DPCO Registration & Requirements

Definition and Duties of DPCO

Section 33 of the Nigerian Data Protection Ac 2023 t provides that a Data Protection Compliance Organisation (DPCO) is any entity duly licensed by NDPC for the purpose of training, auditing, consulting, and rendering services aimed at ensuring compliance with the NDP Act 2023 or any foreign Data Protection law or regulation having effect in Nigeria.

With evidence of professional, academic certification or experiences in one or more of the following areas:

DPCOs are licensed to provide one or more of these services:

Documents Required for Licensing

DPCO Relationship with NDPC

Article 3.1.4 of the NDP Act 2023 provides; The Commission shall by this NDP Act 2023 register and license Data Protection Compliance Organizations (DPCOs) who shall on behalf of the Commission monitor, audit, conduct training and provide data protection compliance consulting to all Data Controllers under this NDP Act 2023. The DPCOs shall be subject to NDP Act 2023 and Directives of NDPC issued from time to time. Every filing by Data Controllers pursuant to this NDP Act 2023 shall be accompanied by a DPCO Verification Statement. NDPC  may appoint other DPCOs or by itself conduct investigation into a suspected breach of the NDP Act 2023 .

Liabilities of a DPCO

A DPCO, found to be guilty of concealing or abetting a data breach by a Data Controller or Processor shall immediately lose its license and prior reports may be subject of investigation. This is without prejudice to right to legal redress by complainants, statutory investigation and prosecutorial functions of other organs of government.