Businesses whose core operations involve data control and processing have been placed on high alert following a directive to conduct mandatory annual Data Protection Compliance Audits.

Failure to comply with this requirement now carries the risk of sanctions up to N10 million or 2 per cent of a company’s annual gross revenue.

The directive, which targets Data Controllers and Data Processors of Major Importance across Nigeria, is being enforced by the Nigeria Data Protection Commission (NDPC) under the provisions of the Nigeria Data Protection Act (NDPA) 2023 and the General Application and Implementation Directive (GAID) 2025.

The compliance requirement applies annually, with audit returns expected to be filed within the first quarter of the year.

With the current audit season officially underway, regulators have signalled that oversight in 2026 will be significantly stricter than in previous years. This nationwide directive covers all organisations operating within Nigeria’s data ecosystem, including companies handling personal and sensitive data.

According to the NDPC, the move is aimed at strengthening data privacy, safeguarding citizens’ personal information, and ensuring organisations align with global best practices.

The Commission has explicitly warned that enforcement this year will be rigorous, with higher penalties for defaulters.

Providing context on the new regulatory regime, data analyst Amoo Francis noted that data protection compliance in Nigeria is now fully governed by the NDPA 2023 and the GAID 2025, effectively replacing the former Nigeria Data Protection Regulation (NDPR).

He explained that the new framework introduces clearer obligations, including mandatory registration for major data processors, the appointment of Data Protection Officers (DPOs), the execution of Data Protection Impact Assessments (DPIAs), and stricter breach reporting timelines.

Francis highlighted that the GAID, which became effective in September 2025, provides the operational roadmap for the NDPA, signalling a definitive shift from advisory compliance to active enforcement.

Reinforcing the urgency of the situation, Mikun Adeseyoju of DataPro Nigeria Limited, a licensed Data Protection Compliance Organisation (DPCO), urged organisations to integrate data protection audits into their annual work plans immediately.

He advised companies to move beyond ticking the compliance box to building real resilience.

Adeseyoju emphasized that early audits allow organisations to identify risks, uncover hidden vulnerabilities, and remediate gaps before facing regulatory scrutiny.

With the NDPC already issuing compliance notices and penalties, experts warn that organisations delaying action may face severe financial and reputational consequences.