NDPA Compliance: Why the May 30 Deadline Matters for Your Business

The Nigeria Data Protection Commission is actively enforcing the Nigeria Data Protection Act, with a compliance deadline for audits set for May 30. Businesses must prioritize data privacy to avoid hefty fines of up to 2% of revenue. Immediate steps include appointing a Data Protection Officer, conducting a data audit, and registering with the NDPC.

If you handle customer data emails, phone numbers, or residential addresses the window for “ignoring” the Nigeria Data Protection Act (NDPA) has officially closed. The Nigeria Data Protection Commission (NDPC) has moved past the education phase and into active enforcement.

1. The “Major Importance” Trap

Many small and medium enterprises assume the law only applies to banks or telcos. However, under the current General Application and Implementation Directive (GAID), you may be classified as a Data Controller of Major Importance if you:

  • Process the personal data of more than 200 individuals within a six-month period.
  • Operate in sensitive sectors like fintech, healthcare, or hospitality.
  • Handle data in a “fiduciary capacity” (e.g., as a consultant or professional service provider).

If you have a customer database or even a growing mailing list, you likely cross this threshold.

2. The 2% Revenue Risk

The NDPC has been clear: non-compliance is expensive. The penalties for failing to register or filing late are designed to be “deterrent”:

  • Fines: Up to 2% of your annual gross revenue or ₦10,000,000, whichever is greater.
  • Reputational Damage: The NDPC maintains a public registry of compliant and non-compliant organizations. Being left off the compliant list can disqualify your business from government contracts and international partnerships.

3. The 72-Hour Rule

In the event of a data breach (a hack, a lost laptop, or a leaked database), the law now mandates a 72-hour notification window.

  • You must inform the NDPC of the breach within three days of discovery.
  • If you don’t have a documented “Breach Response Plan” in place before an incident happens, meeting this deadline is nearly impossible.

Three Immediate Steps to Compliance

  1. Appoint a Data Protection Officer (DPO): This doesn’t have to be a new hire; it can be a senior staff member or an external consultant who ensures your data handling meets the legal standard.
  2. Conduct a Data Audit: Map out exactly where your customer data is stored. Is it on a physical server in your office? Is it in an overseas cloud? Knowing “where” your data lives is the first question the regulator will ask.
  3. Register with the NDPC: Use a licensed Data Protection Compliance Organisation (DPCO) to verify your setup and file your audit returns before the May 30 cutoff.

The Bottom Line

Data protection is the new standard of business integrity in Nigeria. Compliance protects your customers, but more importantly, it protects your balance sheet from avoidable regulatory fines.


Is your business ready for an NDPC audit?

Six-Cores helps businesses simplify the path to compliance by securing their physical and digital infrastructure. We ensure your hardware setup meets the technical security standards required by the NDPA.

Avoid the rush. Contact us today for a Data Security Readiness Check.


Discover more from Six-Cores Solutions Limited

Subscribe to get the latest posts sent to your email.

Share with love

Leave a Reply

Your email address will not be published. Required fields are marked *