NDPC Raises the Bar for Data Protection Officers with New CPD Framework
The Nigeria Data Protection Commission (NDPC) has issued a Guidance Notice on Continuous Professional Development (CPD) for Data Protection Officers (DPOs) pursuant to Schedule 3 of the General Application and Implementation Directive (GAID) 2025. This marks an important shift in Nigeria's data protection landscape, from viewing DPO certification as a one-time achievement to recognising it as an ongoing professional obligation.
Under the new framework, certified DPOs are required to earn a minimum of 20 CPD points annually (out of a possible 40) to maintain their active verification status, with at least 10 points coming from structured learning and training activities. The framework also recognises knowledge contributions, professional engagement, and ecosystem participation as part of a DPO's continuous development.
This development reinforces a key principle of modern privacy governance: effective data protection depends not only on policies and processes but also on competent, up-to-date professionals. As privacy laws, cybersecurity risks, AI technologies, and regulatory expectations continue to evolve, continuous learning is no longer optional; it is essential.
For organisations, this is an opportunity to:
Review whether your designated DPO meets the new CPD expectations.
Invest in continuous privacy and data protection training.
Strengthen your organisation's overall privacy governance and compliance programme.
The guidance is another indication that the NDPC is moving beyond basic compliance towards building a mature, accountable, and professional data protection ecosystem in Nigeria.
At Oguntoye & Oguntoye LP, we will be publishing a detailed analysis of the Guidance Notice and its practical implications for organisations and Data Protection Officers.
