Lutheran World Relief (LWR) is a member of Corus International. Corus International combines over 150 years of experience of our non-profit and for-profit subsidiary organizations - IMA World Health, Lutheran World Relief, CGA Technologies, Ground Up Investing, and Farmers Market Brands.
Applications are invited for:
Title: Request for Proposal - Request for the Service of Data Privacy Compliance Organization (DPCO)
Location: Nigeria
Objective
The objective of this engagement is to secure the services of a licensed Data Protection Compliance Organization (DPCO) that will support [Organization] in achieving and sustaining compliance with the Nigeria Data Protection Act (NDPA) 2023 and the General Application and Implementation Directive (GAID) 2025.
The selected DPCO shall:
Ensure compliance with all obligations of a Data Controller/Processor as stipulated under the NDPA and GAID.
Safeguard the rights of data subjects, including access, correction, erasure, objection, and portability.
Support the organization in fulfilling registration requirements with the Nigeria Data Protection Commission (NDPC), where applicable, particularly as a Data Controller/Processor of Major Importance.
Establish and implement data protection policies, frameworks, and operational controls aligned with NDPA principles.
Strengthen technical and organizational measures for the confidentiality, integrity, and availability of personal data.
Provide advisory and operational support on incident response and breach notification in line with statutory timelines.
Build capacity of staff and management through training and awareness to embed a culture of compliance.
Ensure that all cross-border transfers of personal data comply with NDPA and GAID requirements.
Conduct periodic compliance audits, reporting, and monitoring to ensure continuous adherence to the Act.
Serve as liaison between [Organization] and the NDPC, supporting regulatory interactions and inspections.
Deliverables / Commodity list with specifications
The DPCO will be expected to deliver the following outputs in line with the approved Scope of Work and Level of Effort (LoE):
Inception Report and NDPC Registration Documentation – A comprehensive inception report outlining the project workplan, methodology, level of effort schedule, and evidence of NDPC registration or facilitation of [Organization]’s DCPMI registration.
Data Mapping and Compliance Gap Assessment Report – A detailed documentation of personal data flows, processing systems, data subjects, and identification of compliance gaps against NDPA and GAID standards.
Comprehensive Data Protection Policy Pack – Development or update of organizational data protection policies including Privacy Notice, Data Retention Policy, Data Sharing/Processing Agreement templates, Consent Management Procedure, and Breach Response Policy.
Data Protection Officer (DPO) Appointment and Role Integration Report – Guidance on the appointment or designation of a Data Protection Officer, including clear terms of reference, reporting lines, and compliance functions.
Data Protection Impact Assessment (DPIA) Report – DPIAs conducted for high-risk data processing operations, detailing risks, mitigation measures, and where necessary, summary of NDPC consultation.
IT and Organizational Security Review Report – Evaluation of technical and organizational data security measures with specific recommendations for access control, encryption, data backup, and incident response improvements.
Data Subject Access Rights (DSAR) and Breach Response Toolkit – Tools and procedures for handling data subject requests (access, correction, deletion) and breach notifications in compliance with NDPA timelines.
Cross-Border Data Transfer Assessment – Documentation of existing or potential international data flows and establishment of lawful transfer mechanisms in line with NDPA provisions.
Capacity Building and Awareness Materials – Training programs for management and operational staff, including delivery of workshop sessions and training manuals to strengthen internal data protection awareness.
Quarterly Compliance Audit and Monitoring Report – A final audit report detailing organizational compliance status, remediation progress, and recommendations for continuous monitoring and improvement.
Preferred Qualifications and Competences
Institutional Qualifications:
Licensed DPCO accredited by the Nigeria Data Protection Commission (NDPC).
At least five (5) years of experience in data protection, privacy compliance, or digital governance advisory.
Demonstrated experience in large-scale data system compliance within agriculture, financial services, or the public sector.
Proven capacity to conduct privacy audits, DPIAs, and compliance certifications.
Technical Competences:
Expertise in NDPR, NDPA, GDPR, and international data privacy frameworks.
Experience with traceability systems, supply chain databases, or agricultural data systems.
Proficiency in developing and auditing data privacy frameworks for cloud-based and geospatial systems.
Demonstrated understanding of data sovereignty, cross-border data transfers, and digital identity systems.
Team Composition:
Lead Data Protection Specialist (Team Lead) – Minimum 10 years’ experience, certified NDPR/GDPR professional.
ICT/Data Governance Expert – Background in data architecture, cybersecurity, and database management.
Legal/Regulatory Compliance Expert – Experience drafting and reviewing privacy policies, data sharing agreements, and legal frameworks.
Training and Capacity Development Specialist – Experienced in data protection training and institutional awareness creation.
Audit and Monitoring Specialist – Skilled in compliance assessments, risk evaluation, and corrective action planning.
Application Closing Date
15th December, 2025.
How to Apply
Interested and qualified candidates or a consultancy firm should send their Technical Proposal to: nigeriaprocurement@corusinternational.orgusing "Technical Proposal for Data Privacy Compliance Organization" as the subject of the mail.
Note
Kindly see the link below for the full RFP: CLICK HERE