Qantid
Class CScoped engagementRenews

NDPA Compliance Audit and Annual Return Filing

The annual data protection compliance audit and the filing of your Compliance Audit Return with the NDPC.

Fee & intake

Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.

Renews
Every 12 months

Regulatory and standards basis

This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.

  • Nigeria Data Protection Act 2023
  • NDPC General Application and Implementation Directive
  • Nigeria Data Protection Regulation 2019 audit filing requirement

Who this is for

  • Data controllers of major importance
  • Any entity with an annual filing obligation

What you receive

  1. 01Compliance audit against the NDPA and the NDPC directive
  2. 02Compliance Audit Return prepared and filed
  3. 03Findings and remediation plan
  4. 04Filing acknowledgement

How the engagement runs

  1. Phase 1

    Intake and scoping

    You complete an intake form. We issue a scoped quote within 3 business days.

  2. Phase 2

    Engagement start

    On acceptance and first milestone payment, the engagement team is assigned and introduced by name.

  3. Phase 3

    Fieldwork

    Document preparation, testing or application assembly, depending on the engagement. Progress and outstanding requests are visible in the portal throughout.

  4. Phase 4

    Review and sign-off

    Internal quality review, then approval under Qantid Limited's signature. For licence-application work, we prepare and facilitate the filing; the regulator decides the outcome.

  5. Phase 5

    Submission and closure

    Filing or delivery, then support through any regulator queries until the matter closes.

Accreditation disclosure

The Compliance Audit Return must be filed through a Data Protection Compliance Organisation licensed by the NDPC. Qantid conducts the audit and prepares the return; the licensed DPCO files and signs it.

Questions

Who approves the deliverable?

A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.

Who signs it?

The Compliance Audit Return must be filed through a Data Protection Compliance Organisation licensed by the NDPC. Qantid conducts the audit and prepares the return; the licensed DPCO files and signs it.

How is this priced?

The engagement fee is shown in your portal after you choose this service. You complete an intake form, pay the charge shown, then submit. Milestone billing may apply where the intake confirms a Class C schedule.

What happens next year?

The portal reminds you 90, 60 and 30 days before it is due, and you start a new version of this engagement pre-filled from the answers you gave last time. You update only what has changed, and you see a side-by-side of what changed before you submit.

Where do our documents live?

In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.

How do we pay?

By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.

Related engagements in Data Protection and Privacy

Breach Response Playbook and Notification Templates

A playbook that gets you to a defensible regulator notification inside the statutory window, written before you need it.

Cross-Border Transfer Impact Assessment

An assessment of your international data transfers and the mechanism each one relies on, including cloud processing outside the country.

Data Protection Impact Assessment

A documented impact assessment for a high-risk processing activity, with mitigations and a residual risk conclusion your DPO can sign.