Regulatory
Nigeria Data Protection Act: what your business must do
In short: If your business handles personal data about Nigerians, whether customers, staff, applicants or website visitors, the Nigeria Data Protection Act 2023 applies to you. It is enforced by the Nigeria Data Protection Commission (NDPC), and organisations above a defined processing scale have registration and annual audit obligations on top of the general duties.
What counts as personal data
Any information that identifies a living person, directly or with other data you hold: name, phone number, email, address, bank details, biometric data, a photograph, a device identifier, a customer number that can be tied back to a person.
Two terms decide your obligations:
- Data controller: you decide why and how the data is processed. Most businesses are controllers of their customer and staff data.
- Data processor: you process data on someone else's instructions. A payroll bureau or a hosting provider is typically a processor.
You can be both at once: a controller of your own staff data and a processor of a client's customer data. The obligations differ, so be clear which hat you are wearing for each dataset.
The duties that apply to everyone
Regardless of size:
- Have a lawful basis for every processing activity: consent, contract, legal obligation, vital interests, public interest or legitimate interest. Decide it before you start processing, and record it.
- Collect only what you need, and keep it only as long as you need it.
- Be transparent. A privacy notice that tells people what you collect, why, who you share it with, how long you keep it, and how to exercise their rights.
- Keep it secure, with measures proportionate to the risk.
- Honour data subject rights: access, correction, erasure, objection, portability, and withdrawal of consent, all within the statutory timeframe.
- Control your transfers, including sending data outside Nigeria, which requires an adequate legal basis.
- Report breaches to the NDPC, and to affected individuals where the risk requires it, within the statutory window.
Consent, done properly
Consent has to be freely given, specific, informed and unambiguous, and the person must be able to withdraw it as easily as they gave it.
In practice that rules out:
- Pre-ticked boxes.
- A single tick covering unrelated purposes at once.
- Burying permissions in terms and conditions nobody reads.
- Treating silence or continued use as agreement.
- Making a service conditional on consent you do not actually need for it.
If you rely on consent, you must be able to show when and how it was given. Log it.
Registration and annual audit
Organisations processing personal data above the thresholds set by the Commission must register as a data controller or processor of major importance, and file an annual compliance audit return prepared through a licensed compliance organisation.
Confirm your threshold position with the NDPC. It turns on the volume of data subjects and the nature of the data, and organisations regularly discover they are in scope. A modest company with a large customer database can be caught.
Appointing a Data Protection Officer
Organisations meeting the criteria must designate a DPO, someone with the knowledge to advise on compliance, monitor it, and act as the contact point for the Commission and for data subjects.
The role must be able to operate without conflict. Putting the person who owns the marketing database in charge of policing it does not work, and the Commission looks at independence.
Practical steps to get in order
- Build a data inventory. Every system holding personal data, what it holds, why, who can see it, where it is hosted, how long it is kept.
- Record a lawful basis for each processing activity.
- Publish a privacy notice that matches what your systems actually do, not a template describing a different business.
- Write a retention schedule and enforce it. Indefinite retention is a common finding.
- Paper your processors. A written agreement with anyone who processes data for you, covering security, sub-processing, breach notification and deletion.
- Check your transfers, including cloud hosting located outside Nigeria.
- Write a breach response procedure and rehearse it, because the reporting clock is short.
- Train the staff who touch personal data.
- Assess high-risk processing before launching it.
Where businesses are most exposed
- Marketing lists built without a lawful basis, and no record of consent.
- Staff data: recruitment records and CVs kept for years with no retention rule.
- Customer support inboxes and chat logs full of personal data nobody inventoried.
- Spreadsheets on personal laptops, outside every control you documented.
- Vendors with no data agreement, especially small suppliers and freelancers.
- CCTV and biometric attendance systems, which involve sensitive data and often have no notice at all.
Common mistakes
- Assuming it only applies to large companies.
- Copying another company's privacy notice.
- Relying on consent where a different basis would be both sounder and simpler.
- No retention schedule, so nothing is ever deleted.
- No written processor agreements.
- Discovering the breach reporting window after a breach.
- Naming a DPO on paper with no authority or time to act.
Verify before you rely on this
Registration thresholds, audit filing requirements, DPO criteria, breach reporting windows, transfer conditions and penalties are set and revised by the NDPC. Confirm the current position with the Commission or a licensed compliance organisation before acting. This guide is not legal advice.
