OUR BLOG

NDPC Registration: How to Register Your Organisation with the NDPC (Step-by-Step)

Technology
5 Min
6 August 2026
4

The Nigeria Data Protection Commission has already begun sanctioning businesses that process personal data without being registered. If your organisation's name is not in their system, you are not compliant, and "I didn't know I had to register" will not save you from a fine.

If you run a business in Nigeria that collects, stores, or uses people's personal information in any form: customer records, employee files, website data, transaction histories, then registering with the NDPC is not optional. It is a legal requirement under the Nigeria Data Protection Act 2023.

This guide walks you through exactly what NDPA registration is, who must do it, and the step-by-step process to get your organisation registered correctly. We will also cover the compliance stakes, the mistakes businesses commonly make, and what you should do immediately after reading this.

Why This Issue Exists and What the Current Landscape Looks Like

Before the NDPA came into force in June 2023, Nigeria's data protection framework was governed primarily by the Nigeria Data Protection Regulation 2019, the NDPR. Under the NDPR, certain organisations were required to engage a licensed Data Protection Compliance Organisation, a DPCO, and file annual audit reports. Many businesses either didn't know this existed or chose to ignore it.

The NDPA changed the landscape significantly. It established the Nigeria Data Protection Commission as a standalone, independent regulatory body with full powers to register data controllers and processors, conduct audits, investigate complaints, and impose sanctions. One of the most important new obligations the NDPA introduced is the formal registration of data controllers and processors of major importance, a category that covers far more Nigerian businesses than most people realise.

For Nigerian businesses, the registration requirement is not a bureaucratic formality. It is the foundation of your entire data protection compliance posture. Without it, every other compliance effort you make sits on an unstable base.

1. Who Is Required to Register with the NDPC?

The first and most important thing to establish is whether your organisation falls within the registration requirement. Many business owners assume registration is only for large corporations or tech companies. That assumption is wrong and costly.

Under the NDPA, organisations classified as Data Controllers or Processors of Major Importance, commonly referred to as DCPMIs, are required to register with the NDPC. The Commission defines a DCPMI as any organisation that:

  1. Processes the personal data of more than 1,000 data subjects within a period of six months, or
  2. Processes the personal data of more than 2,000 data subjects within a period of twelve months

Let that sink in. If you are a retailer with a customer loyalty database, a hospital with patient records, a school with student files, a logistics company with delivery addresses, a fintech with user accounts, or an employer with more than a few dozen staff, you almost certainly qualify.

Beyond the volume threshold, the NDPC can also designate an organisation as a DCPMI based on the nature of the data they process, particularly where sensitive categories are involved, such as health data, financial data, biometric information, or data relating to children.

Here is a practical Nigerian example: a mid-size e-commerce platform in Lagos with ten thousand registered users processes names, phone numbers, delivery addresses, and payment histories. They are a DCPMI by volume alone, regardless of their revenue or size. They are required to register.

Action: Count the number of individuals whose personal data your organisation holds across all databases: customer lists, employee records, mailing lists, transaction histories. If that number exceeds one thousand, registration is not a question. It is an obligation.

2. What You Need Before You Begin: Pre-Registration Requirements

Rushing into the registration portal without the right information is one of the most common mistakes businesses make. Registration requires specific documentation and internal decisions that you need to make before you open the form.

Here is what you need to have ready:

  1. Your organisation's corporate information: Your CAC registration number, registered business name, and official address. If your organisation operates under a different trading name, have both the legal and trading names available.
  2. Your Data Protection Officer (DPO) details: The NDPA requires DCPMIs to designate a Data Protection Officer. This is either an internal staff member with the relevant competence or an external consultant. You cannot complete registration without nominating a DPO: their name, contact details, and a description of their role will be required.
  3. A summary of your data processing activities: You need to be able to describe, at a basic level, what personal data your organisation collects, why you collect it, how you store it, and who has access to it. This does not need to be an exhaustive technical document at the registration stage, but you need a working understanding of your own data flows.
  4. Evidence of your internal data protection framework: While not always required as an upload at the point of registration, the NDPC may request your Privacy Policy, your Records of Processing Activities (ROPA), and evidence of staff training during subsequent audits. Having these in place before you register is strongly recommended because registration opens the door to regulatory scrutiny.
  5. Payment readiness: Registration attracts a fee. The fee structure is tiered based on the size of your organisation. At the time of writing, the NDPC has published fee categories aligned to annual turnover. Confirm the current applicable fee on the NDPC's official portal at ndpc.gov.ng before proceeding, as fee schedules can be updated.

Action: Designate your DPO before anything else. If your organisation does not yet have one, either internally or through an external compliance firm, that appointment must happen first. Everything else in the registration process flows from it. You don't have to worry yourself searching for an external auditor, as Accuvice Solutions Limited offers DPO services without the overhead cost of a full-time position. Our outsourced DPOs provide continuous oversight, guidance, and representation to ensure your organisation meets its regulatory obligations.

3. The Step-by-Step Registration Process

With your documentation in order, here is how the actual registration process works.

  1. Step One: Access the NDPC Registration Portal. Visit the official NDPC website at ndpc.gov.ng and navigate to the registration or compliance portal. Ensure you are on the official government domain. There have been cases of third-party sites mimicking official portals; always verify the URL.
  2. Step Two: Create an Organisational Account. You will be required to create an account using your organisation's official email address. Use a monitored business email, not a personal Gmail account, because all regulatory correspondence, including audit notices and renewal reminders, will be sent to this address.
  3. Step Three: Complete the Organisation Profile. Fill in your organisation's details: legal name, CAC number, sector of operation, address, and nature of data processing activities. Be accurate and consistent with your CAC registration. Discrepancies between your NDPC registration and your CAC documents can cause delays and raise compliance questions.
  4. Step Four: Nominate Your Data Protection Officer. Enter your DPO's full name, professional contact details, and a brief description of their responsibilities. If your DPO is an external consultant or a licensed DPCO firm, include their organisation's details as well. The NDPC may verify this appointment independently.
  5. Step Five: Describe Your Data Processing Activities. You will be asked to provide a summary of the categories of personal data you process, the purposes for processing, the categories of data subjects (customers, employees, website visitors, etc.), and whether you transfer data outside Nigeria. Answer these questions carefully and honestly. Inaccurate declarations at registration can constitute a compliance violation in themselves.
  6. Step Six: Pay the Registration Fee. Select your organisation's applicable fee tier and complete payment through the portal's designated payment gateway. Retain your payment receipt. You will need this as proof of registration payment if any questions arise during your compliance history.
  7. Step Seven: Await Confirmation and Receive Your Certificate. Upon successful submission and payment, the NDPC will process your registration and issue a Certificate of Registration. This certificate confirms your organisation's registration as a data controller or processor of major importance. The processing timeline can vary; build this into your compliance planning rather than waiting until a deadline or audit forces your hand.
  8. Step Eight: File Your Annual Data Protection Audit Report. Registration is not a one-time event. Registered organisations are required to file an annual Data Protection Audit Report with the NDPC, prepared by a licensed DPCO. This audit assesses your organisation's compliance with the NDPA across the year and must be submitted within the NDPC's published deadline; typically in the first quarter of the following year.

Action: Do not wait until you receive a regulatory inquiry to begin this process. Start Step One today. The portal is live, the requirement is active, and enforcement is ongoing.

4. The Role of Your Data Protection Officer in Registration and Beyond

Your DPO is not just a name on a form. Under the NDPA, the DPO has defined responsibilities that the NDPC takes seriously, and designating someone without the competence to carry out those responsibilities can itself be a compliance failure.

The DPO's responsibilities include:

  1. Monitoring your organisation's compliance with the NDPA on an ongoing basis,
  2. Advising on Data Protection Impact Assessments when new processing activities are introduced, serving as the point of contact between your organisation and the NDPC, and
  3. Handling data subject requests: for example, when a customer asks to access, correct, or delete their personal data.

A practical example: a Nigerian telecoms company designates their IT manager as DPO simply because they are the most "tech-savvy" person in the office. The IT manager has no knowledge of the NDPA's requirements, has never conducted a DPIA, and has no system for handling data subject access requests. When the NDPC conducts an audit, this gap is identified, and the company is found to have a non-compliant DPO designation.

The DPO does not have to be a lawyer. But they must be trained, competent, and genuinely empowered to carry out the role. Many organisations, especially small to mid-size businesses, outsource the DPO function to a licensed DPCO firm. This is fully permissible under the NDPA and is often the most practical solution.

Action: Assess your current DPO designation honestly. Does this person have adequate knowledge of the NDPA? Do they have time to carry out the role? Do they have authority within the organisation to raise compliance concerns? If the answer to any of these is no, address it before your registration is reviewed.

5. What Happens After Registration: Staying Compliant Year-Round

Many organisations treat NDPC registration as the finish line. It is, in fact, the starting line. Registration opens you to a higher level of regulatory scrutiny, and your compliance obligations do not pause between filing dates.

Here is what ongoing compliance looks like after registration:

  1. Maintain your Records of Processing Activities (ROPA): This is a living document that catalogues every way your organisation processes personal data: what data, for what purpose, stored where, retained for how long, and shared with whom. It must be kept current. The NDPC can request it at any time.
  2. Conduct Data Protection Impact Assessments (DPIAs): Whenever your organisation introduces a new product, service, or system that involves processing personal data, particularly at scale or involving sensitive data, a DPIA must be conducted before the processing begins.
  3. Respond to data subject requests within statutory timelines: The NDPA gives individuals the right to access their data, request corrections, withdraw consent, and request deletion. Your organisation must have a system to receive and respond to these requests within 30 days.
  4. Report data breaches to the NDPC within 72 hours: If your organisation suffers a data breach affecting personal data, you are legally required to notify the NDPC within 72 hours of becoming aware of it. Have an incident response plan in place before you need it.
  5. Renew your registration and file your annual audit: Your registration is not permanent. Annual renewal and audit filing are ongoing obligations. Missing these deadlines, even if your original registration was perfect, can result in sanctions.

The Legal Stakes: What Non-Compliance Actually Costs

The NDPA is not a paper tiger. The NDPC has published its enforcement framework and is actively using it.

For organisations that fail to register when required, or that file false or incomplete registration information, penalties under the NDPA can reach:

  1. Up to 2% of annual gross revenue for general violations, or
  2. ₦10 million, whichever is higher

For more serious violations, such as unlawful processing of sensitive personal data or systematic non-compliance, the penalty rises to up to 3% of annual gross revenue.

Beyond financial penalties, the NDPC has the power to issue public sanctions, which affect your brand reputation, and to restrict or prohibit your data processing activities entirely. For a business that relies on its customer database or digital operations, a processing prohibition is existential.

There is also the civil liability dimension. Under the NDPA, data subjects, your customers and employees, have the right to seek compensation in court for damages resulting from non-compliance. A single data breach, combined with a failure to register or maintain adequate safeguards, can expose your organisation to regulatory fines and civil claims simultaneously.

For organisations with operations or customers in the European Union, non-compliance with your NDPA obligations can also trigger scrutiny under GDPR, since the two frameworks share substantive requirements around processor obligations, data subject rights, and international transfers.

Three Mistakes Nigerian Businesses Make During NDPA Registration

Mistake 1: Assuming Small Means Exempt

Many small business owners assume the NDPA registration requirement applies only to large corporations. The 1,000 data subject threshold is lower than most people expect. A neighbourhood clinic, a secondary school, a small fintech startup, or a medium-sized logistics company can all cross this threshold and be legally required to register. Do not assume your size exempts you; count your data subjects and verify.

How to avoid it: Conduct a simple data audit. Count the individuals whose personal data you hold across all your systems. If you exceed one thousand, you are in scope.

Mistake 2: Designating a DPO in Name Only

Ticking the DPO box with the name of a senior staff member who has no data protection training and no time to carry out the role is not compliance; it is a documentation exercise. When the NDPC investigates a complaint or conducts an audit, they will engage your DPO directly. A DPO who cannot answer basic questions about your organisation's data processing activities immediately signals a compliance failure.

How to avoid it: Either train your designated DPO properly or engage an external DPCO firm like Accuvice Solutions Limited to fill the role. The latter option is often faster, more cost-effective for smaller businesses, and immediately effective.

Mistake 3: Registering and Then Going Silent

Some organisations complete their registration, receive their certificate, and then treat data protection as resolved. They miss their annual audit filing deadline, fail to update their ROPA when they add new services, and have no incident response procedure in place. When the NDPC follows up, they find an organisation that was compliant on paper for exactly one day.

How to avoid it: Build your compliance calendar the same day you receive your registration certificate. Schedule your annual audit, your ROPA review, your DPO check-in, and your registration renewal. Compliance is a rhythm, not a one-time event.

Three Steps to Take This Week

Step 1: Determine whether you are a DCPMI. Spend 30 minutes this week doing a rough count of all individuals whose personal data your organisation holds: customers, employees, website users, newsletter subscribers, and transaction records. If that number exceeds 1,000, your registration obligation is confirmed. Do not delay.

Step 2: Appoint or confirm your DPO. Identify who will serve as your Data Protection Officer. If you have someone internal who is trained and available, confirm their appointment formally in writing. If you do not, contact a licensed DPCO firm, including Accuvice Solutions Limited, to discuss an outsourced DPO arrangement. This step must happen before you can complete registration.

Step 3: Begin your registration on the NDPC portal. Go to ndpc.gov.ng this week and start your registration. Even if you cannot complete it in one session, creating your organisational account and beginning the process puts you on the right side of the compliance timeline. Gather your CAC documents, DPO details, and a basic description of your data processing activities before you start.

Final Word

Registering with the NDPC is not an administrative checkbox. It is your organisation's formal declaration that you take data protection seriously, and the foundation on which every other compliance obligation is built.

The businesses that act now are the ones that will be audit-ready when the NDPC comes calling. Those who wait will face penalties that far exceed the cost of getting it right the first time.

Your customers trust you with their data. The law requires you to earn that trust formally. Start this week.

Need help with NDPC registration, DPO designation, or building your full data protection compliance framework? We work with organisations across Nigeria and Africa at every stage, from first registration to annual audit filing. Get in touch with us today.

Related Topics

Technology
OA

Written by Olusola Akinbode

Thanks for reading! If you found this article helpful, feel free to share it with others.

Enjoyed this article?

Share with your network and help others discover great content!

0 Comments

No comments yet. Be the first to comment!

Leave Your Comment

Related Articles