NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Nigeria NDPA Compliance Cost
Learn

Nigeria NDPA Compliance Cost

·Alexander Sverdlov

There is no official figure for what Nigeria Data Protection Act compliance costs, but there is an official price list for part of it. The General Application and Implementation Directive the Nigeria Data Protection Commission issued on 20 March 2025 fixes three fees. Registration as a data controller or processor of major importance costs 250,000 naira at Ultra-High Level, 100,000 naira at Extra-High Level and 10,000 naira at Ordinary-High Level under Schedule 7. Filing annual Compliance Audit Returns costs between 100,000 and 1,000,000 naira a year for Ultra-High and Extra-High organisations under Schedule 10. A late return adds 50% of the filing fee under Article 10(9). Everything else, which is most of the money, is people: a certified Data Protection Officer, the licensed compliance organisation that files your returns, the impact assessments, the training and the breach process.

The number that decides your budget is therefore not a naira figure but a headcount: whether you process the personal data of more than 200 data subjects in six months. Above that line you are of major importance, and the fees, the DPO and the annual returns follow. Below it, the Act still applies but the fixed costs largely fall away.

FactDetail
The fees the GAID fixesRegistration: N250,000 Ultra-High, N100,000 Extra-High, N10,000 Ordinary-High (Schedule 7). Compliance Audit Returns: N100,000 to N1,000,000 a year by level and data subject count (Schedule 10). Late filing: the fee plus 50% (Article 10(9)).
Who pays themControllers and processors of major importance: more than 200 data subjects in six months, commercial ICT services on other people's devices, or one of thirteen listed sectors (Schedule 7).
What recursUltra-High and Extra-High register once and file returns every year; Ordinary-High renews registration every year and files no returns (GAID Article 9(2) and 9(3)).
The filing routeUltra-High and Extra-High organisations file through a Data Protection Compliance Organisation licensed under section 33 of the Act (GAID Article 10(14)). Its fee is set by the market, not the Commission.
The people costA DPO with expert knowledge under section 32, certified and assessed annually by the Commission (GAID Article 14), a DPIA signed by that DPO for every listed processing (GAID Article 28), and training schedules under GAID Article 7(g).
The exposureA penalty of up to the greater of N10,000,000 and 2% of annual gross revenue for major importance, or N2,000,000 and 2% for everyone else (section 48(4) and 48(5)).
The NDPA fees the 2025 GAID fixes: N250,000 Ultra-High Level registration, N100,000 Extra-High Level registration, N10,000 Ordinary-High Level renewed every year, and a 50% surcharge on the Compliance Audit Returns filing fee when a return is late

What does NDPA compliance cost?

Split the question into three kinds of cost, because they behave differently. The first kind is fixed by the Commission and published: registration and the annual returns fee. You can read those off the schedules once you know your level. The second kind is priced by the market but required by the Directive: the licensed compliance organisation that must file returns for Ultra-High and Extra-High organisations, and the certification and annual credential assessment of your DPO, for which Article 14(7) of the GAID says the Commission may charge a fee without stating one. The third kind is internal and invisible on any invoice: the DPO's time, the impact assessments, the processor agreements, the semi-annual reports, the training and the breach rehearsal. For most organisations the third kind is the largest, and it is the one that recurs.

Any page that gives you a single figure without saying which level you are at, whether the compliance organisation's fee is included, and whether the DPO is an employee or a contractor, is describing someone else's programme.

Which fees does the NDPC actually fix?

Registration under section 44

Section 44(1) of the Act requires controllers and processors of major importance to register with the Commission within six months of the Act commencing or of becoming of major importance, and section 45 lets the Commission prescribe fees for them. Schedule 7 to the GAID, which reproduces the Commission's Guidance Notice on registration, sets the amount by level: 250,000 naira for Ultra-High Level, 100,000 naira for Extra-High Level and 10,000 naira for Ordinary-High Level. Article 9(2) of the GAID has Ultra-High and Extra-High organisations register once and then file returns each year; Article 9(3) has Ordinary-High organisations renew their registration annually and file no returns. Paragraph 7 of Schedule 7 adds a data processing fee of 5,000 naira that an Ultra-High Level controller pays for each processor it engages in a twelve month period.

Compliance Audit Returns under GAID Article 10

Article 10(6) requires organisations of major importance to file returns annually, which Article 9(3) narrows to Ultra-High and Extra-High Level by letting Ordinary-High organisations renew their registration instead. Article 10(7) sets the deadline at 31 March for organisations established before 12 June 2023, and Article 10(8) gives organisations established after that date fifteen months from establishment and then annually. Article 10(10) sends Ultra-High and Extra-High organisations to Schedule 10 for the fee, which scales with the number of data subjects.

Level and tierData subjectsAnnual filing fee
Ultra-High, tier A50,000 and aboveN1,000,000
Ultra-High, tier B25,000 to 49,999N750,000
Ultra-High, tier CBelow 25,000N500,000
Extra-High, tier A10,000 and aboveN250,000
Extra-High, tier B2,500 to 5,000N200,000
Extra-High, tier CBelow 2,500N100,000

Article 10(9) attaches the one penalty the GAID prices itself: a return filed late costs the filing fee plus an administrative penalty of 50% of that fee. Article 10(14) requires Ultra-High and Extra-High organisations to file through a Data Protection Compliance Organisation licensed by the Commission under section 33 of the Act, except where the Commission approves otherwise, so the filing fee is never the whole cost of the return.

What each level of major importance pays under GAID Schedules 7 and 10: Ultra-High N250,000 to register and N500,000 to N1,000,000 a year in Compliance Audit Returns fees, Extra-High N100,000 to register and N100,000 to N250,000 a year, Ordinary-High N10,000 renewed yearly with no returns filing

Which level are you at?

Schedule 7 designates you of major importance if you keep or have access to a filing system and process the personal data of more than 200 data subjects in six months, carry out commercial ICT services on devices belonging to other people, or operate in one of thirteen sectors: aviation, communication, education, electric power, export and import, financial, health, hospitality, insurance, oil and gas, tourism, e-commerce and public service. It then sorts that group. Ultra-High Level covers organisations processing more than 5,000 data subjects in six months and named types such as commercial banks, telecommunications companies, insurers, multinationals, electricity distributors, oil and gas companies, payment gateways and fintechs. Extra-High Level covers more than 1,000 but fewer than 5,000, plus government ministries and agencies, microfinance and mortgage banks, higher institutions and secondary or tertiary hospitals. Ordinary-High Level covers more than 200 but fewer than 1,000, plus primary and secondary schools, primary health centres, independent laboratories and hotels with fewer than 50 suites. Schedule 7 also lists who is not of major importance: traders with fewer than 15 employees who keep no filing system beyond contact details and receipts, and artisans who do not pass personal data on.

The level sets both the registration fee and the returns fee, and it is measured on your own numbers over six months. Our guide to Nigeria NDPA requirements sets out every duty that follows from the designation.

NDPA dashboard in Venvera showing the gap assessment score, processing activities, DPIAs completed, open data subject requests, open breaches, cross-border transfers and compliance audits

The six budget lines every NDPA programme carries

1. Registration and renewal. The Schedule 7 fee on registration, then annual renewal at Ordinary-High Level, plus 5,000 naira per processor a year at Ultra-High Level. Section 44(3) requires any significant change to the registered information to be notified within 60 days, which is administrative time rather than a fee.

2. A certified Data Protection Officer. Section 32(1) requires a controller of major importance to designate a DPO with expert knowledge of data protection law and practice, as an employee or under a service contract. GAID Article 14 puts DPOs on a Commission database, subjects them to an Annual Credential Assessment, verifies the certification as part of registration or the returns, and lets the Commission charge for the verification. Article 12(2)(c) requires the organisation to make adequate provision for the DPO's continuous training. Whether the DPO is a salary or a retainer, this is the largest recurring line for most organisations.

3. The annual audit and the returns. Article 7(b) of the GAID expects every controller and processor to conduct a compliance audit within fifteen months of commencing business and annually thereafter. For Ultra-High and Extra-High organisations that audit becomes a filing through a licensed compliance organisation, at the Schedule 10 fee plus whatever the organisation charges. Article 13(4) has the DPO's semi-annual reports verified during that audit, so the audit cost includes the cost of having the reports to verify.

4. Data privacy impact assessments. GAID Article 28(3) makes a DPIA mandatory, and filed with the Commission, for a long list of processing that includes profiling, automated decisions, systematic monitoring, sensitive data, vulnerable data subjects and new technologies. Article 28(4) requires it to be vetted by a certified DPO, Article 28(9) requires it before processing starts, and Article 28(12) requires the filed version to be signed by that DPO. Each new product or system on the list is a DPIA, which makes this line scale with change rather than with size.

5. Processor agreements and transfer records. Section 29 requires a written agreement with every processor, and sections 41 to 43 require a recorded basis for every transfer out of Nigeria. The cost is legal drafting once and review at every renewal, multiplied by the processor count.

6. Training and breach readiness. Article 7(g) requires schedules for organisation-wide sensitisation and training, and section 40 gives 72 hours from awareness to notify the Commission of a breach likely to result in a risk to data subjects. Neither costs much to write down. Both cost something every year to keep true.

The six NDPA budget lines around one programme: registration under section 44, a certified DPO under section 32, Compliance Audit Returns under GAID Article 10, the licensed compliance organisation under section 33, DPIAs under section 28 and training under GAID Article 7(g)

What recurs every year?

Almost all of it. The registration is a one-off for Ultra-High and Extra-High organisations and an annual renewal for Ordinary-High ones. The returns are annual, by 31 March or fifteen months from establishment. The compliance audit behind them is annual under Article 7(b). The DPO's report to management is semi-annual under Article 13(1). The DPO's credential assessment is annual under Article 14(2). Training runs to a schedule under Article 7(g). A budget that treats year one as the expensive year and year two as maintenance has the shape backwards: the fixed fees are small and the recurring people cost is the programme.

The NDPA cycle that recurs every year under GAID Articles 7, 9, 10 and 13: register or renew, the semi-annual DPO report, annual staff training, the compliance audit through a licensed organisation, and filing Compliance Audit Returns by 31 March

What does non-compliance cost?

Section 48(3) of the Act caps a penalty or remedial fee at the higher maximum amount for organisations of major importance and the standard maximum amount for everyone else. Section 48(4) defines the higher maximum as the greater of 10,000,000 naira and 2% of annual gross revenue in the preceding financial year; section 48(5) defines the standard maximum as the greater of 2,000,000 naira and the same 2%. Section 48(2) adds orders to remedy the violation, to compensate data subjects and to account for the profits made from the violation, and section 48(6) lists the seven factors the Commission weighs, including the degree of cooperation and the mitigation measures taken. The late filing surcharge under GAID Article 10(9) sits on top. Our guide to NDPA fines and penalties explains how an enforcement order is reached and what the criminal provisions add.

What an NDPA budget has to fund, on a board: days to the next Compliance Audit Returns deadline, processors covered by a section 29 agreement, DPIAs signed by the certified DPO before processing, and staff trained in the last twelve months under GAID Article 7(g)

What the other results get wrong

The first error is quoting registration fees that are not in Schedule 7. Several pages describe a three-tier fee with a small business rate. The GAID has three levels tied to data subject counts and sectors, and the lowest is 10,000 naira for Ordinary-High Level. The Commission's own schedule is the only current source.

The second is quoting an all-in annual figure without saying what it covers. A figure that includes the licensed compliance organisation's fee for an Ultra-High tier A filing and a figure for an Ordinary-High school that files nothing differ by an order of magnitude, and both get quoted as the cost of NDPA compliance.

The third is treating registration as a one-off for everyone. Ordinary-High Level organisations renew every year under Article 9(3). Ultra-High and Extra-High organisations register once but file returns every year at the Schedule 10 fee. Either way there is an annual line; it is a different one depending on the level.

The fourth is leaving out the filing route. Article 10(14) makes the licensed compliance organisation mandatory for Ultra-High and Extra-High returns, so the Schedule 10 fee is a floor for the cost of the return, not the cost itself.

Size your own NDPA budget

Fill this in from your own records. Each row moves a specific line.

QuestionEffect on your number
How many data subjects did you process in the last six months?Above 200 you are of major importance; above 1,000 and above 5,000 the level and the fees step up (Schedule 7)
Are you in one of the thirteen Schedule 7 sectors, or a named type such as a bank, insurer or fintech?Sector or type sets the level regardless of headcount, and with it the registration and returns fees
Is your DPO an employee or a contractor, and is the certification current?The largest recurring line, plus the Article 14 annual credential assessment and Article 12(2)(c) training
How many processors do you engage?Each needs a section 29 agreement; at Ultra-High Level each adds a 5,000 naira data processing fee a year
Is any planned processing on the Article 28(3) list?Each item is a DPIA vetted and signed by the certified DPO and filed before processing starts
Were you established before 12 June 2023?Sets whether your returns are due by 31 March or fifteen months from establishment (Article 10(7) and 10(8))

If several rows are blank, the sensible next step is a baseline rather than a quote. Our Nigeria NDPA compliance checklist works through the obligations behind each line, our guide to NDPA compliance software explains where a spreadsheet stops being enough, and a free compliance check gives you a scored starting position. Our NDPA compliance software keeps the records of processing, the processor agreements, the DPIAs and the transfer bases that the returns are built from, runs the 72 hour breach clock, and tracks the DPO and registration dates. Pricing is published and flat, from EUR 399 per month.

NDPA gap assessment in Venvera scoring compliance maturity across ten chapters of the Act, with a completed initial assessment
The bottom line on Nigeria NDPA compliance cost: the fees are fixed, the recurring people cost is the budget

Frequently asked questions

How much does it cost to register with the NDPC?

Under Schedule 7 to the 2025 GAID, 250,000 naira at Ultra-High Level, 100,000 naira at Extra-High Level and 10,000 naira at Ordinary-High Level. Ultra-High and Extra-High organisations register once; Ordinary-High organisations renew annually.

How much are the Compliance Audit Returns fees?

Schedule 10 sets them by level and data subject count: 500,000 to 1,000,000 naira a year at Ultra-High Level and 100,000 to 250,000 naira a year at Extra-High Level. Ordinary-High organisations file no returns. A late return adds 50% of the fee under Article 10(9).

Do we have to pay a compliance organisation as well?

If you are Ultra-High or Extra-High Level, yes, unless the Commission approves otherwise. Article 10(14) of the GAID requires those returns to be filed through a Data Protection Compliance Organisation licensed under section 33 of the Act. Its fee is set by the organisation, not by the Commission.

Does a small business have to pay anything?

A business below the 200 data subject line, outside the thirteen sectors and outside the named types is not of major importance and pays no registration or returns fee. It still has to meet the section 24 principles, hold a section 25 lawful basis, secure the data under section 39 and notify breaches within 72 hours under section 40.

Is the DPO's certification a cost?

Yes. Article 14 of the GAID has the Commission verify DPO certification as part of registration or the returns and run an Annual Credential Assessment, and Article 14(7) provides for a fee for the verification without fixing the amount. Article 12(2)(c) also requires you to fund the DPO's continuous training.

Primary sources

Section references are to the Nigeria Data Protection Act 2023 as published by the Nigeria Data Protection Commission, in particular sections 29, 32, 33, 40, 44, 45 and 48. The registration levels and fees, the Compliance Audit Returns rules and fees, the DPO provisions and the DPIA rules are from Articles 7, 9, 10, 12, 13, 14 and 28 and Schedules 7 and 10 of the General Application and Implementation Directive of 20 March 2025. All amounts are in naira as stated in those instruments. Confirm the current text before relying on a figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING