InsightsData & Compliance

Data Protection and Compliance Under the NDPA – What Your Business Must Know

By Geraldine Raphael-Usuomon, Co-Founding Partner ~4 minutes

Target Audience: Business owners, compliance officers, data protection officers, multinational companies

Introduction

Data protection in Nigeria has undergone a significant transformation. The Nigeria Data Protection Act (NDPA) 2023 established a comprehensive legal framework for the processing of personal data, replacing the earlier Nigeria Data Protection Regulation (NDPR) 2019.

The most recent development is the General Application and Implementation Directive (GAID) 2025, issued by the Nigeria Data Protection Commission (NDPC) on 20 March 2025. The GAID took effect on 19 September 2025 and, from that date, the NDPR 2019 ceased to be applicable.

This article outlines the key compliance obligations every business operating in Nigeria must understand.

1. Classification, Registration, and Audits

Organisations designated as Data Controllers/Processors of Major Importance (DCPMIs) must register with the NDPC. DCPMIs are classified into three tiers—Ultra-High, Extra-High, and Ordinary-High Level—based on specific criteria.

Key Obligations for DCPMIs:

  • Complete an initial data protection audit within 15 months of registration
  • Submit annual Compliance Audit Returns (CARs) thereafter
  • Pay tiered filing fees introduced under the new directive

2. Appointment of Data Protection Officers (DPOs)

DCPMIs must appoint qualified Data Protection Officers, supported by associate DPOs or privacy champions. These entities are also required to submit internal compliance reports semi-annually.

3. Strengthened Data Subject Rights and Redress Mechanisms

The GAID introduces several enhancements to protect data subjects:

  • Clear, accessible privacy notices are now mandatory
  • A Standard Notice to Address Grievance (SNAG) enhances internal complaint resolution processes for data subjects

4. Data Protection Impact Assessments (DPIAs)

DPIAs are now mandatory for high-risk processing activities, particularly where:

  • Emerging technologies (such as blockchain and IoT) are involved
  • Sensitive personal data is being processed

5. Cross-Border Transfers and Consent

All data transfers outside Nigeria require either:

  • Adequate safeguards, or
  • Prior approval from the NDPC

6. Semi-Annual Data Protection Reports

A Semi-Annual Data Protection Report must be prepared by the DPO, outlining the organisation's compliance status under the NDPA. This report should be incorporated into the organisation's Record of Processing Activities (RoPA) and is subject to verification by a licensed Data Protection Compliance Organisation (DPCO) during the annual compliance audit.

7. Compliance Schedules

Organisations must create detailed Schedules of Compliance, serving as structured roadmaps outlining:

  • Each NDPA obligation
  • Required actions
  • Responsible personnel
  • Specific timelines for implementation

Consequences of Non-Compliance

The NDPA and GAID significantly raise the bar for data governance across both public and private sectors. Non-compliance can result in substantial fines, regulatory sanctions, and reputational damage. Organisations that fail to meet their obligations risk enforcement action from the NDPC.

Conclusion

The transition from the NDPR to the NDPA and GAID represents a major shift in Nigeria's data protection landscape. Businesses must act now to ensure compliance—conducting audits, appointing DPOs, updating privacy policies, and implementing robust data governance frameworks.

At RG Castle Law Firm, we advise clients on data protection compliance, helping organisations navigate the complexities of the NDPA, GAID, and related regulations to protect both their business and their customers' data.

By Geraldine Raphael-Usuomon, Co-Founding Partner

Geraldine Raphael-Usuomon is a Co-Founding Partner at RG Castle Law Firm, Abuja. She specializes in corporate governance, regulatory compliance, and data protection. She holds certifications in Negotiation, Forensic Studies, and Human Resources (University of Minnesota), and is awaiting her ICSAN results. She is also a certified Microsoft Security Essentials professional.