By Musskart Technology Editorial Team Published: Updated: Reviewed by Musskart Senior Engineers

250+

Projects Delivered Since 2020

NDPA

Readiness & DPO-as-a-Service

Licensed

DPCO Partner For Statutory Filing

₦1.5M+

Typical Readiness Engagement

We reply on WhatsApp within minutes.

Read This First: What Musskart Can and Cannot Do

The Nigeria Data Protection Act 2023 does not let just anybody audit you. Under section 33 of the NDPA, a data protection compliance audit and the Compliance Audit Return that follows it must be carried out and filed through a Data Protection Compliance Organisation (DPCO) licensed by the Nigeria Data Protection Commission. An unlicensed firm cannot issue the statutory verification that makes your return valid.

So be clear about what you are buying. Musskart Technology Limited is a software and security engineering company. We do the readiness work — the data mapping, the records of processing, the DPIAs, the consent and retention plumbing, the breach register, the technical controls — and we build the tooling that keeps it all current. We do not hold ourselves out as a licensed DPCO and we do not file your CAR. The statutory audit and filing go through a licensed DPCO. If you already use one, we hand them a clean, evidenced file. If you do not have one, we introduce you to one and work alongside them.

Anybody who tells you they can "handle your NDPC audit and filing" without naming their DPCO licence is either cutting a corner or about to cost you a re-audit. Ask for the licence. It is a fair question and a licensed DPCO will answer it in one line.

Do You Actually Have to Register and File?

Two different obligations get confused constantly, so take them one at a time.

1. Registration as a data controller or processor of major importance

If you process the personal data of a significant number of data subjects in Nigeria, or you handle data in a sector the Commission treats as critical, you are expected to register with the NDPC. The commonly quoted working threshold is processing the personal data of more than 2,000 data subjects in a twelve-month period, with sectoral judgement applied on top. If you run a fintech, a hospital, a school, a microfinance bank, an e-commerce store, an HR or payroll bureau, a logistics platform or an insurance business in Nigeria, assume you are in scope until somebody qualified tells you otherwise.

2. The annual Compliance Audit Return (CAR)

Registered controllers and processors of major importance then have to be audited annually by a licensed DPCO, which files the Compliance Audit Return on their behalf. This is the part with the money attached to it, and the part people leave until the last three weeks.

A quick self-test. If you cannot answer all five of these today, you are not ready to be audited: Where is every piece of personal data you hold, and which vendor holds a copy? What is your lawful basis for each processing activity? Who is your designated Data Protection Officer? Where is your breach register, and what is your 72-hour notification process? When did you last run a DPIA on a high-risk activity, and where is it written down?

What the NDPC Charges, and What Missing It Costs

Fees are set out in the Commission's General Application and Implementation Directive and scale with your classification tier. The figures below are the ones published for the current cycle — confirm the live numbers and your own tier against the NDPC's own schedule before you budget, because tiers and fees are revised.

ClassificationRegistration feeAnnual CAR filing fee
Ordinary High Level (OHL)₦10,000Not in the CAR filing band
Extra High Level (EHL)₦100,000₦100,000 – ₦250,000
Ultra High Level (UHL)₦250,000₦500,000 (Tier C) – ₦1,000,000 (Tier A)

Those are the Commission's fees. Your DPCO's professional fee sits on top, and the readiness work sits underneath both.

The penalties are the reason this gets attention. Late filing attracts a surcharge reported at 50% of the applicable filing fee. Failing to file at all is far worse: the NDPA exposes a data controller of major importance to a sanction of up to 2% of annual gross revenue in the preceding financial year, or ₦10 million, whichever is higher. For a business turning over ₦2 billion, that is a ₦40 million exposure against a ₦1 million filing fee. The arithmetic makes itself.

On timing: the Commission extended the filing deadline for the 2025 audit cycle from 31 March 2026 to 30 May 2026. That date has passed. If you did not file, you are late and accruing the surcharge, and the right move is to get audited and filed now rather than roll it into next cycle. If you did file, the next annual cycle is already close enough that starting readiness now is the cheap version — the expensive version is starting in March.

What We Actually Do

The Compliance Dashboard We Build

Readiness decays. You pass an audit in May, hire four people in July, sign two new vendors in August, and by the next cycle the file is stale again. For clients who want to stop repeating the exercise from scratch every year, we build an internal compliance dashboard that holds the state instead of a folder of Word documents.

It carries the live RoPA with change history, the vendor and DPA register with renewal dates, DPIAs with review triggers, the breach log with clocks running against the 72-hour window, DSAR tickets with due dates, staff training records, and an evidence library indexed against the questions a DPCO will ask. When audit season arrives you export the pack rather than rebuild it.

Standalone

Hosted for you, plugged into your systems through read-only connectors and manual entry where needed.

Embedded

Built into a product we already maintain for you, so consent, retention and audit logging live inside the app itself.

For DPCOs

White-labelled for licensed DPCOs running many client files at once, with per-client workspaces and an evidence export.

What It Costs

Readiness sprint

from ₦1,500,000

Data mapping, RoPA, gap assessment against the NDPA and GAID, policy set, vendor register and a prioritised remediation plan. Four to six weeks. This is the engagement most businesses need before a DPCO will get a clean result.

DPO-as-a-Service

from ₦350,000 / month

Named DPO, register upkeep, DSAR handling, quarterly review, staff training refresh, board reporting and liaison with your licensed DPCO through the audit cycle. Twelve-month term.

Remediation build

₦2,000,000 – ₦12,000,000

The engineering: consent and retention, DSAR endpoints, encryption, audit logging, access control rework, and the compliance dashboard. Scoped from the gap assessment, so you only pay for the gaps you actually have.

Two costs are not ours and never come through us: the NDPC's own registration and filing fees, and your licensed DPCO's professional fee for the statutory audit and return. We will tell you what to expect for both so your budget is honest, but you pay them directly.

How the Engagement Runs

Week 0 — Scoping call

Thirty minutes on WhatsApp or a call. What you do, how many data subjects, which systems, whether you are registered, whether you have ever been audited, and whether you already have a DPCO. We come back with a fixed price.

Weeks 1–2 — Discovery

Department interviews, system inventory, vendor list, sample records. We find the shadow spreadsheets and the WhatsApp groups where customer data lives. Everybody has them.

Weeks 3–4 — Documentation and gap report

RoPA, privacy notices, internal policies, DPIAs where needed, and a gap report scored by risk and effort, with the ones that will fail an audit flagged in red.

Weeks 5–8 — Remediation

We fix what we can fix in code and process, train your staff, run the breach tabletop, and stand up the dashboard if you are taking it.

Then — Hand to your DPCO

Evidence pack goes to your licensed DPCO. They conduct the statutory audit and file the CAR. We stay on the line to answer their technical questions and close anything they raise.

Why a Software Company for This

Most NDPA compliance in Nigeria is sold by law firms and consultancies, and the legal analysis they produce is genuinely good. The trouble is what happens next. The report says "implement data minimisation and a retention schedule", and then it sits in a shared drive because nobody on the client side can translate that into a migration, a cron job and a changed database schema.

We are the people who write that code. Musskart Technology Limited is a registered Nigerian software company headquartered in Asaba with an Abuja office and 250+ projects delivered since 2020, and we already build the systems that hold this data — fintech platforms, hospital systems, school management, loan apps, HR and payroll. We know where personal data hides in a Laravel application because we have put it there and taken it back out.

Pair us with your licensed DPCO and you get both halves: the statutory audit and filing from the people legally entitled to do it, and the engineering from the people who can actually change the system.

Related Musskart Pages

Already thinking about certification?

NDPA readiness overlaps heavily with information security certification. If you are chasing ISO 27001, CMMI or HIPAA alongside this, start with ISO 27001, CMMI and HIPAA compliance readiness in Nigeria — the control work overlaps and doing them together is cheaper than doing them twice.

Frequently Asked Questions

No, and you should be wary of any software company that says it can. Under section 33 of the Nigeria Data Protection Act 2023, only a Data Protection Compliance Organisation licensed by the Nigeria Data Protection Commission may conduct the statutory compliance audit and file the Compliance Audit Return. Musskart is a software and security engineering company, not a licensed DPCO. What we do is the readiness work that makes the audit pass: data mapping, records of processing, DPIAs, the breach register, DPO-as-a-Service, and the actual engineering changes to your systems. Then we hand a clean evidence pack to your licensed DPCO, or introduce you to one if you do not have one, and they conduct the audit and file the return.

Data controllers and processors of major importance. In practice that means organisations processing the personal data of a significant number of Nigerians, with the commonly applied working threshold being more than 2,000 data subjects in a twelve-month period, plus sectoral judgement on how sensitive the data is. Fintechs, hospitals and clinics, schools and universities, microfinance banks, insurers, HMOs, e-commerce platforms, HR and payroll bureaus, logistics platforms and marketing companies almost always qualify. Registration and the annual audit return are two separate obligations. Your classification tier determines the fees for both, and your licensed DPCO will confirm which tier you fall into.

There are three separate costs and they get conflated. First, the Commission's own fees: registration is published at 10,000 Naira for Ordinary High Level, 100,000 Naira for Extra High Level and 250,000 Naira for Ultra High Level, and the annual filing fee runs from 100,000 to 250,000 Naira at Extra High Level and from 500,000 to 1,000,000 Naira at Ultra High Level. Second, your licensed DPCO's professional fee for the statutory audit and filing, which they quote. Third, the readiness and remediation work, which is our part. Our readiness sprint starts at 1,500,000 Naira, DPO-as-a-Service starts at 350,000 Naira a month, and remediation engineering runs from 2,000,000 to 12,000,000 Naira depending on the gaps found. Confirm the Commission's current published fees before budgeting, because they are revised.

Late filing attracts a surcharge reported at 50 percent of the applicable filing fee. Not filing at all is the serious one: the Nigeria Data Protection Act exposes a data controller of major importance to a sanction of up to 2 percent of annual gross revenue in the preceding financial year, or 10 million Naira, whichever is higher. For a business with meaningful turnover that penalty dwarfs the filing fee many times over. The Commission extended the 2025 audit cycle deadline from 31 March 2026 to 30 May 2026, and that date has now passed, so if you did not file you are late and should get audited and filed rather than waiting for the next cycle.

The Act expects a designated Data Protection Officer with real independence and a direct line to management. It does not require that person to be a full-time employee, which is why outsourced DPO arrangements are common and accepted. Most Nigerian SMEs cannot justify a dedicated hire, and the usual fallback of naming the IT manager creates a conflict of interest because the person running the systems should not be the person auditing them. Our DPO-as-a-Service gives you a named, trained officer on retainer who maintains the registers, handles data subject access requests, runs the quarterly review, trains your staff, reports to your board and acts as the contact point for the Commission and your DPCO.

A readiness sprint for a mid-sized Nigerian business takes four to six weeks: one to two weeks of discovery across departments, two weeks producing the records of processing, policies and DPIAs, and a gap report at the end. Remediation then depends entirely on what the gap report finds. Fixing consent capture, retention jobs, data subject access endpoints and audit logging in a well-built application typically takes four to eight weeks of engineering. An older system with personal data scattered across spreadsheets and third-party tools takes longer because the cleanup is the real work. Start at least three months before your filing window, not three weeks.

Get NDPA-Ready Before Your Next Audit Cycle

Tell us what you process, how many data subjects you hold and whether you are already registered. We will come back with a fixed-price readiness scope — and if you need a licensed DPCO for the statutory filing, we will introduce you to one.

Chat on WhatsApp Get a Quote Call +234 813 168 6721 See Our Full Pricing
WhatsApp