Websites11 min read

PCI DSS Compliance for Online Payments in Nigeria in 2026

Mohamed Bah·Fondateur, Kolonell
August 21, 2026
Share:
PCI DSS Compliance for Online Payments in Nigeria in 2026

PCI DSS Compliance for Online Payments in Nigeria in 2026

Websites

The verdict in three sentences

For a Nigerian online merchant, the best PCI DSS strategy is to never touch the card number: with a redirect or tokenisation, the sensitive data flows through the certified provider, not you. You then move from the heavy SAQ-D questionnaire to SAQ-A, and your audit scope shrinks by roughly 80 %. Legally, the NDPR in Nigeria (and Senegal's Law 2008-12) requires protection, minimisation and controlled retention of personal data.

Don't store what you don't need to keep

The founding PCI DSS principle: the less card data you handle, the less exposed you are. Three architectures dominate in 2026.

ArchitecturePCI scopeApplicable SAQEffort
Redirect (hosted page)MinimalSAQ-ALow
iframe field / tokenisationReducedSAQ-A-EPMedium
Direct API + storageFullSAQ-DHigh

Tokenisation replaces the card number with a harmless token: the real number stays with the provider. That cuts PCI scope by about 80 % and removes the risk of a card-data breach in your database.

Local compliance: NDPR and Law 2008-12

PCI DSS compliance does not replace data-protection law. In Nigeria, the NDPR (Nigeria Data Protection Regulation) sets penalties and requires consent. In Senegal, Law 2008-12 requires a filing with the CDP, a clear purpose and proportionate security.

ObligationNigeria (NDPR)Senegal (Law 2008-12)
AuthorityNDPCCDP
Max penaltyUp to 2 % of revenueFine + criminal
ConsentRequiredRequired
Log retention12 months recommended12 months recommended
Breach notificationMandatoryMandatory
PCI audit cost500k-2M FCFA500k-2M FCFA

Remember two figures: an NDPR breach can cost up to 2 % of annual revenue, and a high-level PCI audit runs between 500,000 and 2,000,000 FCFA. Avoiding storage avoids both.

What to put in place concretely

HTTPS everywhere, redirect or iframe for payment, tokenisation for recurring charges, access logging for 12 months, and a compliant privacy policy. For most stores, SAQ-A is enough: a short self-assessment questionnaire, no costly audit.

Mini case study

Emeka launches an electronics store in Lagos. Tempted by a direct API integration to "control everything", he discovers it places him in SAQ-D: annual audit, quarterly scans, estimated cost 1,200,000 FCFA/year. By switching to a hosted payment page (redirect) plus Paystack and card, he drops to SAQ-A.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

His new compliance cost: the SAQ-A questionnaire (internal) plus an SSL certificate, about 80,000 FCFA/year. Saving: about 1,120,000 FCFA/year, and crucially no card data in his database, so no breach to notify.

FAQ

Do I need PCI DSS certification to sell online in Nigeria?

You must be compliant, not necessarily audited. With a redirect, a self-declared SAQ-A is enough in most cases, without a costly external audit.

Does tokenisation really reduce my obligations?

Yes: it takes the real card number out of your system and cuts PCI scope by about 80 %. Recurring payments run on a token, not the card.

How much does a full PCI audit cost?

Between 500,000 and 2,000,000 FCFA depending on size and architecture. That is exactly what a well-designed redirect lets you avoid.

Does Senegal's Law 2008-12 apply if I sell there?

Yes, as soon as you process data of Senegalese residents. It requires a CDP filing, so minimising the data you collect is the safest path.

How long should I keep access logs?

Keep at least 12 months of logs. That is the common benchmark for audits and post-incident investigations.

Let's talk about your project. We design your checkout with tokenised redirect to stay in SAQ-A and compliant with the NDPR. WhatsApp +221 77 596 93 33.

Tags:#PCI DSS#compliance#Nigeria#Senegal#NDPR#tokenisation#payment security#bank card
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.