For businesses operating in Nigeria’s digital economy, collecting personal information is often unavoidable. Banks need customer details to provide financial services, employers process employee records, fintechs handle financial and identity information, hospitals manage patient records, and online businesses collect information to deliver products and services.
But collecting personal data also comes with legal responsibilities.
The Nigeria Data Protection Commission (NDPC) is the regulator responsible for overseeing Nigeria’s data protection framework, and organisations that fall within the category of Data Controllers and Data Processors of Major Importance (DCPMIs) have registration obligations under the Nigeria Data Protection Act 2023.
The registration process is more than an administrative requirement. It is part of the system through which the NDPC identifies organisations carrying out significant data-processing activities and brings them under regulatory oversight.
The Commission’s current Data Controller/Processor Registration service provides the platform for registration, while its NDP Act 2023 and subsequent regulatory guidance establish the legal and compliance framework organisations must follow.
So, who actually needs to register, what information is required, what happens after registration, and does registration mean a business is automatically compliant?
Before looking at the registration process, it helps to understand what the NDPC does and why it matters to Nigerians and businesses.
What is NDPC registration?
NDPC registration is the process through which qualifying data controllers and data processors register with the Nigeria Data Protection Commission.
The legal basis for the requirement is found in Section 44 of the Nigeria Data Protection Act 2023. The Act requires a data controller or data processor of major importance to register with the Commission and provide information about its identity, data-processing activities and safeguards.
This information can include the organisation’s name and address, details of its Data Protection Officer, the categories and volume of personal data it processes, the purposes for which the data is processed, recipients of the data, processors engaged by the organisation, countries to which personal data may be transferred and a general description of the security measures and risks associated with its processing activities.
The purpose is not simply to create a database of companies.
Registration gives the regulator visibility into organisations carrying out significant data-processing activities and creates a formal point of accountability between those organisations and the regulator.
The NDPC’s 2024 Annual Report describes DCPMI registration as a regulatory requirement under the NDP Act for organisations that process significant volumes of personal data or operate in critical sectors.
Who needs to register with the NDPC?
One of the most important things to understand is that the registration requirement is not simply a rule that every business in Nigeria must register regardless of what it does with personal data.
The NDP Act specifically places the registration obligation on Data Controllers and Data Processors of Major Importance.
A data controller is an organisation or person that determines the purposes and means of processing personal data. A data processor processes personal data on behalf of a data controller.
For example, a fintech that determines why and how its customers’ personal information is processed may be a data controller. A third-party technology provider processing that information on behalf of the fintech may be a data processor, depending on the nature of the relationship.
The NDPC’s current framework classifies DCPMIs according to the scale and nature of their processing activities.
The Commission’s updated Guidance Notice on the Registration of Data Controllers and Data Processors identifies three categories:
- Ultra-High Level (UHL)
- Extra-High Level (EHL)
- Ordinary-High Level (OHL)
The classification is not based solely on the number of people whose data an organisation processes. The NDPC considers factors including the sensitivity of the data, financial assets entrusted to the organisation, reliance on third-party or cloud infrastructure, cross-border data flows and the potential impact of processing on data subjects.
That distinction matters for businesses because having a particular number of customers is only one part of determining where an organisation falls within the regulatory framework.
Be the first to get top stories, insights, trends, events, and conversations shaping the future of tech and innovation across Africa, and beyond.
What are OHL, EHL and UHL?
The NDPC’s tiered approach is designed to apply different levels of regulatory oversight according to the nature and scale of data processing.
According to the Commission’s 2026 International Journal of Data Privacy and Protection, the categories include the following broad thresholds:
| Category | Broad threshold | Registration fee | Continuing requirement |
|---|---|---|---|
| Ordinary-High Level (OHL) | Among other factors, processing personal data of more than 200 data subjects | ₦10,000 | Annual registration renewal |
| Extra-High Level (EHL) | Among other factors, processing personal data of more than 1,000 data subjects | ₦100,000 | Annual Compliance Audit Return |
| Ultra-High Level (UHL) | Among other factors, processing personal data of more than 5,000 data subjects | ₦250,000 | Annual Compliance Audit Return and applicable processing activity fees |
These figures and requirements are drawn from the NDPC’s published regulatory materials and should not be interpreted as a simple customer-count test. The Commission’s guidance includes additional factors for determining the appropriate category.
For UHL controllers, the Commission’s guidance also provides for a ₦5,000 data-processing activity fee for each processor engaged for applicable processing activities within 12 months.
Because regulatory guidance can be updated, organisations should check the NDPC’s current registration guidance before making a filing or payment.
What information does an organisation need to provide?
Registration requires an organisation to provide the Commission with information that allows it to understand who is processing the data and what that processing involves.
Under Section 44 of the NDP Act, this includes information such as:
Organisation details
The organisation must provide identifying information about the data controller or processor, including its name and address.
Data Protection Officer information
The organisation must provide information about its Data Protection Officer.
The DPO has an important role in an organisation’s internal data protection governance. The NDPC’s current guidance reinforces the DPO as an accountability mechanism and provides for notification of DPO appointments to the Commission.
Categories of personal data
The organisation must identify the categories and volume of personal data it processes.
This could include information such as names and contact details, identification information, financial information, employment records, health information or other categories depending on the organisation’s activities.
Categories of data subjects
The organisation also needs to identify the people whose data it processes.
These may include customers, employees, job applicants, students, patients, suppliers or other individuals.
Purpose of processing
The organisation must explain why it processes personal data.
This is important because data protection is not simply about knowing what information a company holds. Organisations must also be able to explain the purposes for which the information is being processed.
Data recipients and processors
The registration information includes details about who receives the data and the processors involved in processing it.
This makes third-party data handling an important part of the registration and compliance process.
International data transfers
Organisations must also account for countries to which personal data may be transferred.
This is particularly relevant to Nigerian businesses using international cloud platforms, software providers and other technology infrastructure.
Risks and safeguards
The organisation must provide a general description of the risks associated with its processing activities and the measures it has taken to address those risks.
This connects registration directly to the organisation’s wider data protection and information-security practices.
The requirements are set out in Section 44 of the NDP Act 2023.
How do you register with the NDPC?
The NDPC operates an online Information Management Portal (NIMP) for e-registration, enquiries and payments.
The portal currently provides a Data Controller/Processor registration option and asks applicants to provide organisational information as part of the registration process.
For an organisation preparing to register, the process can broadly be approached in the following stages.
1. Determine whether your organisation falls within the registration framework
Before submitting anything, the organisation should assess whether it qualifies as a Data Controller or Data Processor of Major Importance.
This means looking beyond the number of customers or users and considering the nature, sensitivity and scale of the organisation’s data-processing activities.
The NDPC’s classification guidance should be used for this assessment.
2. Determine your applicable classification
If the organisation falls within the DCPMI framework, it should determine whether it falls within the OHL, EHL or UHL category.
This classification matters because it affects the applicable registration fee and continuing compliance obligations.
For example, OHL organisations have an annual renewal obligation, while EHL and UHL organisations are required to file Compliance Audit Returns annually.
3. Prepare your registration information
The organisation should gather the information required under Section 44 of the NDP Act.
This means understanding the organisation’s data flows before starting the registration process.
A business should know:
- What personal data it collects
- Whose data it processes
- Why it processes the data
- Where the data is stored
- Who can access it
- Which third parties process it
- Whether information is transferred outside Nigeria
- What safeguards protect the information
- Who is responsible for data protection internally
Preparing these details in advance can make the registration process more straightforward and can also reveal compliance gaps that need to be addressed.
4. Submit the registration through the NDPC portal
The NDPC’s Information Management Portal provides the Commission’s online registration service.
Organisations should provide accurate information rather than treating registration as a formality. The information submitted should reflect the organisation’s actual processing activities.
5. Pay the applicable fee
The applicable registration fee depends on the organisation’s classification.
The current published framework identifies ₦10,000 for OHL, ₦100,000 for EHL and ₦250,000 for UHL registration, with an additional data-processing activity fee applicable to UHL controllers for processors they engage in relevant circumstances.
Organisations should verify the applicable amount on the NDPC’s current portal before making payment because regulatory fees and procedures can change.
6. Keep the information submitted to the Commission accurate
Registration does not mean the organisation can forget about its filing.
Section 44 of the NDP Act requires significant changes to information supplied during registration to be communicated to the Commission within 60 days.
That means a business should treat its registration information as something that needs to be maintained as its data-processing activities change.
Does NDPC registration mean an organisation is compliant?
No.
This is probably the most important distinction in the entire registration process.
Being registered with the NDPC does not automatically mean that an organisation has satisfied every requirement under the Nigeria Data Protection Act.
Registration is one part of a wider compliance framework.
An organisation can be registered and still have problems with how it collects, stores, shares or protects personal data.
The NDPC’s own regulatory materials distinguish registration from other compliance activities, including privacy breach reporting, compliance audits and other regulatory responsibilities. The Commission also provides separate services for filing audit returns and maintains lists of registered DCPMIs and licensed DPCOs.
For businesses, this distinction is critical.
A registration certificate should not be treated as proof that every internal data-processing practice is compliant.
What responsibilities continue after registration?
Once an organisation is registered, it still has ongoing responsibilities under the NDP Act and applicable regulatory guidance.
1. Protect personal data
Organisations remain responsible for putting appropriate technical and organisational measures in place to protect personal data.
The NDPC’s current framework emphasises accountability, security and responsible processing rather than simply documenting compliance.
2. Respect data-subject rights
Registration does not remove the organisation’s responsibility to respond appropriately when individuals exercise their rights under the NDP Act.
Depending on the circumstances, these can include rights relating to access, rectification, objection, restriction, erasure and data portability.
3. Maintain appropriate records and governance
An organisation should understand its data-processing activities and be able to demonstrate how it complies with applicable requirements.
This includes knowing what information it holds, why it holds it, who processes it and what safeguards are in place.
4. Manage third-party processors carefully
Using a vendor or technology provider does not automatically transfer the organisation’s data-protection responsibilities to that vendor.
The NDPC’s 2025 General Application and Implementation Directive (GAID) includes due-diligence expectations around engaging data processors, including data-processing agreements, ongoing compliance monitoring, storage and transfer safeguards, incident-response protocols and other measures.
This is particularly important for businesses that depend on cloud services, SaaS platforms, payment providers, CRM systems or other external technology providers.
5. Manage data breaches appropriately
If personal data is compromised, an organisation may have obligations relating to the incident regardless of whether it is already registered.
This is one reason registration should not be confused with compliance. The organisation needs an operational process for identifying, containing, assessing and responding to privacy and security incidents.
For more context on the relationship between data protection and cybersecurity incidents in Nigeria, see Techsoma’s earlier analysis, Nigeria’s data breach claims exposed a critical cybersecurity coordination gap.
6. Meet applicable audit requirements
The continuing obligations differ according to classification.
The NDPC currently states that EHL and UHL organisations register once but file Compliance Audit Returns annually, while OHL organisations renew their registration annually but do not file CAR.
The NDPC FAQ states that Compliance Audit Returns are filed through a licensed Data Protection Compliance Organisation.
This means organisations need to understand not only how to register but also what their category requires after registration.
What is a Compliance Audit Return?
A Compliance Audit Return, commonly called a CAR, is part of the NDPC’s continuing regulatory oversight.
The NDPC FAQ states that Data Controllers are expected to file their audit returns annually before 31 March each year under the relevant provisions of the NDP Act and GAID 2025.
These returns are filed through licensed Data Protection Compliance Organisations (DPCOs). Learn more about what DPCOs do and how they support organisations with data-protection compliance.
The Commission also states that CARs are filed through a licensed Data Protection Compliance Organisation.
This creates an important distinction between the different categories of DCPMIs.
An EHL or UHL organisation cannot simply register and assume that its regulatory obligations have ended. It must maintain the compliance processes necessary to support its annual return.
For an OHL organisation, the current framework instead provides for annual registration renewal without the CAR requirement applicable to EHL and UHL organisations.
What role does the Data Protection Officer play?
The Data Protection Officer is another important part of an organisation’s compliance structure.
The NDP Act provides for the appointment of DPOs, and the NDPC’s current guidance places emphasis on their independence, reporting responsibilities and access to relevant processing activities.
The Commission’s 2026 publication explains that DPOs are expected to have access to personal data and processing activities relevant to their responsibilities, while maintaining confidentiality. It also states that organisations must notify the Commission of DPO appointments and that DPOs have structured internal reporting responsibilities.
For businesses, this means the DPO should not simply be someone whose name is placed on a registration form.
The role should have enough organisational access and authority to identify data protection issues, advise management and monitor compliance.
What happens if an organisation fails to comply?
The NDP Act gives the NDPC enforcement powers, and non-compliance can have financial, legal and operational consequences.
According to the Commission’s FAQ, a breach of data privacy can result in administrative and criminal sanctions, while data subjects can also bring civil actions in appropriate circumstances.
Section 48 of the NDP Act provides for remedies that can include an order requiring an organisation to remedy a violation, compensation to a data subject, an order to account for profits arising from a violation or a remedial fee.
For a Data Controller or Data Processor of Major Importance, the Act provides for a maximum remedial fee of the greater of ₦10 million or 2% of annual gross revenue from the preceding financial year. For a controller or processor that is not of major importance, the maximum is the greater of ₦2 million or 2% of annual gross revenue from the preceding financial year.
These are maximum figures under the relevant provision, not an automatic fine that every organisation receives for every compliance failure.
The consequences can also extend beyond a financial sanction. The NDPC identifies potential business consequences including reputational damage, loss of customers and difficulties relating to international market opportunities.
Why does NDPC registration matter to businesses?
It can be tempting to view registration as another regulatory form that businesses have to complete.
But the significance is broader.
Registration encourages organisations to answer fundamental questions about their data practices.
What personal information do we hold?
Why are we collecting it?
Who has access to it?
Which vendors process it for us?
Where is the information stored?
Is it transferred outside Nigeria?
What risks does the processing create?
What safeguards are protecting it?
Those questions are central to responsible data governance.
The NDPC’s 2025 Annual Report states that more than 38,000 entities had been placed under regulatory oversight through DCPMI registration by the end of 2025, describing the increase as strengthening accountability and transparency in data processing.
That scale also shows why registration is becoming an increasingly important part of doing business in Nigeria’s digital economy.
Registration is the beginning of compliance, not the end
For organisations that fall within the DCPMI framework, registering with the NDPC is an important regulatory obligation.
But the certificate or registration status itself is not a guarantee that an organisation has satisfied all of its data protection responsibilities.
The real work happens in the organisation’s day-to-day operations: how it collects personal information, how it obtains and manages lawful processing grounds, how it protects data, how it handles data-subject requests, how it manages vendors, how it responds to breaches and how it demonstrates accountability.
The NDPC’s regulatory framework increasingly reflects this broader approach.
Its current Information Management Portal provides registration and related services, while the Commission separately provides mechanisms for privacy breach reporting, compliance audits, DPCO licensing and access to the official register of Data Controllers and Processors of Major Importance.
For a business, therefore, the right question is not simply:
“Are we registered with the NDPC?”
It is:
“Can we demonstrate that the way we collect and process personal data complies with Nigeria’s data protection framework?”
That is the bigger responsibility that comes with operating in a data-driven economy.
Final thoughts
Nigeria’s data protection regime is becoming important as businesses collect more information and move more services online.
The NDPC registration requirement provides a formal mechanism for bringing qualifying Data Controllers and Data Processors of Major Importance under regulatory oversight. But registration is only one component of the wider compliance framework established by the NDP Act and subsequent NDPC guidance.
Businesses therefore need to look beyond the registration form.
They need to understand the personal data they process, the risks associated with that processing, the rights of the people whose information they hold and the controls required to protect that information.
For organisations operating in Nigeria’s digital economy, that makes data protection a continuing governance responsibility rather than a one-time regulatory task.
