Data Protection

Nigeria's data protection obligations, mapped to what actually applies to you.

Blaecwood is a licensed Data Protection Compliance Organisation. We assess how your organisation processes personal data, document the gaps against the NDPA 2023 and applicable NDPC guidance, and prepare the record your filing depends on.

The classification check is an indicative self-assessment. It is not an NDPA compliance audit and does not constitute a compliance opinion.

The requirement

What the NDPA asks of you depends on how you are classified.

The Nigeria Data Protection Act 2023 and applicable NDPC guidance require qualifying data controllers and processors of major importance to meet applicable audit, registration and reporting obligations. Depending on classification and processing activity, this may include an annual Compliance Audit Return. High-risk processing may also require a Data Protection Impact Assessment. The Compliance Audit Report must be prepared with a licensed Data Protection Compliance Organisation before it reaches the Nigeria Data Protection Commission.

Whether any of this applies to your organisation, and in what form, depends on how the NDPC classifies it. That is the first question worth answering, and it is the one most organisations skip.

Section 48 of the Act sets the enforcement context: for data controllers and processors of major importance, a remedial fee of up to ₦10,000,000 or 2% of gross revenue, whichever is greater. That is the statutory ceiling written into the Act, not a prediction about any particular organisation.

Who this is for

  • Fintechs and payment companies processing Nigerian personal data at scale
  • Organisations the NDPC may classify as data controllers or processors of major importance
  • Platforms launching a product that changes what personal data they collect
  • Teams with a privacy policy on the site and no data map behind it
  • Groups processing Nigerian data from outside Nigeria

Engage when

  • You do not know which NDPC classification applies to you
  • A reporting obligation or registration renewal is approaching
  • New processing looks likely to require a DPIA
  • A partner, bank or enterprise customer has asked how you handle personal data
  • A previous filing was prepared without a data map behind it
  • A personal data breach has exposed a gap in your records

What Blaecwood does

  1. 01
    Data Mapping and Gap Assessment
    We review your data flows, lawful bases, consents, third-party transfers and retention against applicable NDPA requirements, and document each gap with the evidence behind it so your team can prioritise remediation.
  2. 02
    Compliance Audit Report
    Where a Compliance Audit Return applies to your organisation, we prepare the report with you as a licensed DPCO, to the NDPC's format and evidentiary standard. The formal audit, Verification Statement and filing are contracted separately.
  3. 03
    DPIA for High Risk Processing
    For processing likely to result in high risk to data subject rights, we document the assessment: the processing described, the risks identified, and the mitigations your team records against each one, before the processing goes live.
  4. 04
    Policies and Consent Framework
    We draft privacy notices, consent language and retention schedules that describe what your product actually does rather than a template. Your team implements the flows, the systems changes and the retention rules.
  5. 05
    Ongoing Filing Support
    We track the reporting obligations that apply to you and refresh the documentation as your processing changes, so the next filing window is prepared for rather than discovered late.

Filing deadlines, as the NDPC has set them

The NDPC's General Application and Implementation Directive sets the annual Compliance Audit Return deadline at 31 March, within a 15-month window from the start of the reporting obligation.

Organisations in the lower "other" tier renew their registration rather than filing a Compliance Audit Return. The two are different obligations, and being in the wrong one is a common and expensive assumption.

Which of these applies to your organisation, and from what date, depends on how the NDPC classifies it. We do not quote a filing date we cannot source to the GAID, and we will tell you plainly when a date circulating in the market is unverified.

Start with the classification. The rest follows from it.

Check your NDPA classification

The classification check is an indicative self-assessment. It is not an NDPA compliance audit and does not constitute a compliance opinion.

Book a Call

Why Blaecwood

  • Licensed Data Protection Compliance Organisation · NDPC/DPCO/17469
  • Documentation prepared to the NDPC's format and evidentiary standard
  • Assessment of how personal data is actually processed, not policy-only consulting
  • Human review for every material privacy conclusion
  • Privacy, cloud security and assurance-readiness capability in one delivery model

Assurance note

Readiness work does not guarantee a licence, certification, audit result or partner decision. Blaecwood's advisory and readiness work is separate from its DPCO assurance work.

The formal NDPA compliance audit, DPCO Verification Statement and Compliance Audit Return filing are contracted separately, with separate scope and review. SOC 2 examinations are performed by an eligible independent CPA or equivalent. PCI DSS validation follows the applicable SAQ, ASV or QSA route.