Guide · GAID 2025
GAID 2025 explained.
The Nigeria Data Protection Act told you what you owe. The General Application and Implementation Directive 2025 tells you when, how, in what form, and to whom you must prove it. This guide sets out what the directive actually changes for your organisation.
Estreat Limited · Reviewed August 2026 · General information, not legal advice. Confirm your obligations with the Commission, a qualified DPO, or a licensed DPCO.
Where GAID came from
The Nigeria Data Protection Act 2023 created the Nigeria Data Protection Commission and set out rights, principles and duties in the language of statute: broad, principle-level, and silent on mechanics. A statute cannot tell you whether your registration renews in January or March, what document proves your security measures, or who audits your return. That gap between principle and practice is what the General Application and Implementation Directive 2025 closes. It was issued by the Commission under the Act and dated 20 March 2025, and it is the single most operationally important instrument in Nigerian data protection today.
What GAID actually does
Four things matter to almost every organisation:
- It formalises registration levels. Controllers and processors of major importance sit at levels from Ordinary-High up to Ultra-High, and the level determines what you file and how deep the scrutiny goes. Our guide to being a controller of major importance covers designation.
- It creates the annual Compliance Audit Return. Article 10 of the directive obliges designated organisations to account to the Commission yearly, through a licensed DPCO, against the Schedule 2 question set. We cover the return in detail in our Compliance Audit Return explainer.
- It sets the rhythm. Registration renewals, the standing 31 March return deadline, and the expectation that records exist continuously rather than appearing each spring. Compliance stops being an event and becomes a calendar.
- It raises the evidentiary bar. Assertions no longer suffice. Each answer on the return is expected to carry the register, policy, log or agreement behind it.
How it changes your compliance year
Before GAID, a typical organisation met data protection once a year: a consultant produced an audit-style report, it was filed, and everyone moved on. Under GAID that document has been replaced by something stricter. The return interrogates whether records exist at all: your processing register, impact assessments, subject request outcomes, breach decisions, training logs, processor agreements. Those cannot be reconstructed honestly in March because they describe what happened across the whole year.
The practical consequence is a different shape of work:
- New processing enters your record when adopted, not when audited.
- Breach clocks run from awareness, which means awareness itself must be provable.
- Evidence accumulates against the controls it satisfies, dated as it lands.
- The return assembles from the record instead of interrupting the business to rebuild one.
What happens if you ignore it
GAID carries the force of the Act behind it. Designated organisations that do not register, renew or file expose themselves to the Commission’s enforcement powers, including the administrative fines under section 48 of the Act for controllers and processors of major importance, the greater of ten million naira or two percent of annual gross revenue. The actual penalty is determined through an enforcement order and the factors in section 48(6). Our guide to penalties and enforcement sets out the exposure in full.
The one-sentence version
GAID 2025 turned Nigerian data protection from a document you buy once a year into a record you hold all year, and every part of the directive points the same direction: the organisations that keep the record file calmly, and the ones that reconstruct it do not survive follow-up questions.
This guide summarises GAID 2025 (issued by the NDPC under the NDPA 2023, dated 20 March 2025) for general information. The directive text and the Commission’s published guidance govern; confirm your designation and obligations with a licensed DPCO or qualified counsel. Reviewed August 2026.
Questions we are asked.
Short answers to the questions behind most searches about this topic. The body of the guide above carries the detail and the citations.
What is GAID 2025?
The General Application and Implementation Directive 2025 is a directive issued by the Nigeria Data Protection Commission under the NDPA 2023, dated 20 March 2025. It converts the Act’s broad obligations into an operating system: registration levels, filing routes, deadlines, and evidence expectations.
Does GAID 2025 apply to small organisations?
It applies to data controllers and processors of major importance at every designation level, including Ordinary-High Level organisations, though the depth of obligation rises with level. Confirm your designation with the Commission or a licensed DPCO.
Is GAID 2025 a law or a guideline?
It is a directive made under sections 1(a), 6(c), 61 and 62 of the NDPA 2023 by the Commission, which gives it regulatory force. Non-compliance exposes an organisation to the enforcement powers of the Act, including administrative fines under section 48.
Continue with
Compliance Audit Return, explained
The article 10 obligation GAID creates, and its Schedule 2 content.
Read the guideController of major importance
Which designation level your organisation holds.
Read the guideRoPA in Nigeria
The record GAID expects to find underneath every answer.
Read the guideBreach notification in 72 hours
The statutory clock the directive expects you to be able to prove.
Read the guideTurn this guidance into your next step.
Estreat keeps your processing registers, impact assessments, subject requests, breach clocks and evidence current all year, then assembles the Compliance Audit Return from that record for filing through a licensed DPCO. We are software, not a DPCO or a law firm, and we will introduce you to a licensed partner if you need one.