Data has become one of the most valuable assets for Nigerian businesses. Whether you run a bank, hospital, logistics company, fintech, e-commerce platform, school, or small online business, you almost certainly collect and process personal information daily. Customer names, phone numbers, email addresses, delivery addresses, employee records, bank account details, photographs, and even IP addresses all qualify as personal data under Nigerian law.
Many Nigerian business owners assume data protection laws only apply to large tech companies. This is a common misconception. If your business collects, stores, uses, shares, or processes the personal data of individuals in Nigeria, you must comply with the Nigeria Data Protection Act, 2023 (NDPA).
Consider a fintech collecting Bank Verification Numbers (BVNs) and account details, a logistics company storing customers’ delivery addresses and phone numbers, or an e-commerce platform like Jumia or Konga maintaining purchase histories. All of these businesses fall within the Act’s scope. The law also applies to foreign companies like Temu, where they process the personal data of individuals in Nigeria, even though they are located in China.
The NDPA, administered by the Nigeria Data Protection Commission (NDPC), empowers the Commission to investigate data breaches, conduct compliance audits, issue enforcement notices, and impose penalties for violations. Depending on the nature and severity of the breach, non-compliant businesses may face fines or other regulatory sanctions.
Who is a Data Controller, Data Processor and Data Subject?
Before discussing the compliance obligations under the Nigeria Data Protection Act (NDPA) 2023, it is important to understand the key parties regulated by the Act.
Under Section 65 of the NDPA, a data controller is any individual, organisation, public authority, or other body that determines the purpose and means of processing personal data. In simple terms, it is the person or organisation that decides why personal data is collected and how it will be used. For example, a bank that collects customers’ BVNs and account information for account management is acting as a data controller.
A data subject is the identifiable individual to whom the personal data relates, such as a customer, employee, patient, student, or job applicant. The Act grants data subjects several rights, including the rights to be informed, access their personal data, request correction or deletion, and object to certain processing activities.
The Act also defines a data processor in Section 65 as a person or organisation that processes personal data on behalf of a data controller. Examples of data processors include cloud storage providers like Google Cloud, payroll service providers, human resource outsourcing firms, payment processors, etc. While processors have their own compliance obligations, the data controller bears the primary responsibility for ensuring that personal data is processed lawfully and in accordance with the NDPA.
Data Privacy Compliance Requirements for Nigerian Companies
Below are the major compliance obligations every Nigerian business should understand under the NDPA. In no particular order;
1. Every Data Processing Activity must have a Legal Basis
The NDPA does not allow businesses to collect or process personal information simply because it might be useful. Every processing activity must rest on one of the lawful bases set out in Section 25 of the Act.
These lawful bases include:
- Consent of the data subject;
- Performance of a contract;
- Compliance with a legal obligation;
- Protection of an individual’s vital interests;
- Performance of a task carried out in the public interest; and
- Legitimate interests pursued by the data controller or a third party, provided these interests do not override the rights and freedoms of the individual.
Many businesses rely heavily on consent, but consent under the NDPA is subject to strict conditions. It must be freely given, specific, informed, and unambiguous. Pre-ticked boxes, hidden consent clauses, or vague statements buried in lengthy terms and conditions will not satisfy the Act’s requirements. Individuals must also be able to withdraw consent as easily as they gave it.
Businesses should therefore review every point where they collect personal information from websites, mobile apps, customer registration forms, employee onboarding documents, and vendor agreements, and confirm the lawful basis behind each processing activity.
2. Publish a Clear and Transparent Privacy Policy
Transparency is one of the core principles of the NDPA. Individuals have the right to know what personal information is collected about them, why it is collected, how it will be used, and who it will be shared with.
Section 27 of the Act requires data controllers to provide this information through a clear, accessible privacy notice or policy. A compliant Privacy Policy must contain:
- Identity of the business including the name, physical address, and contact details of the data controller.
- The specific, legitimate reasons for collecting the personal data.
- The exact types and categories of personal data collected (e.g., names, emails, financial records).
- Who the data will be shared with (e.g., third-party processors, partners, or regulators).
- The legal justification for processing, such as consent, contractual necessity, or legitimate interests.
- An outline of the data subject rights guaranteed under the NDPA, including access, rectification, deletion, and data portability.
- A clear explanation of how individuals can withdraw consent at any time, without penalty.
- How long the data will be stored and the criteria used to determine this timeframe.
- Channels through which individuals can raise complaints or inquiries about their data privacy or seek redress.
Unfortunately, many Nigerian businesses simply copy generic privacy policies from the internet without tailoring them to their actual operations. The NDPC expects privacy notices to be written in plain, understandable language rather than technical legal jargon. A compliant Privacy Policy must accurately reflect how the business actually handles personal data, and should be reviewed regularly to stay compliant with the law.
3. Register as a Data Controller or Processor of Major Importance
Not every business is required to register with the NDPC. However, organizations that qualify as Data Controllers or Data Processors of Major Importance (DCPMIs) are required to register with the Commission.
Businesses that process data of more than 200 data subjects within 6months, or operate in sectors including banks, fintech companies, telecommunications providers, logistics, insurance companies, hospitals, educational institutions, and digital platforms must register.
Organizations that fail to meet these registration and governance requirements face strict regulatory sanctions, including fines of up to ₦10 million or 2% of annual gross revenue. Businesses should assess whether they fall within this category to avoid regulatory exposure.
4. Appoint a Data Protection Officer (DPO)
Under Section 32 of the NDPA, organizations whose core activities involve the large-scale processing of sensitive personal data must appoint and designate a qualified DPO to oversee privacy practices and liaise with the Nigeria Data Protection Commission (NDPC).
A DPO oversees compliance with the Act, advises management on data protection obligations, monitors internal compliance, conducts staff awareness programmes, and serves as the organization’s liaison with the NDPC.
Smaller businesses may not immediately fall within these categories, but appointing someone to oversee privacy compliance is good corporate governance and helps reduce compliance risk as the business grows.
5. Conduct Data Protection Impact Assessments (DPIAs)
Some processing activities carry a higher risk to individuals’ privacy rights. In such situations, the NDPA requires organizations to carry out a Data Protection Impact Assessment (DPIA) before commencing the processing activity. A DPIA helps an organization identify potential privacy risks, evaluate the impact of those risks, implement measures to reduce or eliminate them, and demonstrate compliance with the Act.
A DPIA may be required, for example, when an organization introduces facial recognition technology, processes large volumes of biometric data, conducts large-scale monitoring of individuals, processes sensitive health information, or deploys new technologies that significantly affect people’s privacy. Conducting DPIAs before launching high-risk projects helps businesses identify compliance issues early and avoid costly regulatory consequences later.
6. Secure Personal Data and Report Data Breaches Within 72 Hours
The NDPA requires organizations to put in place technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, loss, or destruction. These security measures may include encryption, access controls, secure passwords, regular system updates, employee training, and internal security policies.
Where a breach is likely to put individuals’ rights and freedoms at risk, Section 40 of the NDPA requires organizations to notify the NDPC within 72 hours of becoming aware of it. Where the breach poses a high risk to affected individuals, the organization must also notify those individuals without undue delay. It is best to have a documented incident response plan in place before a breach occurs, given the short 72-hour timeline for investigation and regulatory reporting.
7. Conduct Annual Protection Audits
The NDPA and the NDPC’s regulations require many organizations that process significant volumes of personal data to carry out annual data protection compliance audits. Generally, organizations that process the personal data of more than 2,000 data subjects within 12 months must file annual audit reports with the NDPC.
These audits assess whether an organization’s data protection practices comply with the Act and help identify areas that need improvement. More importantly, the audits must be conducted through licensed Data Protection Compliance Organizations (DPCOs) accredited by the NDPC. Engaging a licensed DPCO ensures that the audit meets regulatory standards and that the required reports are properly submitted.
Are There Penalties for Non-Compliance with Data Privacy?
Yes, there are. The NDPC has extensive enforcement powers under the NDPA. Where an organization fails to comply with the Act, the Commission may investigate complaints, conduct compliance audits, issue enforcement notices, direct the organization to stop unlawful processing activities, require corrective measures, and impose significant administrative penalties.
Depending on the seriousness of the breach, penalties may reach ₦10,000,000 or 2% of the organization’s annual gross revenue, whichever is higher. Beyond financial penalties, organizations may also suffer reputational damage, loss of customer confidence, disruption to business operations, and possible civil claims from affected individuals.
Conclusion
The Nigeria Data Protection Act 2023 has made data protection a legal obligation, not just good business practice. Any organization that collects, stores, or processes personal data in Nigeria must comply with its requirements. However, compliance goes beyond publishing a privacy policy as you have learnt above.
As digital transactions continue to grow in Nigeria, organizations that prioritize data protection will reduce regulatory risk and build stronger customer trust. If you would like to know more about data privacy compliance or need legal advice on bringing your organization into compliance with the NDPA, schedule a consultation with the law firm today.





















Leave a Reply