CAR deadline · 31 MarchBreach notice · 72h from awarenessStay ahead with CARPath

Guide · GAID 2025 art. 10

The NDPC Compliance Audit Return, explained.

One document, one deadline, one intermediary. Everything a Nigerian organisation needs to understand about the annual Compliance Audit Return: who files it, when it is due, what it contains, and where most organisations fail it.

Estreat Limited · Reviewed August 2026 · General information, not legal advice. Confirm your obligations with the Commission, a qualified DPO, or a licensed DPCO.

What the CAR is

The Compliance Audit Return is the annual filing through which designated organisations account to the Nigeria Data Protection Commission for their data protection compliance. It is created by the General Application and Implementation Directive 2025 (GAID 2025), made under the Nigeria Data Protection Act 2023 and dated 20 March 2025. Article 10 of the directive establishes the obligation; Schedule 2 defines what the return asks.

Who must file

Controllers and processors of major importance designated at Ultra-High or Extra-High Level file the full return. Organisations at Ordinary-High Level renew their registration with the Commission annually instead. If you are unsure which level applies to your organisation, start with our guide to being a controller of major importance and confirm with a licensed DPCO.

The deadline and the route

The standing deadline is 31 March each year. Two structural facts about the deadline matter more than its date:

  • You cannot file alone. The return goes to the Commission through a Data Protection Compliance Organisation licensed by the Commission. There were 317 licensed DPCOs as of February 2026, and their capacity in the final weeks of March is finite. Your DPCO conducts an audit before filing, which means they need your evidence weeks before the deadline, not on it.
  • Late costs money. Missing the date attracts a surcharge on the applicable fee. The Commission did extend the 2026 cycle, which organisations should read as a one-cycle reprieve, not a precedent.

What Schedule 2 actually asks

Schedule 2 organises the return into four broad parts:

  • Governance and accountability. Who owns data protection: the DPO’s appointment and standing, board oversight, the internal policy set, and the training record behind them.
  • Security of processing. Technical and organisational measures in force, tested against the processing they protect rather than described in the abstract.
  • Rights, risk and incidents. Subject request volumes and outcomes, impact assessments for high-risk processing, and the breach register with notification timing.
  • Third parties and transfers. Processors engaged, the agreements that govern them, and the legal instrument relied on for each cross-border transfer.

Every one of those questions is answered from a record: a register, a policy, a log, an agreement. That is the whole difficulty of the CAR in one sentence. The return is not hard because any single question is hard; it is hard because it interrogates whether records exist at all.

Why most organisations struggle

Commission figures reported in February 2026 put 38,677 controllers and processors of major importance on the register, against 8,155 returns ever filed. Barely a fifth of the registered population has filed even once. The gap is not indifference; it is architecture. Most organisations treat the return as a document produced once a year by a consultant, reconstructed from records that were never kept. Under audit, a reconstructed answer survives exactly as long as it takes to ask a follow-up question.

The organisations that file calmly treat the return as an export. They keep the registers during the year — processing, assessments, requests, breaches, evidence — and the return assembles from them. That is the approach our CARPath product page describes, including how each part of Schedule 2 maps to a named register.

A working calendar

  • April to September: maintain the registers as the business changes; new systems enter the record when adopted.
  • October to December: run a readiness pass against Schedule 2; every unanswered question becomes an owned task.
  • January to February: assemble the draft return, attach evidence answer by answer, brief your DPO.
  • March: the DPCO audits against a complete pack and files ahead of the deadline.

This guide summarises obligations created by GAID 2025 (20 March 2025) under the NDPA 2023. The authoritative structure and wording of the return are those published by the Commission, and your DPCO’s audit opinion governs what is finally filed. Reviewed August 2026.

Questions we are asked.

Short answers to the questions behind most searches about this topic. The body of the guide above carries the detail and the citations.

Who must file the Compliance Audit Return?

Organisations designated as controllers or processors of major importance at Ultra-High and Extra-High Level under GAID 2025. Ordinary-High Level organisations renew their registration annually instead of filing a full return.

When is the CAR deadline?

31 March each year under article 10 of GAID 2025. Late filing attracts a surcharge on the applicable fee. The Commission extended the 2026 cycle beyond that date, which was a reprieve for one cycle rather than a change to the standing deadline.

Can Estreat file my CAR?

No. The return is filed with the Commission through a Data Protection Compliance Organisation licensed by the Commission. Estreat prepares, evidences and packages the return so your DPCO audits and files it without re-interviewing your whole company. We are software, not a licensed DPCO.

Keep the record, and every deadline answers itself.

Estreat keeps your processing registers, impact assessments, subject requests, breach clocks and evidence current all year, then assembles the Compliance Audit Return from that record for filing through a licensed DPCO. We are software, not a DPCO or a law firm, and we will introduce you to a licensed partner if you need one.