Start & structureBusinessNigeria
Comply with data protection (NDPA / NDPC)
Meet Nigeria Data Protection Act 2023 obligations: register with NDPC, appoint a Data Protection Officer, and (if processing 2,000+ data subjects/yr) file an annual Compliance Audit Report via a licensed DPCO.
- Procedure
- 3steps
- Coordination
- 3agencies
- Category
- Start & structureBusiness
Task links
Go to the exact next page
Application, requirements, forms, fees, and tracking are labelled separately.
Routing map
Who you will deal with
Nigeria Data Protection Commission (NDPC)Data Controller/ProcessorLicensed DPCO → NDPC
Procedure
The steps, in order
Each route below is scoped to the step it can actually complete.
01 Register with the NDPC
- Agency
- Nigeria Data Protection Commission (NDPC)
- What is required
- Register (or renew) with the NDPC on its portal and confirm the entity's data controller/processor classification.
- Documents
- Company details; processing description
- Typical timeline
- Registration stage
02 Appoint a Data Protection Officer (DPO)
- Agency
- Data Controller/Processor
- What is required
- Appoint or confirm a DPO and register their details with the NDPC; assemble a data inventory, privacy policies, consent mechanisms and processing register.
- Documents
- DPO details; data inventory; privacy policies
- Typical timeline
- Ongoing
03 File the annual Compliance Audit Report (CAR)
- Agency
- Licensed DPCO → NDPC
- What is required
- Organisations processing 2,000+ data subjects in 12 months must engage a licensed Data Protection Compliance Organisation (DPCO) to audit and file the CAR with the NDPC by the annual deadline (15 March; extensions have applied).
- Documents
- Compliance evidence; DPCO engagement
- Typical timeline
- Annual (by ~15 March)