The March 31 deadline has passed. If you haven't filed your Compliance Audit Return, you're already late, but filing late is still better than not filing at all.
I keep seeing the same confusion from Nigerian businesses about this filing. So let me walk through what the CAR actually is, who has to file it, and what you're supposed to put in it. No filler.
What the CAR is
The NDPC requires an annual filing from organisations that process personal data at scale. They call it the Compliance Audit Return. It's basically your organisation telling the regulator: here's what data we hold, here's why we hold it, here's how we protect it.
It replaced the old NDPR audit framework. Same idea, updated for the Nigeria Data Protection Act 2023.
You can't file it yourself. It goes through a licensed Data Protection Compliance Organisation (DPCO). That's a mandatory intermediary: think of them as your compliance auditor for this specific filing.
Do you need to file?
Probably. The threshold is lower than most people think.
You qualify as a "data controller or processor of major importance" from a much lower bar than most people expect: processing the data of more than 200 individuals within six months puts you in the Ordinary-High Level tier under the NDPC's classification. More than 1,000 makes you Extra-High Level, more than 5,000 Ultra-High Level, and some sectors are Ultra-High by name regardless of count: commercial banks, telcos, insurers, payment gateways and their fintech kin. If you run a fintech app, an e-commerce platform, a payroll system, or basically any digital business with a Nigerian customer base, you're classified. Which tier you're in decides what you file: Extra-High and Ultra-High entities file the CAR annually through a licensed DPCO, while Ordinary-High entities renew their NDPC registration each year and file no CAR.
The NDPC's classification factors also weigh the sensitivity of what you process (health, biometric and financial data, data of children and vulnerable people), reliance on cloud and cross-border flows, and the degree of automation in your processing.
For most digital businesses the filing obligation is already settled. The open question is how long it takes the NDPC to notice the gap.
The deadline situation
The 2026 filing covered your 2025 processing activities. The standing deadline under the GAID is 31 March each year (businesses established after June 2023 file within 15 months of establishment, then annually). For the 2026 cycle the NDPC extended the deadline once, to 30 May 2026, and that date has now passed.
If you missed it: late filers pay up to 50% extra on the filing fee under the GAID. Not filing at all can cost a controller of major importance whichever is higher of ₦10 million or 2% of annual gross revenue for the preceding year, under section 48 of the NDPA.
My advice if you're late: file anyway. The penalty for late filing is manageable. The penalty for non-filing is not.
What goes into the CAR
This is where organisations waste time, because they try to make it perfect instead of making it accurate. The CAR is a set questionnaire with defined fields. Here's what you're actually filling in:
Your organisation details. Legal name, registration, sector, rough number of data subjects, and your DPO's name and contact info. If you don't have a DPO appointed, that's a problem you need to fix before filing.
Your data processing inventory. This trips people up. You need to list what personal data you collect (names, emails, financial records, biometrics, location: all of it), who you collect it from (customers, employees, app users), why you collect it (service delivery, marketing, fraud detection), and your legal basis for each one (consent, contract, legitimate interest, legal obligation).
If you run AI systems, those go in here too. Your credit scoring model processes personal data. Your chatbot processes conversation data. Your fraud detection system processes transaction data. Don't pretend these don't exist; the NDPC knows what fintechs are building.
Your security measures. What are you actually doing to protect this data? Encryption, access controls, staff training, incident response plans. They also want to know about any DPIAs you've done and any breaches you've had.
Your cross-border transfers. If data leaves Nigeria, and it almost certainly does if you use any cloud provider, SaaS tool, or AI API, you need to document where it goes, what safeguards are in place, and why the transfer is lawful. Every OpenAI API call sends data to the US. Every AWS instance might sit in Ireland. Document it.
Your data subject rights process. How do people request access to their data? How do they ask you to delete it? The NDPA gives you 30 days to respond. You need a process, and you need records showing you've used it.
How filing actually works
- Register on the NDPC compliance portal if you haven't
- Engage a licensed DPCO (for Extra-High and Ultra-High Level entities they prepare and submit the CAR on your behalf)
- Complete the structured questionnaire
- Attach your supporting docs: data protection policy, DPIA reports, breach records
- Pay the filing fee. The GAID's fee schedule sets the bands: ₦100,000-₦250,000 for Extra-High Level entities, and ₦500,000, ₦750,000 or ₦1,000,000 for Ultra-High Level entities depending on how many data subjects you process
- Keep your confirmation receipt
For Extra-High and Ultra-High Level entities the DPCO route is how filing works, except where the Commission approves otherwise. If you don't have a DPCO relationship, start there. We've written a guide on choosing one.
What the NDPC does if you ignore this
They fine you. They've been clear about this.
The enforcement capacity at NDPC has grown significantly since the NDPA passed. They're hiring, they're investigating, and they're building a track record of enforcement. The days of assuming nobody's watching are winding down.
Beyond fines: non-filers get flagged for deeper scrutiny. That means mandatory audits, compliance orders, and the kind of regulatory attention that makes your legal team nervous. Plus the NDPC publishes enforcement actions, so your clients, partners, and competitors can see it.
If you're running AI
AI systems create specific wrinkles in the CAR that a lot of businesses try to gloss over:
Automated decisions. If your AI decides things about people (credit approvals, fraud flags, insurance pricing), you have to disclose the logic, at the level of plain description rather than source code. "We use a model trained on transaction history to predict default probability" is the kind of explanation they're looking for.
Training data. If you trained models on personal data, that's processing. It needs a lawful basis. And yes, it should show up in the CAR.
Third-party AI providers. Data flows to OpenAI, Anthropic, Google, wherever your API calls go. That's a cross-border transfer. Document the safeguard (usually a Data Processing Agreement with Standard Contractual Clauses), and name the provider.
We've written more about this in our guide on NDPA compliance for Nigerian fintechs using AI.
What I'd do if I were you
If you've filed: good. Set a reminder for next year and keep your processing inventory updated as things change.
If you haven't filed: file late. The late fee stings less than the non-filing fine. Get a DPCO engaged this week. Build a processing inventory; even a rough one is better than nothing. Appoint a DPO if you haven't. And file.
If this feels overwhelming: that's normal. Most businesses don't have a clean data inventory sitting around. The first year is always the hardest. After that, it's an update, not a rebuild.
Need to move on this now? Message Michael on WhatsApp at +353 89 943 8223. Quick reply, no scheduling overhead, and we start with your CAR pack readiness and where the gaps are. If you want the whole privacy function run for you, CAR pack included, the fractional DPO service is the ongoing version.
Start with an NDPA Readiness Diagnostic
If you need NDPA compliance advice or a compliant AI build, the first step is a written diagnostic. You get a written assessment with priced next steps.
Related Articles
Nigeria
Data Protection for Nigerian Banks Using AI: NDPA, CBN, and GDPR in One Framework
How Nigerian banks and financial institutions handle data protection across three regulatory layers when deploying AI. NDPA obligations, CBN requirements, and GDPR extraterritorial reach.
Nigeria
Cross-Border Data Transfers Nigeria: NDPA Rules for Cloud, AI & SaaS
Using AWS, OpenAI, or any cloud service from Nigeria? Your data is leaving the country. Here are the NDPA transfer rules, what safeguards you need, and what happens if you get it wrong.
Nigeria
NDPA Breach Notification Timeline (Nigeria): The 72-Hour Rule
Nigeria's NDPA 2023 (s.40) and the GAID 2025 require NDPC notification within 72 hours of awareness, and affected individuals told immediately where the risk is high. When the clock starts, what to send, what happens if you miss.