Questions
The questions people actually ask, answered at length.
Grouped by what you are trying to work out. Several have answers you will not like — the Act says what it says, and a page that only tells you comfortable things is not worth searching. The count is under the search box, where it is counted rather than claimed.
44 questions · updated 30 Jul 2026 · nothing here is gated
The Act, and whether it applies to you
6 questionsAlmost certainly, yes. The Act applies to anyone processing personal data in Nigeria, with no minimum size. What changes with size is your tier — and therefore how much you must do and who is allowed to file for you.
At or below 200 data subjects in six months you sit outside the registration regime, but you still owe people their rights, still owe a lawful basis for what you do, and still owe notification if you lose their data.
Check where you sitThe Act is the law. GAID — the General Application and Implementation Directive, issued 20 Mar 2025 — is the mechanics: it sets the tiers, the thresholds, the filing routes and what counts as a controller of major importance.
In practice you read the Act to know what you owe and GAID to know how to discharge it.
GAID in fullThree ways in, and you only need one: two hundred data subjects in six months, membership of any of thirteen listed sectors, or selling commercial ICT services. Any single one makes you a controller of major importance.
Above that, the levels are volume-based until the top: ordinary high level from more than 200 up to 1,000; extra high level above 1,000 and up to 5,000 unless a sector rule decides it first; ultra high level above that, or on a factor test of 6 questions where 4 is the threshold. Every boundary is "more than", not "at least".
How tiers are assessedYes. The Act follows the processing, not the customer. If the processing happens in Nigeria or you are established here, you are inside it — and you may also be inside the GDPR at the same time, which is a separate set of obligations rather than a substitute.
Where GDPR also appliesNo. The obligations start when the processing starts. What is realistic is that a company registering in good faith and filing late for the first time is treated very differently from one that never registered at all — but that is the Commission exercising discretion, not a right you can rely on.
Fully. Your staff are data subjects with the same rights as any customer, and sick notes, accommodations and insurance claims are special category data held to the same standard as a patient diagnosis.
The retention period is not yours to choose either — six years after they leave, because employment and tax law says so.
Both sides of the HR questionThe annual return, and filing
6 questions31 March, for the preceding year. The pack itself should be assembling from January, which leaves two months to fix whatever it surfaces rather than two weeks.
What the return containsOnly if you are not a controller of major importance. Above that line the return must go through a licensed DPCO — a firm or individual officer authorised by the Commission — and self-signing is not an option however competent your team is.
Find a licensed DPCOEleven sections. Nine resolve straight from registers you should already keep: who you are, what you do with personal data, who else touches it, cross-border flows, retention, protection, incidents, requests and your DPO.
The tenth is the board’s statement, which a person writes because nothing generates a signature. The eleventh is any high-risk impact assessment — and that one can block the whole submission.
See the pack assembleA late-filing fee, and a much worse position if anything else goes wrong that year. Late notification and late filing are separate findings from the underlying failure — you can be penalised for the delay even where the substance was fine.
What it would costYes, and this is where people lose. The acknowledgement from the Commission is the only evidence the return was accepted, and it usually lives in one person’s mailbox. Keep it with the return itself.
No. Registration is an administrative step, not a verdict. Companies conflate the two constantly and then discover at audit that a registration number proves nothing about how they handle data.
Penalties and enforcement
4 questionsThe Act sets the remedial fee as the greater of a fixed floor and a percentage of last year’s gross revenue. For most companies of any size the percentage decides it and the floor never comes into play.
Note gross revenue, not profit. A loss-making year does not reduce it.
Work it out on your numbersYes, and increasingly through letters rather than headline fines. An enquiry with a seven-day clock on it is the common form, and answering it badly is what escalates matters.
Most companies we read have never received one. Most companies we read would struggle to answer one inside a week.
What a letter looks likeThe return carries named individuals and the board’s statement is signed. That is precisely why the statement is the one section of the pack that a person has to write rather than a system generate.
No — the opposite. Notification is an obligation, not a confession, and the Commission weighs cooperation and remediation. What makes it worse is a late notification, because the delay is its own finding on top of the breach.
The 72-hour clockDoing the work day to day
8 questionsAt awareness — the moment somebody in your organisation had reasonable grounds to believe personal data was compromised. Not when the incident was confirmed, not when a meeting agreed it counted.
Which means it usually started hours before anyone wrote a timestamp down. "We notified within 72 hours of confirming" is not a defence; it answers a question nobody asked.
Read the full guideThere is no number, and anyone who gives you one is quoting commentary. §34 states no period; §34(1)(d) and §38(2)(a) say without undue delay, and §38(3)(b) leaves timing to the Commission, which has prescribed none. So a schedule is not a defence — and the common failure is not lateness anyway but incompleteness, answering from the systems support can see and marking it done while a warehouse copy goes unmentioned.
How requests are trackedA DPO is your officer — an internal role, or an outsourced individual, accountable for data protection inside your organisation. A DPCO is a firm or individual licensed by the Commission to audit and file on behalf of others.
You may need both, and one cannot substitute for the other. People are sold the wrong one regularly.
The independence problemSometimes, but not if the other function is one they would have to audit. An officer who also owns fraud operations has a self-review conflict, and an auditor will reject the appointment on that basis alone.
For anything high risk to the people in it — automated decisions, large-scale sensitive data, systematic monitoring. And it has to happen before launch, because the point is to change the design rather than describe it afterwards.
Where residual risk stays high, the assessment goes to the Commission before the thing goes live.
How assessments workIt is the most-abused basis in the Act, and it is unavailable entirely for health data and other special categories. Where it does apply you owe a balancing test and the person owes nothing to object.
Reaching for it because consent is inconvenient is the pattern regulators look for.
Six bases, and their limitsYes. The Act does not care that you own the recipient. Monthly management reporting to a UK holding company leaves Nigeria, needs a mechanism, and belongs on the transfer register beside every supplier.
How groups workIt depends on whether the period is a fact or a decision. Seven years after account closure is inherited from a regulator; two years on a marketing list is something you chose and will have to defend.
A schedule must record the source of every period, not just the number.
Building a scheduleHow Asiri works
8 questionsShapes rather than contents. Which tables exist, which columns look like personal data, how many rows, when it last changed. Never card numbers, never balances, never support ticket bodies, never backup contents.
That is a real trade: because ticket bodies are never read, nobody can search them to answer an access request. We think it is the right trade and it is still a trade.
What the readers doNo. Not aggregated, not anonymised, not to improve the service. Every serious buyer asks this and most vendors answer with a paragraph — the honest answer is one sentence long.
How we hold dataaf-south-1, Cape Town. For a product about cross-border discipline, running it in Ireland would be indefensible.
Deployment optionsYes, and you should know what it costs you. Eri is off unless you open an egress path or run a model yourself — the assistant cannot answer from registers it cannot read. You also carry the upgrades, the monitoring and the recovery.
The four rungsOne system connected is usually enough for the first finding, and that often happens inside twenty minutes on the demo call. The full picture takes as long as your integrations take.
Answer an access request, read an individual’s record, publish your trust page, or file anything. It proposes; a person disposes. Every action it takes appears on your audit trail under its own name with a reason attached.
What Eri can and cannot doThat is the intended way. A licensed DPCO gets engagement-scoped access — five registers of eighteen in the reference workspace — and every read they make inside that scope lands on your audit trail, not only theirs.
How engagements runNo, and this is the product’s central refusal. Badge wording is derived from the assurance behind it, so "SOC 2 certified" and "GDPR certified" cannot be printed — neither thing exists.
You will regularly be handed a weaker sentence than the one you asked for.
All 23 frameworksPricing and buying
7 questionsFree is genuinely free and permanent. Starter is ₦120,000 a year, Growth ₦600,000, Enterprise listed at ₦3,000,000 within a ₦2.4m–₦6m band by group size. VAT at 7.5% is shown separately rather than folded in.
Full pricingNo. Every plan is annual. Monthly billing turns a compliance tool into a subscription somebody cancels in March and remembers in December.
Buy a planNo. There is no countdown, no card, and no expiry. It is a distribution decision rather than a discount — the register you build on Free is yours to keep whatever you do next.
Through Paystack: card, bank transfer, USSD, or an invoice on thirty-day terms for Growth and Enterprise. Bank transfer is what most Nigerian finance teams choose.
No card details are ever typed on an Asiri page, which is why our PCI DSS scope is narrow and yours does not widen by using us.
See pricingNothing, ever. Firms and individual officers list free, which is the only reason the ranking means anything — placement cannot be bought.
List your practiceThe year already paid still runs, and you can export every register at any time in a format that opens elsewhere. Leaving is a product feature, not a support ticket.
No. Charging for the people who make you compliant would be perverse.
Security and trust
5 questionsYes, published under exactly the rules we sell — same wording tiers, same access levels, same refusal to keep a badge alive past its expiry.
Our trust pageYou are told, on the register itself. An expired credential used to leave the last known figures on screen looking current — that failure was reported through our disclosure programme, took us 38 days against a 30-day band, and is published as a miss.
Release notesYes, with published bands up to ₦600,000, a response clock, and safe harbour for good-faith research. Every valid report reaches the release notes with the reporter credited — including the two we fixed late, which are marked late.
Scope and rewardsOnly with time-boxed, reason-bound support access — and it appears on your audit trail under our own name. If somebody from Asiri opened your register, you find out from the trail rather than from us.
The audit trailNobody. Not your administrator, not your auditor, not us. Append-only with no exception, which is the only thing that makes it worth reading when somebody finally asks who changed the record and why.
Questions we answer with no
Four things people ask for that we will not build
Each has been asked by a paying customer or a serious prospect. Publishing the refusals is cheaper than having the argument four times a month.
A compliance score out of 100
Every competitor sells one. A single number hides which of the eleven sections would stop a filing, and it is the first thing an auditor ignores.
Auto-generated policies you never read
A policy pack describes a company. The register reads one. Selling the first while claiming the second is how this market got its reputation.
A trust page published on your behalf
We hold every register needed to generate one. A trust page is a statement a company chooses to make — produced without that choice it would be our claim about you.
Filing while a high-risk fix is unstarted
The submission is held, not warned about. Compliance software that lets you file anyway is a filing cabinet with a progress bar.
Still unanswered is a gap in this page, not in you
If the answer is not here, the page has failed. Ask and we will answer within a working day, then add it — because the next person searching for it should not have to write to anybody.