Data Protection & NDPC Compliance Advisory.
The Nigeria Data Protection Act (NDPA) 2023 turned every controller into a regulated entity overnight. Our dedicated NDPC practice — leadership-led, audit-grade, breach-ready — opens its books to new clients from Q1 2026.
What the launch practice will cover
- NDPA 2023 gap assessments
- Data Protection Impact Assessments (DPIA)
- NDPC annual audit filings
- Data Protection Compliance Organisation (DPCO) appointment
- 72-hour breach response playbooks
- Cross-border transfer safeguards
- Data subject rights operationalisation
- Board and staff NDPA training
Early-access clients get a complimentary NDPA gap assessment.
Limited to the first twenty controllers who join the list. Leadership-led, delivered before Q2 2026.
Reserve your slotNigeria Data Protection Commission (NDPC): NDPA 2023 and Privacy Governance
The Nigeria Data Protection Commission (NDPC) oversees data protection in Nigeria under the Nigeria Data Protection Act (NDPA) 2023. Organisations that collect or process personal data typically need appropriate privacy governance, and NDPA principles align closely with globally recognised data protection standards.
What it covers
- Lawful processing of personal data under the NDPA 2023
- Data Protection Impact Assessments (DPIA)
- Privacy governance and documentation
- Personal data breach handling and reporting
- Appointment of a data protection officer where relevant
- Filing or registration obligations that may apply to certain organisations
Common obligations
- Establishing a lawful basis for processing
- Maintaining privacy notices and policies
- Conducting DPIAs where relevant
- Breach reporting within applicable timelines
- Registration or compliance filing where applicable
Depending on the entity's structure, sector, location and data processing activities, obligations may apply.
Whether — and how — registration or filing obligations apply will depend on the organisation's processing activities and current NDPC guidance, which should be confirmed directly.
Who may need support
Data protection leads, DPOs, compliance officers, technology and product teams, founders, and organisations handling significant volumes of personal data.
How Outliers Professionals can help
We support clients with data protection readiness, DPIA and policy documentation, governance frameworks, review and advisory guidance aligned with the NDPA 2023 and recognised international practice. We are not a regulator and cannot guarantee registration, acceptance or a specific outcome. Businesses should confirm applicable obligations with the NDPC or a professional adviser.
Related on Outliers Professionals
Nigeria Data Protection Commission (NDPC): A Practical Guide to NDPA 2023 Compliance
The Nigeria Data Protection Commission (NDPC) regulates how organisations handle personal data in Nigeria. Its framework aligns closely with globally recognised data protection principles, so building good privacy governance both meets local obligations and supports international interoperability. Whether specific registration or filing duties apply depends on an organisation's processing activities and current NDPC guidance.
Relevant laws and official guidance
The primary law is the Nigeria Data Protection Act (NDPA) 2023. The NDPA received presidential assent on 12 June 2023 and established the independent NDPC, consolidating the earlier NDPR 2019 approach into a statutory framework. Operational detail comes from the GAID: the General Application and Implementation Directive (GAID) 2025 was issued on 20 March 2025 and became effective on 19 September 2025, covering registration, compliance audits, DPOs, breach notification, DPIAs, cross-border transfers and categories of Data Controllers/Processors of Major Importance. Because classification and filing turn on the GAID's schedules, map your activities to the current guidance rather than assuming a fixed trigger.
Who the obligations may apply to
Depending on the nature, scale and sensitivity of processing, this may apply to a wide range of organisations that collect or process personal data, with heavier obligations for those classified as Data Controllers/Processors of Major Importance (DCPMIs). Under the GAID, only Data Controllers and Processors of Major Importance are required to file Compliance Audit Returns, and ultra-high and extra-high level entities must file through a licensed Data Protection Compliance Organisation. Whether an organisation falls into these categories depends on its processing activities and current NDPC guidance.
Basic compliance expectations
In general terms, organisations are expected to establish a lawful basis for processing, maintain clear privacy notices and policies, uphold data-subject rights, conduct DPIAs for higher-risk processing, appoint a DPO where relevant, and handle breaches properly. Data controllers must notify the Commission within 72 hours of becoming aware of a personal data breach, and notify affected individuals immediately where the breach is likely to result in high risk. DPIAs are required for high-risk processing and, in defined cases, must be submitted to the Commission within set timelines.
Common filings and submissions
Depending on classification, these may include registration with the NDPC as a DCPMI, filing of Compliance Audit Returns (via a licensed DPCO for the higher categories), breach notifications, and DPIA submissions where required. Whether registration or CAR filing applies depends on the organisation's processing activities and current NDPC guidance.
Documents or records usually required
Typically: a record of processing activities (ROPA), privacy notices and policies, DPIA reports where relevant, a data protection agreement framework for processors, breach records and response procedures, DPO appointment details, and evidence of staff awareness measures.
Practical readiness checklist
- Map your processing activities and assess whether you may be a DCPMI under current NDPC guidance.
- Confirm a lawful basis for each processing purpose and document it.
- Maintain a ROPA and keep privacy notices current.
- Establish a DPIA process for higher-risk or new processing.
- Put a breach-response plan in place that can meet the 72-hour notification expectation.
- Confirm whether you need a DPO and, for higher categories, a licensed DPCO for filings.
Common mistakes to avoid
Assuming the NDPA does not apply because you are small or online-only; relying on outdated NDPR-era assumptions; treating consent as the only lawful basis; skipping DPIAs for high-risk processing; and lacking a breach plan that can act within 72 hours. Confirm your specific obligations with the NDPC or a qualified adviser.
How Outliers Professionals can support
We support clients with data protection readiness, DPIA and policy documentation, governance frameworks, review and advisory guidance aligned with the NDPA 2023 and recognised international practice. We are not a regulator and cannot guarantee registration, acceptance or a specific outcome.
