NDPA Compliance Audit & CAR Filing in Nigeria
Who has to register with the NDPC, who has to file a Compliance Audit Return, what it costs, what the penalties are — and the readiness work and tooling Musskart does so your filing is a formality instead of a fire drill.
250+
Projects Delivered Since 2020
NDPA
Readiness & DPO-as-a-Service
Licensed
DPCO Partner For Statutory Filing
₦1.5M+
Typical Readiness Engagement
We reply on WhatsApp within minutes.
Read This First: What Musskart Can and Cannot Do
The Nigeria Data Protection Act 2023 does not let just anybody audit you. Under section 33 of the NDPA, a data protection compliance audit and the Compliance Audit Return that follows it must be carried out and filed through a Data Protection Compliance Organisation (DPCO) licensed by the Nigeria Data Protection Commission. An unlicensed firm cannot issue the statutory verification that makes your return valid.
So be clear about what you are buying. Musskart Technology Limited is a software and security engineering company. We do the readiness work — the data mapping, the records of processing, the DPIAs, the consent and retention plumbing, the breach register, the technical controls — and we build the tooling that keeps it all current. We do not hold ourselves out as a licensed DPCO and we do not file your CAR. The statutory audit and filing go through a licensed DPCO. If you already use one, we hand them a clean, evidenced file. If you do not have one, we introduce you to one and work alongside them.
Anybody who tells you they can "handle your NDPC audit and filing" without naming their DPCO licence is either cutting a corner or about to cost you a re-audit. Ask for the licence. It is a fair question and a licensed DPCO will answer it in one line.
Do You Actually Have to Register and File?
Two different obligations get confused constantly, so take them one at a time.
1. Registration as a data controller or processor of major importance
If you process the personal data of a significant number of data subjects in Nigeria, or you handle data in a sector the Commission treats as critical, you are expected to register with the NDPC. The commonly quoted working threshold is processing the personal data of more than 2,000 data subjects in a twelve-month period, with sectoral judgement applied on top. If you run a fintech, a hospital, a school, a microfinance bank, an e-commerce store, an HR or payroll bureau, a logistics platform or an insurance business in Nigeria, assume you are in scope until somebody qualified tells you otherwise.
2. The annual Compliance Audit Return (CAR)
Registered controllers and processors of major importance then have to be audited annually by a licensed DPCO, which files the Compliance Audit Return on their behalf. This is the part with the money attached to it, and the part people leave until the last three weeks.
A quick self-test. If you cannot answer all five of these today, you are not ready to be audited: Where is every piece of personal data you hold, and which vendor holds a copy? What is your lawful basis for each processing activity? Who is your designated Data Protection Officer? Where is your breach register, and what is your 72-hour notification process? When did you last run a DPIA on a high-risk activity, and where is it written down?
What the NDPC Charges, and What Missing It Costs
Fees are set out in the Commission's General Application and Implementation Directive and scale with your classification tier. The figures below are the ones published for the current cycle — confirm the live numbers and your own tier against the NDPC's own schedule before you budget, because tiers and fees are revised.
| Classification | Registration fee | Annual CAR filing fee |
|---|---|---|
| Ordinary High Level (OHL) | ₦10,000 | Not in the CAR filing band |
| Extra High Level (EHL) | ₦100,000 | ₦100,000 – ₦250,000 |
| Ultra High Level (UHL) | ₦250,000 | ₦500,000 (Tier C) – ₦1,000,000 (Tier A) |
Those are the Commission's fees. Your DPCO's professional fee sits on top, and the readiness work sits underneath both.
The penalties are the reason this gets attention. Late filing attracts a surcharge reported at 50% of the applicable filing fee. Failing to file at all is far worse: the NDPA exposes a data controller of major importance to a sanction of up to 2% of annual gross revenue in the preceding financial year, or ₦10 million, whichever is higher. For a business turning over ₦2 billion, that is a ₦40 million exposure against a ₦1 million filing fee. The arithmetic makes itself.
On timing: the Commission extended the filing deadline for the 2025 audit cycle from 31 March 2026 to 30 May 2026. That date has passed. If you did not file, you are late and accruing the surcharge, and the right move is to get audited and filed now rather than roll it into next cycle. If you did file, the next annual cycle is already close enough that starting readiness now is the cheap version — the expensive version is starting in March.
What We Actually Do
Data mapping and RoPA
We sit with each department and trace personal data from the point it enters your business to the point it is deleted. Output is a real Record of Processing Activities: every activity, the data categories, the lawful basis, the retention period, the systems, and every third party who gets a copy. This is the document an auditor asks for first and the one almost nobody has.
DPO-as-a-Service
The Act expects a designated Data Protection Officer. Most Nigerian SMEs cannot justify a full-time hire, so they name the IT manager and hope. We provide a named, trained DPO on retainer who owns the register, runs the quarterly review, handles data subject access requests, is the contact point for the Commission, and briefs your board.
DPIAs on high-risk processing
Credit scoring, biometrics, location tracking, ANPR, children's data, large-scale profiling and automated decisions all need a Data Protection Impact Assessment before you go live. We run them properly — risk, necessity, proportionality, mitigations, residual risk, sign-off — and hand you a document that survives scrutiny.
Breach register and 72-hour drill
You need a register, a severity rubric, an escalation path and a notification template ready before the incident, not during it. We install the process, run a tabletop exercise with your team, and wire the detection alerts into it so a breach is recorded within minutes rather than discovered in a forum post.
The engineering nobody else does
This is where a software company beats a pure consultancy. Consent capture with timestamps and versioning. Retention jobs that actually delete. Export and erasure endpoints so a DSAR takes minutes. Field-level encryption on the sensitive columns. Audit logs on every read of a customer record. Access reviews. We write the code, not just the policy.
Vendor and cross-border review
Your processors are your exposure. We inventory them, check what each one actually receives, review the data processing agreements, and flag transfers out of Nigeria that need an adequacy or safeguard argument. Most businesses discover two or three vendors they forgot they had.
The Compliance Dashboard We Build
Readiness decays. You pass an audit in May, hire four people in July, sign two new vendors in August, and by the next cycle the file is stale again. For clients who want to stop repeating the exercise from scratch every year, we build an internal compliance dashboard that holds the state instead of a folder of Word documents.
It carries the live RoPA with change history, the vendor and DPA register with renewal dates, DPIAs with review triggers, the breach log with clocks running against the 72-hour window, DSAR tickets with due dates, staff training records, and an evidence library indexed against the questions a DPCO will ask. When audit season arrives you export the pack rather than rebuild it.
Standalone
Hosted for you, plugged into your systems through read-only connectors and manual entry where needed.
Embedded
Built into a product we already maintain for you, so consent, retention and audit logging live inside the app itself.
For DPCOs
White-labelled for licensed DPCOs running many client files at once, with per-client workspaces and an evidence export.
What It Costs
Readiness sprint
from ₦1,500,000
Data mapping, RoPA, gap assessment against the NDPA and GAID, policy set, vendor register and a prioritised remediation plan. Four to six weeks. This is the engagement most businesses need before a DPCO will get a clean result.
DPO-as-a-Service
from ₦350,000 / month
Named DPO, register upkeep, DSAR handling, quarterly review, staff training refresh, board reporting and liaison with your licensed DPCO through the audit cycle. Twelve-month term.
Remediation build
₦2,000,000 – ₦12,000,000
The engineering: consent and retention, DSAR endpoints, encryption, audit logging, access control rework, and the compliance dashboard. Scoped from the gap assessment, so you only pay for the gaps you actually have.
Two costs are not ours and never come through us: the NDPC's own registration and filing fees, and your licensed DPCO's professional fee for the statutory audit and return. We will tell you what to expect for both so your budget is honest, but you pay them directly.
How the Engagement Runs
Week 0 — Scoping call
Thirty minutes on WhatsApp or a call. What you do, how many data subjects, which systems, whether you are registered, whether you have ever been audited, and whether you already have a DPCO. We come back with a fixed price.
Weeks 1–2 — Discovery
Department interviews, system inventory, vendor list, sample records. We find the shadow spreadsheets and the WhatsApp groups where customer data lives. Everybody has them.
Weeks 3–4 — Documentation and gap report
RoPA, privacy notices, internal policies, DPIAs where needed, and a gap report scored by risk and effort, with the ones that will fail an audit flagged in red.
Weeks 5–8 — Remediation
We fix what we can fix in code and process, train your staff, run the breach tabletop, and stand up the dashboard if you are taking it.
Then — Hand to your DPCO
Evidence pack goes to your licensed DPCO. They conduct the statutory audit and file the CAR. We stay on the line to answer their technical questions and close anything they raise.
Why a Software Company for This
Most NDPA compliance in Nigeria is sold by law firms and consultancies, and the legal analysis they produce is genuinely good. The trouble is what happens next. The report says "implement data minimisation and a retention schedule", and then it sits in a shared drive because nobody on the client side can translate that into a migration, a cron job and a changed database schema.
We are the people who write that code. Musskart Technology Limited is a registered Nigerian software company headquartered in Asaba with an Abuja office and 250+ projects delivered since 2020, and we already build the systems that hold this data — fintech platforms, hospital systems, school management, loan apps, HR and payroll. We know where personal data hides in a Laravel application because we have put it there and taken it back out.
Pair us with your licensed DPCO and you get both halves: the statutory audit and filing from the people legally entitled to do it, and the engineering from the people who can actually change the system.
Related Musskart Pages
Already thinking about certification?
NDPA readiness overlaps heavily with information security certification. If you are chasing ISO 27001, CMMI or HIPAA alongside this, start with ISO 27001, CMMI and HIPAA compliance readiness in Nigeria — the control work overlaps and doing them together is cheaper than doing them twice.
- Virtual CISO & Managed Cybersecurity in Nigeria — fractional security leadership to own this all year round
- Cybersecurity & Penetration Testing in Nigeria — the technical testing behind your security controls
- Fintech App Development in Nigeria — where most of our data-protection work starts
- HR & Payroll Software for Nigeria — payroll bureaus are processors of major importance too
- Musskart Pricing — how we price work across all our services
- Contact Musskart — phone, email and office details
Frequently Asked Questions
Get NDPA-Ready Before Your Next Audit Cycle
Tell us what you process, how many data subjects you hold and whether you are already registered. We will come back with a fixed-price readiness scope — and if you need a licensed DPCO for the statutory filing, we will introduce you to one.