Nigeria has moved from educating businesses about data protection to enforcing it. Here is what your obligations actually are — and what it takes to meet them in the systems your business already runs on.
Every Nigerian business holds personal data. Customer names and phone numbers. Bank details. BVN and NIN records. Employee files. Transaction histories. CCTV footage. For most organisations that data sits in Microsoft 365, Google Workspace, a CRM, a payment processor and a handful of spreadsheets nobody has audited in years.
Until recently, the consequences of handling that data badly were mostly theoretical. That is no longer the case. The Nigeria Data Protection Commission (NDPC) has shifted into active enforcement, and the regulatory framework now sets out specific, dated, auditable obligations — with financial penalties attached.
This guide explains what changed, who it applies to, what it costs to get it wrong, and — the part most articles skip — how the requirements translate into actual configuration in the cloud platforms you already pay for.
What changed: from the NDPR to the NDPA and GAID 2025
Three instruments matter, in this order:
- The Nigeria Data Protection Act (NDPA) 2023 — the primary legislation. It replaced the Nigeria Data Protection Regulation (NDPR) 2019 and established the NDPC as the regulator with statutory enforcement powers.
- The General Application and Implementation Directive (GAID) 2025 — issued on 20 March 2025 and effective from 19 September 2025. This is the operational rulebook: registration criteria, audit returns, Data Protection Officer requirements, breach notification, data protection impact assessments and cross-border transfer templates.
- Sector directives — regulators such as the CBN, NCC and NAICOM continue to issue their own data and cybersecurity requirements on top of the NDPA. If you are in financial services, telecoms or insurance, the NDPA is a floor, not a ceiling.
The practical takeaway: if your compliance documentation still references the NDPR, it is out of date. The NDPR ceased to apply once GAID took effect. Policies, privacy notices, vendor contracts and internal frameworks all need to be re-pointed at the NDPA and GAID.
Who has to register as a Data Controller or Processor of Major Importance?
GAID formalises a category called Data Controllers and Data Processors of Major Importance (DCPMI). If your organisation falls into it, you have obligations that ordinary controllers do not — registration with the NDPC, annual filings, and in some tiers a mandatory Data Protection Officer.
Designation turns on the volume and sensitivity of the personal data you process and the sector you operate in, and GAID sets out tiers (including Ultra-High Level and Extra-High Level categories) with different filing routes and fees. Organisations in banking, fintech, telecoms, health, education, insurance and large-scale e-commerce should assume they are in scope until confirmed otherwise.
Do not guess at your tier. The thresholds and fee schedule are set out in GAID and are updated by the Commission — confirm your classification against the current directive on the NDPC portal, or through a licensed Data Protection Compliance Organisation (DPCO).
What are the deadlines?
Two recurring obligations drive the compliance calendar:
Annual Compliance Audit Returns (CAR) — DCPMIs are required to file their CAR with the NDPC by 31 March each year, covering the preceding calendar year, in accordance with the applicable GAID requirements. Organisations in the Ultra-High and Extra-High tiers are subject to the requirement to engage a licensed DPCO for their compliance filing. Organisations established after 12 June 2023 are subject to the applicable first-filing timeline under the GAID.
Breach notification — Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the NDPC must be notified within 72 hours of the data controller becoming aware of the breach. Where the breach is likely to result in a high risk to affected data subjects, the organisation must also communicate the breach to the affected data subjects immediately, subject to the conditions provided by the NDP Act.
Practical point: although the NDPC may extend filing deadlines from time to time, organisations should not rely on extensions. Plan internally for the statutory 31 March deadline each year.
What are the penalties for non-compliance?
The NDPA gives the NDPC real teeth, and the Commission has been using them.
- For a data controller or processor of major importance: a fine of up to ₦10 million or 2% of annual gross revenue in the preceding financial year, whichever is greater.
- For a controller or processor not of major importance: ₦2 million or 2% of preceding-year annual gross revenue, whichever is greater.
- Late CAR filing attracts an administrative surcharge of up to 50% of the applicable filing fee, on top of any enforcement exposure.
- The Act also provides for enforcement orders and, in cases of wilful or negligent mishandling, criminal prosecution of responsible officers.
This is not hypothetical. By early 2026 the NDPC had concluded well over 200 breach investigations, taken a number of significant enforcement actions, and collected several billion naira in registration revenue and penalties. The Commission has stated publicly that 2026 marks a move into full enforcement, including against public sector bodies and higher education institutions.
What security measures does GAID actually require?
The NDPA requires appropriate technical and organisational measures. GAID makes that concrete by expecting risk-based, periodic compliance audits across people, processes and technology — and by expecting audits to be more frequent where personal data is accessible through online systems, precisely because the cyber risk is higher.
In practice, an auditor filing your CAR will be looking for evidence of:
- A current data inventory and data flow map — what you hold, why, where it sits, who can reach it, how long you keep it, and who you share it with
- Lawful basis documented for each processing activity, and privacy notices that match reality
- Access control on a least-privilege, role-based model, with privileged accounts separately governed
- Multi-factor authentication, enforced rather than optional
- Encryption in transit and at rest where appropriate to the risk
- Patch and update management across endpoints and servers
- Tested, recoverable backups — not just backups that run
- Logging and monitoring sufficient to detect and evidence an incident
- A documented incident response and breach notification procedure that can meet 72 hours
- Vendor and processor due diligence, with data processing terms in contracts
- Records of staff data protection and security training
- DPIAs for high-risk processing, and a documented basis for any cross-border transfer
Notice how much of that list is configuration, not paperwork. A business can have an immaculate privacy policy and still fail an audit because MFA was never enforced on legacy accounts, or because a shared drive containing customer ID documents is open to the whole organisation.
Mapping the requirements to Microsoft 365, Google Workspace and Adobe
This is where most compliance advice stops and implementation begins. The good news for most Nigerian businesses is that a large share of the required controls are already available in licences you hold — they are simply switched off, misconfigured, or unmonitored.
Microsoft 365
- Identity and access: Microsoft Entra ID for enforced MFA, Conditional Access policies that restrict access by device, location and risk, and Privileged Identity Management for time-bound admin rights.
- Data discovery and classification: Microsoft Purview to find where personal data actually lives across Exchange, SharePoint, OneDrive and Teams, then apply sensitivity labels and data loss prevention rules — this is the fastest route to a defensible data inventory.
- Retention: Purview retention labels and policies to enforce the storage limitation principle instead of keeping everything forever.
- Threat protection and evidence: Microsoft Defender for Office 365 and Defender for Cloud Apps for phishing and anomalous-access detection, with the unified audit log providing the trail an incident report depends on.
- Devices: Microsoft Intune for device compliance, encryption enforcement and remote wipe on lost or stolen endpoints.
Google Workspace
- Identity and access: enforced 2-Step Verification, security keys for administrators, and Context-Aware Access to condition access on device posture and location.
- Data protection: DLP rules for Gmail and Drive, Drive sharing restrictions and trust rules to stop customer data being shared outside the domain by default.
- Retention and investigation: Google Vault for retention policies, legal hold and eDiscovery; the security investigation tool and admin audit logs for incident evidence.
- Devices: endpoint management with encryption and screen-lock enforcement.
Adobe
- Adobe Admin Console with SSO and enterprise identity, so document access is governed alongside everything else rather than sitting in personal accounts.
- Acrobat Sign audit trails and identity verification, which are useful evidence for consent and contract records.
A note on data residency and cross-border transfers
The NDPA restricts transfers of personal data outside Nigeria to specific lawful mechanisms, and GAID provides templates and guidance for them. Most global cloud platforms will store or process at least some of your data outside Nigeria, and the major providers do not currently offer a Nigerian data region for these services.
That does not make cloud adoption non-compliant — it makes it something you must document. You need to know which service stores data where, which regional or data-location controls your licence tier actually supports, what contractual protections your provider offers, and which transfer mechanism under the NDPA you are relying on. This is one of the most common gaps we see in audit preparation, and one of the easiest to close before a filing rather than after a query from the Commission.
Your people remain the largest single risk
Most reportable incidents do not begin with a sophisticated intrusion. They begin with an employee forwarding a customer list to a personal Gmail account to work on at home, reusing a password that appeared in a breach three years ago, approving an MFA prompt they did not initiate, or clicking a convincing invoice attachment.
Technical controls reduce the blast radius, but they do not remove the need for training — and GAID expects evidence that training happened.
Practical steps: run simulated phishing campaigns, train new joiners during onboarding rather than annually, make the reporting route for a suspected incident obvious and blame-free, and keep dated attendance records. That last point matters more than it sounds; undocumented training is, for audit purposes, training that did not occur.
A seven-point readiness check
Before your next filing, work through these carefully:
- Do we have a current, written inventory of the personal data we hold, and can we produce it on request?
- Are we registered with the NDPC, and do we know our correct DCPMI classification?
- Is MFA enforced on every account, including service accounts, shared mailboxes and long-tenured admin logins?
- Could we detect a breach, assemble the required detail and notify the NDPC within 72 hours — and has anyone tested that?
- Do our privacy notices describe what we actually do with data, rather than what a template said?
- Have we carried out due diligence on the third parties that process personal data on our behalf, with data processing terms in the contracts?
- Do we know where each category of personal data is physically stored, and on what lawful basis it leaves Nigeria?
If more than two of those produce an uncomfortable pause, you have a gap to close before 31 March — not a document to write, but a set of controls to configure and evidence.
Compliance is a business requirement, not a filing exercise
It is tempting to treat data protection as an annual scramble ahead of a deadline. That approach is expensive in three ways: it produces evidence that does not survive scrutiny, it leaves the underlying security weaknesses in place, and it ignores the commercial reality that enterprise customers, banks and international partners increasingly ask about your data protection posture before they sign anything.
Built into everyday operations, the same work becomes an asset. Clean access controls reduce insider risk. A real data inventory shortens every future audit, tender response and due diligence questionnaire. Tested backups and incident procedures reduce downtime when something does go wrong.
The question is no longer whether Nigerian businesses need to worry about data protection. It is how well you can demonstrate — with evidence, on a deadline — that you are protecting what your customers have trusted you with.
Frequently asked questions
Is the NDPR still in force in Nigeria?
No. The NDPR 2019 was superseded by the Nigeria Data Protection Act 2023, and once the General Application and Implementation Directive (GAID) 2025 took effect on 19 September 2025 the NDPR ceased to apply as the operative administrative instrument. Actions validly taken under the NDPR before that point remain valid, but current compliance should be built against the NDPA and GAID.
When must Compliance Audit Returns be filed with the NDPC?
Data controllers and processors of major importance must file annually on or before 31 March, covering the previous calendar year. Ultra-High Level and Extra-High Level entities must file through a licensed Data Protection Compliance Organisation. Late filing attracts an administrative surcharge of up to 50% of the applicable filing fee. The Commission has occasionally extended the deadline, but extensions are discretionary.
How long do I have to report a data breach in Nigeria?
The NDPC must be notified within 72 hours of the organisation becoming aware of a personal data breach, with the incident details prescribed under GAID. Where the breach poses a systemic or public risk, relevant authorities should be notified immediately, and affected data subjects may also need to be informed.
What is the maximum fine under the Nigeria Data Protection Act?
For a data controller or processor of major importance, up to ₦10 million or 2% of annual gross revenue in the preceding financial year, whichever is greater. For entities not of major importance, ₦2 million or 2% of preceding-year annual gross revenue, whichever is greater. Enforcement orders and criminal prosecution of responsible officers are also available to the Commission.
Do we need a Data Protection Officer?
GAID requires the appointment of a Data Protection Officer in defined circumstances, principally for data controllers and processors of major importance. The Commission has also introduced verification and continuing professional development requirements for DPOs, so the role cannot simply be added to an IT manager’s job title without further steps.
Can we use Microsoft 365 or Google Workspace and still comply with the NDPA?
Yes, provided the transfer of personal data outside Nigeria is documented and rests on a lawful mechanism under the Act, and provided the platform controls are actually configured. Both platforms include capabilities that map directly onto GAID’s expectations around access control, encryption, retention, logging and data loss prevention — but those capabilities do not enforce themselves, and default tenant settings are rarely sufficient.
Does compliance apply to small businesses?
The NDPA applies to any organisation processing personal data in Nigeria. Registration, DPO and audit-filing obligations are targeted at controllers and processors of major importance, so a small business may fall outside those specific duties — but the core obligations around lawful processing, transparency, data subject rights and security still apply.






