The Data Protection Compliance Organisation (DPCO) is a distinctive feature of Nigeria's data protection framework under the NDPA 2023 and the General Application and Implementation Directive (GAID) 2025. Unlike the DPO model familiar from GDPR, the DPCO is an external licensed entity – not an individual – appointed to conduct audits, provide training, and file regulatory returns on behalf of organisations. Understanding the DPCO requirement is essential for any organisation subject to the NDPA.

What is a DPCO and what does it do?

A DPCO is an entity licensed by the Nigeria Data Protection Commission (NDPC) to provide data protection compliance services to organisations operating in Nigeria. Licensed DPCOs are listed on the NDPC's public register, which is updated as licences are granted.

The DPCO's primary functions are: conducting data protection compliance audits of the organisation's data handling practices; identifying gaps and recommending remediation; providing staff training on NDPA requirements; drafting and reviewing privacy policies and data processing agreements; and filing the annual Compliance Audit Return (CAR) with the NDPC on the organisation's behalf.

The GAID also requires DPCOs to assess whether organisations apply global best practices on data ethics when handling personal data – a function beyond the audit and filing scope that positions the DPCO as an ongoing compliance adviser.

Who is required to appoint a DPCO?

Under the GAID, only Ultra-High Level (UHL) and Extra-High Level (EHL) Data Controllers and Processors of Major Importance are required to file their annual CAR through a licensed DPCO. The GAID classifies organisations based on the volume and sensitivity of data processed, sector, and other risk factors.

However, the practical expectation from NDPC guidance and enforcement practice is broader. Organisations classified as Data Controllers of Major Importance – whether UHL, EHL, or Ordinary-High Level (OHL) – should engage a licensed DPCO for their compliance audit, even if formal filing through a DPCO is only mandatory for the two highest tiers.

Foreign organisations subject to the NDPA by virtue of its extraterritorial scope are also expected to engage a DPCO as part of their compliance programme for Nigerian operations.

What are the criteria for selecting a DPCO?

The NDPC maintains the list of licensed DPCOs and can revoke licences for non-compliance with licensing conditions. When selecting a DPCO, organisations should assess the following.

NDPC licensing status: The DPCO must be on the NDPC's current public register. Licence status should be verified directly with the NDPC, as the register is updated as licences are granted or revoked.

Sector expertise: The NDPA and GAID include sector-specific provisions for financial services, health, telecommunications, oil and gas, and other sectors. A DPCO with experience in the organisation's sector will be better placed to assess obligations that go beyond the general framework.

Capability to conduct cross-border analysis: For organisations subject to both the NDPA and other frameworks – GDPR, POPIA, or the Kenya DPA – the DPCO should demonstrate understanding of how those frameworks interact with Nigerian requirements. Most compliance failures in multinational organisations arise at the intersection of frameworks, not within any single one.

Audit methodology: The DPCO should be able to demonstrate a structured audit methodology that covers all areas required by the GAID, including the review of data processing agreements, ROPA entries, consent records, breach logs, and staff training evidence.

Filing capability: The CAR must be filed through the NDPC's online portal. The DPCO must have operational familiarity with the filing system and awareness of current deadlines – 31 March annually for the prior year's data.

How does the DPCO relate to the DPO role?

The DPCO and DPO are complementary but distinct. The DPO is an individual (internal or external) designated to oversee the organisation's data protection programme on an ongoing basis – monitoring compliance, handling data subject requests, and serving as the NDPC liaison. The DPCO is an external licensed entity engaged to conduct formal audits and file regulatory returns.

The same professional cannot serve simultaneously as the organisation's DPO and as the DPCO conducting the organisation's audit – this would present a structural conflict of interest incompatible with the independence requirements of both roles. The GAID requires that the DPO's compliance report be verified by the DPCO during the annual compliance audit.

What this means for your organisation

  • If you are classified as a Data Controller of Major Importance under the NDPA, engaging a licensed DPCO for your compliance audit is not optional. The GAID introduced this requirement effective September 2025.
  • The CAR filing deadline is 31 March annually. Missing this deadline attracts a penalty fee. NDPC enforcement practice treats late or absent filings as a compliance signal.
  • The same professional cannot serve simultaneously as your DPO and as the DPCO auditing your programme – this is a structural conflict of interest that the GAID's independence requirements prohibit.
  • Foreign organisations subject to the NDPA by virtue of its extraterritorial scope are expected to engage a licensed DPCO as part of their Nigerian compliance programme, not merely to meet their obligations through a local law firm.

What you should do now

  1. Confirm your classification under the GAID – UHL, EHL, or OHL – and the specific filing obligations that apply to your category.
  2. Verify your chosen DPCO's current licence status on the NDPC public register before engagement.
  3. Ensure your DPO is separate from your DPCO – the two roles must be held by different individuals or entities.
  4. Confirm your DPO holds or is pursuing NDPC-recognised certification, as required by the GAID's annual credential assessment process.
  5. Map your CAR filing calendar – the 31 March deadline requires audit completion well in advance, particularly for organisations with complex processing activities.

How Priventia helps

Priventia's Nigeria coverage maps NDPA and GAID obligations, including DPCO engagement requirements, CAR filing timelines, and DPO designation criteria. The Compliance Intelligence Assessment produces a prioritised remediation roadmap for your Nigerian compliance posture, covering both the substantive NDPA obligations and the procedural requirements of the GAID.