NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Nigeria NDPA Requirements Explained
Learn

Nigeria NDPA Requirements Explained

·Alexander Sverdlov

The Nigeria Data Protection Act 2023 asks two things of every organisation it reaches, and a third of the ones the Nigeria Data Protection Commission designates as being of major importance. Everyone must process personal data on the principles in section 24 and one of the lawful bases in section 25, and must meet the duties that follow from them: a privacy notice under section 27, security measures under section 39, notification of a breach to the Commission within 72 hours under section 40, and a recorded basis for any transfer out of Nigeria under section 41. Data controllers and data processors of major importance must, in addition, register with the Commission under section 44, designate a Data Protection Officer under section 32, and file annual Compliance Audit Returns under the General Application and Implementation Directive the Commission issued on 20 March 2025.

The line between those two groups sits far lower than most guidance implies. Under Schedule 7 to the GAID, processing the personal data of more than 200 data subjects in six months is enough to be of major importance. Most employers cross that on headcount alone, before a single customer record is counted.

RequirementWhere it sitsWho it binds
Principles of processingSection 24Everyone, including processing that is otherwise exempt under section 3(2)
A lawful basis for each processing purposeSection 25Everyone
Privacy notice before collectionSection 27Every data controller
Data privacy impact assessment for high risk processingSection 28, GAID Article 28Every data controller
Written agreement with each processorSection 29Every controller or processor that engages a processor
Security, integrity and confidentiality measuresSection 39Everyone
Breach notification to the Commission within 72 hoursSection 40Every data controller
Recorded basis for cross-border transfersSections 41 to 43Everyone moving personal data out of Nigeria
Registration with the CommissionSection 44, GAID Article 9Major importance only
Data Protection OfficerSection 32, GAID Articles 11 to 14Major importance only
Annual Compliance Audit ReturnsGAID Article 10Major importance, Ultra-High and Extra-High levels
The Nigeria Data Protection Act 2023 duties mapped around one programme: section 24 principles, section 25 lawful basis, section 32 DPO, section 40 breaches, section 44 registration and Part VIII transfers

What are the Nigeria NDPA requirements?

Three layers, and the Act is structured so that each one rests on the one below it.

The first is the principles in section 24. Personal data must be processed fairly, lawfully and transparently; collected for specified, explicit and legitimate purposes and not further processed incompatibly; adequate, relevant and limited to the minimum necessary; retained no longer than needed; accurate, complete and kept up to date; and processed with appropriate security. Section 24(2) adds technical and organisational measures for confidentiality, integrity and availability, and section 24(3) makes the controller owe a duty of care and demonstrate accountability for all of it. That last clause is why a policy nobody can evidence does not count.

The second is the lawful basis in section 25. Processing is lawful where the data subject has given and not withdrawn consent, or where it is necessary for a contract, a legal obligation, a vital interest, a public task, or a legitimate interest. Section 25(2) takes legitimate interest away where it overrides the data subject's rights, where it is incompatible with the other bases, or where the data subject would not reasonably expect the processing. Section 26 then puts the burden of proving consent on the controller, rules out silence and pre-selected boxes, and requires the right to withdraw to be explained before consent is given.

The third is the set of duties that flow from those two, which is where the actual work lives. They are listed below by section.

Who has to comply with the NDPA?

Section 2 applies the Act to the processing of personal data whether by automated means or not, and in three situations: the controller or processor is domiciled in, resident in or operating in Nigeria; the processing occurs within Nigeria; or the controller or processor is outside Nigeria but is processing the personal data of a data subject in Nigeria. Article 1(2) of the GAID reads that third limb as reaching organisations that process or target the personal data of data subjects in Nigeria from abroad, so a foreign platform with Nigerian users is in.

Section 3 exempts purely personal or household processing, and disapplies most of Part V for competent authorities dealing with crime, public health emergencies and national security, for journalism and similar publication, and for legal claims. The carve-out is narrower than it looks. Section 3(2) keeps sections 24, 25, 32 and 40 in force even for exempt processing, so the principles, the lawful basis, the DPO duty and breach notification follow you into the exemption.

NDPA gap assessment in Venvera scoring each obligation area from registration to breach notification

What must every controller and processor do?

Tell people before you collect

Section 27 requires a controller, before collecting personal data directly from someone, to tell them who the controller is and how to reach it, the specific lawful basis and the purposes, the recipients, the rights in Part VI, the retention period, the right to complain to the Commission, and whether automated decision-making including profiling is involved. Section 27(3) says this goes in a privacy policy written in clear, concise and accessible language. The GAID adds a practical rule in Article 7(l): a cookie notice on the home page that lets the data subject accept or decline, placed where it obstructs the page rather than tucked at the bottom where it can be ignored.

Assess high risk processing before it starts

Section 28 requires a data privacy impact assessment before any processing likely to result in high risk to data subjects, and consultation with the Commission where the assessment says the risk remains high. The GAID turns that into a list. Article 28(3) makes a DPIA mandatory, and filed with the Commission, for profiling, automated decisions with legal effects, systematic monitoring, sensitive data, vulnerable data subjects, new technologies that pose significant risk, financial services delivered through digital devices, health care, e-commerce, education records, hospitality, public-facing surveillance cameras and cross-border transfer. Article 28(9) requires it before processing starts, and Articles 28(4) and 28(12) require it to be vetted and signed by a DPO certified by the Commission.

Bind your processors in writing

Section 29 makes whoever engages a processor responsible for ensuring the processor complies with the Act, assists with data subject rights, implements security measures, provides the information needed to demonstrate compliance, and gives notice when it engages a further processor. Section 29(2) requires a written agreement to carry those terms.

Secure the data

Section 39 requires appropriate technical and organisational measures for security, integrity and confidentiality, weighed against the amount and sensitivity of the data, the likely harm, the extent of processing, the retention period, and the cost of available measures relative to the organisation's size. The named measures include pseudonymisation, encryption, resilience of systems, timely restoration after an incident, periodic risk assessments, and regular testing of what is in place.

Report breaches inside 72 hours

Section 40 runs two clocks. A processor must notify the controller on becoming aware of a breach. A controller must notify the Commission within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals, describing where feasible the categories and approximate numbers of data subjects and records. Where the risk is high, section 40(3) requires the controller to communicate the breach to the data subjects immediately, in plain language, with advice on mitigating it. Article 33(5) of the GAID lists what the notification to the Commission has to contain, starting with the circumstances, the period and the personal data involved.

Honour the rights in Part VI

Section 34 gives data subjects confirmation of processing, the purposes, categories, recipients, retention period, source and any automated decision-making, plus a copy of their data in a commonly used electronic format. Section 35 makes withdrawing consent as easy as giving it. Section 36 gives a right to object, absolute for direct marketing. Section 37 gives a right not to be subject to a decision based solely on automated processing with legal or similar effects, with human intervention available. Section 38 provides for portability once the Commission makes regulations for it.

Record the basis for every transfer out of Nigeria

Section 41 permits a transfer only where the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism affording adequate protection, or where one of the section 43 conditions applies: informed consent, contract, the data subject's sole benefit, public interest, legal claims or vital interests. Section 41(2) requires the basis and the adequacy to be recorded, and Article 45(2) of the GAID points to Schedule 5 for evaluating a destination country until the Commission issues transfer regulations.

The deadlines set by the Nigeria Data Protection Act and the GAID: 72 hours to notify a breach, six months to register, 31 March for Compliance Audit Returns, and 60 days to notify a change in registration

What extra duties fall on organisations of major importance?

Section 65 defines a data controller or data processor of major importance as one domiciled, resident in or operating in Nigeria that processes the personal data of more than a number of data subjects the Commission prescribes, or that the Commission designates as processing data of particular value to Nigeria's economy, society or security. The Commission prescribed the number in the Guidance Notice reproduced as Schedule 7 to the GAID. You are of major importance if you keep or have access to a filing system, analogue or digital, and you process the personal data of more than 200 data subjects in six months, or you carry out commercial ICT services on devices belonging to other people, or you operate in one of thirteen sectors: aviation, communication, education, electric power, export and import, financial, health, hospitality, insurance, oil and gas, tourism, e-commerce and public service.

Schedule 7 then sorts that group into three levels. Ultra-High Level covers organisations processing more than 5,000 data subjects in six months, together with named types such as commercial banks, telecommunications companies, insurers, multinationals, electricity distributors, oil and gas companies, payment gateways and fintechs. Extra-High Level covers more than 1,000 but fewer than 5,000, together with government ministries and agencies, microfinance and mortgage banks, higher institutions and secondary or tertiary hospitals. Ordinary-High Level covers more than 200 but fewer than 1,000, together with primary and secondary schools, primary health centres, independent laboratories, hotels with fewer than 50 suites and any processor handling the sensitive personal data of more than 200 people commercially. Schedule 7 sets the registration fee at 250,000 naira for Ultra-High, 100,000 for Extra-High and 10,000 for Ordinary-High. The same designation decides which of the two NDPA penalty ceilings applies to you.

Register, and keep the registration current

Section 44(1) requires registration within six months of the Act commencing or of becoming of major importance. The notification under section 44(2) covers the organisation and its DPO, the categories and number of data subjects, the purposes, the recipients, any processors, the countries data is sent to, and a description of the safeguards. Section 44(3) requires any significant change to be notified within 60 days. Article 9 of the GAID splits the cycle by level: Ultra-High and Extra-High organisations register once and then file Compliance Audit Returns each year, while Ordinary-High organisations renew their registration annually and file no returns.

Designate a certified Data Protection Officer

Section 32(1) requires a data controller of major importance to designate a DPO with expert knowledge of data protection law and practice. The DPO may be an employee or engaged under a service contract, and must advise the organisation, monitor compliance and act as the contact point for the Commission. The GAID adds the parts that take time. Article 11(2) requires the DPO's contact details to be published and communicated to the Commission. Article 13 requires the DPO to compile a semi-annual data protection report to management, acknowledged in writing, kept as part of the record of processing activities, and verified by the auditor at the annual compliance audit. Article 14 puts DPOs on a Commission database and subjects them to an annual credential assessment, verified as part of the returns.

File Compliance Audit Returns every year

Article 7(b) of the GAID expects every controller and processor to conduct a compliance audit within fifteen months of commencing business and annually thereafter. Article 10 turns that into a filing for organisations of major importance. Under Article 10(7), an organisation established before 12 June 2023 files its returns by 31 March each year. Under Article 10(8), one established after that date files within fifteen months of establishment and annually thereafter. Article 10(9) attaches an administrative penalty of 50% of the filing fee to a late return, and Article 10(14) requires Ultra-High and Extra-High organisations to file through a Data Protection Compliance Organisation licensed under section 33 of the Act. The filing fees in Schedule 10 run from 100,000 naira for an Extra-High organisation below 2,500 data subjects to 1,000,000 naira for an Ultra-High organisation at 50,000 data subjects and above.

The extra cycle for organisations of major importance under the NDPA and the GAID: test against Schedule 7, register with the NDPC, designate a certified DPO, semi-annual DPO report, and file Compliance Audit Returns by 31 March

What did the 2025 GAID add?

The General Application and Implementation Directive, reference NDPC/NDP ACT-GAID/01/2025, was issued on 20 March 2025 and, under its Article 3(3), replaces the Nigeria Data Protection Regulation 2019 as the instrument the Commission applies. Its Article 7 sets out what the Commission expects of every controller and processor, and several of those items have no counterpart in the Act itself: the fifteen month compliance audit, semi-annual data protection reports, staff training within six months of commencing business and at least annually after that, a published privacy policy, the cookie notice placement rule, and a documented complaints process that tells data subjects they can go to the Commission.

Two transitional rules matter for anyone already processing. Article 28(10) requires a DPIA within six months of the GAID's issuance for processing that began before the Act, and Article 28(8) requires one within four months for anyone deploying software to process sensitive personal data. Article 49(3) adds a default retention rule: where no time-bound obligation exists, storage lapses no later than six months after the original purpose has been accomplished, subject to a legal claim or due diligence exception in Article 49(4).

NDPA dashboard in Venvera showing obligation status, open breaches and the next filing date

Which requirements cannot be met by writing a document?

Five, and they set the calendar for any programme that starts from scratch. A DPO who is certified by the Commission and assessed annually has to be found or trained. A Compliance Audit Return for an Ultra-High or Extra-High organisation has to go through a licensed compliance organisation, which means engaging one before 31 March, not after. A DPIA on any listed processing has to be signed by that certified DPO and filed before the processing starts. A 72 hour breach notification has to be rehearsed, because the people who decide whether a breach is likely to result in a risk are rarely the people who discover it. And registration has a six month clock that starts when you cross the 200 data subject line, whether or not anyone noticed the crossing.

The three levels of major importance under GAID Schedule 7: Ordinary-High at more than 200 data subjects in six months, Extra-High at more than 1,000, and Ultra-High at more than 5,000

What the other results get wrong

Four errors recur in the published guides. The first is stating that registration with the Commission is mandatory for everyone. Section 44 applies to controllers and processors of major importance, and the reason it feels universal is the 200 data subject threshold, which catches most organisations of any size. The distinction still matters, because Ordinary-High organisations renew rather than file returns, and organisations outside the designation do neither.

The second is presenting the DPO as a universal duty. Section 32(1) and Article 7(i) of the GAID both attach it to major importance. The third is collapsing the two breach clocks into one. The Act gives 72 hours to notify the Commission and requires immediate communication to data subjects where the risk is high, and the GAID's Article 33(3) repeats that immediacy. Telling individuals inside 72 hours is not what section 40(3) says.

The fourth is quoting audit thresholds and penalty splits from the 2019 Regulation. The GAID says in terms that the Commission has ceased to apply it, and the current thresholds are the ones in Schedule 7.

Check your own position, section by section

Fill this in. If you cannot answer a row, that row is where your programme starts.

QuestionYour answerWhy it matters
How many data subjects did you process in the last six months?Above 200 you are of major importance under Schedule 7, and sections 32 and 44 apply.
Are you in one of the thirteen Schedule 7 sectors?Sector membership alone makes you of major importance, whatever the headcount.
Does every processing activity have a recorded section 25 basis?Section 24(3) requires you to demonstrate accountability, not just to have a basis.
Is any processing on the Article 28(3) list?That DPIA has to be signed by a certified DPO and filed before processing starts.
Who decides, out of hours, whether a breach is likely to result in a risk?The 72 hours in section 40(2) run from awareness, not from the meeting.
Do you have a written section 29 agreement with each processor?Without it you carry the processor's failures as your own.
Is every transfer out of Nigeria recorded with its basis?Section 41(2) requires the record, and Schedule 5 governs adequacy.
When is your next Compliance Audit Return due?31 March, or fifteen months from establishment, with a 50% surcharge for lateness.

If most rows are blank, the sensible next step is a baseline rather than a legal opinion. Our Nigeria NDPA compliance checklist turns these sections into 60 checkable items, the framework overview sits on our NDPA page, and a free compliance check gives you a scored starting position across all of them.

The bottom line on Nigeria NDPA requirements: two hundred data subjects in six months is the line that doubles the list

Frequently asked questions

Do we have to register with the NDPC?

Only if you are a data controller or data processor of major importance under section 65 and Schedule 7 to the GAID. In practice that means more than 200 data subjects in six months, commercial ICT services on other people's devices, or one of thirteen listed sectors. Registration is due within six months of qualifying under section 44(1).

Do we need a Data Protection Officer?

Section 32(1) requires one for a data controller of major importance, and Article 7(i) of the GAID repeats the duty for processors of major importance. The DPO may be an employee or a contractor, must have expert knowledge of data protection law and practice, and under Article 14 of the GAID is subject to an annual credential assessment by the Commission.

How long do we have to report a breach?

72 hours from becoming aware, to the Commission, where the breach is likely to result in a risk to the rights and freedoms of individuals, under section 40(2). Where the risk is high, section 40(3) requires immediate communication to the data subjects.

Does the NDPA apply to companies outside Nigeria?

Yes, under section 2(2)(c), where a controller or processor outside Nigeria processes the personal data of a data subject in Nigeria. Article 1(2) of the GAID reads that as including organisations that target data subjects in Nigeria.

When are Compliance Audit Returns due?

By 31 March each year for an organisation of major importance established before 12 June 2023, under Article 10(7) of the GAID. An organisation established later files within fifteen months of establishment and annually thereafter under Article 10(8). Ordinary-High Level organisations renew their registration annually instead of filing.

What happens if we file late?

Article 10(9) of the GAID adds an administrative penalty of 50% of the filing fee. Any underlying violation of the Act is dealt with separately through the enforcement orders in section 48, which our guide to NDPA fines and penalties explains.

Primary sources

Section references are to the Nigeria Data Protection Act 2023 as published by the Nigeria Data Protection Commission, in particular sections 2, 3, 24 to 44 and 65. The major importance test, the three levels, the registration and filing fees, the DPO rules and the Compliance Audit Returns deadlines are from Articles 1, 3, 7 to 14, 28, 33, 45 and 49 and Schedules 7 and 10 of the General Application and Implementation Directive issued by the Commission on 20 March 2025 under reference NDPC/NDP ACT-GAID/01/2025. Confirm the current text before relying on a figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING