By Sandra Adeniran, Principal Partner
The Definitive Guide to Nigeria Data Protection Act Compliance (2026)
Many Nigerian business owners think a data breach is something that happens to large banks or multinational tech companies. They are dangerously mistaken. A single misconfigured customer database or a lost employee laptop can trigger regulatory scrutiny, crippling fines, and a complete loss of customer trust. The legal framework governing this is no longer a paper tiger; it has teeth.
Achieving Nigeria Data Protection Act compliance requires a fundamental shift in how your business handles personal information. It means you must identify a lawful basis for all data processing, implement robust security measures, respect the rights of data subjects, and maintain detailed records of your data activities. This is not just an IT task but a core business-wide responsibility, mandated by the Nigeria Data Protection Act (NDPA) 2023, with significant penalties for failure. Instead, view ndpa as opportunity.
What is the Nigeria Data Protection Act (NDPA) 2023?
The NDPA 2023, signed into law on June 12, 2023, established a new principal legislation for data protection in Nigeria. It superseded the previous Nigeria Data Protection Regulation (NDPR) 2019, creating a more robust and comprehensive framework. The Act established the Nigeria Data Protection Commission (NDPC) as an independent regulatory body with powers to enforce compliance.
As a firm providing comprehensive legal services across various sectors, we’ve seen firsthand that the transition from NDPR to NDPA represents a significant elevation of data privacy standards, moving closer to global benchmarks like the GDPR.
The Shift from NDPR to NDPA
The move from the NDPR to the NDPA was a transition from subsidiary legislation to a principal act of parliament. This change carries substantial weight. An Act of the National Assembly has greater legal authority, broader scope, and provides a stronger basis for enforcement. While the NDPR laid the groundwork, the NDPA introduces more stringent requirements, higher penalties, and clarifies the roles and responsibilities of the regulatory body, the NDPC. The official text of the Act provides the full legal basis for these enhanced powers.
Who Must Comply? Key Definitions Explained
Understanding your role under the NDPA is the first step. The Act defines two primary roles:
- Data Controller: An individual, private entity, public commission, agency, or any other body that, alone or jointly with others, determines the purposes and means of processing personal data. If you decide “why” and “how” data is collected and used (e.g., collecting customer details for a mailing list), you are a data controller.
- Data Processor: An individual or entity that processes personal data on behalf of a data controller. This could be a cloud hosting provider, a payroll company, or a marketing agency that handles customer data based on the controller’s instructions.
Crucially, the Act applies to all businesses that process the personal data of Nigerian citizens and residents, regardless of the business’s size.
Territorial Scope: Does it Affect Businesses Outside Nigeria?
Yes. The NDPA has extraterritorial scope. This means it applies to data controllers and processors who are not based in Nigeria, if they are processing the personal data of a data subject who is in Nigeria. For any international company with customers in Nigeria, or even those targeting Nigerian residents with goods or services (for example through an e-commerce platform), achieving Nigeria Data Protection Act compliance is mandatory. This is a critical consideration for global businesses operating in the Nigerian market.
Key Principles of the NDPA
The NDPA is built on a set of core principles that should guide all data processing activities. Adherence to these principles is the foundation of compliance.
Lawfulness, Fairness, and Transparency
All data processing must be lawful. This means you must have a valid legal basis for every piece of data you process. The NDPA outlines several lawful bases, including consent from the data subject, contractual necessity, legal obligation, vital interests, public interest, or the legitimate interests of the controller. Furthermore, processing must be fair and transparent to the data subject. You must clearly communicate what data you are collecting and for what purpose, typically through a clear and accessible privacy policy.
Purpose Limitation and Data Minimisation
You must collect personal data for specified, explicit, and legitimate purposes. You cannot collect data for one reason (e.g., processing an order) and then use it for an entirely different, undisclosed purpose later. The principle of data minimisation requires you to collect only the data that is adequate, relevant, and necessary for the stated purpose. Collecting a customer’s date of birth and marital status to sell them a product online would likely be deemed excessive.
The NDPA treats data privacy not as a suggestion, but as a fundamental right. Compliance isn’t about ticking boxes; it’s about embedding a culture of data respect into your organization’s DNA.
Accuracy, Storage Limitation, and Integrity
Personal data must be accurate and, where necessary, kept up to date. You must take reasonable steps to ensure that inaccurate data is erased or rectified without delay. The storage limitation principle means you should not keep personal data in a form that permits identification of data subjects for longer than is necessary for the purposes for which it was processed. Finally, the principle of “integrity and confidentiality” requires you to use appropriate technical and organisational measures to ensure the security of the data, protecting it against unauthorised or unlawful processing, accidental loss, destruction, or damage.
Data Subject Rights and How to Exercise Them
The NDPA grants individuals (data subjects) a robust set of rights over their personal data. Businesses must have procedures in place to facilitate the exercise of these rights promptly.
The Right to Access, Rectification, and Erasure
Data subjects have the right to obtain from a data controller confirmation as to whether or not personal data concerning them is being processed. If it is, they have the right to access that data and receive supplementary information. They can also request the rectification of inaccurate personal data and, under certain conditions (e.g., the data is no longer necessary for the purpose it was collected), they can request its erasure (the “right to be forgotten”).
The Right to Data Portability and to Restrict Processing
Data portability allows a data subject to receive their personal data in a structured, commonly used, and machine-readable format and have the right to transmit that data to another controller without hindrance. This empowers users to switch between service providers more easily. Data subjects also have the right to request the restriction of processing in certain situations, such as when the accuracy of the data is contested.
The Right to Object to Automated Decision-Making
A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. This is particularly relevant in areas like automated credit scoring or online recruitment. There are exceptions, but the general rule is that a human must be involved in significant decisions.
Roles and Responsibilities Under the NDPA
Compliance requires a clear understanding of the specific obligations placed on your organisation, whether you are a controller or a processor.
The Data Controller’s Core Obligations
The controller bears the primary responsibility for compliance. Key obligations include:
- Implementing a data protection policy.
- Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
- Appointing a Data Protection Officer (DPO) where required.
- Maintaining records of all processing activities.
- Ensuring contracts with data processors are NDPA-compliant.
- Reporting data breaches to the NDPC within 72 hours of becoming aware of them.
Appointing a Data Protection Officer (DPO)
Data controllers and processors of “major importance” must appoint a DPO. The NDPA defines this as an organisation that processes the data of more than 200,000 data subjects within a six-month period. The DPO is responsible for monitoring internal compliance, advising on data protection obligations, and acting as a contact point for the NDPC and data subjects. This applies to many organisations, including those in high-volume sectors like banking, telecoms, and even specialized fields like Oil & Gas law where sensitive employee and contractor data is processed on a large scale.
A Data Protection Officer is not a ceremonial role. They are your organization’s designated expert and watchdog, requiring genuine authority and resources to function effectively under the Act.
Requirements for Data Processors
Data processors are not exempt from responsibility. They must only process data on the documented instructions of the controller. They are also directly responsible for implementing appropriate security measures to protect the data. A processor must notify the controller without undue delay after becoming aware of a personal data breach. The relationship between controller and processor must be governed by a legally binding contract that sets out the specifics of the processing.
Steps to NDPA Compliance for Businesses
Achieving Nigeria Data protection Act compliance is a continuous process, not a one-time project. Here is a step-by-step process for businesses to follow.
- Conduct a Data Audit and a Data Protection Impact Assessment (DPIA): The first step is to understand what personal data you hold, where it comes from, what you do with it, and who you share it with. For processing activities that are likely to result in a high risk to data subjects, a DPIA is mandatory. This assessment helps you identify and mitigate privacy risks proactively.
- Develop and Implement a Privacy Framework: This involves creating key documentation. You need a clear and comprehensive privacy policy that is easily accessible to customers and employees. We have a detailed guide on privacy policy requirements. You also need internal policies that govern how your staff handle data.
- Establish a Data Breach Response Plan: You must be prepared to act quickly in the event of a breach. This plan should outline the steps to take to contain the breach, assess the risk, notify the NDPC and affected individuals if required, and learn from the incident.
- Train Your Staff: Your employees are your first line of defense. Regular training ensures they understand their responsibilities under the NDPA, can identify potential risks, and know the correct procedures for handling personal data and responding to data subject requests.
- Vendor and Third-Party Management: You must review your contracts with all data processors (e.g., cloud providers, software vendors) to ensure they provide sufficient guarantees to implement appropriate technical and organisational measures in an NDPA-compliant manner. Remember, you can be held liable for the actions of your processors.
How the NDPA Compares to Global Data Protection Laws
For businesses operating internationally, understanding how the NDPA fits into the global privacy landscape is essential. The International Association of Privacy Professionals (IAPP) notes that the Act brings Nigeria’s legal framework more in line with global standards.
Nigeria’s NDPA vs. Europe’s GDPR
The NDPA was heavily influenced by the EU’s General Data Protection Regulation (GDPR), and they share many core principles. However, there are key differences in their specifics, particularly regarding fines and the thresholds for appointing a DPO.
| Feature | Nigeria Data Protection Act (NDPA) 2023 | EU General Data Protection Regulation (GDPR) |
|---|---|---|
| Maximum Fine | Higher of ₦10 million or 2% of annual gross revenue in the preceding year. | Higher of €20 million or 4% of annual global turnover in the preceding year. |
| DPO Appointment | Mandatory for controllers/processors of “major importance” (processing data of >200,000 subjects). | Mandatory for public authorities, or if core activities involve large-scale regular monitoring or large-scale processing of sensitive data. |
| Data Breach Notification | Within 72 hours of becoming aware of the breach. | Within 72 hours of becoming aware of the breach, where feasible. |
| Territorial Scope | Applies to processing the data of subjects in Nigeria, regardless of the company’s location. | Applies to processing the data of subjects in the EU, regardless of the company’s location. |
Key Distinctions from US Privacy Laws
Unlike Europe’s comprehensive GDPR or Nigeria’s NDPA, the United States does not have a single, overarching federal privacy law. Instead, it has a patchwork of federal and state-level laws. The most prominent is the California Consumer Privacy Act (CCPA), as amended by the CPRA. The CCPA is less prescriptive than the NDPA, focusing more on the consumer’s right to opt-out of the sale of their personal information. The NDPA, similar to GDPR, is an “opt-in” regime, requiring a lawful basis before data can even be processed. For entities like legal for nigerian e-commerce, this distinction is critical for designing compliant user experiences.
Consequences of Non-Compliance
The Nigeria Data Protection Commission (NDPC) is empowered to enforce the Act, and the consequences of a violation are severe. The era of treating data protection as an afterthought in Nigeria is over.
Financial Penalties: Understanding the Tiers
The NDPA specifies significant financial penalties for non-compliance. These are divided into two tiers:
- For Data Controllers/Processors of Major Importance: The penalty is the greater of ₦10,000,000 or 2% of the organization’s annual gross revenue from the preceding year.
- For Other Data Controllers/Processors: The penalty is the greater of ₦2,000,000 or 2% of the organization’s annual gross revenue from the preceding year.
The NDPC has publicly stated its intent to enforce these provisions vigorously.
Reputational Damage and Loss of Goodwill
Beyond financial penalties, a data breach or enforcement action can cause irreparable harm to a company’s reputation. In an increasingly privacy-conscious world, customers will abandon brands they do not trust to protect their data. Rebuilding that trust is a long and expensive process.
Criminal Liability for Directors and Officers
The NDPA also provides for criminal sanctions. Offences such as unlawfully obtaining or disclosing personal data can lead to imprisonment for individuals. This personal liability extends corporate accountability directly to the decision-makers within an organization.
FAQ
What is the difference between a Data Controller and a Data Processor?
A Data Controller is the entity that determines the “why” and “how” of data processing. A Data Processor is a separate entity that processes data on behalf of the controller. For example, your company is the controller of its employee data, but the payroll company you hire is a data processor.
Does my small business really need to comply with the NDPA?
Yes. The NDPA does not have an exemption for small businesses. If you process the personal data of anyone in Nigeria—customers, employees, or even website visitors—the Act applies to you. The penalties are tiered based on revenue and scale, but the core compliance obligations apply to all.
What is a Data Protection Impact Assessment (DPIA) and when is it required?
A DPIA is a process to help you identify and minimize the data protection risks of a new project or processing activity. It is mandatory under the NDPA whenever processing is “likely to result in a high risk” to the rights and freedoms of individuals. This includes large-scale processing of sensitive data or systematic monitoring of a publicly accessible area.
How long do I have to report a data breach under the NDPA?
You must report a personal data breach to the NDPC within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. You may also need to communicate the breach to the affected data subjects without undue delay.
Can I transfer personal data outside of Nigeria?
Yes, but only under specific conditions. The NDPA permits transfer if the recipient country is deemed to have an adequate level of data protection. If not, you must use other legal mechanisms such as Binding Corporate Rules, Standard Contractual Clauses approved by the NDPC, or obtain the data subject’s explicit consent after informing them of the risks.
Navigating the requirements of the NDPA can be a complex undertaking. As one of the leading law firms in Nigeria, Ardnas Legal provides a comprehensive range of legal services to help businesses of all sizes understand their obligations and implement practical, effective compliance programs. If you have questions about your specific situation, contact our team for a consultation.
About the author

Sandra Adeniran
Principal Partner
Adebola Adeniran is the Founding Partner of Ardnas Legal Practitioners. She is a dynamic and forward-thinking lawyer with a passion for providing innovative legal solutions to businesses and individuals. Adebola combines deep legal expertise with a practical, business-oriented approach, ensuring that clients receive advice that is both strategic and actionable.



