The Nigeria Data Protection Act 2023 (NDPA) is Nigeria's principal data protection legislation, replacing the Nigeria Data Protection Regulation 2019. With the General Application and Implementation Directive (GAID) taking effect in September 2025, organisations processing personal data in Nigeria or of Nigerian residents are now operating under a fully consolidated regulatory framework.
Who does the NDPA apply to?
The NDPA applies to any organisation that processes the personal data of individuals in Nigeria, regardless of where the organisation is established. This extraterritorial scope mirrors the GDPR: a company based in Europe that targets Nigerian users, monitors the behaviour of individuals located in Nigeria, or processes Nigerian citizens' data for commercial purposes falls within scope.
Within Nigeria, the Act covers all organisations – private companies, government agencies, non-profits, and religious organisations – that collect, process, or store personal data.
What are the key compliance obligations?
The NDPA establishes obligations familiar from the GDPR but with Nigeria-specific requirements that organisations must address separately.
Registration: All Data Controllers and Processors of Major Importance must register with the Nigeria Data Protection Commission (NDPC). Registration thresholds are based on processing volume, data sensitivity, and sector. Financial services, healthcare, and telecommunications organisations must register regardless of size. Registration must be renewed annually.
Lawful basis: Processing must rest on one of six lawful grounds: consent, contractual necessity, legal obligation, vital interests, public interest, or legitimate interests. Consent requirements are strict – freely given, specific, informed, and unambiguous. The GAID clarifies that explicit consent is required for direct marketing, children's data, sensitive personal data, automated decision-making, and cross-border transfers.
Annual compliance audit: Data Controllers and Processors of Major Importance are required to file a Compliance Audit Return (CAR) annually. Under the GAID, only Ultra-High Level (UHL) and Extra-High Level (EHL) entities must file through a licensed Data Protection Compliance Organisation (DPCO). The deadline under GAID is 31 March each year. Late filing attracts a penalty fee.
Data Protection Officer: Organisations classified as Data Controllers of Major Importance must designate a DPO with expert knowledge of data protection law. The DPO monitors compliance, handles data subject access requests, and serves as the primary liaison with the NDPC. The GAID requires DPOs to hold recognised certification, assessed annually by the NDPC.
Breach notification: Organisations must notify the NDPC within 72 hours of becoming aware of a breach that poses a high risk to individuals. Affected individuals must also be notified without undue delay where a high risk is present.
Cross-border transfers: Transfers of personal data outside Nigeria are only permitted where the destination country or organisation provides adequate protection. For sensitive personal data, explicit consent is additionally required.
What enforcement action has the NDPC taken?
The NDPC has demonstrated a willingness to impose substantial penalties. Fines of ₦766.2 million were imposed against Multichoice Nigeria and $220 million against Meta Platforms. In 2025, Kenyan data subjects collectively received over KES 30 million in compensation – a signal of the enforcement direction across the region. Nigerian enforcement has followed a similar trajectory.
What this means for your organisation
- If you offer goods or services to individuals in Nigeria, process Nigerian citizens' data, or have operations in Nigeria, the NDPA applies to you regardless of where you are established.
- The GAID came into effect in September 2025. Organisations that have not updated their compliance programmes to reflect the GAID are operating against an outdated framework.
- The annual CAR filing deadline is 31 March. Missing this deadline attracts a penalty fee and signals non-compliance to the NDPC.
- The NDPC has demonstrated willingness to impose substantial fines. Non-compliance is not a theoretical risk.
What you should do now
- Determine whether your organisation meets the threshold for classification as a Data Controller or Processor of Major Importance under the updated GAID guidance.
- Register with the NDPC if not already registered. Registration must be renewed annually.
- Appoint a DPO with appropriate data protection expertise and ensure they hold or are pursuing NDPC-recognised certification.
- Engage a licensed DPCO to conduct your compliance audit and file your annual CAR by 31 March.
- Review cross-border transfer arrangements – transfers of personal data outside Nigeria require adequate safeguards, and explicit consent is additionally required for sensitive personal data.
How Priventia helps
Priventia's Regulatory Intelligence layer covers NDPA and GAID obligations, mapping them against GDPR to surface additional or stricter requirements for organisations operating across both jurisdictions. The Compliance Intelligence Assessment produces a prioritised remediation roadmap specific to your Nigerian compliance posture.