Privacy education, consultancy & implementation, in 50+ jurisdictions.contact@vedhacon.com
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Nigeria · NDPA 2023

Nigeria’s NDPA, the country’s comprehensive data law.

The Nigeria Data Protection Act 2023 establishes the Nigeria Data Protection Commission and sets out principles, lawful bases, data subject rights and obligations for data controllers and processors.

Core of the regime

Key points

Principles & lawful bases

Lawful, fair and transparent processing on consent or another lawful basis.

Data subject rights

Access, rectification, erasure, restriction, portability and objection.

Data protection officers

Appointment where processing warrants, plus registration for major handlers.

Breach notification

Notify the Commission and, where relevant, affected data subjects.

The Nigeria Data Protection Act 2023 (NDPA) was signed into law on 12 June 2023. It replaced the regulation-based regime built on the Nigeria Data Protection Regulation 2019 with a full statute, and it established the Nigeria Data Protection Commission (NDPC) as an independent regulator with investigative and sanctioning powers.

In March 2025 the NDPC issued the General Application and Implementation Directive (GAID), which supplies the operational detail the Act left open, including registration thresholds, timelines and audit expectations. Reading the Act without the GAID will leave gaps in any Nigerian compliance programme.

Sections 2 and 65

Scope and key terms

Territorial application

Applies where the controller or processor is domiciled, resident or operating in Nigeria, where processing occurs in Nigeria, or where a controller or processor not in Nigeria processes the personal data of data subjects in Nigeria.

Controller and processor

Familiar roles with familiar meanings. Both carry direct statutory duties, and both can be designated as being of major importance.

Exemptions

Purely personal or household purposes, and processing by competent authorities for prevention and investigation of crime, national security and similar public functions, subject to conditions.

Sensitive personal data

Includes genetic and biometric data, race or ethnic origin, religious or similar beliefs, health, sex life, political opinions and trade union membership.

Sections 24 to 27

Principles and lawful bases

The structure will be recognisable to anyone who has implemented the GDPR, with Nigerian specifics on consent.

Lawful bases for processing under the NDPA
BasisWhen it applies
ConsentFreely given, specific, informed and unambiguous, by a clear affirmative action. It must be capable of being withdrawn at any time, and withdrawal must be as easy as giving it. Consent obtained through deception or undue influence is invalid.
ContractNecessary for performance of a contract to which the data subject is a party, or to take steps at the data subject’s request before entering one.
Legal obligationNecessary for compliance with a legal obligation to which the controller is subject.
Vital interestsNecessary to protect the vital interests of the data subject or another person.
Public interestNecessary for a task carried out in the public interest or in the exercise of official authority vested in the controller.
Legitimate interestsNecessary for the legitimate interests of the controller or a third party, except where overridden by the data subject’s interests or fundamental rights, and subject to the data subject’s reasonable expectations.
Consent is not a default. Nigerian practice inherited a heavy reliance on consent from the 2019 regulation. The NDPA puts six bases on an equal footing, and using consent where a contract or legitimate interest applies creates a fragile position, because withdrawal then stops the processing.
Sections 44 and 65

Data controllers and processors of major importance

The NDPA’s distinctive compliance tier, and the first question a Nigerian programme has to answer.

A data controller or processor of major importance (commonly DCMI or DCPMI) is one that is domiciled, resident in or operating in Nigeria and processes the personal data of more than a number of Nigerian data subjects prescribed by the Commission, or that the Commission designates because the data is of particular value or significance to the economy, society or security of Nigeria.

Being designated is what pulls an organisation into the heavier obligations: registration with the NDPC, appointing a Data Protection Officer, and filing periodic compliance audit returns. Sector matters as much as volume, so financial services, telecommunications, health and education operators frequently qualify even at moderate scale.

Register with the NDPC

Registration is made through the Commission and the register of controllers and processors of major importance is published.

Appoint a DPO

A Data Protection Officer with expert knowledge, accessible to data subjects and to the Commission, and able to act independently.

File audit returns

Periodic compliance audits, filed with the Commission, in practice prepared with a licensed Data Protection Compliance Organisation.

Data Protection Compliance Organisations (DPCOs) are entities licensed by the NDPC to provide compliance services, including audits and filing. The NDPC publishes the list of licensed DPCOs, and using one is the normal route for the annual audit return.
Section 32

Security, impact assessments and accountability

Security measures

Appropriate technical and organisational measures, taking account of the state of the art and the risk, including where appropriate encryption or pseudonymisation, resilience, and the ability to restore availability after an incident.

Impact assessments

Required before processing likely to result in a high risk to the rights and freedoms of data subjects, considering the nature, scope, context and purposes of the processing.

Processor contracts

Processors must be engaged under a written contract and must provide sufficient guarantees. Controllers remain accountable for processing carried out on their behalf.

Children and vulnerable persons

Processing the data of a child requires the consent of a parent or guardian and age verification using appropriate mechanisms, subject to defined exceptions such as education, medical need and the child’s best interests.

Sections 34 to 37

Data subject rights

Access

Confirmation of processing and a copy of the personal data, together with the supporting information about purposes, recipients and retention.

Rectification

Correction of inaccurate data and completion of incomplete data without undue delay.

Erasure

Deletion where the data is no longer necessary, consent is withdrawn and no other basis applies, or the processing is unlawful.

Restriction and objection

Restriction in defined circumstances, objection to processing based on public interest or legitimate interests, and an absolute right to object to direct marketing.

Portability

Receipt of data in a structured, commonly used, machine-readable format and transmission to another controller where technically feasible.

Automated decisions

Not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to exceptions with safeguards.

Sections 41 to 43

Cross-border transfers

Personal data may leave Nigeria where the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism that affords an adequate level of protection. The controller must be satisfied of this, and the Commission may assess adequacy by reference to the rule of law, respect for human rights, the existence of a competent supervisory authority, and international commitments.

Where adequacy is not established, the transfer may still proceed on a narrow set of grounds, including the data subject’s explicit consent after being informed of the risks, necessity for contract performance, important public interest, legal claims, and protecting the vital interests of a person who cannot give consent.

Section 40

Personal data breaches

Where a breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the NDPC within 72 hours of becoming aware of it. The notification describes the nature of the breach, the likely consequences and the measures taken or proposed.

Where the breach is likely to result in a high risk, the controller must also communicate it to the affected data subjects without undue delay, in plain language, with advice on steps they can take. A processor that becomes aware of a breach must notify its controller without undue delay.

Sections 46 to 48

Enforcement and sanctions

The NDPC can investigate on complaint or on its own initiative, issue compliance orders, and impose remedial fees and penalties. It has been actively issuing enquiries requiring evidence of DPO appointment, technical and organisational measures, and registration status within short deadlines.

Maximum sanctions for a proven breach
CategoryUpper limit
Data controller or processor of major importanceThe greater of NGN 10,000,000 or 2% of annual gross revenue in the preceding financial year
Any other data controller or processorThe greater of NGN 2,000,000 or 2% of annual gross revenue in the preceding financial year
Accompanying ordersCompliance orders, remediation directions, payment of compensation to data subjects, and accounting for profits made from the violation
Because the cap is expressed as the higher of a fixed sum or a percentage of turnover, the percentage limb is the one that matters for larger organisations. A data subject may also pursue civil remedies independently of regulatory action.
Practical steps

An NDPA implementation roadmap

1

Test for major importance

Assess volume against the thresholds in the GAID and consider sector significance. Document the conclusion either way, because the answer drives everything that follows.

2

Register and appoint

If in scope, register with the NDPC and appoint a Data Protection Officer with genuine independence and a reporting line to senior management.

3

Rebase the lawful bases

Move away from blanket consent. Map each activity to the most appropriate of the six bases and record the legitimate interests assessment where you rely on it.

4

Build the records and assessments

Maintain processing records and run impact assessments for high-risk processing before launch, not after.

5

Fix the transfer basis

Identify every export, assess adequacy, and put contractual clauses or binding rules in place where it is not established.

6

Stand up a 72-hour breach process

Define detection, assessment and escalation so the Commission can be notified within 72 hours and data subjects informed where the risk is high.

7

Plan the audit return

Where you are of major importance, schedule the compliance audit and engage a licensed DPCO in good time before the filing window.

Questions

Frequently asked

How do we know if we are of “major importance”?

Two routes lead to the designation. The first is volume, measured against the thresholds the Commission prescribes in the General Application and Implementation Directive. The second is significance, where the Commission designates a controller or processor because the data it handles matters to the economy, society or security of Nigeria. Sector is often decisive, so banks, fintechs, telecoms operators, hospitals and schools frequently qualify without being especially large.

Do we have to appoint a Data Protection Officer?

It is a specific obligation for data controllers and processors of major importance. Other organisations are not required to appoint one, though doing so is a practical way of discharging the accountability duties the Act imposes on everyone.

Is the NDPA just the GDPR for Nigeria?

The principles, bases, rights and breach mechanics are closely comparable, so a GDPR programme transfers well. The genuinely Nigerian layers are the major-importance designation with its registration and audit duties, the role of licensed Data Protection Compliance Organisations, the operational detail in the GAID, and a penalty cap calculated as the higher of a fixed sum or a percentage of turnover.

What is a DPCO?

A Data Protection Compliance Organisation is an entity licensed by the Nigeria Data Protection Commission to provide data protection compliance services, including carrying out audits and filing returns on behalf of controllers. The Commission publishes the list of licensed DPCOs, and engaging one is the usual route to the compliance audit filing.

How long do we have to report a breach?

Seventy-two hours from becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of individuals. Where the risk is high, the affected data subjects must also be told without undue delay, in clear language, with practical advice.

Does the old NDPR 2019 still matter?

The Act is now the governing instrument and the Commission established under it is the regulator. Work done under the 2019 regulation, particularly audit discipline and DPO structures, remains useful groundwork, but compliance should be assessed against the Act read together with the 2025 General Application and Implementation Directive.

Sources and scope. This guide summarises the Nigeria Data Protection Act 2023 and the NDPC General Application and Implementation Directive 2025 in original wording, citing section numbers as factual references only. It is general information, not legal advice, and reproduces no statutory text. Confirm the current position with the NDPC or Nigerian counsel before relying on it.
How we help

From applicability to evidence

We map your processing to this regime, build the controls behind the obligations, and prepare the evidence that proves compliance.

Start a conversation