NDPC Compliance Audit Return (CAR) 2026: Who Files, Deadlines and Evidence
By Oluwafemi Ofobutu · Founder & CEO, StackWeaver · 7 min read
Sourced from primary regulatory documents where available. How we research and correct our guides.
Short answer: Under the Nigeria Data Protection Act (NDPA) 2023 and the NDPC’s General Application and Implementation Directive (GAID) 2025, data controllers and processors of major importance in the Ultra-High (UHL) and Extra-High (EHL) tiers must file an annual Compliance Audit Return (CAR) through a licensed DPCO by 31 March. For 2025 returns the NDPC extended the deadline to 30 May 2026 12.
Last updated 3 October 2026. Not legal advice — confirm details with your DPCO or counsel.
Who files
| Tier | Typical organisations | Threshold (data subjects in 6 months) | CAR |
|---|---|---|---|
| Ultra-High Level (UHL) | Commercial banks, telecoms, insurers, large platforms | over 5,000 | Required, via a DPCO |
| Extra-High Level (EHL) | Microfinance banks, universities, government agencies | over 1,000 | Required, via a DPCO |
| Ordinary-High Level (OHL) | SMEs, schools, contractors | over 200 | Check GAID for your obligations |
Thresholds and examples come from the NDPC’s registration guidance and law-firm summaries 13. Most CBN-licensed fintechs process enough customer data to fall into the higher tiers — see Am I a data controller of major importance?.
Key dates
| Date | What happens |
|---|---|
| 20 March 2025 | GAID issued by the NDPC |
| 19 September 2025 | GAID takes effect 4 |
| 31 March (every year) | CAR due for the previous year |
| 30 May 2026 | Extended deadline for 2025 returns 2 |
Penalties
- Late filing: an additional administrative fee of up to 50% of the filing fee.
- Not filing: a fine of up to 2% of the previous year’s annual gross revenue or ₦10 million, whichever is greater 1.
Evidence to have ready for your DPCO
- Record of processing activities (what personal data, why, where it goes).
- Lawful basis for each processing activity and consent records where consent is used.
- Data protection impact assessments for high-risk processing.
- Your appointed Data Protection Officer and their reporting line.
- Privacy notices as published, with dates.
- Data subject request log — received, answered, on time.
- Breach register and notifications made to the NDPC.
- Cross-border transfer basis for data leaving Nigeria.
- Processor contracts with data protection clauses.
- Security controls evidence (access reviews, encryption, backups) — often shared with SOC 2 or ISO 27001 work.
StackWeaver keeps each of these as a reviewed, fingerprinted evidence item your DPCO can receive as one verifiable package. See NDPA compliance or talk to us.
Sources
Footnotes
-
Templars (via Mondaq), “Data Protection Compliance In Nigeria: Audit Return Obligations For 2026”, 28 January 2026. https://www.mondaq.com/nigeria/data-protection/1736914/data-protection-compliance-in-nigeria-audit-return-obligations-for-2026 ↩ ↩2 ↩3
-
OAL, “NDPC extends 2025 data protection audit return deadline to 30 May 2026”, April 2026. https://oal.law/ndpc-extends-2025-data-protection-audit-return-deadline-to-30-may-2026/ ↩ ↩2
-
Andersen Nigeria, “NDPC issues Guidance Notice on the registration of data controllers and processors of major importance”, 2024. https://ng.andersen.com/ndpc-issues-guidance-notice-on-the-registration-of-data-controllers-and-processors-of-major-importance/ ↩
-
Aluko & Oyebode, “NDPC GAID takes effect on 19 September”. https://www.aluko-oyebode.com/insights/ndpc-gaid-takes-effect-on-19-september-is-your-organisation-prepared/ ↩