Guide · NDPA s.48
NDPA penalties and enforcement.
Compliance obligations are easier to prioritise once their price is explicit. This guide sets out what non-compliance costs under the Nigeria Data Protection Act 2023: the section 48 fines, the GAID 2025 surcharge on late returns, the Commission's other remedies, and how enforcement has actually been applied.
Estreat Limited · Reviewed August 2026 · General information, not legal advice. Confirm your obligations with the Commission, a qualified DPO, or a licensed DPCO.
Section 48: the headline fines
Section 48 of the NDPA 2023 gives the Commission power to impose administrative fines. The amounts scale with whether you are designated as a controller or processor of major importance:
- Controllers and processors of major importance: the greater of ₦10,000,000 or 2% of annual gross revenue of the preceding financial year.
- All other organisations: the greater of ₦2,000,000 or 2% of annual gross revenue.
Two features matter more than the headline numbers. First, the percentage leg makes the ceiling proportional: for a mid-size Nigerian business, two percent of gross revenue dwarfs ten million naira. Second, liability attaches to breaches of the Act’s obligations generally, not only to spectacular leaks. Operating without required records, ignoring subject requests, failing to notify a notifiable breach, filing no return: each is the kind of failure the fine regime contemplates.
The GAID surcharge on late returns
Beyond the Act’s fines, GAID 2025 adds its own economic pressure on the annual Compliance Audit Return: filing past the standing 31 March deadline attracts a surcharge on the applicable fee. Check the Commission’s current notices for any filing-period extension before setting your deadline.
The rest of the toolkit
Fines are the visible remedy, not the only one. The Commission can also:
- Order remediation: specific steps to bring processing back into compliance, on a timetable.
- Order compensation: to data subjects who suffered damage.
- Suspend or cease processing: up to bans that stop a business line entirely.
- Pursue offences: unlawful disclosure, handling data without lawful basis, and obstructing the Commission carry criminal exposure, including for officers who consented or connived.
Alongside all of these sits the reputational dimension: the Commission names investigated organisations publicly, and breach notifications themselves reach the affected people by design.
How the sanction is determined
Section 48(6) requires the Commission to consider the nature, gravity and duration of the infringement, the processing purpose, the people affected, harm and mitigation, intent or negligence, cooperation, and the types of personal data involved. Keep evidence of your decisions and corrective action alongside the underlying records.
How to price your own exposure
- Designation first. Designation determines whether the higher or standard maximum applies; both use a 2% revenue comparison in section 48. Our guide covers designation levels.
- Records second. Almost every fine scenario begins with records that did not exist when asked for. The RoPA guide shows what auditors expect.
- Clocks third. A notifiable breach handled well is a defensible incident; handled silently, it becomes the enforcement file. See the 72-hour duty.
The cheapest mitigation remains unglamorous: hold the record during the year, so that when the Commission, a DPCO auditor or a data subject asks, the answer exists dated, sourced and complete.
This guide summarises penalties under section 48 and related provisions of the NDPA 2023 and the surcharge mechanism in GAID 2025, for general information. It is not legal advice, and enforcement practice evolves; confirm current positions with the Commission’s published guidance or qualified counsel. Source checked 4 September 2026: NDPA 2023, section 48.
Questions we are asked.
Short answers to the questions behind most searches about this topic. The body of the guide above carries the detail and the citations.
What is the maximum fine under the NDPA?
For a controller or processor of major importance, the higher maximum is the greater of ₦10,000,000 or 2% of annual gross revenue of the preceding financial year. For a controller or processor not of major importance, the standard maximum is the greater of ₦2,000,000 or 2% of annual gross revenue.
Is the fine per breach or per year?
Section 48 permits a penalty or remedial fee after an investigation. The amount depends on the enforcement order and factors including gravity, duration, harm, mitigation and cooperation; it is not an automatic annual charge.
Can directors be personally liable?
The Act creates offences with personal dimensions, including for officers who consent to or connive in violations, alongside the Commission’s powers to seek compensation orders for affected data subjects.
Continue with
Compliance Audit Return, explained
The annual obligation whose lateness carries a surcharge.
Read the guideGAID 2025 explained
The directive behind the deadline and the fee structure.
Read the guideBreach notification in 72 hours
The clock whose silence turns incidents into cases.
Read the guideRoPA in Nigeria
The record whose absence starts most penalty files.
Read the guideTurn this guidance into your next step.
Estreat keeps your processing registers, impact assessments, subject requests, breach clocks and evidence current all year, then assembles the Compliance Audit Return from that record for filing through a licensed DPCO. We are software, not a DPCO or a law firm, and we will introduce you to a licensed partner if you need one.