GAID Registration in Nigeria: Requirements and Deadlines

GAID registration in Nigeria on laptop with smartphone and Nigerian flag

GAID Registration in Nigeria: Preparing, Registering, and Staying Compliant

NDPC enforcement has been live since September 2025. For organisations required to register, not having done so is not simply a missed deadline. It is a current compliance gap with real exposure.

Classification is covered in full in Key Features of the NDPA 2023, including the Ultra-High, Extra-High, and Ordinary-High Level tiers. Once that classification is settled, the practical questions start.

What does an organisation need before it registers? How does it submit the application? What does it cost? And once registered, what does staying compliant require? The sections below work through each of those in turn.

Registration with the NDPC is a milestone within a compliance programme, not the start of one. What an organisation needs in place before it registers, and what registration commits it to going forward, carry more weight than the mechanics of completing a form.

This article is part of PlanetWeb’s GAID compliance series. For the broader compliance programme context, see our data protection compliance strategies guide.

Confirming Your Classification Before You Register

GAID 2025 classifies data controllers and processors of major importance into three tiers: Ultra-High Level (UHL), Extra-High Level (EHL), and Ordinary-High Level (OHL). The number of data subjects processed within six months is one of the classification factors, with thresholds of over 5,000 for UHL, over 1,000 for EHL, and over 200 for OHL.

Other sector and risk factors also determine classification, and Key Features of the NDPA 2023 covers the full framework.

The classification thresholds refer to data subjects rather than transactions or individual records. A customer who places fifty orders remains one data subject, although those transactions may generate many separate records and processing activities.

Organisations should assess the people whose personal data they process against the classification framework, rather than using transaction volume or record count as a substitute. Where an organisation’s circumstances make the applicable threshold unclear, the full classification framework and relevant sector criteria should be considered before registration.

One important risk is underclassifying: registering at a lower tier than the organisation genuinely falls within. The 200-data-subject OHL threshold means that registration can apply at a relatively modest scale, and organisations that cross it without realising find the gap surfaces at audit rather than at registration.

What You Need Before You Register

Registration is a regulatory requirement, and preparing for it properly gives an organisation a much stronger position if the NDPC later reviews its compliance.

A Completed Data Inventory

Before the registration form can be completed accurately, an organisation needs to know what personal data it collects, why, where it is stored, who has access, and what the lawful basis is for each category of processing. This provides the information needed to describe processing accurately during registration and to demonstrate how that processing is managed if the NDPC later conducts a review.

A working data inventory does not need to be sophisticated. A spreadsheet covering the categories of data collected, the purpose, storage location, retention period, and lawful basis is sufficient to start, provided it reflects actual processing activities and is kept current. An inventory completed once and left untouched for two years becomes a liability rather than a compliance asset.

A DPO or Designated Compliance Owner

Data controllers and processors of major importance are required to designate a Data Protection Officer under Section 32 of the NDPA. The DPO should be in place as part of registration preparation, with appropriate independence, access, and authority to perform the role.

Data Protection Officers in Nigeria covers the independence requirement and outsourced DPO options in more depth.

DPIA Documentation (Where Applicable)

Where an organisation conducts high-risk processing, including automated decision-making, biometric data processing, large-scale monitoring, or profiling, a Data Protection Impact Assessment must be completed before those activities begin. Registration does not substitute for that requirement.

Data protection impact assessments in Nigeria covers the trigger criteria and process.

The Registration Process

The NDPC registration portal at ndpc.gov.ng is the only official channel. Account creation, form completion, document upload, fee payment, and status tracking all happen there.

Registration begins by creating an organisational account and selecting a role, Data Controller, Data Processor, or both, alongside the classification tier. Having a completed data inventory before this stage means the information provided comes from documented records rather than reasoned guesses. This is where organisations that skipped the pre-registration groundwork tend to stall.

What to Upload

Documents typically required include the CAC certificate and the DPO appointment letter with evidence of qualification, alongside the classification and processing information the portal requests. Supporting documentation, such as a privacy policy, breach response plan, and staff training records, may not be mandatory for submission, but will be expected in any audit.

Registration Fees

Fees are set out in GAID’s Schedule 10 and are subject to revision by the NDPC, so they should be verified at the portal before payment.

ClassificationRegistration Fee
Ultra-High Level₦250,000
Extra-High Level₦100,000
Ordinary-High Level₦10,000
Government / Public EntityNo fee

UHL organisations should also account for a separate data processing activities fee of ₦5,000 for each processor engaged within a 12-month period, confirmed in the NDPC’s registration guidance notice. Where a controller replaces one processor with another within that same 12-month period, no additional fee is due for the newly engaged processor.

After Submission

Status can be tracked from the applicant’s dashboard. The period following submission is a useful opportunity to confirm internal documentation is consistent with what was submitted and that any outstanding compliance gaps are being closed.

What Registration Commits You To

Registration is the beginning of an ongoing compliance posture, and that posture differs meaningfully depending on classification tier.

UHL and EHL: Annual CAR Filing

UHL and EHL organisations register once with the NDPC and do not renew their registration annually. Instead, they must file a Compliance Audit Return (CAR) every year, through a Data Protection Compliance Organisation licensed by the NDPC, unless otherwise approved; a report from an unlicensed firm will not satisfy the requirement.

The NDPC maintains a register of licensed DPCOs at ndpc.gov.ng, and checking it before engaging any firm takes minutes and avoids an expensive detour.

The standing annual CAR deadline is 31 March. Organisations established after 12 June 2023 must file their initial CAR no later than 15 months after establishment, and annually thereafter. Failure to file on time attracts an administrative penalty of 50% of the stipulated CAR filing fee, in addition to the fee itself.

OHL: Annual Renewal

OHL organisations renew their NDPC registration annually and are not required to file an annual CAR. This is the main difference in ongoing obligation between OHL and the higher tiers, and organisations that assume every tier carries the same audit-return requirement are either overbuilding an OHL compliance process or underbuilding a UHL or EHL one.

Change Notifications Within 60 Days

If the DPO changes, the business expands into new data processing categories, its data subject volume crosses a classification threshold, or its processing activities shift materially, the NDPC must be notified of the significant change within 60 days, through the portal or by the channel the Commission specifies.

Many organisations get registration right and then neglect this during periods of growth, particularly when a compliance owner leaves and the function drifts.

Maintaining Compliance After Registration

The NDPC can request evidence during a review that a registered organisation’s practices match what was submitted: the data inventory and lawful basis records, the data subject request log, the breach response plan and incident records, vendor contracts with data processing provisions, and evidence of staff training.

On vendor contracts specifically: many Nigerian businesses use cloud platforms, payroll providers, CRM systems, and payment gateways that process personal data for them.

Under the NDPA, the controller remains responsible for ensuring that any processor handling that data complies with the applicable data protection requirements. A contract without a breach notification clause, audit rights, or data processing terms is a gap that scrutiny will expose.

The SNAG process, the Standard Notice to Address Grievance introduced under GAID 2025, should also be understood by whoever manages an organisation’s data protection complaints and NDPC communications.

For a fuller treatment of building and demonstrating an ongoing compliance programme, see our data protection compliance strategies guide, and for how data breach obligations fit into that picture, see our data breach response guide.

Where Organisations Go Wrong

Underclassifying

An organisation incorrectly registered at a lower tier can fail to meet the obligations that apply to its actual classification, exposing it to enforcement action under Section 48 of the NDPA. For a data controller or processor of major importance, the maximum penalty or remedial fee can be the greater of ₦10 million or 2% of annual gross revenue in the preceding financial year.

Appointing an Unqualified or Conflicted DPO

Assigning the Head of IT or the Finance Director to the role without assessing whether their other responsibilities create a conflict can undermine the DPO’s independence.

GAID sets requirements around the DPO’s position, reporting lines, access, and conflicts of interest, and Data Protection Officers in Nigeria covers the independence requirements and when an outsourced DPO makes sense.

Registering Without a Completed Data Inventory

Registration answers built on estimates are internally inconsistent and will not match the documented position the NDPC expects to find on closer review. The data inventory should precede registration, not follow it.

Missing the CAR Deadline or Letting Renewal Lapse

Many organisations miss their CAR deadline or renewal date because no one owns the calendar obligation. Assigning ongoing responsibility for these deadlines and change notifications to a named person, with a reminder set well ahead of each date, is straightforward and frequently overlooked.

Get Help With GAID Registration

Registration errors are rarely discovered at the point of submission. They emerge months later during a review, a data subject complaint, or when an NDPC notice arrives, and by then the gap between what was submitted and what genuinely exists in the organisation’s compliance programme is harder and more expensive to close.

Our IT consulting work covers classification review, pre-registration preparation, and ongoing compliance support. Contact us to talk through where your organisation currently stands.

Frequently Asked Questions

Does every business need to register with the NDPC?
Formal NDPC registration applies to organisations classified as data controllers or processors of major importance under GAID’s UHL, EHL, or OHL tiers, subject to specific exemptions the GAID sets out for certain categories of organisation. All organisations, including those below these thresholds, remain subject to the NDPA’s other compliance requirements.
How do I know which registration tier applies to my organisation?
Classification considers several factors, including the number of data subjects processed within a six-month period. The thresholds are over 5,000 for UHL, over 1,000 for EHL, and over 200 for OHL, alongside sector and other factor-based criteria. Key Features of the NDPA 2023 covers the full framework.
How much does NDPC registration cost?
Under GAID’s Schedule 10, registration fees are ₦250,000 for UHL, ₦100,000 for EHL, and ₦10,000 for OHL, with UHL organisations also paying ₦5,000 per engaged processor annually. Government and public entities register without a fee. Fees are subject to revision, so confirm the current amount at the portal before payment.
What happens if I miss my CAR deadline or registration renewal?
Missing the CAR deadline attracts an administrative penalty of 50% of the filing fee in addition to the fee itself. More broadly, an organisation not meeting its registration obligations is non-compliant under the NDPA and can face enforcement action under Section 48, including penalties of up to the greater of ₦10 million or 2% of annual gross revenue.
Do OHL organisations have to file Compliance Audit Returns?
No. OHL registrants renew their registration annually but are not required to file an annual CAR. UHL and EHL registrants, by contrast, register once and file a CAR every year by 31 March instead of renewing annually.
Share this article:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top