Key points
Lawful, fair and transparent processing on consent or another lawful basis.
Access, rectification, erasure, restriction, portability and objection.
Appointment where processing warrants, plus registration for major handlers.
Notify the Commission and, where relevant, affected data subjects.
The Nigeria Data Protection Act 2023 (NDPA) was signed into law on 12 June 2023. It replaced the regulation-based regime built on the Nigeria Data Protection Regulation 2019 with a full statute, and it established the Nigeria Data Protection Commission (NDPC) as an independent regulator with investigative and sanctioning powers.
In March 2025 the NDPC issued the General Application and Implementation Directive (GAID), which supplies the operational detail the Act left open, including registration thresholds, timelines and audit expectations. Reading the Act without the GAID will leave gaps in any Nigerian compliance programme.
Scope and key terms
Territorial application
Applies where the controller or processor is domiciled, resident or operating in Nigeria, where processing occurs in Nigeria, or where a controller or processor not in Nigeria processes the personal data of data subjects in Nigeria.
Controller and processor
Familiar roles with familiar meanings. Both carry direct statutory duties, and both can be designated as being of major importance.
Exemptions
Purely personal or household purposes, and processing by competent authorities for prevention and investigation of crime, national security and similar public functions, subject to conditions.
Sensitive personal data
Includes genetic and biometric data, race or ethnic origin, religious or similar beliefs, health, sex life, political opinions and trade union membership.
Principles and lawful bases
The structure will be recognisable to anyone who has implemented the GDPR, with Nigerian specifics on consent.
| Basis | When it applies |
|---|---|
| Consent | Freely given, specific, informed and unambiguous, by a clear affirmative action. It must be capable of being withdrawn at any time, and withdrawal must be as easy as giving it. Consent obtained through deception or undue influence is invalid. |
| Contract | Necessary for performance of a contract to which the data subject is a party, or to take steps at the data subject’s request before entering one. |
| Legal obligation | Necessary for compliance with a legal obligation to which the controller is subject. |
| Vital interests | Necessary to protect the vital interests of the data subject or another person. |
| Public interest | Necessary for a task carried out in the public interest or in the exercise of official authority vested in the controller. |
| Legitimate interests | Necessary for the legitimate interests of the controller or a third party, except where overridden by the data subject’s interests or fundamental rights, and subject to the data subject’s reasonable expectations. |
Data controllers and processors of major importance
The NDPA’s distinctive compliance tier, and the first question a Nigerian programme has to answer.
A data controller or processor of major importance (commonly DCMI or DCPMI) is one that is domiciled, resident in or operating in Nigeria and processes the personal data of more than a number of Nigerian data subjects prescribed by the Commission, or that the Commission designates because the data is of particular value or significance to the economy, society or security of Nigeria.
Being designated is what pulls an organisation into the heavier obligations: registration with the NDPC, appointing a Data Protection Officer, and filing periodic compliance audit returns. Sector matters as much as volume, so financial services, telecommunications, health and education operators frequently qualify even at moderate scale.
Register with the NDPC
Registration is made through the Commission and the register of controllers and processors of major importance is published.
Appoint a DPO
A Data Protection Officer with expert knowledge, accessible to data subjects and to the Commission, and able to act independently.
File audit returns
Periodic compliance audits, filed with the Commission, in practice prepared with a licensed Data Protection Compliance Organisation.
Security, impact assessments and accountability
Security measures
Appropriate technical and organisational measures, taking account of the state of the art and the risk, including where appropriate encryption or pseudonymisation, resilience, and the ability to restore availability after an incident.
Impact assessments
Required before processing likely to result in a high risk to the rights and freedoms of data subjects, considering the nature, scope, context and purposes of the processing.
Processor contracts
Processors must be engaged under a written contract and must provide sufficient guarantees. Controllers remain accountable for processing carried out on their behalf.
Children and vulnerable persons
Processing the data of a child requires the consent of a parent or guardian and age verification using appropriate mechanisms, subject to defined exceptions such as education, medical need and the child’s best interests.
Data subject rights
Access
Confirmation of processing and a copy of the personal data, together with the supporting information about purposes, recipients and retention.
Rectification
Correction of inaccurate data and completion of incomplete data without undue delay.
Erasure
Deletion where the data is no longer necessary, consent is withdrawn and no other basis applies, or the processing is unlawful.
Restriction and objection
Restriction in defined circumstances, objection to processing based on public interest or legitimate interests, and an absolute right to object to direct marketing.
Portability
Receipt of data in a structured, commonly used, machine-readable format and transmission to another controller where technically feasible.
Automated decisions
Not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to exceptions with safeguards.
Cross-border transfers
Personal data may leave Nigeria where the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism that affords an adequate level of protection. The controller must be satisfied of this, and the Commission may assess adequacy by reference to the rule of law, respect for human rights, the existence of a competent supervisory authority, and international commitments.
Where adequacy is not established, the transfer may still proceed on a narrow set of grounds, including the data subject’s explicit consent after being informed of the risks, necessity for contract performance, important public interest, legal claims, and protecting the vital interests of a person who cannot give consent.
Personal data breaches
Where a breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the NDPC within 72 hours of becoming aware of it. The notification describes the nature of the breach, the likely consequences and the measures taken or proposed.
Where the breach is likely to result in a high risk, the controller must also communicate it to the affected data subjects without undue delay, in plain language, with advice on steps they can take. A processor that becomes aware of a breach must notify its controller without undue delay.
Enforcement and sanctions
The NDPC can investigate on complaint or on its own initiative, issue compliance orders, and impose remedial fees and penalties. It has been actively issuing enquiries requiring evidence of DPO appointment, technical and organisational measures, and registration status within short deadlines.
| Category | Upper limit |
|---|---|
| Data controller or processor of major importance | The greater of NGN 10,000,000 or 2% of annual gross revenue in the preceding financial year |
| Any other data controller or processor | The greater of NGN 2,000,000 or 2% of annual gross revenue in the preceding financial year |
| Accompanying orders | Compliance orders, remediation directions, payment of compensation to data subjects, and accounting for profits made from the violation |
An NDPA implementation roadmap
Test for major importance
Assess volume against the thresholds in the GAID and consider sector significance. Document the conclusion either way, because the answer drives everything that follows.
Register and appoint
If in scope, register with the NDPC and appoint a Data Protection Officer with genuine independence and a reporting line to senior management.
Rebase the lawful bases
Move away from blanket consent. Map each activity to the most appropriate of the six bases and record the legitimate interests assessment where you rely on it.
Build the records and assessments
Maintain processing records and run impact assessments for high-risk processing before launch, not after.
Fix the transfer basis
Identify every export, assess adequacy, and put contractual clauses or binding rules in place where it is not established.
Stand up a 72-hour breach process
Define detection, assessment and escalation so the Commission can be notified within 72 hours and data subjects informed where the risk is high.
Plan the audit return
Where you are of major importance, schedule the compliance audit and engage a licensed DPCO in good time before the filing window.
Frequently asked
How do we know if we are of “major importance”?
Two routes lead to the designation. The first is volume, measured against the thresholds the Commission prescribes in the General Application and Implementation Directive. The second is significance, where the Commission designates a controller or processor because the data it handles matters to the economy, society or security of Nigeria. Sector is often decisive, so banks, fintechs, telecoms operators, hospitals and schools frequently qualify without being especially large.
Do we have to appoint a Data Protection Officer?
It is a specific obligation for data controllers and processors of major importance. Other organisations are not required to appoint one, though doing so is a practical way of discharging the accountability duties the Act imposes on everyone.
Is the NDPA just the GDPR for Nigeria?
The principles, bases, rights and breach mechanics are closely comparable, so a GDPR programme transfers well. The genuinely Nigerian layers are the major-importance designation with its registration and audit duties, the role of licensed Data Protection Compliance Organisations, the operational detail in the GAID, and a penalty cap calculated as the higher of a fixed sum or a percentage of turnover.
What is a DPCO?
A Data Protection Compliance Organisation is an entity licensed by the Nigeria Data Protection Commission to provide data protection compliance services, including carrying out audits and filing returns on behalf of controllers. The Commission publishes the list of licensed DPCOs, and engaging one is the usual route to the compliance audit filing.
How long do we have to report a breach?
Seventy-two hours from becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of individuals. Where the risk is high, the affected data subjects must also be told without undue delay, in clear language, with practical advice.
Does the old NDPR 2019 still matter?
The Act is now the governing instrument and the Commission established under it is the regulator. Work done under the 2019 regulation, particularly audit discipline and DPO structures, remains useful groundwork, but compliance should be assessed against the Act read together with the 2025 General Application and Implementation Directive.
From applicability to evidence
We map your processing to this regime, build the controls behind the obligations, and prepare the evidence that proves compliance.
Start a conversation