Navigating NDPC Registration: A Practical Guide for Data Controllers and Processors in Nigeria

Businesses across Nigeria routinely collect and process personal data relating to customers, employees, vendors, contractors, website users, and other individuals. This may include names, telephone numbers, email addresses, identification details, financial information, health information, photographs, and other information relating to an individual.

The Nigeria Data Protection Act (NDPA), 2023, together with the Nigeria Data Protection Act – General Application and Implementation Directive (GAID), 2025, provides the principal framework for the protection and processing of personal data in Nigeria. 

The Nigeria Data Protection Commission (NDPC) is responsible for regulating and enforcing this framework.

Not every organisation that processes personal data is required to register with the NDPC. Registration applies to Data Controllers and Data Processors that fall within the Data Controller or Data Processor of Major Importance (DCPMI) framework.

This guide explains who may be required to register, the different registration categories, and what organisations should expect from the registration process.

Understanding Data Controllers and Data Processors

A Data Controller is a person or organisation that determines the purpose and manner in which personal data is processed. For example, an e-commerce company that decides what customer information to collect, why it is collected, and how it will be used will generally be acting as a Data Controller.

A Data Processor processes personal data on behalf of a Data Controller. Examples may include cloud service providers, payroll providers, data analytics companies, and technology service providers.

An organisation may also act as both a Data Controller and a Data Processor, depending on the processing activity involved. For example, a technology company may act as a Data Controller in relation to the personal data of its own employees and customers, while acting as a Data Processor when it processes customer data on behalf of another company. 

This is why registration assessments should examine the organisation’s actual processing activities, rather than simply its registered business objects or industry description.

Who Needs to Register With the NDPC?

The NDPA requires Data Controllers and Data Processors of Major Importance to register with the NDPC.

An organisation may fall within the DCPMI framework based on factors including the volume and nature of personal data it processes, its sector, the nature of its services, and other applicable criteria under the NDPA and GAID.

The fact that an organisation processes personal data does not, by itself, mean that it must register with the NDPC. Equally, an organisation should not assume that it is exempt simply because it is a small business.

A proper assessment of the organisation’s processing activities is therefore important before determining whether registration is required.

SMEDAN Registration 2026: How to Get A SMEDAN Certificate | Complete Guide

The Three NDPC Registration Categories

The NDPC classifies DCPMIs into three categories:

1. Ultra-High Level (UHL)

This category includes certain organisations such as telecommunications companies, insurance companies, multinational companies, electricity distribution companies, oil and gas companies, payment gateway service providers and fintechs, among others.

Organisations processing the personal data of more than 5,000 data subjects within six months may also fall within this category.

2. Extra-High Level (EHL)

The EHL category includes specified organisations such as Ministries, Departments, and Agencies (MDAs) of government, microfinance banks, higher institutions, certain hospitals and mortgage banks.

Organisations processing the personal data of more than 1,000 but fewer than 5,000 data subjects within six months may also fall within this category.

3. Ordinary-High Level (OHL)

The OHL category includes organisations such as primary and secondary schools, corporate training service providers, primary health centres, independent medical laboratories and certain hotels and guest houses.

Organisations processing the personal data of more than 200 but fewer than 1,000 data subjects within six months may also fall within this category.

Regulatory fees are separate from professional fees charged by lawyers, consultants, or Data Protection Compliance Organisations (DPCOs), where applicable.

How to Register a School in Nigeria: Legal Documents Guide

How Does the NDPC Registration Work?

1. Assess the organisation

The first step is to determine whether the organisation acts as a Data Controller, Data Processor, or both, and whether its processing activities bring it within the DCPMI framework.

2. Determine the registration category

Where registration is required, the organisation should determine whether it falls within the UHL, EHL, or OHL category based on its processing activities and the applicable NDPC criteria.

3. Prepare the required information

The registration process requires information about the organisation and its data-processing activities, including details of the organisation, Data Protection Officer, categories of personal data and data subjects, purposes of processing, recipients of personal data, relevant processors or representatives, international data transfers, and applicable safeguards.

4. Submit the registration

The organisation submits the required information through the NDPC’s designated registration platform and pays the applicable regulatory fee.

Registration, however, is not the end of an organisation’s data protection obligations. Depending on the organisation and its processing activities, ongoing compliance may include data security measures, management of data subject rights, breach-response procedures, Data Protection Impact Assessments (DPIAs), cross-border transfer compliance, and other requirements under the NDPA and GAID.

UHL and EHL organisations must also comply with applicable annual Compliance Audit Return (CAR) requirements, which are filed through a licensed DPCO.

Conclusion

The NDPC registration should not be treated as a standalone filing. It forms part of an organisation’s broader data protection compliance obligations.

Organisations should first determine whether they fall within the DCPMI framework, identify the appropriate registration category, and ensure that their registration information accurately reflects their actual data-processing activities.

Also, obtaining an NDPC registration certificate does not, by itself, mean that an organisation has fulfilled all of its obligations under the NDPA and GAID. Therefore, organisations should treat registration as an entry point into an ongoing process of accountability, governance, and responsible personal data processing.

Frequently Asked Questions

1. Does every company in Nigeria need NDPC registration?

No. Registration is specifically required for Data Controllers and Data Processors that fall within the DCPMI framework.

2. What is a Data Controller?

A Data Controller determines the purpose and manner of processing personal data.

3. What is a Data Processor?

A Data Processor processes personal data on behalf of a Data Controller.

4. What are the NDPC registration categories?

The three categories are Ultra-High Level (UHL), Extra-High Level (EHL), and Ordinary-High Level (OHL).

5. Does NDPC registration end an organisation’s data protection obligations?

No. Registration is only one part of an organisation’s broader data protection compliance obligations.

6. Can TCorporate assist with NDPC compliance?

Yes. TCorporate can assist organisations with NDPC registration, data protection documentation, regulatory compliance, and related advisory services.

Why Choose TCorporate?

TCorporate is a fast-growing law firm with a robust regulatory compliance practice. We have advised a diverse range of businesses on data protection compliance, including NDPC registration and other regulatory requirements.

At TCorporate, we can help you assess your NDPC registration obligations, prepare the required documentation, and navigate the registration process.

Contact TCorporate today to discuss your data protection compliance needs.

Phone: 0806 234 8867, 0908 011 9975, 0908 011 9980

Email: info@tcorporatelegaladvisory.com

Website: www.tcorporatelegaladvisory.com

Click the WhatsApp button (bottom right) to chat with us now.

Disclaimer: This publication is for general informational purposes only and does not constitute legal advice. The information provided should not be relied upon as a substitute for professional legal advice. For guidance specific to your circumstances, please consult a qualified legal practitioner.

Written by: Precious Uzo Fred

Legal Associate

TCorporate Legal Advisory

Leave a Reply

Your email address will not be published. Required fields are marked *