inappropriate consent.
9Transparency and Privacy Noticess.27Explain and apply controller identity, purposes and lawful basis, recipients and retention, rights and complaints, automated decisions and profiling.
10Data Privacy Impact Assessments.28Explain and apply high-risk screening, necessity and proportionality, risks to rights, mitigation and residual risk, prior consultation.
11Controller and Processor Obligationss.29 and s.65Explain and apply role classification, capable processor selection, written instructions and agreement, subprocessors, assistance security and evidence.
12Sensitive Personal Datas.30 and s.65Explain and apply sensitive-data identification, general prohibition, special processing grounds, safeguards, two-layer legal analysis.
13Children and Persons Lacking Capacitys.31 and s.65Explain and apply parent or guardian consent, age and authority verification, statutory exceptions, electronic information services, Child Rights Act safeguard.
14Data Protection Officer Functionss.32-33Explain and apply designation by controllers of major importance, knowledge and position, advice and monitoring, regulatory contact, licensed compliance services.
15Data-Subject Rights Is.34Explain and apply confirmation and access, processing information, copies, correction, erasure and transfer information.
16Data-Subject Rights IIss.35-36Explain and apply withdrawal of consent, effect on future processing, right to object, direct marketing, documented response workflow.
17Automated Decision-Makings.37Explain and apply solely automated processing, legal or significant effects, profiling, exceptions, safeguards and challenge mechanisms.
18Data Portabilitys.38Explain and apply qualifying automated processing, consent or contract basis, structured machine-readable format, direct transmission, technical feasibility and others rights.
19Security, Integrity and Confidentialitys.39Explain and apply risk-based security, technical controls, organisational controls, resilience restoration and testing, vendor physical and staff controls.
20Personal Data Breachess.40Explain and apply breach identification, processor notification, controller risk assessment, 72-hour Commission notification, high-risk communication and records.
21Cross-Border Transfers Iss.41-42Explain and apply transfer identification, adequacy, enforceable rights and redress, independent supervision, transfer records and monitoring.
22Cross-Border Transfers IIs.43Explain and apply informed consent, contract necessity, sole benefit, important public interest, legal claims and vital interests.
23Registration and Feesss.44-45 and s.65Explain and apply major-importance status, registration timing, registration information, significant changes, fees levies and evidence pack.
24Complaints and Investigationss.46Explain and apply data-subject complaint, Commission-initiated investigation, attendance and information, documents and electronic material, investigation response.
25Compliance and Enforcement Ordersss.47-48Explain and apply warnings and compliance requirements, cease-and-desist, written-order contents, remedies compensation and profit accounting, penalty ceilings.
26Offences, Remedies and Liabilityss.49-53Explain and apply failure to obey an order, judicial review, civil damages, forfeiture, corporate and vicarious liability.
27Legal Proceedings and Enforcement Powersss.54-59Explain and apply limitation and pre-action rules, service of documents, execution against Commission property, indemnity, arrest search seizure and court appearance.
28Miscellaneous and Interpretationss.60-66Explain and apply ministerial policy directions, regulations codes and guidelines, priority of the Act, transition, definitions and citation.
29The 90-Day Compliance ProgrammeWhole ActExplain and apply days 1-30 priorities, days 31-60 implementation, days 61-90 remediation, governance evidence, dashboard and management reporting.
30Final Assessment and Teaching DemonstrationWhole ActExplain and apply integrated legal analysis, objective testing, short-answer technique, scenario analysis, practical implementation and teaching.

Roadmap source: Guide, pages 2-4, Act Map and 30-Day Study Plan.

Table of Contents

Days 1-15Days 16-30 and assessment
Day 1 Orientation and Act MapDay 16 Data-Subject Rights II
Day 2 Scope and ExemptionsDay 17 Automated Decision-Making
Day 3 The RegulatorDay 18 Data Portability
Day 4 Governance of the CommissionDay 19 Security, Integrity and Confidentiality
Day 5 Finance, Audit and ReviewDay 20 Personal Data Breaches
Day 6 Processing PrinciplesDay 21 Cross-Border Transfers I
Day 7 Lawful BasesDay 22 Cross-Border Transfers II
Day 8 ConsentDay 23 Registration and Fees
Day 9 Transparency and Privacy NoticesDay 24 Complaints and Investigations
Day 10 Data Privacy Impact AssessmentDay 25 Compliance and Enforcement Orders
Day 11 Controller and Processor ObligationsDay 26 Offences, Remedies and Liability
Day 12 Sensitive Personal DataDay 27 Legal Proceedings and Enforcement Powers
Day 13 Children and Persons Lacking CapacityDay 28 Miscellaneous and Interpretation
Day 14 Data Protection Officer FunctionDay 29 The 90-Day Compliance Programme
Day 15 Data-Subject Rights IDay 30 Final Assessment and Teaching Demonstration

Final Mock CDPO Examination • Final Evaluation Record • Source Register

LESSON 01 OF 30

Orientation and Act Map

Read the assigned provisions, attempt the diagnostics, then compare your reasoning with the model responses.

Today’s topicOrientation and Act Map
Estimated time60-90 minutes
Primary Act referenceLong title, arrangement of sections and s.1
Guide referenceGuide pp.2-4

Learning Objectives

Explain and apply purpose.

Explain and apply 12 Parts and 66 sections.

Explain and apply objectives.

Explain and apply Act navigation.

Explain and apply source hierarchy.

Diagnostic Assessment

Attempt these questions before reading the model responses.

1. What is the principal compliance issue addressed by Long title, arrangement of sections and s.1?

Show model response

Model response: It is orientation and act map. The analysis should focus on purpose and the connected statutory conditions.

2. Identify two concepts that must be considered when analysing orientation and act map.

Show model response

Model response: Any two of the following are relevant: purpose, 12 Parts and 66 sections, objectives, Act navigation.

3. Why should a DPO cite the exact section instead of relying only on a general privacy principle?

Show model response

Model response: The section contains the controlling conditions, limits and exceptions. A general principle may guide analysis but cannot replace the specific statutory test.

4. What evidence should an organisation retain when applying Long title, arrangement of sections and s.1?

Show model response

Model response: It should retain the facts considered, the statutory test, the decision, supporting records, responsible approval and any review or corrective action.

5. How should the organisation respond when the uploaded sources do not resolve a material detail?

Show model response

Model response: It should record the limitation and avoid inventing a requirement. The DPO should return to the full statutory wording and seek current authoritative material when permitted.

Structured Lesson

LEGAL RULE: The controlling statutory material for this lesson is Long title, arrangement of sections and s.1. Apply its precise language, conditions and exceptions to the facts.

1. Purpose

Purpose is a central issue for this study day. The DPO should locate the exact statutory conditions in Long title, arrangement of sections and s.1, apply them to the particular processing activity and retain evidence supporting the conclusion.

2. 12 Parts And 66 Sections

12 parts and 66 sections is a central issue for this study day. The DPO should locate the exact statutory conditions in Long title, arrangement of sections and s.1, apply them to the particular processing activity and retain evidence supporting the conclusion.

The Guide maps the Act into 12 Parts and 66 sections. This structure lets a DPO move from objectives and scope to the regulator, operational obligations, rights, security, transfers, registration, enforcement and interpretation.

3. Objectives

Objectives is a central issue for this study day. The DPO should locate the exact statutory conditions in Long title, arrangement of sections and s.1, apply them to the particular processing activity and retain evidence supporting the conclusion.

4. Act Navigation

Act navigation is a central issue for this study day. The DPO should locate the exact statutory conditions in Long title, arrangement of sections and s.1, apply them to the particular processing activity and retain evidence supporting the conclusion.

5. Source Hierarchy

Source hierarchy is a central issue for this study day. The DPO should locate the exact statutory conditions in Long title, arrangement of sections and s.1, apply them to the particular processing activity and retain evidence supporting the conclusion.

GUIDE GUIDANCE: The Guide assigns Day 1 to orientation and act map and requires study of Long title, arrangement of sections and s.1. Its practical emphasis is purpose, 12 Parts and 66 sections, objectives.
TUTOR EXPLANATION: Use a five-step analysis: identify the processing facts, confirm the actor and role, locate the controlling section, test every condition and exception, then document the decision and evidence.

Nigerian Scenario and Model Analysis

A Akwa Ibom State ministry begins a project involving staff or customer personal data. The project raises questions about purpose and 12 Parts and 66 sections. Identify the controller, any processor, the data subjects, likely personal data, the required statutory analysis under Long title, arrangement of sections and s.1, key risks and the compliance evidence that should be retained.

Show model response

Model analysis: The organisation determining why and how the project operates is normally the controller. A vendor acting only on documented instructions is normally a processor. Staff or customers are the data subjects. The DPO should inventory the data, apply Long title, arrangement of sections and s.1 to the stated purpose, document the decision, assign controls and retain evidence. The final conclusion depends on the precise facts and statutory conditions.

Lesson Summary

Day 1 establishes how a DPO should understand and apply orientation and act map. The legal starting point is Long title, arrangement of sections and s.1. The main operational lesson is to connect purpose, 12 Parts and 66 sections, objectives to documented facts and evidence.

Ten Key Terms

TermWorking definition
ControllerA person or body that determines the purposes and means of processing personal data.
ProcessorA person or body that processes personal data on behalf of a controller.
Data SubjectThe identified or identifiable individual to whom personal data relate.
Personal DataInformation relating to an identified or identifiable individual.
ProcessingAn operation performed on personal data, including collection, use, storage, disclosure or deletion.
AccountabilityResponsibility for compliance and the ability to demonstrate it with evidence.
Purpose LimitationUsing personal data for specified, explicit and legitimate purposes and controlling further use.
DpoA Data Protection Officer who advises, monitors compliance and acts as a regulatory contact under section 32.
Major ImportanceThe statutory classification relevant to DPO designation, registration and penalty treatment.
Lawful BasisA statutory justification that permits processing under section 25.

Definitions are paraphrased for study. Check section 65 and the relevant operative provision for controlling wording.

Five Revision Questions and Responses

1. What provisions govern this lesson?

Show model response

Response: Long title, arrangement of sections and s.1

2. What are the principal concepts?

Show model response

Response: purpose, 12 Parts and 66 sections, objectives, Act navigation, source hierarchy.

3. What is the correct source hierarchy?

Show model response

Response: The Act is primary authority. The Guide supports learning and professional application. Tutor explanation assists interpretation without creating new law.

4. What is the central evidence requirement?

Show model response

Response: Record the facts, applicable test, conclusion, approval, controls and review trigger.

5. What common error should be avoided?

Show model response

Response: Do not assume a broad principle answers the issue. Test the exact conditions and exceptions in the assigned section.

Five Multiple-Choice Questions

1. Which source provides the primary statutory rule for Day 1?

A. The Guide

B. The Act

C. A workplace policy

D. A vendor contract

2. Which provision set should be consulted first?

A. Section 1 only

B. Long title, arrangement of sections and s.1

C. Section 65 only

D. No statutory provision

3. What should follow identification of the relevant section?

A. Assume compliance

B. Test conditions and exceptions

C. Ignore evidence

D. Use consent automatically

4. Which record best supports accountability?

A. An undocumented opinion

B. A reasoned decision record

C. A verbal assurance

D. A marketing brochure

5. If the sources do not resolve a detail, what should the learner do?

A. Invent a rule

B. State the limitation

C. Cite an unrelated law

D. Ignore the uncertainty

Show model response

Answer key: 1-B, 2-B, 3-B, 4-B, 5-B. Review the lesson citations before marking.

Practical Workplace Task

Prepare a one-page compliance record for a Nigerian organisation applying Long title, arrangement of sections and s.1. Include the processing purpose, actors, data subjects, personal data, statutory test, risks, decision, controls, owner, evidence and review date.

Show model response

Expected deliverable: A dated, approved record that links factual evidence to each applicable statutory condition and records any unresolved issue.

Three Flashcards

Front: Act reference for Day 1? | Back: Long title, arrangement of sections and s.1

Front: Central topic? | Back: Orientation and Act Map

Front: Best analysis habit? | Back: Facts → role → section → conditions → evidence.

Reread and Progress Record

Reread: Long title, arrangement of sections and s.1; Guide pp.2-4.

Date completed________________Score______%
Strong areas________________Weak areas________________
Recommended revision________________ReadinessDeveloping / Competent / Ready