Guide · NDPA 2023 / GAID 2025
Data controller of major importance: designation and what follows from it.
Almost every duty in Nigeria's data protection regime keys off one question first: has your organisation been designated a controller or processor of major importance? Here is how designation works and what each level obligates.
Estreat Limited · Reviewed August 2026 · General information, not legal advice. Confirm your obligations with the Commission, a qualified DPO, or a licensed DPCO.
Why the designation matters
The Nigeria Data Protection Act 2023 gives the Nigeria Data Protection Commission a supervisory toolkit that scales with risk. Organisations designated as data controllers or processors of major importance sit at the centre of that toolkit: they register with the Commission, maintain the statutory registers, observe the breach clock, and answer for all of it annually. The General Application and Implementation Directive 2025, made under the Act on 20 March 2025, grades those organisations into levels and attaches concrete obligations to each.
The scale is no longer theoretical. Commission figures reported in February 2026 count 38,677 controllers and processors of major importance on the register. Designation is the norm for formal organisations in Nigeria, not the exception.
What points toward major importance
The Act and its guidance weigh the nature and scale of processing rather than any single threshold. Indicators that consistently point toward major importance include:
- Processing carried out on a large scale, in absolute volume or across markets.
- Sensitive categories of data: health, biometrics, financial information, children’s data.
- Operating in a regulated sector where data protection intersects existing supervision, such as financial services, telecommunications, healthcare or education.
- Systematic monitoring or profiling of individuals.
- Cross-border transfer of personal data as a routine part of the business.
None of these factors alone settles the question, and the Commission’s designation guidance governs. But if several apply to you, plan on the assumption that you are designated, and verify formally with a qualified DPO or licensed DPCO.
The GAID 2025 levels
GAID 2025 grades designated organisations into levels. Three matter most in practice:
- Ultra-High Level. The heaviest scrutiny. Files the full annual Compliance Audit Return through a licensed DPCO, with everything that implies for evidence quality.
- Extra-High Level. Also files the full annual return through a licensed DPCO under article 10 of the directive.
- Ordinary-High Level. Renews registration with the Commission annually rather than filing a complete return, and remains fully subject to the Act’s substantive duties: the processing record under section 29, impact assessments under section 28, the breach clock under section 40, and data subject rights under Part V.
Levels can change as your organisation grows or changes what it does with data. A designation review belongs in due diligence for any new product line, market or acquisition, not only in the annual calendar.
What a designated organisation must actually do
Strip away the terminology and the obligations reduce to five standing duties:
- Register with the Commission at the correct level, and keep the registration current.
- Maintain a record of processing activities (NDPA s.29) that describes today’s reality.
- Assess high-risk processing before it ships (NDPA s.28).
- Run the statutory clocks: 72 hours for breach notification (s.40), and the deadlines attached to data subject requests under Part V.
- File or renew annually: the Compliance Audit Return for Ultra-High and Extra-High, registration renewal for Ordinary-High.
Each of those duties produces evidence, which is why the annual return asks where the evidence lives rather than whether you believe you are compliant. See our guides to the Compliance Audit Return, breach notification and RoPA for the detail.
If you are not sure, act designated
The cost asymmetry is stark. Building the registers and keeping them current costs an organisation working time it would mostly spend anyway. Being designated and unprepared costs a scramble every March, a harder audit, and exposure under the Act’s penalty regime described in our penalties guide. When the facts are unclear, act designated and confirm with the Commission or a licensed DPCO.
Questions we are asked.
Short answers to the questions behind most searches about this topic. The body of the guide above carries the detail and the citations.
Is my organisation a data controller of major importance?
Designation turns on the nature and scale of your processing, not your headcount alone. Regulated sectors, large-scale processing of personal data, and sensitive data categories all point toward major importance. The definitive test is the Commission’s designation guidance under the NDPA 2023 and GAID 2025; confirm your level with a qualified DPO or licensed DPCO.
What is the difference between Ultra-High, Extra-High and Ordinary-High levels?
Under GAID 2025 these are grades of designation. Ultra-High and Extra-High organisations file a full annual Compliance Audit Return through a licensed DPCO. Ordinary-High organisations renew their registration with the Commission annually rather than filing a complete return. Higher levels carry correspondingly heavier scrutiny.
Do processors of major importance have obligations too?
Yes. The NDPA and GAID 2025 apply duties to processors of major importance directly, including registration and, at the relevant levels, the annual return. A processor designation does not outsource your compliance to your customers.
Continue with
The NDPC Compliance Audit Return, explained
Who files, when, through whom, and what Schedule 2 asks.
Read the guideGAID 2025 explained
The directive that creates the levels and the annual return.
Read the guideRoPA in Nigeria
The section 29 record every designated organisation maintains.
Read the guideBreach notification in 72 hours
Section 40 duties and how to prove when you became aware.
Read the guideKeep the record, and every deadline answers itself.
Estreat keeps your processing registers, impact assessments, subject requests, breach clocks and evidence current all year, then assembles the Compliance Audit Return from that record for filing through a licensed DPCO. We are software, not a DPCO or a law firm, and we will introduce you to a licensed partner if you need one.