The Nigeria Data Protection Act 2023: From Privacy Compliance to Data Governance
DATA PROTECTION & PRIVACY

The Nigeria Data Protection Act 2023: From Privacy Compliance to Data Governance

← Back to Insights
Lex Firma LP15 min read

Data has become one of the most valuable assets in the modern economy. Nigeria's response to this changing environment is the Nigeria Data Protection Act 2023, which established a comprehensive statutory framework for the protection of personal data and created the Nigeria Data Protection Commission as the country's principal data protection regulator.

Data has become one of the most valuable assets in the modern economy. Businesses use personal information to identify customers, assess creditworthiness, deliver services, personalise products, prevent fraud, recruit employees and make increasingly sophisticated commercial decisions. Governments likewise depend on data for public administration, security, healthcare and the delivery of essential services.

The value of data, however, is inseparable from the risks associated with its misuse.

Nigeria's response to this changing environment is the Nigeria Data Protection Act 2023 (the "NDPA" or "the Act"), which established a comprehensive statutory framework for the protection of personal data and created the Nigeria Data Protection Commission (NDPC) as the country's principal data protection regulator. The Act was signed into law on 12 June 2023.

The legislation builds on the constitutional guarantee of privacy contained in section 37 of the Constitution of the Federal Republic of Nigeria 1999 (as amended) and represents a significant evolution from the regulatory framework previously anchored principally on the Nigeria Data Protection Regulation 2019.

Importantly, the regulatory landscape has continued to develop since the enactment of the Act. The NDPC issued the General Application and Implementation Directive 2025 (GAID) on 20 March 2025, which became effective on 19 September 2025. The GAID provides practical guidance on the implementation of the NDPA, including registration, compliance returns, data protection officers, cross-border transfers and risk-based regulatory oversight.

The significance of the NDPA, therefore, extends beyond privacy notices and consent forms. It introduces a framework under which organisations are expected to understand what personal data they hold, why they hold it, how they use it, where it goes, how long they retain it, who has access to it and what safeguards protect it.

1. The Central Objective: Protecting Privacy in a Data-Driven Economy

The Act has a dual character. On one hand, it is a rights-protection statute. It seeks to protect the fundamental rights, freedoms and interests of individuals whose personal data is processed. On the other, it is an economic statute. By establishing trusted rules for the use of personal data, it seeks to strengthen Nigeria's digital economy and facilitate participation in regional and global markets.

The NDPC itself identifies among the principal objectives of the Act the regulation of personal-data processing, protection of data-subject rights, promotion of secure and accountable data-processing practices, and strengthening of the legal foundations of Nigeria's digital economy.

Data protection is not intended to prevent businesses from using data. Rather, the objective is to ensure that the economic value of data is realised without sacrificing the privacy and other legally protected interests of the individuals to whom the data relates.

2. Who Does the Act Apply To?

The Act has a deliberately broad reach. It applies to persons and organisations processing personal data in Nigeria and can also apply to controllers or processors outside Nigeria where they process personal data relating to Nigerian data subjects. This means that the geographical location of a business is not necessarily determinative of whether Nigerian data-protection obligations apply.

A foreign technology company providing services to Nigerian customers, a multinational storing Nigerian customer information abroad, or a cloud-service arrangement involving personal data of Nigerian residents may therefore have to consider the NDPA. The Act does, however, recognise specific exemptions, including certain processing for personal or household purposes, criminal investigations, national security, public-interest publications and the establishment, exercise or defence of legal claims, subject to the statutory conditions.

The practical lesson is straightforward: organisations should determine the applicability of the Act by examining their data-processing activities rather than simply their place of incorporation.

3. The Six Principles that Should Govern Personal Data Processing

At the heart of the NDPA is section 24, which establishes the principles governing the processing of personal data. Personal data must be processed in a manner that is: fair, lawful and transparent; collected for specific, explicit and legitimate purposes; adequate, relevant and limited to what is necessary; accurate and kept up to date; retained only for as long as necessary; and protected against unlawful or unauthorised processing, loss, destruction, damage or other security risks.

These principles have an important practical consequence for businesses. Data minimisation is now a legal consideration, not simply a matter of good information-management practice. An organisation should be able to explain why it needs each category of personal data it collects. A business that collects information merely because it might be useful in the future may face difficulty demonstrating compliance with the principle that data should be limited to what is necessary for the relevant purpose.

Similarly, retaining customer or employee information indefinitely creates unnecessary legal and cybersecurity exposure where the information is no longer required. The appropriate question for businesses is therefore not simply, "Do we have permission to collect this information?" but also, "Do we need this information, for what purpose and for how long?"

4. Consent Is Important—but It Is Not the Only Legal Basis

A common misconception about data protection is that every form of personal-data processing requires consent. The NDPA takes a more sophisticated approach. Section 25 recognises several lawful bases for processing personal data, including consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public-interest task and legitimate interests.

For example, an organisation may not need to obtain consent every time it processes personal data that is genuinely necessary to perform a contract with the data subject. Similarly, processing required by law may have a different legal basis from processing undertaken for marketing purposes.

The introduction and recognition of legitimate interest as a lawful basis is particularly relevant to businesses. It does not, however, provide an unrestricted licence to process personal data. Where the fundamental rights and freedoms of the data subject override the relevant interest, reliance on that basis may not be justified. Businesses should consequently avoid treating consent as a universal solution. The better approach is to identify the specific legal basis for each significant processing activity and document the reasoning supporting it.

5. Consent Must Be Genuine

Where consent is the applicable legal basis, the Act imposes substantive requirements. Consent must be freely given, specific, informed and unambiguous. It must involve a genuine affirmative action and cannot simply be inferred from silence or inactivity. This has practical implications for websites, mobile applications, fintech platforms, e-commerce businesses and other digital services. Pre-ticked boxes, vague privacy statements or consent mechanisms that make refusal materially more difficult than acceptance may create compliance risks.

The Act also gives data subjects the right to withdraw consent, and organisations must ensure that withdrawing consent is not unnecessarily more difficult than providing it. In other words, consent is a continuing legal relationship, not a one-time checkbox.

6. The Rights of Data Subjects

The NDPA places the individual at the centre of the regulatory framework. The NDPC identifies several rights available to data subjects, including the right to be informed, access personal data, seek rectification, object to processing, restrict processing, obtain data portability, seek erasure and challenge certain forms of automated decision-making.

These rights have important operational implications for businesses. A company must be capable of responding when a customer asks: What personal information do you hold about me? Why are you processing it? Who has received it? Can inaccurate information be corrected? Can I object to the processing? Can my information be deleted? Can my information be transferred to another service provider?

Compliance therefore requires more than publishing a privacy policy. Organisations need internal systems capable of locating, retrieving, correcting, restricting and, where appropriate, deleting personal data.

7. Automated Decision-Making and Artificial Intelligence

One of the most forward-looking aspects of the Act is its recognition of the implications of automated processing and profiling. The legislation recognises a data subject's right not to be subjected to a decision based solely on automated processing, including profiling, where that decision produces legal or similarly significant effects. This provision is increasingly important as businesses deploy artificial intelligence, machine learning, automated credit scoring, recruitment algorithms, fraud-detection systems and personalised digital services.

The legal question is no longer simply whether an organisation has collected data lawfully. It is also whether the organisation is using that data to make consequential decisions about individuals in a manner consistent with their rights. For technology-driven businesses, this means that privacy considerations should form part of product development and AI governance from the outset, rather than being addressed only after deployment.

8. Data Protection Impact Assessments: Privacy Before Deployment

The Act also introduces the concept of the Data Protection Impact Assessment (DPIA). A DPIA is essentially a structured process for identifying and addressing privacy risks associated with data-processing activities, particularly where the proposed processing is likely to create a high risk to the rights and freedoms of individuals. The process requires consideration of matters such as the nature and purpose of the processing, its necessity and proportionality, potential risks to data subjects and the safeguards available to mitigate those risks.

The NDPC has subsequently incorporated DPIA requirements into the GAID framework, reinforcing the shift towards a more proactive and risk-based approach to compliance. The commercial significance is considerable. A business developing a facial-recognition system, large-scale profiling platform, biometric database or AI-driven decision-making tool should not wait until the product is operational before considering privacy risks. The emerging principle is privacy by design—building compliance and safeguards into the architecture of a product or service from its inception.

9. Data Protection Officers and Compliance Structures

The NDPA places additional responsibilities on organisations of major importance. Data controllers of major importance are required to designate a Data Protection Officer (DPO) with appropriate knowledge and expertise in data protection law and practice. The DPO serves an important advisory and regulatory interface function within the organisation. The regulatory framework has subsequently been developed through the GAID, which provides further guidance concerning the designation and functions of DPOs.

Data protection should no longer be regarded solely as an IT department responsibility. It intersects with legal, compliance, risk management, cybersecurity, human resources, marketing, procurement and corporate governance. An effective compliance structure should therefore involve senior management and multiple business functions.

10. Data Security and the 72-Hour Breach Notification Obligation

The Act places substantial responsibility on controllers and processors to maintain the security of personal data. Appropriate technical and organisational safeguards are expected, having regard to the nature and risks of the processing. These may include encryption, pseudonymisation, access controls, resilience measures, security testing, risk assessments and procedures for restoring access to information following an incident.

Perhaps one of the most important operational requirements is the statutory breach-notification framework. Where a data controller becomes aware of a personal-data breach likely to result in a risk to the rights and freedoms of individuals, the Commission is to be notified within 72 hours. A processor that discovers a breach must notify the relevant controller and provide information necessary for compliance. A company cannot afford to begin asking "What do we do?" after a cyberattack has occurred. There should already be a documented process identifying who investigates the incident, who makes the legal assessment, who communicates with the regulator, who informs affected individuals where required and how evidence is preserved.

11. Cross-Border Transfers: Data Does Not Lose Its Protection at the Border

Modern businesses rarely operate within a single jurisdiction. Customer information may be stored on cloud servers outside Nigeria, processed by foreign technology providers or transferred to group companies in other countries. The NDPA therefore establishes a framework governing the transfer of personal data outside Nigeria. Depending on the circumstances, transfers may rely on adequate protection in the recipient jurisdiction, appropriate safeguards or specified statutory exceptions.

This is particularly important for multinational companies and Nigerian businesses using international cloud, payment, HR, CRM and other technology providers. The legal question is no longer simply "Where is our server?" It is: "Where does our data travel, who receives it, on what legal basis, and what safeguards protect it?"

12. Registration and the Concept of Controllers and Processors of Major Importance

The Act introduces the category of data controllers and data processors of major importance, subjecting qualifying entities to enhanced regulatory obligations. The GAID has subsequently provided greater clarity on how the Commission approaches the designation and registration of such entities. It also addresses compliance audit returns and related regulatory obligations. The NDPC now provides registration and compliance services through its regulatory framework, including requirements involving licensed Data Protection Compliance Organisations (DPCOs).

Businesses should therefore assess their status rather than assuming that data protection registration is relevant only to large technology companies. Banks, fintechs, telecommunications companies, healthcare providers, educational institutions, employers, e-commerce businesses, professional-service firms and public-sector organisations may all process significant quantities or categories of personal data.

13. Enforcement: Data Protection Has Become a Financial and Commercial Risk

The NDPA introduces meaningful enforcement powers and financial sanctions. For a data controller or processor of major importance, the maximum penalty may be the greater of ₦10 million or 2% of its annual gross revenue in the preceding financial year. For other controllers or processors, the maximum may be the greater of ₦2 million or 2% of annual gross revenue, subject to the statutory framework.

The significance of the sanctions extends beyond the fine itself. A serious data breach may produce: regulatory investigations; financial penalties; civil claims; contractual disputes; business interruption; reputational damage; loss of customer confidence; and increased scrutiny from investors, lenders and commercial partners. Data protection should therefore be regarded as a corporate risk-management issue, not simply a compliance expense.

14. The GAID 2025: From Legislation to Operational Compliance

The enactment of the NDPA was only the beginning of the regulatory transition. The NDPC's General Application and Implementation Directive 2025, effective from 19 September 2025, provides a more detailed operational framework for implementing the Act. The Commission describes the GAID as addressing matters including compliance measures, registration, compliance audit returns, designation of data controllers and processors of major importance, DPOs and cross-border data transfers.

This is particularly important for businesses that previously relied primarily on the NDPR 2019 framework. The regulatory environment has evolved. Organisations should therefore not assume that historical compliance with the NDPR automatically means that their present arrangements satisfy the NDPA and GAID. Indeed, the NDPC has expressly stated that the NDP Act applies across sectors even where sector-specific data-protection rules exist.

15. What Businesses Should Be Doing Now

For most organisations, compliance should begin with a data-mapping exercise. Businesses should know: (1) what personal data they collect; (2) where it is collected; (3) the purpose for which it is processed; (4) the lawful basis relied upon; (5) who has access to it; (6) which third parties receive it; (7) whether it leaves Nigeria; (8) how long it is retained; (9) what security measures protect it; and (10) how requests, complaints and breaches are handled.

Organisations should also review their privacy notices, contracts with processors, employee-data practices, marketing practices, cybersecurity arrangements, retention policies and incident-response procedures. For businesses deploying artificial intelligence or automated decision-making systems, the analysis should go further: what data is being used to train or operate the system, what decisions are being made, whether individuals can challenge consequential decisions, and whether the processing creates risks requiring a DPIA?

Conclusion: Data Protection Is Now a Boardroom Issue

The Nigeria Data Protection Act 2023 represents a fundamental shift in Nigeria's approach to personal data. It is no longer sufficient for organisations to regard privacy as a disclaimer placed at the bottom of a website or as a document prepared solely for regulatory purposes. The NDPA establishes a framework in which data governance, cybersecurity, corporate governance and individual rights increasingly intersect.

The subsequent introduction of the GAID 2025 has moved the regulatory framework further from broad statutory principles towards operational compliance requirements. For businesses, the central lesson is clear: personal data is an asset, but it is also a responsibility.

Organisations that understand where their data comes from, establish lawful purposes for its use, minimise unnecessary collection, protect it appropriately and respect the rights of data subjects will be better positioned not only to comply with Nigerian law but also to build the trust upon which the digital economy depends. As Nigeria continues to expand its fintech, artificial intelligence, e-commerce, digital-health and technology ecosystems, the importance of effective data governance will only increase.

Lex Firma LP advises businesses, technology companies, financial institutions, public-sector organisations and other data-driven enterprises on data protection, regulatory compliance, technology transactions, privacy governance and risk management. We continue to monitor developments in Nigeria's data protection regime and assist clients in navigating the evolving requirements of the NDPA and the regulatory framework administered by the NDPC.
NEED ADVICE ON THIS?

This article is general commentary, not legal advice. Speak to our team about how it applies to your circumstances.

CONTACT US →