Morrnaire

Morrnaire

Privacy Policy Generator

A privacy policy generator creates a custom privacy policy for your Nigerian business website that complies with the Nigeria Data Protection Regulation (NDPR) and includes required disclosures about data collection, cookies, and user rights.

Business information

Settings

Data collection & features

Sections

Privacy Policy (562 words)

How to generate an NDPR privacy policy for your Nigerian website

Select the NDPR jurisdiction under Settings to generate a policy that complies with the Nigeria Data Protection Regulation 2019 and the Nigeria Data Protection Act 2023, as well as Lagos State data protection guidelines for SaaS platforms operating in the state. Fill in your business name, website URL, email, and Lagos or Abuja address — then toggle the data collection checkboxes to match what your site actually gathers, from customer names to payment details processed through Paystack or Flutterwave. Finally, use the Sections panel to include or exclude parts like cookie policy, data breach notification, and user rights, then export as Markdown or HTML.

When should a privacy policy be used?

Every Nigerian website or app that collects personal data — from a Lagos e-commerce store handling customer addresses to an Abuja fintech processing payments via Paystack — must have a privacy policy. The NITDA guidelines and the FCCPC consumer protection framework require businesses to inform users about what data is collected, how it is used, and who it is shared with. Even a simple blog with a contact form, a Port Harcourt freelancer with a newsletter signup, or a Kano-based agro-business accepting online orders needs one to stay compliant and build trust.

Practical use cases for Nigerian businesses

  • A Lagos-based fashion brand collecting customer names, phone numbers, and delivery addresses for order fulfilment via GTBank payment links — the policy explains how that data is stored and shared with logistics partners like Gokada or Max.ng.
  • An Abuja fintech startup processing payment card details through Paystack and Flutterwave — the policy clarifies PCI compliance, data retention periods, and breach notification procedures under NDPR.
  • A Port Harcourt digital agency using Google Analytics, Meta ads, and Mailchimp for email marketing — the policy discloses cookie usage, third-party tracking, and user opt-out rights.
  • An Ibadan health-tech platform collecting patient medical records — the policy addresses sensitive data handling, consent under NDPR, and retention schedules aligned with NITDA guidelines.
  • An Enugu e-learning platform storing student names, email addresses, and payment histories via Remita — the policy covers data sharing with payment processors, storage duration, and parental consent for minors.
  • A Kano agro-processing company using Moniepoint POS data for customer loyalty tracking — the policy clarifies how transaction data is collected, stored, and protected.

Frequently asked questions

Is a privacy policy legally required in Nigeria?

Yes. The Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act 2023 require any organisation that processes the personal data of Nigerian residents to have a privacy policy. The Lagos State Data Protection Authority also enforces additional guidance for SaaS businesses operating within the state. NITDA can impose fines of up to 2% of annual gross revenue for non-compliance, and the FCCPC may also take action under consumer protection laws.

What is the difference between NDPR, GDPR, and CCPA?

NDPR is Nigeria\u2019s data protection law focused on consent, data minimisation, and breach notification. GDPR applies if you serve EU citizens and requires stronger consent mechanisms. CCPA applies if you collect personal data from California residents and gives them rights to know, delete, and opt out of data sales.

How often should I update my privacy policy?

Update your policy whenever you change how you collect or use data — for example, if you add a new analytics tool, start using customer data for a new purpose, or change your third-party vendors. It is good practice to review it at least once a year even if nothing changes.

Can I use the same policy for my website and my mobile app?

Yes, as long as the policy covers all data collection methods across both platforms. If your app collects additional data types — such as GPS location, device identifiers, USSD codes, or camera access — make sure those are listed in the data collection section of the generated policy. This is especially important if your app integrates with mobile money services like Moniepoint, Paga, or OPay.

Do I need a separate cookie policy?

The generated policy includes a dedicated Cookie Policy section. If you use analytics services like Google Analytics, advertising platforms like Meta Ads, or Nigerian ad networks, that section explains what cookies are used and how users can manage them through browser settings. MTN, Glo, Airtel, and 9mobile subscribers should also be informed about carrier-level tracking where applicable.

More free tools