CAR deadline · 31 MarchBreach notice · 72h from awarenessStay ahead with CARPath

Guide · NDPA s.29

RoPA in Nigeria: building a record that survives an audit.

The record of processing activities is the spine of NDPA compliance: every impact assessment, subject request answer, breach decision and Compliance Audit Return answer traces back to it. Here is what it must contain, who should own it, and where Nigerian organisations go wrong.

Estreat Limited · Reviewed August 2026 · General information, not legal advice. Confirm your obligations with the Commission, a qualified DPO, or a licensed DPCO.

What the RoPA is for

A record of processing activities is exactly what the name says: a record, not a report. It inventories the personal data processing your organisation carries out (payroll, customer onboarding, marketing, CCTV, vendor due diligence) and for each activity answers the questions a regulator asks first: why do you hold this, on what basis, for how long, and who else touches it. Under the NDPA 2023 it anchors the accountability duties in section 29, and under GAID 2025 it is the register the annual Compliance Audit Return interrogates answer by answer.

What each entry must capture

A defensible RoPA entry carries, at minimum:

  • Purpose: the business reason, stated plainly, not recited legalese.
  • Lawful basis: consent, contract, legal obligation, vital interest, public interest, or legitimate interest, and why that basis fits this purpose.
  • Categories: of data subjects and of personal data, flagging special-category and children’s data where present.
  • Recipients: processors and third parties who receive the data, each tied to an agreement.
  • Transfers: any movement outside Nigeria, and the legal instrument relied on for it.
  • Retention: how long, and what happens at the end of the period.
  • Security measures: the technical and organisational measures protecting this specific processing.

If an entry cannot answer all seven, it is not a record; it is a claim. Auditors probe exactly the gaps: a retention period with no deletion mechanism, a transfer with no instrument, a “consent” basis for data collected before any consent was requested.

Who owns it

The DPO is accountable for the RoPA but cannot author it alone, because the knowledge lives in the business: HR knows the payroll processors, marketing knows the ad-tech tags, engineering knows the logs. The pattern that works is a named owner per business function, a lightweight intake question set, and a review cycle that catches new systems when they are adopted. The pattern that fails is a spreadsheet the DPO rebuilds every March from memory.

The three failures auditors see

  • The frozen snapshot. A RoPA written once in 2024 describing an organisation that no longer exists. Every new vendor, product and tool since then is invisible to the record and therefore unprotected.
  • The consultant artefact. Accurate on delivery day, owned by no one internally, and un-updatable without paying for the consultant again.
  • The disconnected register. A RoPA that exists but is not linked to anything: impact assessments, breach decisions and the annual return are produced separately, so they contradict the register under follow-up questions.

What good looks like

A defensible RoPA is current, connected and evidenced. Current: processing enters the record when adopted. Connected: a processing activity recorded once appears in the right impact assessments, transfer analyses and return answers without re-keying. Evidenced: each entry carries the documents that prove it: the processor agreement, the transfer instrument, the retention schedule, dated as they land. That is the model our platform page describes: one underlying record, six registers reading from it.

If you are starting from nothing, do not aim for completeness in one pass. Capture your highest-risk processing first, including the activities that would trigger a designation or a breach notification. Widen from there. A partial, accurate record beats a complete, invented one every single time, because only the first survives a follow-up question.

This guide summarises the record-keeping expectations of the NDPA 2023 accountability framework and their enforcement through GAID 2025. It is general information, not legal advice; the Commission’s published guidance and a licensed DPCO’s opinion govern in practice. Reviewed August 2026.

Questions we are asked.

Short answers to the questions behind most searches about this topic. The body of the guide above carries the detail and the citations.

What is a RoPA?

A record of processing activities: the living inventory of every processing your organisation carries out, why it is carried out, on what lawful basis, for how long, and with which recipients and transfers. Under the NDPA regime it is the register every other compliance artefact hangs from.

Is a RoPA legally required in Nigeria?

Yes for controllers and processors of major importance. The duty to maintain records of processing sits in the NDPA 2023 accountability framework (section 29 duties) and is enforced in practice through GAID 2025: the annual Compliance Audit Return interrogates the record directly.

How detailed should each entry be?

Detailed enough that a stranger could trace the processing from purpose to deletion. For each activity: purpose, categories of data subjects and data, lawful basis, recipients, transfers and their legal instrument, retention period, and a description of security measures.

Turn this guidance into your next step.

Estreat keeps your processing registers, impact assessments, subject requests, breach clocks and evidence current all year, then assembles the Compliance Audit Return from that record for filing through a licensed DPCO. We are software, not a DPCO or a law firm, and we will introduce you to a licensed partner if you need one.