GAID 2025: What Nigerian Businesses Need to Know about the New Data Processing Obligations
Data protection is no longer just a concern for tech giants or global corporations, even smaller companies need to pay attention. Here's why...
In 2023, Nigeria enacted the Nigeria Data Protection Act (NDPA) to establish a national framework for the collection, usage, processing, and protection of personal data. While the Act laid the foundation for data privacy and protection, it left many businesses uncertain about how to implement its provisions in practical terms.
To fill this lacuna, the Nigerian Data Protection Commission (NDPC) released the General Administrative Implementation Directive (GAID 2025) to replace the NDPR (2019) and NDPR Implementation Framework (2020). This comprehensive guide tells Nigerian businesses, NGOs, startups, and public institutions exactly how to handle data, what to document, what not to do, and several other steps necessary to comply with the NDPA.
Whether you run a school, a fintech or SaaS platform, or any business that requires data gathering, the GAID 2025 has something to say about how you collect, use, process, and protect a data subject’s personal information and the consequences for doing otherwise.
So,
What does GAID 2025 require? and;
How can businesses comply?
At its core, the GAID 2025 is about clarity and accountability. It was designed to eliminate the gray areas many businesses faced under the NDPR and ensure that personal data is processed responsibly, transparently, and securely. Its main objective is to provide detailed guidance and practical directives for the implementation of the Nigeria Data Protection Act (NDPA) 2023, to clarify the NDPA's provisions and ensure consistent application across various data processing activities in Nigeria.
Key Obligations for Businesses under GAID 2025
1. Registration as a Controller/Processor of Major Importance (DCPMI)
The GAID 2025 introduces a tiered compliance structure that distinguishes between ordinary data controllers/processors and Data Controllers and Data Processors of Major Importance (DCPMIs). This classification isn’t arbitrary; it is based on the scale and sensitivity of the data being processed.
While ordinary processors handle personal data on a relatively moderate scale and are subject to general compliance requirements under the NDPA, DCPMIs operate in critical sectors, such as healthcare, finance, telecommunications, and digital services, or engage in high-risk processing activities involving large volumes of sensitive data. As a result, DCPMIs are subject to stricter obligations, including mandatory registration, annual compliance audits, appointment of a certified Data Protection Officer (DPO), and submission of biannual data activity reports.
Building on this classification, the GAID categorizes organisations handling high volumes of sensitive data into three tiers;
Ultra-High-Level (UHL),
Extra-High-Level (EHL), and
Ordinary-High-Level (OHL).
This tiering system is designed to reflect the varying levels of risk and national impact associated with each organisation’s data processing activities. UHL and EHL tiers are reserved for DCPMIs based on the magnitude of their operations and sectoral importance, while OHL applies to ordinary data controllers and processors. The higher the tier, the more rigorous the compliance expectations, ensuring that obligations are proportionate to the data risks involved.
2. Core Obligations of DCPMIs
Under the GAID 2025, all data controllers and processors must adhere to a set of core obligations, but DCPMIs must go further. They must comply with the following updated registration and reporting requirements:
Mandatory Registration: Organizations classified as data controllers or processors of major importance (DCPMI) are required to formally register with the Nigeria Data Protection Commission (NDPC), following the procedures outlined in the Commission’s Guidance Notice.
Category-Specific Obligations: Entities under the Ultra High-Level (UHL) and Extra High-Level (EHL) categories are only required to register once but must submit a Compliance Audit Return (CAR) every year, whereas those in the Ordinary High-Level (OHL) category must renew their registration annually but are not obligated to file CARs each year.
Reporting Changes: Any significant updates to the information provided during registration must be communicated to the NDPC within 60 days, using either the online portal or an official email channel.
Declassification Requests: If a company no longer falls within the criteria for major importance, it can apply to be delisted from the register, provided it has cleared any outstanding regulatory fees and obligations.
Public Disclosure: To promote transparency, the NDPC will publish and periodically update the official list of registered data controllers and processors of major importance on its website every year.
3. Appointment of a Data Protection Officer
Under the GAID 2025, every data controller and processor is required to appoint a Data Protection Officer (DPO). This individual may be an internal staff member or an external consultant contracted through a service agreement. The DPO is entrusted with overseeing all data protection matters within the organization and must collaborate with senior management to resolve such issues effectively. To ensure independence and accountability, the GAID outlines several guiding principles for the role:
DPOs must operate free from external pressure or undue influence and cannot be penalized or dismissed for executing their responsibilities in good faith.
They must report directly to top management, ensuring that data protection issues receive adequate attention at the leadership level.
Individuals (data subjects) should be able to contact the DPO easily, especially when seeking to exercise their rights under the Nigeria Data Protection Act (NDPA).
While DPOs may hold other roles, those additional responsibilities must not create a conflict of interest. They are also bound by strict confidentiality in the discharge of their duties.
Additionally, the DPO must prepare a semi-annual report on the organization’s data protection compliance status. This report must be validated by a licensed Data Protection Compliance Organisation (DPCO) during the required compliance audit. The content of the report should reflect the organization's standing under the NDPA.
4. Compliance Audit & Filing of Compliance Audit Returns (CARs)
All data controllers and processors of major importance (DCPMIs) must adopt a risk-based approach to their audits, as follows:
New entities must complete their first audit within 15 months of commencement.
Existing entities (those operating before June 12, 2023) must complete and submit their annual audit by March 31 each year.
Entities classified as Ultra High-Level (UHL) and Extra High-Level (EHL) are required to submit their Compliance Audit Returns (CARs) through a licensed Data Protection Compliance Organisation (DPCO). However, Ordinary High-Level (OHL) entities may file directly with the NDPC, unless specifically instructed otherwise. It's also important to note that late submission of CARs attracts a penalty amounting to 50% of the original filing fee. To remain in good standing, all existing organizations must ensure their annual CARs are submitted no later than March 31 each year.
The GAID has also revised the audit filing fees for different categories of data controllers and processors:
UHL: One million Naira for 50,000+ data subjects; NGN 750,000 for less than 50,000 data subjects, and NGN 500,000 for below 25,000 data subjects
EHL: NGN 250,000 for 10,000 data subjects; NGN 200,000 for below 5,000, and NGN 100,000 for below 2,500 data subjects
OHL: This is omitted in the schedule as they have been exempted from audit filing.
5. Data Protection Impact Assessments (DPIAs)
DPIAs are legally required for any data processing activity that poses a high risk to the rights and freedoms of individuals. This includes the use of technologies or systems that involve profiling, biometric data, geolocation tracking, AI-driven decision-making, mass surveillance, or the processing of sensitive personal data, particularly where vulnerable groups such as children are involved.
Organisations must conduct a DPIA before launching any project or service that involves such high-risk processing. Even where size or scale might suggest otherwise, the NDPC may still mandate a DPIA depending on the nature of the activity. DPIAs are also required when developing new technologies (e.g., communication software), offering services in sectors like healthcare, finance, education, e-commerce, or hospitality, and when engaging in cross-border data transfers or public policy development involving personal data. Technologies like Artificial Intelligence (AI), Internet of Things (IoT), and blockchain must not be deployed without first conducting a DPIA.
The DPIA process must incorporate privacy by design and default, and must demonstrate how the organisation intends to mitigate risks, ensure transparency, protect data subjects, and enhance security. Completed DPIAs must be vetted by an accredited Data Protection Officer (DPO) and included in the organisation’s audit report to the Commission. Importantly, DPIAs must be submitted before processing begins, or at most within six months of starting, where processing commenced before the NDPA and GAID came into effect. Failure to comply may result in enforcement actions such as platform restrictions.
6. Standard Notice to Address Grievance (SNAG)
One of the GAID’s key innovations is the introduction of SNAG - Standard Notice to Address Grievance, a formal mechanism that empowers data subjects to raise concerns directly with organisations before involving the regulator. Under this framework, individuals who believe their data rights have been violated no longer need to contact the NDPC first. Instead, they are encouraged to send a SNAG notice directly to the data controller or processor responsible. This promotes internal resolution of complaints and holds organisations accountable for addressing data-related issues transparently and promptly.
Upon receiving a SNAG notice, data controllers must formally acknowledge and respond within a specified timeframe. If they fail to do so, the individual has the right to escalate the matter to the NDPC. This approach encourages organisations to develop clear, effective channels for handling data complaints and reinforces their duty to protect data subject rights. Failure to act on a SNAG notice constitutes a breach of the regulation and may trigger regulatory enforcement.
7. Cross‑Border Data Transfers & Transfer Impact Assessments (TIAs)
Before sending personal data outside Nigeria, organisations must take extra steps to ensure that the data will remain safe and protected. This starts with conducting a Transfer Impact Assessment (TIA), a formal risk assessment that demonstrates whether adequate safeguards are in place to protect individuals’ data in the destination country. Under the GAID, data can only be transferred internationally if one of the following conditions is met:
Adequacy Decision – The NDPC (Nigeria Data Protection Commission) has formally recognised that the receiving country has strong data protection laws, fair judicial processes, enforceable rights for data subjects, and an independent regulatory authority that can enforce those rights effectively.
Cross-Border Data Transfer Instrument (CBDTI) – Where there’s no adequacy decision, the organisation must adopt NDPC-approved instruments like binding corporate rules, standard contractual clauses, certification schemes, or codes of conduct that guarantee the safety of the data being transferred.
Other Lawful Bases – In some exceptional cases, other legal justifications for transfer may apply, but these must still comply with the NDPA and GAID requirements.
The NDPC may also consider international commitments, enforcement cooperation agreements with foreign regulators, and the stability of the receiving country's legal system when deciding whether a country meets the adequacy threshold.
8. Entities Exempted from Registration with the NDPC
The NDPC outlines categories of individuals and organizations that are not required to register:
Small-scale traders and artisans who do not share personal data with other entities as part of a commercial service, and whose data handling does not serve another business’s interest, are exempt.
Traders with fewer than 15 employees, or artisans who do not maintain structured records of customer data, beyond basic contacts like phone numbers, receipts, addresses, or emails, are also not required to register.
Social groups or communities, such as friends, professional circles, or hobby groups that simply interact on social media platforms, do not fall under the registration requirement.
In addition, the Updated Guidance Notice specifically exempts the following high-level entities from registration with the NDPC:
Community-Based Associations
Faith-Based Organizations
Foreign Embassies and High Commissions
Judicial bodies or tribunals carrying out court-like functions
Multigovernmental or international organizations
However, they are bound by the Principles of personal data processing, which include:
Lawful basis of personal data processing
Designation of Data Protection Officers
Personal data breaches notification
Data subjects’ rights
Conclusion
The GAID 2025 signals a new era of accountability and operational clarity for Nigerian organisations handling personal data. It’s not just a compliance checklist; it’s a strategic framework designed to embed data protection into the DNA of modern business operations.
Whether you're a startup founder, school administrator, fintech executive, or part of a public institution, the expectations are clear:
assess your risks,
know your obligations,
appoint the right people, and
build systems that protect the rights of data subjects by design and default.
Most importantly, non-compliance no longer has a soft landing; organisations that fail to meet their obligations may face penalties such as enforcement orders, public censure, fines, suspension from the DCPMI register, or even restrictions on data processing activities.
In a world where consumer trust is currency, aligning early with GAID 2025 isn’t just legal prudence, it’s a strategic move to build credibility and long-term competitiveness in Nigeria’s growing digital economy.
About Legal Bytes
We are Adune Legal’s weekly Newsletter, which simplifies the Law for Busy Executives, Entrepreneurs, and Tech Enthusiasts interested in the legal aspects of Business, Technology, and Intellectual Property.
We love emails from our readers— reply to this email and let us know your thoughts and suggestions.
WAIT!!!
Become a paid subscriber and access;
Q&A sessions with Nneoma Grace via chats on Substack.
Detailed Legal Templates and examples to save you time and legal fees
Expert Interviews and Case Studies
Don't miss out on these perks - subscribe today and start enjoying it!
Thanks for reading Legal Bytes
Adune Legal’s Team
P.S. Like Legal Bytes? Please forward us to a friend.
P.P.S. Was this publication forwarded to you? Sign up here & see previous publications.




The primary hurdle isn’t lack of interest, but it may be infrastructure and access. Local partnerships will matter a lot.