Back to Insights
Compliance

Data Protection Compliance for Nigerian Businesses: NDPA & NDPR

Faruk A OlasodeJuly 21, 20266 min read

The Nigeria Data Protection Act, 2023 (NDPA) gives statutory force to Nigeria's data protection regime and establishes the Nigeria Data Protection Commission (NDPC). Together with the Nigeria Data Protection Regulation (NDPR) which preceded it, the NDPA now applies to any person or entity that processes the personal data of individuals in Nigeria — whether you are a bank, a hospital, an e-commerce store or a firm of lawyers.

Who Must Comply

If your organisation collects, stores, uses or shares personal data — customer names, phone numbers, email addresses, biometric data, health records — you are a data controller or processor under the Act. Foreign companies that process the personal data of Nigerians may also be caught by the Act's extraterritorial reach.

Core Obligations

  • Obtain a lawful basis — usually consent — before processing personal data
  • Provide a clear and accessible privacy notice to data subjects
  • Collect only the minimum data necessary for your stated purpose
  • Implement appropriate technical and organisational security measures
  • Register as a data controller with the NDPC
  • Appoint a Data Protection Officer where your processing is significant
  • Conduct Data Protection Impact Assessments for high-risk processing
  • Notify the Commission of breaches that put data subjects at risk
Consent is not a checkbox. It must be freely given, specific, informed and unambiguous — and it can be withdrawn.

Penalties for Non-Compliance

The NDPA empowers the Commission to impose administrative fines on data controllers and processors of up to 2% of annual gross revenue or ten million naira, whichever is greater. Beyond the headline fines, a data breach can cost you customers, contracts and standing in ways no regulator can quantify.

Practical Steps to Compliance

  • Audit the personal data you hold and the flows it travels through
  • Draft or update your privacy policy and consent mechanisms
  • Train staff on handling personal data and recognising breaches
  • Execute data processing agreements with vendors and third parties
  • Put a breach response plan in place before you need one

How We Can Help

We help businesses of every size map their data flows, draft compliant policies and contracts, register with the NDPC, and respond to regulator inquiries. A few focused hours of compliance work today is far cheaper than a penalty notice tomorrow.

Need guidance on this?

Every matter is different. Speak directly with an attorney at Kayyen LP about your situation — in confidence, and without obligation.

Book a Consultation
Continue Reading