Nigeria Data Protection Act 2023
Nigeria
In force since 2023
The NDPA was signed into law on 12 June 2023, replacing the former Nigeria Data Protection Regulation (NDPR) as the central statutory framework for data protection in Nigeria.
Asia & Africa
Nigeria
Nigeria Data Protection Act 2023
NDPA / NDP Act
2023
Nigeria Data Protection Commission (NDPC)
One lawful basis; not universally required
Required
Yes
Required
Required in specified circumstances
Generally within 30 days
Required in circumstances prescribed by the Act and GAID
Required where applicable to processing
Required where applicable
Applies to designated Data Controllers and Processors of Major Importance
Regulated
In force
The NDPA can apply to organisations that are domiciled in Nigeria, are resident in Nigeria, operate in Nigeria, process personal data in Nigeria, or are outside Nigeria but process personal data relating to data subjects in Nigeria. The NDPC's official FAQ confirms that the Act can apply to an organisation outside Nigeria when it processes personal data of a data subject in Nigeria. Potentially affected organisations include Nigerian companies, international companies serving Nigerian users, e-commerce platforms, banks and fintech companies, insurance providers, healthcare organisations, universities and schools, telecommunications businesses, technology companies, SaaS providers, marketing and advertising businesses, employers, government bodies, professional-service organisations, digital platforms and data analytics companies.
Section 48 establishes different maximum penalty levels depending on whether the organisation is a Data Controller or Processor of Major Importance. The NDPC states that for a DCPMI, the penalty or remedial fee can be up to the greater of NGN 10 million or 2% of annual gross revenue in the preceding financial year. For organisations that are not of major importance, the NDPC states that the standard maximum can be the greater of NGN 2 million or 2% of annual gross revenue in the preceding financial year. These are statutory maximum frameworks rather than an automatic fine for every violation, and the actual regulatory outcome depends on the applicable circumstances and enforcement provisions.
Consent is an important lawful basis under the NDPA, but it is not the only lawful basis for processing personal data. Organisations should identify the appropriate legal basis for each processing activity rather than treating consent as universally mandatory.
The Nigeria Data Protection Act 2023 establishes Nigeria's modern statutory framework for personal-data protection.
Its objectives include:
The NDPC was established under the Act to supervise and regulate data protection and privacy in Nigeria.
The NDPC's current materials confirm that the NDPA applies broadly to organisations processing personal data connected with Nigeria and provides rights including access, rectification, objection, restriction, portability, erasure and rights concerning automated decision-making.
The NDPA regulates the processing of personal data relating to natural persons.
Personal data can include information such as:
The exact treatment of a particular data element depends on whether it falls within the statutory definition of personal data and the context in which it is processed.
The NDPA defines processing broadly.
Processing can include:
The NDPC confirms that the definition covers processing whether or not it is carried out through automated means.
Organisations processing personal data should operate according to the core principles established by the NDPA.
Lawfulness, fairness and transparency. Personal data should be processed lawfully, fairly and transparently.
Purpose limitation. Personal data should be collected and used for specified, explicit and legitimate purposes.
Data minimisation. Organisations should avoid collecting personal data that is unnecessary for the relevant purpose.
Accuracy. Personal data should be accurate and kept up to date where necessary.
Storage limitation. Personal data should not be retained longer than necessary for the applicable purpose or legal obligation.
Integrity and confidentiality. Appropriate security measures should protect personal data against unauthorised access, loss, destruction or other unlawful processing.
Accountability. Organisations should be able to demonstrate compliance with applicable data-protection requirements.
The NDPC's 2025 GAID also incorporates assessments of data-protection principles, lawful bases, DPIAs, legitimate interests, data-subject rights, security, international transfers and breach notification into its compliance framework.
Not for every processing activity.
Consent is an important lawful basis under the NDPA, but organisations should first determine which lawful basis applies to the processing activity.
Depending on the circumstances, processing may be supported by grounds such as:
The NDPC's current materials specifically recognise consent as an important component of data protection while also recognising lawful processing in circumstances where consent is not the applicable basis.
Where consent is relied upon, organisations should ensure that it is:
Consent should involve a meaningful choice for the data subject.
Organisations should avoid:
A properly designed consent-management platform can help operationalise these requirements.
Where consent is the applicable legal basis, organisations should provide an accessible mechanism for withdrawing consent.
A consent-management system should allow organisations to:
ConsentX can provide the technical infrastructure for these workflows.
The NDPA provides additional protections for certain categories of personal data.
Organisations handling sensitive information should apply appropriate safeguards and carefully assess:
Sensitive-data processing should receive additional governance attention because the potential impact of misuse or compromise can be significant.
Transparency is a core requirement of the NDPA.
A privacy notice should explain relevant information about the processing activity, including where applicable:
Privacy notices should be presented at appropriate points in the user journey.
A cookie banner should not be treated as a substitute for a comprehensive privacy notice.
Cookies and online tracking technologies should be assessed based on the personal-data processing they perform.
Organisations should determine:
Examples include:
Where consent is the appropriate lawful basis, ConsentX can help collect and enforce that consent before applicable trackers execute.
The NDPC identifies a range of rights under Sections 34 to 38 of the Act.
These include:
Organisations should have operational procedures for receiving, verifying, assessing and responding to these requests.
Data subjects can request access to personal data held about them and information concerning its processing.
The NDPC itself provides a Data Subject Access Request form and states that it aims to respond promptly and, in any event, within 30 days of receiving the request or required additional information.
Organisations should therefore implement workflows that:
Data subjects may have the right to request correction of inaccurate or incomplete personal data.
Organisations should maintain procedures to:
In applicable circumstances, data subjects can request deletion or erasure of personal data.
Organisations should maintain processes for identifying:
Erasure should therefore be incorporated into broader data-lifecycle governance.
The NDPC identifies data portability as one of the rights available to data subjects under the NDPA.
Organisations should consider how they can:
Data subjects may have rights to object to or restrict certain forms of processing.
Organisations should maintain mechanisms for:
The NDPC identifies a data-subject right relating to automated decision-making.
This is increasingly relevant for organisations using:
Organisations using automated decision systems should assess transparency, lawful basis, data-subject rights, fairness and risk.
The NDPA compliance framework includes Data Protection Impact Assessments where applicable.
The 2025 GAID expressly includes assessment of the need for a DPIA as part of the compliance framework.
A DPIA can help organisations evaluate processing that may create significant privacy risks.
A DPIA may examine:
Organisations should determine whether a DPIA is required based on the nature and risk of the processing rather than treating it as a universal requirement for every activity.
The NDPC's 2025 GAID expressly refers to Legitimate Interest Assessments (LIA) where applicable.
An LIA can help an organisation assess whether legitimate interest is an appropriate lawful basis.
A typical assessment can consider:
Organisations should document the assessment and review it when the processing changes.
The NDPA establishes requirements concerning Data Protection Officers.
DPO responsibilities can include:
The 2025 GAID provides additional requirements around DPO credential assessment and certification.
Organisations should determine whether their circumstances require a DPO and ensure that the appointed person has appropriate competence and independence for the role.
The NDPA distinguishes between data controllers and data processors.
A data controller determines the purposes and means of processing personal data. Examples include:
A data processor processes personal data on behalf of a controller. Examples include:
Controllers should maintain appropriate oversight of processors and establish appropriate contractual and security controls.
The NDPA provides for the designation and registration of Data Controllers and Data Processors of Major Importance (DCPMIs).
Current NDPC registration guidance states that an organisation may be considered of major importance based on factors including processing more than 200 data subjects in six months, providing certain commercial ICT services involving storage of personal data, or operating in specified sectors.
The current guidance also identifies sectors including:
Because the NDPC's designation framework can depend on the specific activity and applicable regulatory guidance, organisations should assess their current status against the latest NDPC requirements.
Data controllers and processors that fall within the applicable major-importance registration framework may be required to register with the NDPC.
Registration requirements can involve:
The NDPC currently provides registration services for Data Controllers and Processors of Major Importance.
The NDPC requires applicable organisations to participate in compliance processes established under the Act and its regulatory framework.
The Commission states that certain DCPMIs are subject to Compliance Audit Returns (CAR) requirements.
The NDPC also states that CAR filings are submitted through a Licensed Data Protection Compliance Organisation (DPCO) where applicable.
Organisations should therefore distinguish between:
These are related but distinct compliance activities.
The NDPA provides for licensed Data Protection Compliance Organisations.
DPCOs can provide services including:
The NDPC states that filings by data controllers under the Act may require a DPCO verification statement where applicable.
ConsentX can complement professional compliance services by providing technical consent, tracker and privacy-management infrastructure.
Data controllers and processors must implement appropriate security measures.
Security programmes should address areas such as:
The NDPA treats security as a core part of data protection rather than a separate technical issue.
The NDPA establishes obligations concerning personal-data breaches.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the Commission within 72 hours of becoming aware of the breach.
The breach framework also addresses notification to affected data subjects where appropriate.
Organisations should maintain a documented incident-response process covering:
The NDPA regulates transfers of personal data outside Nigeria.
Organisations transferring personal data internationally should assess:
The 2025 GAID specifically includes assessment of the legal grounds for cross-border data transfers as part of compliance activities.
International organisations should therefore include Nigeria in their broader transfer-governance framework.
Organisations should establish appropriate retention periods based on:
Once personal data is no longer required and there is no legal reason to retain it, organisations should implement appropriate deletion, destruction or anonymisation procedures.
A documented retention schedule can help demonstrate accountability.
Organisations processing children's personal data should apply additional care and consider:
Children's data can create heightened privacy and safety risks, particularly in online services, education, gaming, social platforms and advertising.
Marketing activities can involve extensive personal-data processing.
Examples include:
Organisations should identify the applicable lawful basis and ensure that the processing is consistent with transparency and data-subject rights.
Where consent is the applicable basis, the consent should be appropriately captured and recorded.
Privacy should be incorporated into systems and processes from the beginning.
A privacy-by-design programme can include:
The NDPC has also published materials promoting privacy by design in innovation and digital environments.
The NDPC is responsible for supervising and enforcing the Nigeria Data Protection Act.
The Commission can investigate potential violations and apply regulatory measures.
Consequences of non-compliance can include:
The NDPC states that data subjects may also bring civil actions concerning violations of their rights.
Section 48 establishes different maximum penalty levels depending on whether the organisation is a Data Controller or Processor of Major Importance.
The NDPC states that for a DCPMI, the penalty or remedial fee can be up to the greater of NGN 10 million or 2% of annual gross revenue in the preceding financial year.
For organisations that are not of major importance, the NDPC states that the standard maximum can be the greater of NGN 2 million or 2% of annual gross revenue in the preceding financial year.
These are statutory maximum frameworks rather than an automatic fine for every violation. The actual regulatory outcome depends on the applicable circumstances and enforcement provisions.
Use this checklist to assess your organisation's readiness.
Privacy compliance for a modern website involves more than publishing a privacy policy.
A website may contain:
Without visibility and control, these technologies can create privacy risks.
A consent-management platform can help organisations discover → categorise → obtain consent → block → record → manage preferences → demonstrate evidence.
ConsentX brings these controls together for organisations operating across multiple privacy jurisdictions.
Identify cookies, scripts, pixels and tracking technologies operating across your website.
Collect and manage consent where consent is the applicable lawful basis.
Separate consent choices according to relevant purposes rather than relying on a single blanket choice.
Prevent applicable non-essential technologies from executing before the required consent signal is obtained.
Maintain records of consent choices, timestamps and relevant consent context.
Allow users to revisit and change applicable privacy preferences.
Apply different privacy and consent experiences according to configured jurisdictional requirements.
Support workflows for access, deletion, rectification, objection, portability and related requests.
Maintain evidence of privacy interactions and consent decisions.
Build a more transparent and auditable privacy experience for users in Nigeria. With ConsentX, organisations can scan websites for cookies and trackers, configure NDPA-aware consent experiences, block applicable technologies before consent, capture and document consent, manage privacy preferences, support data-subject requests, maintain consent evidence, apply regional privacy rules and improve privacy governance across digital properties. ConsentX helps turn privacy requirements into operational controls.
No technology platform by itself can make an organisation fully legally compliant. ConsentX can support technical controls including consent management, cookie and tracker governance, prior-script blocking, consent evidence, preference management and data-subject request workflows. NDPA compliance also requires legal, organisational and security measures beyond a consent-management platform. This page provides general information about the Nigeria Data Protection Act 2023 and is not legal advice. Organisations should review the current legislation and NDPC guidance and obtain qualified Nigerian legal advice where appropriate.
Run a ConsentX scan to identify cookies, trackers, scripts and third-party technologies. This creates visibility into what technologies may process or transmit information.
Classify trackers according to their purpose, such as:
Do not assume that every processing activity requires consent. For each processing activity, determine whether consent or another lawful basis applies.
Where consent is required, configure a clear and purpose-specific consent interface.
Prevent applicable non-essential scripts from executing until the required consent signal has been received.
Maintain evidence showing:
Give users an accessible mechanism to change applicable consent preferences.
Use structured workflows to track:
Keep appropriate records demonstrating how consent and privacy controls operate.
The applicable framework depends on factors such as where the organisation operates, where data subjects are located, the nature of the processing and whether information is transferred internationally.