Guides
Nigerian data protection obligations, explained without the fog.
Each guide takes one obligation under the NDPA 2023 or GAID 2025 and sets out who it applies to, what it requires, and what evidence proves it. Written for DPOs and the people who answer for compliance, with instruments cited and dates given.
General information, not legal advice. Estreat is a software company, not a licensed DPCO or law firm.
The NDPC Compliance Audit Return, explained
Who must file the annual CAR, when, through whom, and what GAID Schedule 2 actually asks of you.
Covers: compliance audit return · CAR filing · NDPC audit
Read the guideData controller of major importance
How organisations are designated under the NDPA and GAID tiers, and what each level obligates you to do.
Covers: controller of major importance · Ultra-High · Extra-High
Read the guideGAID 2025 explained
What the General Application and Implementation Directive adds to the Act, and how it changes your compliance year.
Covers: GAID 2025 · implementation directive · registration tiers
Read the guideRoPA in Nigeria
Building a record of processing activities that survives an audit, under NDPA section 29.
Covers: RoPA · record of processing · s.29 register
Read the guideBreach notification in 72 hours
The section 40 duty, when the clock starts, what to report, and how to prove when you became aware.
Covers: 72 hours · data breach notification · NDPA s.40
Read the guideNDPA penalties and enforcement
Administrative fines under section 48, the surcharge on late returns, and what enforcement looks like in practice.
Covers: NDPA fine · 2% of gross revenue · NDPC enforcement
Read the guideTurn this guidance into your next step.
Estreat keeps your processing registers, impact assessments, subject requests, breach clocks and evidence current all year, then assembles the Compliance Audit Return from that record for filing through a licensed DPCO. We are software, not a DPCO or a law firm, and we will introduce you to a licensed partner if you need one.