← Back to Insights
October 3, 2026 · Updated October 3, 2026

NDPC Compliance Audit Return (CAR) 2026: Who Files, Deadlines and Evidence

By Oluwafemi Ofobutu · Founder & CEO, StackWeaver · 7 min read

Sourced from primary regulatory documents where available. How we research and correct our guides.

Short answer: Under the Nigeria Data Protection Act (NDPA) 2023 and the NDPC’s General Application and Implementation Directive (GAID) 2025, data controllers and processors of major importance in the Ultra-High (UHL) and Extra-High (EHL) tiers must file an annual Compliance Audit Return (CAR) through a licensed DPCO by 31 March. For 2025 returns the NDPC extended the deadline to 30 May 2026 12.

Last updated 3 October 2026. Not legal advice — confirm details with your DPCO or counsel.

Who files

TierTypical organisationsThreshold (data subjects in 6 months)CAR
Ultra-High Level (UHL)Commercial banks, telecoms, insurers, large platformsover 5,000Required, via a DPCO
Extra-High Level (EHL)Microfinance banks, universities, government agenciesover 1,000Required, via a DPCO
Ordinary-High Level (OHL)SMEs, schools, contractorsover 200Check GAID for your obligations

Thresholds and examples come from the NDPC’s registration guidance and law-firm summaries 13. Most CBN-licensed fintechs process enough customer data to fall into the higher tiers — see Am I a data controller of major importance?.

Key dates

DateWhat happens
20 March 2025GAID issued by the NDPC
19 September 2025GAID takes effect 4
31 March (every year)CAR due for the previous year
30 May 2026Extended deadline for 2025 returns 2

Penalties

  • Late filing: an additional administrative fee of up to 50% of the filing fee.
  • Not filing: a fine of up to 2% of the previous year’s annual gross revenue or ₦10 million, whichever is greater 1.

Evidence to have ready for your DPCO

  1. Record of processing activities (what personal data, why, where it goes).
  2. Lawful basis for each processing activity and consent records where consent is used.
  3. Data protection impact assessments for high-risk processing.
  4. Your appointed Data Protection Officer and their reporting line.
  5. Privacy notices as published, with dates.
  6. Data subject request log — received, answered, on time.
  7. Breach register and notifications made to the NDPC.
  8. Cross-border transfer basis for data leaving Nigeria.
  9. Processor contracts with data protection clauses.
  10. Security controls evidence (access reviews, encryption, backups) — often shared with SOC 2 or ISO 27001 work.

StackWeaver keeps each of these as a reviewed, fingerprinted evidence item your DPCO can receive as one verifiable package. See NDPA compliance or talk to us.


Sources

Footnotes

  1. Templars (via Mondaq), “Data Protection Compliance In Nigeria: Audit Return Obligations For 2026”, 28 January 2026. https://www.mondaq.com/nigeria/data-protection/1736914/data-protection-compliance-in-nigeria-audit-return-obligations-for-2026 ↩ ↩2 ↩3

  2. OAL, “NDPC extends 2025 data protection audit return deadline to 30 May 2026”, April 2026. https://oal.law/ndpc-extends-2025-data-protection-audit-return-deadline-to-30-may-2026/ ↩ ↩2

  3. Andersen Nigeria, “NDPC issues Guidance Notice on the registration of data controllers and processors of major importance”, 2024. https://ng.andersen.com/ndpc-issues-guidance-notice-on-the-registration-of-data-controllers-and-processors-of-major-importance/ ↩

  4. Aluko & Oyebode, “NDPC GAID takes effect on 19 September”. https://www.aluko-oyebode.com/insights/ndpc-gaid-takes-effect-on-19-september-is-your-organisation-prepared/ ↩