← Framework library

Nigeria Data Protection Act 2023

Core obligations of the Nigeria Data Protection Act 2023, which replaced the NITDA Data Protection Regulation 2019 and established the NDPC as an independent regulator. Included because Nigeria-facing products frequently have to satisfy both NDPA and GDPR, and the two diverge in ways that matter — notably registration of data controllers of major importance and the Nigerian data-transfer regime.

Nigeria Data Protection Commission (NDPC) · Act No. 37 of 2023, assented 12 June 2023 · Nigeria, with extraterritorial application to processing of data of data subjects in Nigeria · Official source

Section references are to the Act as assented (Act No. 37 of 2023). Where a duty comes from the NDPC's General Application and Implementation Directive (GAID) 2025 rather than the Act itself, the control ID says so. Requirement text is paraphrased for assessment purposes and is not legal advice; the NDPC continues to issue subsidiary guidance that refines several of these duties.
21 of 21 controls
s.24 Principles of data processing critical

Personal data shall be processed fairly, lawfully and transparently; for a specified, explicit and legitimate purpose; adequate, relevant and limited to the minimum necessary; retained for no longer than necessary; accurate and kept up to date; and secured against loss, destruction or damage.

Principles lawful-basisdata-minimisationdata-retention
s.25 Lawful basis for processing critical

Processing is lawful only where the data subject has given consent, or processing is necessary for the performance of a contract, compliance with a legal obligation, the protection of vital interests, a task carried out in the public interest, or the legitimate interests of the data controller or a third party.

Lawfulness lawful-basisconsent
s.26 Conditions for valid consent high

Consent must be freely given, specific, informed and unambiguous, evidenced by a clear affirmative act; it must not be bundled with other terms; and the data subject must be able to withdraw it at any time without detriment.

Lawfulness consent
s.27 Information to be provided to data subjects high

A data controller shall, at the point of collection, provide the data subject with the identity and contact details of the controller, the purposes and lawful basis of processing, recipients, transfer arrangements, retention period, the data subject's rights and the right to lodge a complaint with the Commission.

Transparency privacy-notice
s.30 Sensitive personal data critical

Sensitive personal data — including genetic and biometric data, race or ethnic origin, religious or similar beliefs, health, sex life, political opinions or affiliations and trade union membership — may be processed only where an additional statutory condition is met and with heightened safeguards.

Special categories data-classificationlawful-basis
s.31 Processing the data of children and persons lacking capacity high

A data controller shall obtain the consent of a parent or legal guardian before processing the personal data of a child, and shall apply appropriate mechanisms to verify age and consent.

Children consentlawful-basischildren
s.34(1)(a)-(c) Right of access and rectification high

A data subject has the right to obtain confirmation of whether their personal data is being processed, a copy of it and information about the processing, and the correction of inaccurate, out-of-date or incomplete data, without undue delay (s.34(1)(a)–(c)).

Data subject rights data-subject-rights
s.34(1)(d)-(e) Right to erasure and restriction high

A data subject may have personal data erased without undue delay where it is no longer necessary, consent has been withdrawn (s.35) or it was processed unlawfully, and may have processing restricted while a complaint or legal claim is resolved (s.34(1)(d)–(e)).

Data subject rights data-subject-rightsdata-deletion
s.38 Right to data portability medium

Where processing is by automated means and based on consent or contract, the data subject may receive their personal data in a structured, commonly used and machine-readable format.

Data subject rights data-subject-rights
s.36-37 Objection and automated decision-making medium

A data subject may object to processing, including for direct marketing (s.36), and has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to the Act's exceptions and safeguards including human intervention (s.37).

Data subject rights data-subject-rights
s.24(2)-(3) Technical and organisational measures, accountability and privacy by design high

Controllers and processors shall implement appropriate technical and organisational measures to give effect to the processing principles and shall demonstrate accountability, owing a duty of care to data subjects (s.24(2)–(3)). The NDPC's General Application and Implementation Directive (GAID) 2025 requires software that processes personal data to be designed with privacy by design and by default (Art. 31).

Controller obligations sdlcdata-minimisation
s.39 Security, integrity and confidentiality critical

A data controller or processor shall implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data, taking into account the risk — such as pseudonymisation or encryption, access controls, resilience of systems, and periodic testing of the effectiveness of those measures (s.39).

Security encryption-at-restencryption-in-transitaccess-controlbackup
s.40 Personal data breaches: notification and breach records critical

A processor must notify its controller of a personal data breach without undue delay (s.40(1)). Where a breach is likely to result in a risk to the rights and freedoms of individuals, the controller shall notify the Commission within 72 hours of becoming aware of it (s.40(2)), and where the risk is high shall immediately communicate it to affected data subjects in plain and clear language (s.40(3)). Controllers and processors must keep a record of all personal data breaches, their effects and the remedial action taken (s.40(8)).

Security breach-notificationincident-response
s.29 Data processor engagement critical

Where a data controller engages a data processor (or a processor engages another), it shall take reasonable measures, including a written agreement, to ensure the processor complies with the Act's principles, assists with data subject rights, implements appropriate security measures, provides information needed to demonstrate compliance, and notifies the controller of any sub-processor it engages (s.29).

Controller obligations vendor-managementthird-party
s.32 Designation of a Data Protection Officer high

A data controller of major importance shall designate a Data Protection Officer with expert knowledge of data protection law and practice, who may be an employee or engaged under a service contract. The DPO advises the controller and its staff, monitors compliance, and is the contact point for the Commission (s.32). Other organisations should record why they are not required to appoint one.

Governance dporoles-responsibilities
s.44 Registration as a data controller or processor of major importance critical

A data controller or processor of major importance shall register with the Commission within six months of the Act's commencement or of becoming one, and notify the Commission of significant changes (s.44). Under the GAID 2025 these organisations are designated ultra-high, extra-high or ordinary-high level; ordinary-high level registrations are renewed annually. This duty has no direct GDPR equivalent and is frequently missed by organisations that have simply reused their GDPR programme.

Governance policy-governancerecords
GAID Art.10 Compliance audit returns and records of processing (GAID 2025) high

The Act does not itself impose a general duty to keep records of processing, but the NDPC's GAID 2025 requires data controllers and processors of major importance to file annual Compliance Audit Returns with the Commission (by 31 March for established organisations; Art. 10) and requires the DPO's semi-annual data protection reports to form part of a Record of Processing Activities (Art. 13).

Accountability recordsaudit
s.28 Data privacy impact assessment high

Where processing is likely to result in a high risk to the rights and freedoms of a data subject, the data controller shall, before the processing, carry out a data privacy impact assessment (s.28). The GAID 2025 lists mandatory cases — including profiling, automated decisions, systematic monitoring, sensitive data and digital financial or health services (Art. 28).

Accountability dpiarisk-assessment
GAID Art.30 Privacy training and internal sensitisation (GAID 2025) medium

The Act does not itself mandate staff training, but the GAID 2025 requires controllers and processors to train personnel on data protection law and practice (within six months of starting business and at least annually; Art. 7) and to maintain a schedule of internal sensitisation and privacy training (Art. 30).

Governance trainingawareness
s.41-43 Cross-border transfer of personal data critical

Personal data may be transferred out of Nigeria only where the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism affording an adequate level of protection (s.41–42), or where a section 43 basis such as consent or contractual necessity applies; the controller shall record the basis relied upon and the adequacy assessment.

Transfers cross-border-transfervendor-management
s.46 Complaints and cooperation with the Commission medium

A data subject may lodge a complaint with the Commission, which may investigate (s.46). A data controller or processor should operate its own mechanism for receiving and resolving data subject complaints, tell data subjects of their right to complain to the Commission, and cooperate with Commission investigations.

Enforcement data-subject-rightspolicy-governance