The NDPA Corporate Compliance Playbook: How Nigerian Businesses Navigate the Nigeria Data Protection Act 2023
The Nigeria Data Protection Act 2023 (NDPA) requires every organisation collecting or processing personal data in Nigeria to register with the NDPC, appoint a Data Protection Officer, file annual Compliance Audit Returns by 15 March each year, and implement technical safeguards. Organisations processing data of more than 200 persons within six months are classified as Data Controllers of Major Importance and face fines of up to ₦10 million or 2% of annual gross revenue — whichever is higher — for non-compliance. The NDPC’s General Application and Implementation Directive (GAID 2025) is now fully in force.
The Nigeria Data Protection Commission has collected ₦7.2 billion in penalties since the NDPA took effect — and in August 2025 issued compliance notices to 1,369 Nigerian businesses with a 21-day deadline to prove compliance. The enforcement phase is no longer approaching. It is here. This guide explains exactly what the law requires, who it applies to, and what every Nigerian business must do to avoid becoming the NDPC’s next enforcement target.
The Legal Framework: NDPA 2023 and GAID 2025
The Nigeria Data Protection Act 2023 was signed into law on 12 June 2023, replacing the Nigeria Data Protection Regulation (NDPR) 2019. Unlike its predecessor, the NDPA has full legislative authority — it is an Act of the National Assembly, not a regulatory directive — which gives the Nigeria Data Protection Commission (NDPC) significantly greater enforcement powers including the authority to impose substantial financial penalties, conduct mandatory audits, and issue binding compliance orders.
The NDPA established the NDPC as an independent regulatory authority separate from NITDA. The Commission’s mandate covers every organisation that collects, stores, processes, or transfers personal data in Nigeria — regardless of whether that organisation is based in Nigeria or operates from abroad.
The General Application and Implementation Directive (GAID 2025), issued by the NDPC on 20 March 2025 and fully effective from 19 September 2025, is the operational rulebook that translates the NDPA’s principles into concrete day-to-day compliance requirements. The GAID introduced mandatory registration timelines, clarified the annual compliance audit filing deadline, and hardened the obligations placed on organisations classified as Data Controllers or Processors of Major Importance.
Who Must Comply: Data Controllers and Processors of Major Importance
The NDPA applies to any individual, company, government body, or other entity that determines why and how personal data is processed (a data controller) or that processes personal data on behalf of a controller (a data processor). If your business collects customer names, phone numbers, email addresses, transaction records, health information, or any other data that can identify a person — you are within scope.
The most significant compliance tier under the NDPA is the classification of Data Controller or Processor of Major Importance (DCPMI). Organisations in this category face enhanced obligations and the highest penalty tier. Under the GAID 2025, an organisation is classified as a DCPMI if it meets any one of the following criteria:
- Processes personal data of more than 200 data subjects within any six-month period
- Carries out commercial technology services on digital devices belonging to others
- Operates in a sector of major economic importance to Nigeria — which the NDPC has interpreted broadly to include banking, insurance, fintech, telecoms, healthcare, and e-commerce
- Handles confidential data in a fiduciary capacity, such as financial institutions, legal service providers, and healthcare organisations
The NDPA also has extraterritorial reach. Foreign organisations offering goods or services to individuals in Nigeria, monitoring the behaviour of people located in Nigeria, or processing the personal data of Nigerian citizens for any commercial purpose are subject to the Act regardless of where they are based.
The Seven Core Compliance Obligations Every Nigerian Business Must Meet
The NDPA and GAID 2025 together impose seven primary obligations on data controllers and processors operating in Nigeria. These are not aspirational standards — they are enforceable legal requirements with financial penalties attached.
1. Registration with the NDPC
All Data Controllers and Processors of Major Importance must register with the NDPC through the Commission’s online portal. Registration is not optional and must be completed before or alongside any personal data processing activity. The NDPC uses registration data to build its enforcement target list — which is precisely what the August 2025 compliance notice to 1,369 businesses demonstrated.
2. Appointment of a Data Protection Officer (DPO)
Every DCPMI must appoint a qualified Data Protection Officer. The DPO must have expert knowledge of data protection law and practice. The DPO’s responsibilities include monitoring the organisation’s NDPA compliance, handling data subject requests, conducting staff training, and serving as the primary point of contact with the NDPC for all regulatory communications. The DPO appointment must be documented and the DPO must be registered with a licensed Data Protection Compliance Organisation (DPCO).
3. Annual Compliance Audit and Filing
DCPMIs must conduct an annual data protection compliance audit and file a Compliance Audit Return (CAR) with the NDPC by 15 March each year. The audit must be conducted by a licensed DPCO. The CAR must demonstrate that the organisation’s data processing activities comply with the NDPA across all functions — customer data, employee data, marketing data, and supplier data.
4. Data Processing Agreements
Where a data controller shares personal data with a third-party processor — a cloud provider, a payroll company, a marketing agency — a formal Data Processing Agreement (DPA) must be in place. This agreement must specify the scope of processing, the security measures in place, the processor’s obligations, and the consequences of a data breach. Controllers remain liable for the acts of their processors.
5. Privacy Notice and Lawful Basis for Processing
Every organisation must have a clear, NDPA-compliant privacy notice informing data subjects of what personal data is collected, why it is processed, how long it is retained, and with whom it is shared. Data processing must also have a lawful basis — consent, contractual necessity, legal obligation, legitimate interests, or vital interests. Processing personal data without a documented lawful basis is a direct violation of Section 24 of the NDPA.
6. Data Breach Notification
In the event of a personal data breach, data controllers are required under Section 40 of the NDPA and Article 7(p) of the GAID 2025 to notify the NDPC within 72 hours of becoming aware of the breach. Where the breach is likely to negatively impact the rights and freedoms of the data subjects, the affected individuals must also be notified immediately. Failure to report a breach within the 72-hour window is itself a compliance failure and can attract separate penalties.
7. Cross-Border Data Transfer Controls
Personal data may only be transferred outside Nigeria where the NDPC is satisfied that the recipient country provides adequate protection, or where one of the permitted transfer conditions under Section 41 of the NDPA is met — including explicit data subject consent, contractual necessity, or compliance with binding corporate rules. The Multichoice Nigeria fine of ₦766.2 million was partly driven by illegal cross-border transfer of personal data — making this one of the NDPC’s highest enforcement priorities.
Penalties and Enforcement: What the NDPC Has Already Done
The NDPC is no longer in advisory mode. The Commission has publicly stated that 2026 onwards represents full enforcement mode — and the penalty record confirms it.
| Organisation | Violation | Penalty | Year |
|---|---|---|---|
| Meta Platforms Inc. | Unlawful processing of Nigerian users’ personal data; transfer without adequate protections | $220 million | 2024 |
| Multichoice Nigeria | Illegal cross-border data transfer; processing subscriber data without proper consent | ₦766.2 million | 2025 |
| Fidelity Bank | Processing personal data without informed consent | ₦555.8 million | 2024 |
| Four banks + three companies | Various data violation offences | ₦400 million (combined) | 2024 |
| 1,369 companies (investigation open) | Failure to prove compliance: no audit filing, no DPO, no registration | Pending — 21-day compliance notice issued | August 2025 |
The NDPC has now concluded 246 investigations into data protection breaches, generating more than ₦5.2 billion in sanctions revenue and growing a Nigerian data protection compliance industry now valued at ₦16.2 billion. These are not symbolic enforcement actions — they are the NDPC establishing its authority as Africa’s most aggressive data protection regulator.
The maximum penalty structure under the NDPA is:
- Data Controllers/Processors of Major Importance: ₦10 million or 2% of annual gross revenue in the preceding financial year — whichever is higher
- Other data controllers/processors: ₦2 million or 2% of annual gross revenue — whichever is higher
- Late filing of Compliance Audit Returns: Additional late filing fees on top of substantive penalties
Sector-by-Sector Compliance Requirements
While the NDPA applies across all sectors, certain industries face heightened scrutiny from the NDPC based on the volume and sensitivity of personal data they process.
| Sector | Key data types processed | Specific NDPA obligations | NDPC enforcement focus |
|---|---|---|---|
| Banking & Finance | Account details, BVN, transaction records, credit history | Mandatory DCPMI registration; DPO; 72-hr breach notification; DPA with fintech partners | High — multiple banks already fined |
| Fintech & Payments | KYC data, payment data, device identifiers, location data | DCPMI registration; CBN AML/NDPA overlap compliance; cross-border transfer controls | Very high — CBN + NDPC dual oversight |
| Healthcare & Medtech | Medical records, health history, biometric data | Special category data rules under NDPA S.30; mandatory impact assessments; strict consent | Growing — NDPC health data guidelines in force |
| E-commerce & Retail | Customer purchase data, delivery addresses, payment details | Privacy notice; lawful basis per product/service; processor agreements with logistics providers | Medium — consumer-facing platforms targeted |
| Tech & SaaS | User data, usage analytics, device data, employee data | GAID 2025 full compliance; NITDA overlap obligations; cross-border transfer controls | High — digital platforms a primary target |
| Human Resources / Employers | Staff records, payroll, performance reviews, biometrics | Lawful basis for employee data processing; DPA with payroll providers; data retention policy | Medium — employer obligations under scrutiny |
| Legal, Accounting & Professional Services | Client files, financial records, privileged communications | Fiduciary data handler obligations under NDPA; DCPMI classification likely; strict confidentiality rules | Growing — professional services now in scope |
How to Achieve NDPA Compliance: A Step-by-Step Process
NDPA compliance is not a one-time exercise — it is an ongoing operational requirement. The following process reflects the minimum steps every Nigerian business must complete to achieve and maintain compliance under the NDPA 2023 and GAID 2025.
Step 1 — Data Mapping and Classification
Before any compliance programme can be built, the organisation must understand what personal data it holds, where it comes from, how it is processed, who has access to it, and where it goes. This data mapping exercise forms the foundation of every subsequent compliance step. Many businesses discover significant compliance gaps at this stage — data collected years ago with no documented basis, third-party sharing arrangements with no agreements in place.
Step 2 — DCPMI Assessment and NDPC Registration
Determine whether the organisation qualifies as a Data Controller or Processor of Major Importance using the criteria in the GAID 2025. If yes, complete NDPC registration through the Commission’s online portal immediately. Registration must be renewed annually.
Step 3 — Appoint a Qualified DPO
Identify and formally appoint a Data Protection Officer with appropriate expertise. The DPO must be registered with a licensed DPCO. Document the appointment formally — the DPO’s name, qualifications, and terms of reference should be on record and available to the NDPC on request.
Step 4 — Update Privacy Notices and Consent Mechanisms
Review and rewrite all customer-facing privacy notices to meet the NDPA standard. Ensure every data collection point — website forms, mobile apps, customer onboarding, employee contracts — captures consent properly and explains the lawful basis for processing in plain language.
Step 5 — Audit Third-Party Processor Relationships
Identify every third party that handles personal data on the organisation’s behalf. Execute Data Processing Agreements with each one. This includes cloud storage providers, CRM vendors, payroll processors, marketing agencies, and IT service companies.
Step 6 — Implement Breach Detection and Response Procedures
Put in place the technical and organisational measures required to detect a personal data breach quickly, assess its severity, and notify the NDPC within 72 hours. Document the breach response process and train the relevant staff before a breach occurs — not after.
Step 7 — Commission and File the Annual Compliance Audit
Engage a licensed Data Protection Compliance Organisation (DPCO) to conduct the annual compliance audit. File the Compliance Audit Return with the NDPC by 15 March each year. Keep evidence of the audit and all supporting documentation for a minimum of three years.
NDPA Corporate Compliance Checklist — 2026 Edition
A step-by-step checklist covering all seven NDPA compliance obligations, the DCPMI registration process, DPO appointment requirements, and the NDPC audit filing timeline — structured for Nigerian business owners and compliance officers to use immediately.
Download Free →
Common Mistakes and the Consequences
- Assuming the 200 data subjects threshold does not apply. Businesses routinely underestimate how quickly they cross the DCPMI threshold. A company with 250 email newsletter subscribers, a staff database, and a CRM system is almost certainly a DCPMI. Consequence: exposure to the higher penalty tier of ₦10 million or 2% of gross revenue.
- Filing a privacy policy copied from a GDPR template. European GDPR templates do not meet the NDPA standard. The NDPA has Nigeria-specific requirements — including local data residency obligations, NDPC-specific reporting procedures, and GAID 2025 compliance requirements — that a GDPR policy will not cover. Consequence: compliance audit failure; enforcement notice.
- Treating DPO appointment as a paper exercise. Appointing a DPO in name only — without genuine expertise, without DPCO registration, without documented responsibilities — is not compliance. The NDPC investigates the substance of DPO arrangements, not just their existence. Consequence: audit failure; possible enforcement action.
- Failing to have Data Processing Agreements with technology vendors. Almost every Nigerian business uses cloud storage, email marketing platforms, or HR software run by third parties. Without formal DPAs in place, the controller remains fully liable for how those processors handle personal data. Consequence: joint liability for processor breaches; regulatory exposure.
- Missing the 72-hour breach notification window. Many businesses do not detect breaches quickly enough to meet the notification deadline. Without a documented breach detection and response procedure, the 72-hour window is effectively impossible to meet. Consequence: double jeopardy — fined for the breach and separately for the late notification.
Frequently Asked Questions
Does the NDPA apply to my small business?
Yes. The NDPA applies to any organisation that processes personal data in Nigeria, regardless of size. If you collect customer names, phone numbers, or email addresses — even for a small operation — you are within scope. The DCPMI classification with its higher penalty tier applies once you process data of more than 200 people in a six-month period, but the basic obligations of having a privacy notice, a lawful basis for processing, and a data breach procedure apply to all organisations from the first data subject processed.
What is the difference between the NDPA 2023 and the old NDPR 2019?
The NDPR 2019 was a regulatory directive issued by NITDA — it lacked full legislative backing and NITDA’s enforcement powers were limited. The NDPA 2023 is an Act of the National Assembly with independent regulatory authority vested in the NDPC. This gives the NDPC significantly stronger enforcement powers including the ability to impose substantial financial penalties, conduct mandatory audits, issue binding compliance orders, and pursue criminal prosecution in serious cases. The GAID 2025 then operationalised the NDPA’s requirements into day-to-day compliance obligations.
Can a foreign company operating in Nigeria be fined under the NDPA?
Yes. The NDPA has extraterritorial reach. Any organisation that offers goods or services to individuals in Nigeria, monitors the behaviour of people in Nigeria, or processes the personal data of Nigerian citizens for any commercial purpose is subject to the Act — regardless of where the organisation is incorporated or based. The NDPC’s $220 million fine against Meta Platforms demonstrates that the Commission is willing and able to pursue foreign entities at the highest level.
Does Your Business Meet the NDPA Standard?
Lawberon Legals & Co. advises commercial clients across Lagos and Abuja on data protection compliance, NDPC regulatory matters, and the full spectrum of Nigerian commercial law.
Our team assists businesses with DCPMI registration, DPO appointment frameworks, Data Processing Agreements, Compliance Audit Return preparation, and enforcement defence when the NDPC comes knocking.
Contact our team at info@lawberonlegals.com or call +234(0) 902-552-5239.
No. 12 Thomas Laniyan Street, Anthony, Lagos State.
