What the document is
"Data protection compliance" is not one document. It is a small file of evidence that your business has mapped how it handles personal data against the specific law that applies to you, and that a regulator or an investor's lawyer can open that file and check your practice against your claims.
This is different from a privacy policy, and founders conflate the two constantly. A privacy policy is the public-facing promise: it tells a user what data you collect, why, and who you share it with. Data protection compliance is the internal proof that the promise is true. It typically includes:
- A record of processing activities (ROPA), sometimes called a data inventory or data map: what personal data you collect, where it lives, which system processes it, how long you keep it, and who it moves to (payment processors, cloud hosts, analytics tools, HR software).
- A Data Protection Officer (DPO) or Data Protection Compliance Officer (DPCO) appointment, or documented evidence that you assessed whether you need one and decided you don't, with the reasoning kept on file.
- A breach notification procedure: who gets told internally, how fast, and how the regulator and affected users get notified, with named roles and timelines rather than a vague sentence.
- Cross-border transfer documentation: if any of your data (customer records, payroll, analytics) leaves the country it was collected in, whether that's to a US cloud provider or a parent company abroad, you need a lawful basis for that transfer on file: standard contractual clauses, an adequacy finding, or documented consent.
- A registration or notification filing with the relevant data protection authority, where the law requires it (most of the jurisdictions below do, above certain thresholds).
Terminology shifts by jurisdiction, and this trips founders up when they read US or UK material and assume it maps directly. Nigeria and Kenya both use "Data Protection Compliance Officer" or "DPO" language. South Africa's Protection of Personal Information Act (POPIA) uses "Information Officer," a role every company automatically has by default (usually the CEO, unless someone else is registered) and which must be registered with the Information Regulator. Egypt's Personal Data Protection Law refers to a "Data Protection Officer" and additionally requires a processing licence from the Personal Data Protection Centre for certain activities, which is a heavier requirement than registration alone. What a UK GDPR document calls a "Privacy Notice," most African frameworks call a "Privacy Policy" or "Data Protection Notice," same function, different label.
A real, complete file looks unglamorous: a spreadsheet or Notion doc mapping data flows, a one-page appointment letter for the DPO/Information Officer, a filed registration certificate or reference number from the regulator, and a short breach procedure. None of this needs to be elaborate. It needs to be accurate and it needs to exist before someone asks for it.
What an investor is actually checking for
When a diligence lawyer at Series A (or the CFO doing a light pre-acquisition review) opens your data protection file, they are not reading it for tone. They are checking whether it can survive an audit, because an investor who puts money into your company inherits your regulatory exposure the day the round closes.
Here is what they specifically look for, and the failure modes that get flagged:
Does the registration exist and match the entity that's raising. If your NDPC or ODPC registration is under a different legal entity than the one issuing shares (a common gap when founders restructure into a holding company for the round), that's an immediate red flag because it means the entity being invested in has no filed registration at all.
Does the privacy policy match the ROPA. A policy that says "we may share your data with partners" with no defined partner list cannot be checked against your actual data flows, so a lawyer treats it as unverifiable rather than compliant. They will ask for the list of every third party that touches customer data, and if that list doesn't match what the policy discloses, the gap itself is the finding, not just the missing document.
Is there a named, reachable person for the DPO/Information Officer role, not "our legal team" or a role that's been vacant since a hire left. Diligence lawyers will sometimes email the listed DPO contact directly to see if it bounces.
Is there evidence of a lawful basis for cross-border transfer, specifically if you use US-hosted infrastructure (AWS, Google Cloud, Stripe, most SaaS tools) with African user data. This is the single most common gap Trampoline sees flagged: founders have never thought about it because it doesn't show up anywhere in a product build, but every jurisdiction below regulates it.
Has there been a breach, and was it handled per the documented procedure. If your breach procedure exists on paper but there's no record it was ever tested or followed for a real incident, that's a weaker signal than an SME that never had a written procedure at all but can show it acted correctly by instinct, because it suggests the document is decorative.
Does the DPCO/auditor relationship exist where required. In Nigeria specifically, "major" data controllers and processors (broadly: those processing data on 2,000+ people in a 12-month period, or handling sensitive categories) must engage a licensed DPCO for an annual audit. An investor's lawyer will ask for the last DPCO audit report. No report, no audit relationship, and the company is non-compliant regardless of how good its privacy policy reads.
The pattern across all of these: a diligence lawyer is not grading your intentions. They're checking whether the paper trail lets them reconstruct your actual data flows independently of what you've told them. A policy with no underlying inventory, a DPO with no appointment letter, a cross-border transfer with no lawful basis on file: these are all versions of the same failure, which is a document written for users that has nothing behind it for a regulator.
What it costs to get done properly, by African jurisdiction
Costs below are the best publicly available figures as of July 2026. Regulatory filing fees are usually published and stable; law firm drafting costs vary by scope and are shown as ranges reported by the firms or advisory sites cited. Where a jurisdiction has not published a fee schedule, we say so rather than guess.
| Country | Primary law | Regulator | Registration/filing fee | Typical cost to get compliant | Source |
|---|---|---|---|---|---|
| Nigeria | Nigeria Data Protection Act 2023 (NDPA), preceded by the NDPR | Nigeria Data Protection Commission (NDPC) | ₦25,000 for small businesses (under 40 staff, under ₦50m turnover); ₦100,000 for a regular data controller/processor; ₦250,000 for a "major" controller/processor; free for government/public entities | Full compliance programme (assessment, privacy notice, DPO appointment, NDPC registration, and where required, annual DPCO audit): roughly $5,000–$80,000 depending on size and whether you're a "major" controller subject to annual DPCO audit | NigeriaDataProtection.com, AuditXYZ |
| Kenya | Data Protection Act, 2019 | Office of the Data Protection Commissioner (ODPC) | Tiered by employee count and turnover: KES 4,000 for micro/small (1–50 staff, up to KES 5m turnover); KES 16,000 for medium (51–99 staff, KES 5–50m turnover); KES 40,000 for large (99+ staff, over KES 50m turnover); KES 4,000 flat for public/non-profit entities | Filing fee itself is the main published cost; law firm engagement for the underlying ROPA, policy and DPO appointment is typically negotiated per engagement and not separately published | ODPC official FAQs, ODPC Registration Regulations 2021 |
| South Africa | Protection of Personal Information Act, 2013 (POPIA) | Information Regulator | Information Officer registration is free, done online via the Information Regulator's e-services portal; Section 111 allows the Minister to prescribe further fees but none are currently published for standard registration | No mandatory filing cost. The real spend is on the internal work: PAIA manual, data inventory, breach plan, staff training. Founders can do the base filing themselves; law firm or consultant engagement is where the cost sits and is quoted per scope of work | ClearComply, Information Regulator e-services |
| Egypt | Personal Data Protection Law No. 151 of 2020, with executive regulations issued 2025 and a compliance deadline of 31 October 2026 | Personal Data Protection Centre (PDPC) | Not publicly itemised in a single fee schedule; the law additionally requires a processing licence (not just registration) for certain data operations, which is a materially heavier step than registration alone | Not independently verifiable from public sources at time of writing; firms report engagements are scoped individually given the licence requirement is new. Talk to Egyptian counsel directly rather than budgeting off a public number | Lexology briefing on the 31 Oct 2026 deadline, Baker McKenzie client alert |
| Ghana | Data Protection Act, 2012 (Act 843) | Data Protection Commission (DPC) | Registration is done via the DPC's online portal and fees are set "based on sector classification," but the DPC has not published the actual fee table on its public pages as of this writing | Not independently verifiable from public sources. Contact the DPC directly (info@dataprotection.org.gh) for current fees before budgeting | Ghana DPC registration page, DPC contact |
Two things worth flagging plainly rather than smoothing over. First, Nigeria's DPCO licensing fees (for the auditors who certify "major" controllers, not for the controllers themselves) rose sharply in 2026 to ₦1,000,000 for a new licence and ₦500,000 for renewal, up from ₦50,000 and ₦250–500,000 respectively under the old NDPR regime, according to reporting by TheNigeriaLawyer. That cost gets passed through to any Nigerian company that needs a DPCO audit, so if you're a "major" data controller in Nigeria, budget for that pass-through even though it's not your fee directly. Second, Egypt and Ghana simply do not have clean public fee schedules the way Nigeria and Kenya do. If a template or blog post gives you a specific naira-equivalent number for either country without citing the regulator, treat it as unverified.
Where to get it
Start with the regulator, not a template site. Every jurisdiction above has an official registration portal, and registering there is the one step you cannot outsource to a template:
- Nigeria: Nigeria Data Protection Commission (NDPC) portal for data controller/processor registration.
- Kenya: Office of the Data Protection Commissioner (ODPC) registration guidance and portal.
- South Africa: Information Regulator e-services portal for Information Officer registration, which is free and self-serve.
- Egypt: Personal Data Protection Centre (PDPC); consult Egyptian counsel given the licence requirement is new and the compliance deadline is 31 October 2026.
- Ghana: Data Protection Commission registration portal, or contact the DPC directly for the current fee schedule.
For the underlying document (ROPA template, breach procedure, DPO appointment letter), your fastest and safest route is a local law firm with a published data protection practice, not a generic downloadable template. We are not naming specific firm price lists here because published rates change and we'd rather point you to primary sources you can verify live than repeat a number that's gone stale: search "[your country] data protection law firm" and look for a firm with a named data protection or privacy practice group, not a generalist commercial firm doing it as a side service.
On using foreign templates: don't, without a local lawyer's pass. This matters more for data protection than almost any other founder document, because the substance of the document (what counts as personal data, what a lawful basis is, what a breach notification window is) is genuinely different by statute, not just cosmetically different. A GDPR-drafted privacy policy will reference rights (like the right to be forgotten under specific EU articles) that may not exist in the same form under Kenya's DPA 2019 or Ghana's Act 843, and a policy that cites the wrong law is worse than no policy, because it signals to a diligence lawyer that the document was never actually reviewed against the applicable statute.
The same caution applies, for a different reason, to using US-market documents like YC's SAFE or the Series Seed docs as your data protection paperwork's neighbour in a deal. Those instruments are genuinely open: YC publishes the SAFE for free download with versions for the US, Canada, the Cayman Islands and Singapore, and explicitly tells users to "consult with a lawyer licensed in the country where your company was formed" before using them, and the Series Seed documents are published as open source on GitHub. Neither publishes a version drafted for an African-registered entity, and neither addresses data protection at all, that's a separate document. The risk of using an unadapted Delaware instrument doesn't show up at signing, it shows up later: in diligence, when a lawyer notices the governing law clause doesn't match your entity's jurisdiction, or in a dispute, when a term that assumes Delaware corporate law doesn't have a clean equivalent under your actual company law. Use the open templates as a reference for structure, then have local counsel adapt the substance. That's a smaller bill than the one you get from a lawyer untangling a mismatched instrument after money has already moved.
Sources
- https://nigeriadataprotection.com/dpo-registration-cost-and-requirements-in-nigeria-2026/
- https://www.auditxyz.com/frameworks/privacy-data-protection/ndpa
- https://thenigerialawyer.com/ndpc-jacks-up-new-dpco-license-fees-to-n1m-renewal-to-n500000/
- https://www.odpc.go.ke/faqs/
- https://www.odpc.go.ke/wp-content/uploads/2024/03/THE-DATA-PROTECTION-REGISTRATION-OF-DATA-CONTROLLERS-AND-DATA-PROCESSORS-REGULATIONS-2021.pdf
- https://www.clearcomply.co.za/blog/popia-information-officer-registration-south-africa
- https://eservices.inforegulator.org.za/services.aspx
- https://www.lexology.com/library/detail.aspx?g=334b6157-bbeb-474d-ba67-11140e89cc07
- https://www.bakermckenzie.com/-/media/files/insight/publications/2026/01/egypt--important-data-protection-update.pdf
- https://dataprotection.org.gh/registration/
- https://dataprotection.org.gh/
- https://ndpc.gov.ng
- https://www.odpc.go.ke
- https://app.dataprotection.org.gh/en/register/
- https://www.ycombinator.com/documents
- https://github.com/seriesseed/equity