← All operating procedures
Start & structureBusinessNigeria

Comply with data protection (NDPA / NDPC)

Meet Nigeria Data Protection Act 2023 obligations: register with NDPC, appoint a Data Protection Officer, and (if processing 2,000+ data subjects/yr) file an annual Compliance Audit Report via a licensed DPCO.

Procedure
3steps
Coordination
3agencies
Category
Start & structureBusiness
Task links

Go to the exact next page

Application, requirements, forms, fees, and tracking are labelled separately.

Routing map

Who you will deal with

Nigeria Data Protection Commission (NDPC)Data Controller/ProcessorLicensed DPCO → NDPC
Procedure

The steps, in order

Each route below is scoped to the step it can actually complete.

  1. 01

    Register with the NDPC

    Agency
    Nigeria Data Protection Commission (NDPC)
    What is required
    Register (or renew) with the NDPC on its portal and confirm the entity's data controller/processor classification.
    Documents
    Company details; processing description
    Typical timeline
    Registration stage
  2. 02

    Appoint a Data Protection Officer (DPO)

    Agency
    Data Controller/Processor
    What is required
    Appoint or confirm a DPO and register their details with the NDPC; assemble a data inventory, privacy policies, consent mechanisms and processing register.
    Documents
    DPO details; data inventory; privacy policies
    Typical timeline
    Ongoing
  3. 03

    File the annual Compliance Audit Report (CAR)

    Agency
    Licensed DPCO → NDPC
    What is required
    Organisations processing 2,000+ data subjects in 12 months must engage a licensed Data Protection Compliance Organisation (DPCO) to audit and file the CAR with the NDPC by the annual deadline (15 March; extensions have applied).
    Documents
    Compliance evidence; DPCO engagement
    Typical timeline
    Annual (by ~15 March)
Start & structure