Hiring an Offshore Dev Team from Nigeria or Kenya: NDPA, Kenya DPA, Payments
Founder & Lead Engineer, RAITHub
A Nigerian or Kenyan company can hire an offshore development team in Bangladesh, but giving it customers' personal data is a cross-border transfer: Nigeria's Data Protection Act 2023 governs that in sections 41 to 43, and Kenya's 2021 General Regulations require one of four bases before data leaves Kenya. Lagos shares about 4 working hours with Dhaka and Nairobi about 6, so most collaboration is written.
This guide is for founders, CTOs and operations leads in Nigeria and Kenya weighing an offshore team. RAITHub is a software studio in Dhaka, so we have an interest in the answer; we have no office in Africa and work with you remotely, in English. This is general information, not legal advice. Confirm every point with your adviser and the regulator, the Nigeria Data Protection Commission (NDPC) or Kenya's Office of the Data Protection Commissioner (ODPC), before you sign. The Nigerian sections below are quoted from the text of the Act as passed (Nigeria Data Protection Act, 2023), and the Kenyan points from the regulations published by the ODPC (Data Protection (General) Regulations, 2021), both read on 30 September 2026.
Does Nigeria's NDPA apply when I hire an offshore developer?
Yes, if you are a data controller in Nigeria or you process the personal data of people in Nigeria. Section 2(2) applies the Act where the controller or processor is "domiciled in, resident in, or operating in Nigeria", where processing occurs in Nigeria, or where a controller or processor outside Nigeria is processing the personal data of a data subject in Nigeria.
In most engagements your company is the controller, deciding why and how data is processed, and the offshore team is a processor acting on your instructions. Section 29(1) then puts the duty on you: when you engage a processor, you must ensure it complies with the Act's principles, helps you honour data subjects' rights, implements appropriate technical and organisational security measures, gives you the information you need to demonstrate that it meets the Act, and tells you when it engages another processor. Section 29(2) says those measures include "a written agreement" between you and the processor.
When can personal data leave Nigeria under sections 41 to 43?
When the recipient offers adequate protection, or when one of the section 43 conditions applies. Section 41(1) says a controller or processor "shall not transfer or permit personal data to be transferred from Nigeria to another country" unless:
- (a) the recipient is subject to "a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism that affords an adequate level of protection"; or
- (b) one of the conditions in section 43 applies.
Section 41(2) adds a record-keeping duty: you must record the basis for the transfer and the adequacy of protection. Section 42(1) defines adequate as upholding "principles that are substantially similar" to the Act's conditions for processing, assessed against factors such as enforceable data subject rights, an effective data protection law and an independent supervisory authority (42(2)). Section 42(6) matters for a Bangladesh vendor: the absence of an NDPC determination about a country or a set of contractual clauses "shall not imply the adequacy" of the protection they give. Do not assume a country qualifies because it has not been ruled out.
Section 43(1) lists the fallback conditions where adequacy is absent, including the data subject's consent after being informed of the risks, a transfer necessary for a contract with the data subject, and transfers for legal claims or vital interests. For a development vendor these rarely fit; you cannot practically collect informed transfer consent from every customer so that a contractor can debug your app.
For most companies, the realistic route is section 41(1)(a): contractual clauses with the vendor, with the basis recorded under 41(2). The NDPC's FAQs say an adequate level of protection can be obtained by "obtaining an adequacy decision from the Commission" or by "submitting a Cross Border Data Transfer Instrument to the Commission for approval" (NDPC FAQs). Whether you need to submit your clauses, and in what form, is a question for your adviser; confirm the current rule with them and the NDPC.
What does Kenya's Data Protection Act require before data leaves Kenya?
A documented basis for the transfer. Regulation 40 of the Data Protection (General) Regulations, 2021 says that before transferring personal data out of Kenya, a controller or processor must ascertain that the transfer is based on one of four things: appropriate data protection safeguards, an adequacy decision by the Data Commissioner, necessity, or the data subject's consent.
- Appropriate safeguards (regulation 41). Either a legal instrument binding the recipient that is "essentially equivalent" to the Act and Regulations, or your own assessment of the circumstances concluding that appropriate safeguards exist. A transfer on this basis must be documented, and the documentation must include the date and time of the transfer, the name of the recipient, the justification and a description of the data transferred, and be provided to the Commissioner on request.
- Deemed safeguards (regulation 42). A country is taken to have safeguards if it has ratified the African Union Convention on Cyber Security and Personal Data Protection, has a reciprocal data protection agreement with Kenya, or where binding corporate rules apply. Bangladesh is not an African Union member, so the first route does not apply to a Dhaka team; whether any other route fits your arrangement is for your adviser.
- Consent (regulation 46). Explicit consent after the data subject has been informed of the possible risks. As in Nigeria, this is rarely practical for a whole customer base.
- Onward transfers (regulation 47). You must make it a condition of the transfer that the data is not transferred further without your authorisation. For a vendor, that covers its own subcontractors and tools.
Two more provisions shape an offshore engagement. Regulation 26, made under section 50 of the Act, requires processing for "strategic interest of the state" to go through a server and data centre in Kenya, or to keep at least one serving copy there. Its list includes civil registration, elections, public finance systems, protected computer systems, early childhood and basic education, and primary or secondary health care. If you build for schools or clinics in Kenya, check this before anything else. And regulation 24 sets what the controller-to-processor contract must contain, which is the clause table below. The Act's own transfer provisions are in sections 48 to 50; read them with your adviser, and confirm the current rule with the ODPC.
How do Nigeria's and Kenya's rules compare for an offshore team?
| Question | Nigeria: NDPA 2023 | Kenya: Data Protection Act 2019 and 2021 Regulations |
|---|---|---|
| Regulator | Nigeria Data Protection Commission (NDPC) | Office of the Data Protection Commissioner (ODPC) |
| Basis for a transfer | Adequate protection via law, binding corporate rules, contractual clauses, code or certification (s41(1)(a)), or a s43 condition | Safeguards, adequacy decision, necessity or consent (reg 40) |
| Records to keep | The basis for the transfer and the adequacy of protection (s41(2)) | Date and time, recipient, justification and description of data, for safeguard-based transfers (reg 41(2)) |
| Processor contract | A written agreement is part of the required measures (s29(2)) | A written contract with set particulars (reg 24) |
| Subcontractors | The processor must notify you when it engages another processor (s29(1)(e)) | No third party without your prior authorisation; the processor stays liable for them (reg 25) |
| Breach notice | Processor tells controller on becoming aware (s40(1)); controller notifies the NDPC within 72 hours where there is likely risk (s40(2)) | Section 43 of the Act; notification contents in reg 38. Confirm the timeline with your adviser |
| Data that must stay local | The NDPC may designate categories with extra transfer restrictions (s41(4)) | Strategic-interest processing listed in reg 26 |
| Registration | Data controllers and processors "of major importance" register with the NDPC (s44) | Registration with the ODPC, with an exemption described in its FAQs for turnover below five million shillings and fewer than ten people, except in some sectors |
Penalties are real in both. In Nigeria, section 48(4) and (5) set the ceiling as the greater of NGN 10,000,000 or 2% of annual gross revenue for a controller or processor of major importance, and the greater of NGN 2,000,000 or 2% for others. Sources for the table: the Act and the Kenyan regulations linked above, and the ODPC FAQs for Kenya's registration row.
Which contract clauses should you ask an offshore team for?
The ones both laws point to, plus the commercial clauses a software engagement needs. Kenya's regulation 24 is the more specific list, and meeting it goes a long way towards Nigeria's section 29 as well.
| Clause | Where it comes from | What to ask the vendor for |
|---|---|---|
| Subject matter, duration, nature and purpose, types of data, categories of data subjects | Kenya reg 24(2)(a) | A written scope: which systems, which fields, for which tasks, for how long |
| Act only on your instructions | Kenya reg 24(2)(b); Nigeria s29 | An express obligation, with instructions given in writing |
| Confidentiality commitments from everyone with access | Kenya reg 24(2)(c) | Signed confidentiality terms for each engineer, and a named list of who has access |
| Technical and organisational security measures | Kenya reg 24(2)(d); Nigeria s29(1)(c), s39 | A security schedule with real measures: MFA, least privilege, logging, no production data on laptops |
| Delete or return all data at the end | Kenya reg 24(2)(e) | A written deletion confirmation in the offboarding checklist |
| Audit and inspection | Kenya reg 24(2)(f); Nigeria s29(1)(d) | Willingness to answer questionnaires and show evidence |
| Subprocessors | Kenya reg 25; Nigeria s29(1)(e) | Your approval before any new subprocessor or tool that touches data |
| No onward transfer | Kenya reg 47 | Data not moved to any other country without your authorisation |
| Breach notification | Nigeria s40(1) | Notice within an agreed number of hours, with the facts you need to meet your own deadline |
| IP assignment and NDA | Commercial | Full assignment of all code and documents to your company |
For the IP side, the offshore IP assignment checklist is written for US founders, but the repository, account and assignment steps apply in Lagos and Nairobi too; ask your lawyer about local wording.
Can you keep personal data in your own account and still use an offshore team?
Yes, and it is usually the most effective step you have, because it shrinks what the team can see. The design is simple: code travels, customers do not.
- Production runs in your own cloud account, in the region you and your adviser choose. The account, billing and root credentials belong to your company.
- Development and staging use synthetic data: generated records with realistic shape and no real people behind them.
- Deploys go through your CI pipeline. The team merges reviewed code; the pipeline deploys it. Human access to production is an exception, time-limited, approved and logged.
- Access runs through your identity provider with multi-factor authentication, so you can switch off every account in one place.
This does not make the transfer question disappear if the team ever needs production access, for example during a live incident. It does make that access rare, visible and easy to document, which is what the section 41(2) and regulation 41(2) records ask for. Answering your first security questionnaire without SOC 2 shows how to describe these controls honestly to your own customers.
How many working hours do Lagos and Nairobi share with Dhaka?
About 4 with Lagos and about 6 with Nairobi. Dhaka is on UTC+6, Nairobi on UTC+3 and Lagos on UTC+1, and none of the three changes its clocks, so the overlap is the same all year. The table assumes your day starts at 09:00 and the Dhaka day ends at 18:00.
| City | Time zone | Dhaka is ahead by | Shared hours | Window in local time | Window in Dhaka time |
|---|---|---|---|---|---|
| Nairobi | EAT, UTC+3 | 3 hours | 6 | 09:00–15:00 | 12:00–18:00 |
| Lagos or Abuja | WAT, UTC+1 | 5 hours | 4 | 09:00–13:00 | 14:00–18:00 |
So the shared window is your morning and early afternoon. The practical rhythm: questions and reviews in the shared window, working code and a written handoff at the end of the Dhaka day, and your afternoon for testing and feedback. RAITHub agrees the working week with each client; it is not fixed. If you need someone available through the whole Lagos afternoon, a local vendor is the better fit.
How do payments work, for the team and inside your product?
Two different questions, and both belong in the scope before you sign.
Paying an offshore team
The invoice currency, schedule and payment method are agreed in the quote. Ask your bank early what it needs from you to pay a foreign supplier for software services, since documentation requirements differ by bank and change over time; this is general information, so confirm the current rule with your bank and adviser.
Payment rails in your product
In Kenya, that usually means M-Pesa through Safaricom's Daraja APIs; in Nigeria, a payment aggregator such as Paystack or Flutterwave. RAITHub has not shipped M-Pesa, Daraja, Paystack or Flutterwave integrations. We have shipped the same class of problem: bKash, Nagad and SSLCommerz, Bangladesh's mobile-money-style wallets and gateway, in TheSkinProof, the founder's own marketplace venture, and Stripe in PropDesk. The rules transfer directly. Flutterwave's documentation, for example, says it signs webhooks with a secret hash in a verif-hash header, retries a failed webhook "3 times, with a 30-minute interval", and advises: "Before giving value to a customer based on a webhook notification, always re-query our API to verify the transaction details" (Flutterwave: webhooks). The same confirm-server-to-server pattern is in the bKash, Nagad and SSLCommerz guide, and the tests that prove it are in testing payments and webhooks.
If your product holds or moves customer funds, rather than letting a licensed provider do it, get licensing advice before you build. The wider picture is in the payments engineering guide.
What does an offshore team in Bangladesh cost, and how should you engage it?
RAITHub does not publish rates: a free 15-minute technical audit, then a fixed written quote. For market ranges, the cost of hiring developers in Bangladesh covers market ranges, and Bangladesh vs India vs Vietnam compares the main offshore locations. On the model, fixed scope suits a defined release and a dedicated monthly team suits an open-ended roadmap; fixed price vs time and materials explains the trade-off. Before either, run the due-diligence questions in is it safe to hire a Bangladesh software agency.
Why RAITHub for a Nigerian or Kenyan company?
- We design so the data stays with you. Production in your cloud account, synthetic data in development, deploys through your pipeline. That is the default, not an upsell.
- We sign your paperwork. RAITHub signs data processing terms, your transfer clauses and an NDA, fills in security schedules with real measures, and follows your controls. We hold no certifications and make no conformity claims; whether your arrangement meets the NDPA or Kenya's regulations is a judgement for you and your adviser.
- Tested money and data paths. PropDesk runs Stripe rent collection under 1,024 automated tests; Sundor Skin enforces row-level security across 146 PostgreSQL tables with 530+ tests; TheSkinProof, the founder's own venture, runs mobile-money-style wallets with 750+ tests.
- Honest scope on local rails. M-Pesa, Paystack and Flutterwave are quoted as new work and built against their sandboxes, with the failure cases tested before launch.
- Clear terms. Fixed-scope projects or a dedicated monthly team, and you own the IP. See SaaS development for what a build includes.
When you don't need us
- Your procurement requires SOC 2 or ISO 27001. RAITHub holds neither.
- Personal data must never be accessible from outside Nigeria or Kenya, even during an incident, or your processing falls under Kenya's regulation 26 list. Choose a local vendor.
- You want developers placed in your team under your management. RAITHub does not offer staff augmentation.
- You need someone on site in Lagos or Nairobi, or a full afternoon of overlap in Lagos. RAITHub has no office in Africa.
- You need a native mobile app. RAITHub builds web apps and PWAs, not native iOS or Android apps.
- You are building a regulated financial product that needs a licence. RAITHub has not shipped a licensed fintech product; start with a qualified adviser.
Sources checked on 30 September 2026. General information only; confirm with your adviser, the NDPC and the ODPC.
If none of those rule us out, book the free 15-minute technical audit. Bring a list of the personal data your product holds and where it is hosted, and we will tell you on the call what the team would and would not need to see.
Frequently asked questions
Can a Nigerian company send customer data to an offshore developer?
Under section 41 of the Nigeria Data Protection Act 2023, only if the recipient offers adequate protection, for example through contractual clauses, or a section 43 condition applies, and you must record the basis. The NDPC's FAQs describe adequacy decisions and submitting a transfer instrument for approval. Confirm the route with your adviser.
What does Kenya require before personal data leaves the country?
Regulation 40 of Kenya's Data Protection (General) Regulations, 2021 requires the transfer to rest on appropriate safeguards, an adequacy decision, necessity or consent. Safeguard-based transfers must be documented with the date and time, recipient, justification and a description of the data. Confirm with your adviser and the ODPC.
Which data must stay in Kenya?
Regulation 26 lists processing for the strategic interest of the state, including civil registration, elections, public finance systems, protected computer systems, early childhood and basic education, and primary or secondary health care. That processing must use a server and data centre in Kenya, or keep a serving copy there.
How quickly must a data breach be reported in Nigeria?
Section 40(2) of the NDPA requires the controller to notify the NDPC within 72 hours of becoming aware of a breach likely to result in a risk to individuals. A processor must tell the controller on becoming aware of it, so your vendor contract should set a short notice window.
How many hours overlap between Lagos, Nairobi and Dhaka?
About 4 hours with Lagos and about 6 with Nairobi, assuming your day starts at 09:00 and the Dhaka day ends at 18:00. None of the three cities uses daylight saving, so the overlap does not change during the year.
Has RAITHub built M-Pesa, Paystack or Flutterwave integrations?
No. RAITHub has shipped bKash, Nagad and SSLCommerz in TheSkinProof, the founder's own venture, and Stripe rent collection in PropDesk. M-Pesa, Paystack and Flutterwave would be quoted as new work using the same confirm-and-reconcile patterns.
Is RAITHub certified to SOC 2 or ISO 27001?
No. RAITHub signs your contract clauses and NDAs, follows your controls and answers security questionnaires with evidence, but holds neither certification. If your procurement requires one, choose a certified vendor.
Related posts
Hiring an Offshore Dev Team from Australia: APP 8, Contracts and Overlap
12 min readWorking with a Dhaka Dev Team from New Zealand: IPP 12, NZD and Overlap
12 min readOffshore Software Development for Japanese Companies: An English-Speaking Team
11 min readReady to discuss your project?
Book a free 15-minute technical audit with our engineering team.