Why now
A privacy policy is not compliance. The NDPC will not accept it as one.
NDPC enforcement is active. The gap between having a privacy policy and having a filed Compliance Audit Return is where most Nigerian organisations currently sit - and it is the gap that creates regulatory exposure, blocks enterprise partnerships and stalls investor due diligence. This engagement closes it.
The outcome
From unresolved gaps to a completed filing.
A compliance position you can defend in writing
Know exactly what is complete, what is missing and what needs to change: documented, assigned and on a timeline.
The evidence pack ready for NDPC review
Policies, data maps, vendor records, control evidence and audit material organised in the format a licensed DPCO and NDPC auditor will work through. Assembled and verified, ready to submit.
A completed Compliance Audit Return filing
We take the work through licensed DPCO verification, Compliance Audit Return submission and the applicable NDPC registration certificate or Audit Trust Mark process. The engagement ends at completion, not at a report.
What we cover
Everything the NDPC Compliance Audit Return requires.
Data mapping and lawful processing basis
Identify every category of personal data your organisation touches: where it enters, why you process it, who receives it, where it travels and how long it stays. NDPC auditors begin here. Gaps here ripple through everything else.
Privacy notices, policies and processor contracts
Bring your privacy notice, internal data policies, processor agreements, consent language and data-subject request process into one consistent, audit-ready operating system that reflects what the product actually does.
Technical and organisational controls
Authentication, access management, logging, encryption, incident response, backup procedures and vendor access. The compliance filing needs evidence that your controls work in practice, confirmed in the system and the record.
Gap remediation, evidence assembly and NDPC filing
Close the gaps, verify implementation, organise the documentary evidence and coordinate licensed DPCO verification and Compliance Audit Return submission. We manage the process from assessment to filed.
A clear engagement
A direct path from today's gaps to a filed Compliance Audit Return.
- 01
Confirm what applies to your organisation
We identify your data-processing role, current registration status, CAR filing obligations and the systems, people and vendors that bring you into scope.
- 02
Close the compliance gaps
We map personal data flows, complete required policies and records, and convert every missing control into a concrete piece of work with a specific completion date.
- 03
Assemble and verify the audit evidence
We verify that controls are implemented and working, then organise the policies, screenshots, registers and technical evidence needed for DPCO review.
- 04
Coordinate licensed DPCO verification and NDPC filing
We manage the licensed DPCO verification process, prepare and submit the Compliance Audit Return, and support the applicable NDPC certificate or Audit Trust Mark application.
Straight answers
The questions that usually delay the decision.
"We already have a privacy policy."
A privacy policy is the starting point, not the destination. NDPC compliance requires that the policy is consistent with what your product actually does, backed by vendor agreements, data maps, access controls and documented evidence. Most privacy policies we review describe an organisation that does not quite exist.
"We don't know what documents we need."
You are not expected to. We identify your data-processing role, your filing obligations, the systems and vendors in scope, and the specific evidence your Compliance Audit Return will need to demonstrate. You leave the first call knowing what is required and what comes next.
"Our team is too busy for a long compliance project."
We reuse everything that already exists. Your team answers operational questions and makes decisions. We do the document work, gap analysis, evidence assembly and filing coordination. We come back to you with specific, bounded requests rather than an open-ended audit project.
"We need the certificate, not another report."
The engagement is structured around filing. We close the gaps, assemble the evidence, complete the audit work and coordinate licensed DPCO verification and the applicable NDPC certificate or Audit Trust Mark process. The outcome is a completed filing, not a gap list.
"We use several third-party vendors and integrations."
Vendor relationships are part of the scope. We map every processor and data transfer, review the agreements and identify where your NDPA obligations depend on a vendor's controls - because NDPC holds you responsible for what your processors do with your customers' data.
"The NDPC deadline is not pressing us yet."
The NDPC is issuing enforcement notices. Enterprise clients and international partners increasingly require a current compliance certificate before they will share data or integrate systems. Waiting until you need it urgently makes the filing harder, faster and more expensive.
Know what you're working toward
See the process, the documents and the filing route before you start.
Your team sees what the filing requires, what evidence the DPCO auditor will review, and the exact sequence from gap assessment through to a submitted Compliance Audit Return.
Before you book
Frequently asked questions
What happens if we don't file the Compliance Audit Return?
Under the Nigeria Data Protection Act, organisations that fail to file face NDPC enforcement action, including investigations, administrative orders and financial penalties. Beyond regulatory risk, the absence of a compliance certificate is increasingly a blocker in enterprise sales, partnership negotiations and investor due diligence.
Can you take us from the beginning all the way through to filing and certification?
Yes. The engagement covers the gap assessment, remediation plan, required document creation, control evidence review and audit preparation, then coordinates licensed DPCO verification, Compliance Audit Return submission and the applicable NDPC registration certificate or Audit Trust Mark process.
Is this only for fintech companies?
No. The work applies to any Nigerian organisation that processes personal data. Simpa Labs is especially strong where compliance depends on understanding apps, APIs, cloud systems, payment flows and security controls - which is most technology businesses.
Do you also review the product's technical security?
Yes. The compliance scope can include a technical security review where the evidence needs to show that customer data and access controls are protected in practice. This is often required to satisfy the technical controls section of the Compliance Audit Return.
How long does the process take?
Timeline depends on your current compliance position, the complexity of your data flows and vendor relationships, and how quickly your team can provide the required inputs. Most organisations complete the gap-to-filing process in 6-14 weeks. We confirm a specific timeline in the engagement scope.
Start here
Tell us where your organisation is today. We will map the route to filed.
Send your organisation type, product, current compliance status and your target date. We will map the route from today's gaps to a completed NDPC Compliance Audit Return.
Ready to Get Your NDPC Certification?Send your organisation type, current compliance status and target date. We will reply within one business day.