Nigeria Data Protection Act 2023
Core obligations of the Nigeria Data Protection Act 2023, which replaced the NITDA Data Protection Regulation 2019 and established the NDPC as an independent regulator. Included because Nigeria-facing products frequently have to satisfy both NDPA and GDPR, and the two diverge in ways that matter — notably registration of data controllers of major importance and the Nigerian data-transfer regime.
Nigeria Data Protection Commission (NDPC) · Act No. 37 of 2023, assented 12 June 2023 · Nigeria, with extraterritorial application to processing of data of data subjects in Nigeria · Official source
Personal data shall be processed fairly, lawfully and transparently; for a specified, explicit and legitimate purpose; adequate, relevant and limited to the minimum necessary; retained for no longer than necessary; accurate and kept up to date; and secured against loss, destruction or damage.
Processing is lawful only where the data subject has given consent, or processing is necessary for the performance of a contract, compliance with a legal obligation, the protection of vital interests, a task carried out in the public interest, or the legitimate interests of the data controller or a third party.
Consent must be freely given, specific, informed and unambiguous, evidenced by a clear affirmative act; it must not be bundled with other terms; and the data subject must be able to withdraw it at any time without detriment.
A data controller shall, at the point of collection, provide the data subject with the identity and contact details of the controller, the purposes and lawful basis of processing, recipients, transfer arrangements, retention period, the data subject's rights and the right to lodge a complaint with the Commission.
Sensitive personal data — including genetic and biometric data, race or ethnic origin, religious or similar beliefs, health, sex life, political opinions or affiliations and trade union membership — may be processed only where an additional statutory condition is met and with heightened safeguards.
A data controller shall obtain the consent of a parent or legal guardian before processing the personal data of a child, and shall apply appropriate mechanisms to verify age and consent.
A data subject has the right to obtain confirmation of whether their personal data is being processed, a copy of it and information about the processing, and the correction of inaccurate, out-of-date or incomplete data, without undue delay (s.34(1)(a)–(c)).
A data subject may have personal data erased without undue delay where it is no longer necessary, consent has been withdrawn (s.35) or it was processed unlawfully, and may have processing restricted while a complaint or legal claim is resolved (s.34(1)(d)–(e)).
Where processing is by automated means and based on consent or contract, the data subject may receive their personal data in a structured, commonly used and machine-readable format.
A data subject may object to processing, including for direct marketing (s.36), and has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to the Act's exceptions and safeguards including human intervention (s.37).
Controllers and processors shall implement appropriate technical and organisational measures to give effect to the processing principles and shall demonstrate accountability, owing a duty of care to data subjects (s.24(2)–(3)). The NDPC's General Application and Implementation Directive (GAID) 2025 requires software that processes personal data to be designed with privacy by design and by default (Art. 31).
A data controller or processor shall implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data, taking into account the risk — such as pseudonymisation or encryption, access controls, resilience of systems, and periodic testing of the effectiveness of those measures (s.39).
A processor must notify its controller of a personal data breach without undue delay (s.40(1)). Where a breach is likely to result in a risk to the rights and freedoms of individuals, the controller shall notify the Commission within 72 hours of becoming aware of it (s.40(2)), and where the risk is high shall immediately communicate it to affected data subjects in plain and clear language (s.40(3)). Controllers and processors must keep a record of all personal data breaches, their effects and the remedial action taken (s.40(8)).
Where a data controller engages a data processor (or a processor engages another), it shall take reasonable measures, including a written agreement, to ensure the processor complies with the Act's principles, assists with data subject rights, implements appropriate security measures, provides information needed to demonstrate compliance, and notifies the controller of any sub-processor it engages (s.29).
A data controller of major importance shall designate a Data Protection Officer with expert knowledge of data protection law and practice, who may be an employee or engaged under a service contract. The DPO advises the controller and its staff, monitors compliance, and is the contact point for the Commission (s.32). Other organisations should record why they are not required to appoint one.
A data controller or processor of major importance shall register with the Commission within six months of the Act's commencement or of becoming one, and notify the Commission of significant changes (s.44). Under the GAID 2025 these organisations are designated ultra-high, extra-high or ordinary-high level; ordinary-high level registrations are renewed annually. This duty has no direct GDPR equivalent and is frequently missed by organisations that have simply reused their GDPR programme.
The Act does not itself impose a general duty to keep records of processing, but the NDPC's GAID 2025 requires data controllers and processors of major importance to file annual Compliance Audit Returns with the Commission (by 31 March for established organisations; Art. 10) and requires the DPO's semi-annual data protection reports to form part of a Record of Processing Activities (Art. 13).
Where processing is likely to result in a high risk to the rights and freedoms of a data subject, the data controller shall, before the processing, carry out a data privacy impact assessment (s.28). The GAID 2025 lists mandatory cases — including profiling, automated decisions, systematic monitoring, sensitive data and digital financial or health services (Art. 28).
The Act does not itself mandate staff training, but the GAID 2025 requires controllers and processors to train personnel on data protection law and practice (within six months of starting business and at least annually; Art. 7) and to maintain a schedule of internal sensitisation and privacy training (Art. 30).
Personal data may be transferred out of Nigeria only where the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism affording an adequate level of protection (s.41–42), or where a section 43 basis such as consent or contractual necessity applies; the controller shall record the basis relied upon and the adequacy assessment.
A data subject may lodge a complaint with the Commission, which may investigate (s.46). A data controller or processor should operate its own mechanism for receiving and resolving data subject complaints, tell data subjects of their right to complain to the Commission, and cooperate with Commission investigations.