This NDPA compliance checklist is a free Excel workbook that turns the Nigeria Data Protection Act 2023 and the 2025 General Application and Implementation Directive (GAID) into 60 concrete items you can work through line by line. If you are a compliance lead, DPO, or CISO trying to prove that your organisation genuinely meets its obligations, an NDPA compliance checklist beats a stack of policy PDFs you never reopen. It covers the duties the Nigeria Data Protection Commission (NDPC) expects controllers and processors to demonstrate: appointing a data protection officer, fixing a lawful basis, honouring data subject rights, notifying breaches, running impact assessments for high-risk processing, and registering where you qualify as an organisation of major importance. Download it below, then read on for how to use it well.
Get the Nigeria NDPA Compliance Checklist
Check your obligations under the Nigeria Data Protection Act 2023 and the 2025 GAID. 60 items.

What the Nigeria NDPA Compliance Checklist covers
The workbook is one sheet of 60 rows, grouped into the obligation areas the NDPA and GAID actually turn on. Each row is a single, checkable requirement rather than a vague theme, so nothing hides behind a heading. The columns are built for evidence, not just for ticking:
- Requirement - the obligation stated in plain language.
- Obligation area - which part of the regime it maps to: governance, lawful basis, rights, breaches, DPIAs, or registration.
- Status - Not started, In progress, or Done, so you can see coverage at a glance.
- Owner - the named person accountable, because "the team" is not an owner.
- Evidence - the document, record, or screenshot that proves the item is real.
- Notes - gaps, dates, and follow-ups.
The rows are grouped so you can hand whole sections to the right people: accountability and the data protection officer, lawful basis for processing, data subject rights, personal data breach notification, data protection impact assessments for high-risk processing, and registration for controllers and processors of major importance.

Nigeria NDPA the honest way: what actually matters
The NDPA is short on drama and long on the same disciplines GDPR made familiar, so if you have run a GDPR programme, most of this will feel like home. The point is not to memorise the Act. It is to be able to show, on any given day, that six things are true.
- You have a data protection officer where you need one. The Act requires appointing a DPO where applicable. Get the trigger conditions right, and document why you do or do not need one rather than leaving it unsaid.
- Every processing activity has a lawful basis. Before you collect or use personal data, you need a lawful basis for that processing, recorded and defensible, not chosen after the fact.
- Data subject rights are honoured in practice. People can exercise their rights over their data, so you need a route to receive, verify, and answer those requests within a sensible time.
- Breaches are notified, not buried. A personal data breach triggers a notification duty to the NDPC, which means you need detection, an assessment step, and a path to notify that you have actually tested.
- High-risk processing gets a DPIA. Where processing is likely to be high risk, you carry out a data protection impact assessment before you start, and you keep it on file.
- You register if you are of major importance. Controllers and processors of major importance must register with the NDPC, so the first job is to work out honestly whether you meet that bar.
None of these are one-off tasks. The regime, reinforced by the 2025 GAID, expects them to be live and evidenced, which is exactly why a checklist that carries owners and evidence beats a policy that carries only good intentions.

How to use the Nigeria NDPA Compliance Checklist
- Scope it. Decide which entities, systems, and processing activities the checklist applies to before you touch a single row.
- Assign owners. Give every row a named owner. Rows without an owner do not get done.
- Set status honestly. Mark each item Not started, In progress, or Done based on evidence you could show an auditor, not on optimism.
- Attach evidence. For every Done, link the record that proves it in the evidence column. A tick with no evidence is a wish.
- Work the gaps. Filter to Not started and In progress, put lawful basis, breach notification, and registration first, and set dates against each.
- Review on a cadence. Re-check quarterly and after any material change, because the 2025 GAID expects a living programme rather than a one-time audit.

Do this automatically in Venvera
A spreadsheet is a good start and a poor system of record. It does not remind anyone, it does not notice when evidence goes stale, and it does not know that the control you wrote for the NDPA is the same control your other obligations already ask for. Venvera keeps the same NDPA work current: obligations map to controls, evidence is collected and re-checked on a schedule, and a document you upload once is reused everywhere it applies instead of being pasted into five spreadsheets. If Nigeria is one of several regimes you answer to, the Venvera NDPA workspace turns this checklist into a living programme with owners, reminders, and audit-ready evidence, from EUR 399/month. Start with the free file, and move to Venvera when the spreadsheet starts fighting you.
Frequently Asked Questions
Is the NDPA compliance checklist really free?
Yes. Download the Excel workbook through the form above at no cost. There is no trial and no card required. Use it internally, share it with your team, and adapt the rows to your own processing.
Does the checklist cover the 2025 GAID as well as the NDPA?
Yes. The 60 items reflect both the Nigeria Data Protection Act 2023 and the 2025 General Application and Implementation Directive, because the GAID is how the NDPC expects the Act to be applied day to day.
Do I need to register with the NDPC?
You must register if you are a data controller or processor of major importance. The checklist includes a section to record the assessment and your decision, but the determination is yours to make against your actual processing.
We already comply with GDPR. Do we still need this?
Largely, yes. The NDPA maps closely onto GDPR-style practice, so much of your existing programme transfers. This checklist helps you confirm the Nigeria-specific duties, such as NDPC breach notification and registration of organisations of major importance, are covered rather than assumed.




