What it is
The Nigeria Data Protection Act, 2023 (NDPA) is Nigeria's first national data protection statute. It was signed in June 2023 and sets out the rights of data subjects, the duties of organizations that handle personal data, and the powers of the regulator. It builds on the earlier Nigeria Data Protection Regulation (NDPR) of 2019, which was issued as subsidiary legislation and which the Act places on a statutory footing.
Who it applies to
The Act applies to processing of personal data by automated or other means. It covers controllers and processors that are domiciled, resident or operating in Nigeria, processing that takes place in Nigeria, and foreign controllers or processors that process the personal data of people in Nigeria. Purely personal or household processing is outside the scope, unless it violates a data subject's privacy rights. The Act gives special treatment to "data controllers and data processors of major importance", a category the Commission defines by reference to the volume, value or sensitivity of data processed.
Core principles
Personal data must be processed fairly, lawfully and transparently, collected for specified and legitimate purposes, and limited to what is necessary. It must also be accurate, kept no longer than needed, and protected with appropriate technical and organizational measures. Controllers and processors owe a duty of care and must be able to demonstrate accountability for these principles.
Legal bases
Processing is lawful where the data subject has given and not withdrawn consent, or where it is necessary for a contract, a legal obligation, the vital interests of a person, a task carried out in the public interest, or the legitimate interests of the controller or a third party. Legitimate interests cannot be relied on where they override the data subject's rights or where the person would not reasonably expect the processing. The controller bears the burden of proving consent, and sensitive personal data and children's data are subject to extra conditions.
Individual rights
Data subjects can obtain confirmation of processing and access to their personal data, and can have inaccurate data corrected and, in defined cases, erased or restricted. They may withdraw consent, object to processing (including for direct marketing), and challenge decisions made solely by automated means. The Act also provides a right to data portability and the ability to seek civil remedies for injury, loss or harm.
Key obligations
Controllers must complete a data privacy impact assessment where processing is likely to pose a high risk to individuals. Controllers of major importance must appoint a data protection officer and register with the Commission. The Commission's General Application and Implementation Directive (GAID), issued in 2025, adds detail on how the Act is applied. A breach likely to risk individuals' rights and freedoms must be reported to the Commission within 72 hours, and where the risk is high the data subjects must be told without delay.
International transfers
Personal data may be transferred out of Nigeria only if the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification that gives an adequate level of protection. Alternatively, one of the listed conditions applies, such as the data subject's consent, performance of a contract, or important reasons of public interest. Controllers must record the basis for each transfer, and the Commission can assess adequacy and issue guidelines on it.
Enforcement and penalties
The Nigeria Data Protection Commission (NDPC) enforces the Act. It can investigate complaints, issue compliance and enforcement orders, and order a penalty or remedial fee. For a controller or processor of major importance the maximum is the greater of 10 million naira and 2% of annual gross revenue in the preceding financial year. For others it is the greater of 2 million naira and 2% of annual gross revenue. Failing to comply with a compliance order is also an offence and can lead to a fine or imprisonment of up to one year.
The official text
The authoritative version is the Nigeria Data Protection Act, 2023, as published in the Federal Republic of Nigeria Official Gazette and made available by the Nigeria Data Protection Commission. The Act is in English. Use that text, not this summary, for anything that matters.
Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →