Address
1, Obasa Street, Anifowoshe, Ikeja
Lagos, Nigeria
Work Hours
Monday to Friday: 9AM - 5PM
The Nigeria Data Protection Commission is actively enforcing the Nigeria Data Protection Act, with a compliance deadline for audits set for May 30. Businesses must prioritize data privacy to avoid hefty fines of up to 2% of revenue. Immediate steps include appointing a Data Protection Officer, conducting a data audit, and registering with the NDPC.

If you handle customer data emails, phone numbers, or residential addresses the window for “ignoring” the Nigeria Data Protection Act (NDPA) has officially closed. The Nigeria Data Protection Commission (NDPC) has moved past the education phase and into active enforcement.
Many small and medium enterprises assume the law only applies to banks or telcos. However, under the current General Application and Implementation Directive (GAID), you may be classified as a Data Controller of Major Importance if you:
If you have a customer database or even a growing mailing list, you likely cross this threshold.
The NDPC has been clear: non-compliance is expensive. The penalties for failing to register or filing late are designed to be “deterrent”:
In the event of a data breach (a hack, a lost laptop, or a leaked database), the law now mandates a 72-hour notification window.
Data protection is the new standard of business integrity in Nigeria. Compliance protects your customers, but more importantly, it protects your balance sheet from avoidable regulatory fines.
Is your business ready for an NDPC audit?
Six-Cores helps businesses simplify the path to compliance by securing their physical and digital infrastructure. We ensure your hardware setup meets the technical security standards required by the NDPA.
Avoid the rush. Contact us today for a Data Security Readiness Check.
Subscribe to get the latest posts sent to your email.