GAID Compliance Checklist: How Nigerian Businesses Can Audit Their Current Position
A Nigerian fintech preparing for a Series A round gets a due diligence questionnaire asking for the contact details of its Data Protection Officer (DPO), its most recent Compliance Audit Return (CAR), and evidence of a working breach response plan. The founder has a privacy policy and a registration certificate on hand. Nobody can say with confidence what else exists, or where to find it.
That gap, between having started on compliance and being able to prove it, is what this checklist closes. Work through each section and assess the organisation’s honest position: not started, in progress, or done.
This audit is part of PlanetWeb’s GAID compliance series. For the foundational framework, see GAID Nigeria Data Protection Directive: What Every Business Must Know.
For registration and classification, see GAID Registration in Nigeria. For DPO obligations, see Data Protection Officers in Nigeria.
How to Use This Audit
Each section below covers a core area of GAID compliance. For each item, assess the organisation’s position honestly: done, in progress, or not started.
A downloadable spreadsheet tracks all twenty-four items in one file, with a status dropdown for each and a summary tab that totals results automatically.
Done means documented evidence exists and is current, not that the activity happened once, but that records confirm it happened and still hold.
In progress is only accurate when documented work is genuinely underway. Something planned or intended does not qualify.
Not started means the obligation exists, but nothing has been done yet.
The audit covers core GAID obligations. Sector-specific requirements for fintechs, healthcare providers, and organisations processing children’s data are addressed in the sector deep-dive articles elsewhere in this series.
Foundation: Data Inventory and Lawful Basis
A data inventory is the logical starting point for an audit: the organisation needs to know what personal data it processes before the rest of its compliance position can be assessed.
Data Inventory and Record of Processing Activities
A complete inventory records what personal data is collected, why, and where it is stored. It also covers who has access, how long the data is retained, and the lawful basis behind each processing activity. Much of this feeds directly into the organisation’s Record of Processing Activities (ROPA), which Article 13 later ties to the DPO’s semi-annual report.
An inventory that no longer reflects the organisation’s current processing activities is not a reliable audit record.
Auditor’s focus: Ask for the ROPA directly. A current one shows specific documented reasoning in the lawful basis column, not placeholders.
Lawful Basis Documentation
Under the Nigeria Data Protection Act 2023, every processing activity requires a documented legal justification: consent, contract, legal obligation, vital interest, public interest, or legitimate interest.
Legitimate interest requires a documented balancing test; consent requires records showing it was freely given, specific, and informed.
Auditor’s focus: Look for a documented basis behind each processing activity, one that reflects genuine assessment rather than a box ticked in passing.
Retention Schedule
A retention schedule, one of GAID’s core data minimisation requirements, sets out how long each category of data is held and what happens when that period ends.
An informal habit of deleting data occasionally does not count as a retention policy.
Auditor’s focus: A schedule should exist and be followed in practice. The real test is what happens at the end of a retention period, whether deletion or anonymisation follows, or the data simply lingers.
Cross-Border Data Transfers
Where an organisation transfers personal data outside Nigeria, GAID Article 45 requires a documented legal mechanism for that transfer, evaluated against the guidance in Schedule 5: a destination the Commission has recognised as adequate, an approved Cross-Border Data Transfer Instrument, or another lawful ground.
GAID recognises instruments including standard contractual clauses, binding corporate rules, certifications, and codes of conduct.
Auditor’s focus: Start by confirming all cross-border transfers have been identified. Each one needs a documented legal mechanism, with the destination, recipient, purpose, and safeguards written down rather than assumed.
Registration and Classification
NDPC Registration Status
An organisation should know its exact registration status: registered and current, not registered, or lapsed. A lapsed registration is a compliance gap that needs to be addressed.
Auditor’s focus: Ask to see the current registration certificate, then check whether the registered details still match what the organisation currently processes.
Classification Accuracy
A registration can also become inaccurate over time when an organisation’s processing activities change and its classification no longer reflects its current position.
GAID Registration in Nigeria covers the full classification criteria and what Major status commits an organisation to.
Auditor’s focus: Compare the registered tier against the organisation’s actual profile. Where a higher tier applies, obligations like DPO appointment and CAR filing need to be in place too.
Change Notifications
GAID requires organisations to notify the NDPC within 60 days of significant changes to registration information: a change in DPO, a material expansion in processing activities, or a shift into a higher classification tier.
Auditor’s focus: Check whether the registered position still matches current reality, and look for a real process that catches changes as they happen rather than relying on someone remembering.
Compliance Audit Return (CAR) Filing
Initial registration is not the end of the obligation. UHL and EHL organisations file an annual CAR by 31 March through a Data Protection Compliance Organisation licensed by the NDPC; OHL organisations renew registration annually instead, with no CAR requirement. Missing the CAR deadline attracts a penalty of 50% of the filing fee.
A common pattern is registering correctly, then never filing again.
Auditor’s focus: Ask the organisation to produce its most recent CAR. It should be able to name the filing date and the licensed DPCO involved, and that filing should match its current classification and processing activities.
Governance: DPO and Accountability
DPO Appointment or Designated Compliance Owner
A Data Controller or Processor of Major Importance (DCPMI) must appoint a demonstrably independent DPO, one who cannot hold a role that conflicts with their data protection responsibilities. Data Protection Officers in Nigeria covers the qualification and independence requirements in full.
An organisation below that threshold still needs a named person with real authority to act on compliance, not just a title.
Auditor’s focus: A DPO should be named, genuinely independent, listed with the NDPC, and properly certified through the Commission’s database.
Internal Accountability Structure
Beyond the DPO, the NDPC expects data protection responsibility to be embedded across the organisation rather than siloed with one person: staff should know who the DPO is, how to escalate an incident, and what to do with a data subject request.
Auditor’s focus: Training records are the evidence here: do they show staff understand their obligations and who to contact?
DPO Certification and DPCO Licensing
These are two separate checks that Nigerian businesses commonly conflate. The individual acting as DPO needs current certification from the Commission, verified through the Annual Credential Assessment process. Separately, where the arrangement runs through a firm providing regulated compliance services, that firm needs its own DPCO licence. Holding one does not substitute for the other.
Auditor’s focus: The DPO’s certification status should be confirmable directly with the Commission. For outsourced arrangements, check the NDPC’s register of licensed DPCOs separately, since a current DPCO licence covers the firm, not the individual.
Semi-Annual Data Protection Report
GAID requires the DPO to compile a semi-annual data protection report and submit it to an officer of the organisation authorised to receive the ROPA. The report is acknowledged by that officer, forms part of the ROPA, and is verified by a DPCO during the compliance audit.
Auditor’s focus: Two reports should exist for any full year the obligation has applied, each formally submitted and acknowledged.
Data Privacy Impact Assessments
A DPIA is mandatory for specific circumstances GAID lists directly: profiling, automated decision-making with legal or similarly consequential effects, and systematic monitoring, alongside sensitive or highly personal data and vulnerable data subjects. It also covers the deployment of innovative technology and named sectors: financial services, healthcare, e-commerce, and cross-border transfers among them.
A broader test also applies: any processing likely to result in high risk to a data subject’s rights and freedoms requires one, even outside these named circumstances.
Skipping a required DPIA carries a specific consequence: a restriction on the platforms through which the organisation has contact with data subjects, separate from broader enforcement exposure.
Auditor’s focus: Start by confirming whether the organisation has identified which processing activities trigger a mandatory DPIA. Where one applies, the assessment needs to exist, carry a certified and accredited DPO’s signature, predate the processing it covers, and appear in the relevant CAR filing.
Privacy Notices and Consent
Privacy Policy
A compliant privacy policy accurately describes actual processing activities and references the NDPA 2023 and GAID as the applicable legal framework. It also identifies the lawful basis for each processing purpose and provides contact details for the DPO or responsible person.
A template copied from a foreign website does not meet this standard, and neither does a policy describing intended practice rather than actual practice.
Auditor’s focus: Check the policy against four things: accuracy, currency, accessibility, and whether it references the correct regulatory framework.
Collection-Point Notices
Data subjects need to be informed at the point of collection. Every form, sign-up page, app permission screen, and data-collection touchpoint needs a clear notice, visible before the data is submitted, explaining what is collected, why, and how it will be used.
A reference to the privacy policy buried in a footer does not satisfy this on its own.
Auditor’s focus: The test is timing. Are data subjects meaningfully informed before their data is collected, or only after?
Consent Records
Where consent is the lawful basis, it must be documented as freely given, specific to the purpose, and informed. Pre-ticked boxes, consent bundled with terms and conditions, or consent obtained under pressure do not meet the standard, and withdrawal needs to be as straightforward as giving consent was.
Auditor’s focus: Consent records should exist and tie to a specific processing purpose. Test the withdrawal process directly rather than assuming it works.
Data Subject Rights
Request Handling Process
Data subjects can request access to their data, corrections, erasure, restriction of processing, data portability, and can object to certain processing.
The NDPA does not fix a single statutory response window for these requests, but a documented process, a designated recipient, and a log of requests received and resolved within a reasonable time are what a functioning process looks like.
Auditor’s focus: A process should exist and function day to day, and the log is where that gets tested. Does it show consistent, timely handling, or gaps?
SNAG Process
The Standard Notice to Address Grievance gives a data subject a way to raise a complaint directly with an organisation before or instead of escalating to the NDPC. It is not a precondition for a direct complaint, and an organisation that receives one must communicate its decision to the Commission through the designated tracking platform.
SNAG Process in Nigeria covers what triggers a SNAG and how a business should respond.
Auditor’s focus: Look for a documented process with a designated contact point and a clear escalation path. Then check whether the organisation resolved any SNAGs it received and reported them to the NDPC.
Breach Response
Breach Response Plan
GAID requires notification to the NDPC within 72 hours of becoming aware of a breach likely to result in a risk to data subjects’ rights, a window short enough that a documented and tested response process matters. Responding to Data Breaches in Nigeria covers the full notification process.
A sound plan also depends on reasonable security measures already in place before an incident occurs: access controls, authentication, and monitoring capable of detecting a breach in the first place.
Auditor’s focus: A documented plan should exist and have been tested at least once. The people responsible for executing it need to understand the 72-hour threshold.
Incident Log
Incidents that did not meet the notification threshold should still be logged. The log demonstrates an active, consistent assessment process rather than a retrospective record assembled for an audit.
Auditor’s focus: A log should exist, and it should read like ongoing monitoring rather than something assembled after the fact for the audit.
Vendor and Third-Party Management
Data Processing Agreements
Every vendor that processes personal data on an organisation’s behalf needs a Data Processing Agreement. A data controller must ensure that processors handling personal data on its behalf comply with applicable data protection requirements.
At a minimum, a DPA should cover breach notification timelines and audit rights. Clear processing instructions, data transfer provisions where relevant, and termination clauses for non-compliance complete the agreement.
Auditor’s focus: DPAs should exist for every material vendor, and each one needs the required provisions, not a generic commercial contract standing in for one.
Vendor Register
Before DPAs can exist, an organisation needs to know which vendors process personal data on its behalf. Cloud storage providers, payroll platforms, CRM systems, email marketing tools, and payment gateways commonly process personal data without a formal agreement in place.
Auditor’s focus: The register itself is the first test. Where it exists, check whether it is complete and whether DPA coverage lines up with it.
Staff Training and Employee Data
Training Records
Staff who handle personal data need training on their obligations under the NDPA and GAID, and that training needs to be role-specific. A customer service team handling data subject requests has different needs from a finance team processing payroll.
Auditor’s focus: Records should exist and show role-specific coverage, not a single generic session logged for everyone.
Refresh Cycle
Training delivered once at onboarding and never repeated is not sufficient. Regulations change, processing activities evolve, and staff move roles.
Auditor’s focus: Training should repeat at defined intervals, at least annually, with refresh records dated accordingly, not from years ago.
Employee Data Protection
Employee data, HR records, monitoring data, and biometric attendance systems, among them, is a distinct compliance surface many organisations overlook. It remains subject to the same data protection framework, even though the processing purposes and lawful bases may differ.
The power imbalance in employment makes genuinely free consent harder to establish. Employee Data Protection in Nigeria covers these obligations in depth.
Auditor’s focus: The gap to look for is treating HR and monitoring data as a separate, exempt category.
Reading Your Results
Mostly done. No obvious structural gap remains. The priority now is maintenance: a current ROPA, tracked CAR and renewal deadlines, refreshed training, and monitored classification status as the business grows.
Mixed results. Some areas are covered, others have real gaps. Prioritise by risk: data inventory and DPO gaps first, registration and CAR second, privacy notices and consent third. A plan with a named owner beats a broad effort that stalls.
Extensive gaps across multiple areas. Section 48 sets the statutory penalty ceiling at the greater of ₦10 million or 2% of annual gross revenue for DCPMIs. The NDPC’s enforcement actions against MultiChoice Nigeria (₦766,242,500, July 2025) and Fidelity Bank (₦555.8 million, August 2024) show that the figure is not theoretical.
An NDPC audit, a data subject complaint, or a breach can expose those gaps at exactly the point when the organisation needs to demonstrate that its controls are working.
Get Help With Your GAID Compliance Audit
If the results above, whether from working through this article or the downloadable spreadsheet, skew toward not started, that’s a reasonable place to start rather than a sign you’re behind.
Our IT consulting work covers mapping your current compliance position, prioritising remediation, and building a programme that holds up under NDPC scrutiny. Get in touch to talk through where your organisation stands.






