With the passage of the Nigeria Data Protection Act 2023 (NDPA) and the active regulatory enforcement campaigns led by the Nigeria Data Protection Commission (NDPC), data privacy in Nigeria has evolved from voluntary corporate guidelines into an aggressively audited statutory obligation.
Organizations that process personal records—ranging from commercial banks, fintechs, and insurance carriers to telecommunications companies, retail chains, and private hospitals—now face severe financial penalties (up to ₦10,000,000 or 2% of annual gross revenue, whichever is greater) and potential personal criminal liability for corporate directors who fail to protect data subjects.
1. Are You a "Data Controller or Processor of Major Importance" (DCMI)?
Under Section 65 of the NDPA, the Commission categorizes organizations based on the sensitivity, volume, and commercial value of data processed. Organizations classified as DCMIs must fulfill heightened statutory duties:
- Mandatory Registration: Formal registration with the NDPC and payment of prescribed statutory fees.
- Designation of a Certified DPO: Appointing a dedicated Data Protection Officer with direct access to executive management.
- Annual Compliance Audit Filing: Engaging an accredited Data Protection Compliance Organization (DPCO) to audit operations and submit verified compliance returns to the Commission annually.
2. Establishing Lawful Bases for Processing
Under Section 25 of the Act, organizations cannot process personal data without establishing and documenting at least one of six recognized lawful bases:
| Lawful Ground | Legal Context | Practical Application in Business |
|---|---|---|
| Contractual Necessity | Processing is necessary to fulfill a contract with the data subject or take pre-contractual steps. | Onboarding a new client, processing salary payments, or fulfilling service delivery agreements. |
| Legal Obligation | Mandated by Nigerian statutory enactments or supervisory circulars. | KYC reporting to the Central Bank of Nigeria (CBN), tax filings with FIRS, or pension contributions. |
| Legitimate Interests | Pursuing commercial goals balanced against individual rights and expectations. | IT security log monitoring, external fraud prevention, and corporate network security. |
| Explicit Consent | Freely given, specific, informed, and unambiguous affirmative action. | Marketing communications, optional website tracking cookies, or biometric processing for non-statutory purposes. |
3. Data Protection Impact Assessments (DPIAs)
Section 28 of the NDPA mandates that whenever processing involves "high risk to the rights and freedoms of data subjects" by virtue of its nature, scope, context, or automated technologies, the controller must conduct a formal Data Protection Impact Assessment (DPIA) prior to launch.
Triggers that legally require a DPIA include:
- Deploying AI-driven automated credit scoring or risk profiling algorithms.
- Introducing facial recognition or biometric authentication in mobile apps or premises access.
- Migrating core customer databases to multi-tenant foreign cloud providers.
- Mass collection of children's data or sensitive biometric/financial information.
4. Strict 72-Hour Data Breach Notification Window
In the event of a security breach involving unauthorized access, exfiltration, or loss of personal data, the organization has exactly 72 hours from becoming aware of the incident to formally notify the NDPC. The notification must outline:
- The nature and estimated scale of the breach (number of records and categories).
- The name and contact details of the Data Protection Officer.
- Likely consequences and risks to the affected data subjects.
- Measures taken or proposed to contain the breach and mitigate its harmful impact.
5. Practical Action Plan for Corporate Compliance
To avoid enforcement notices and public sanctions from the Commission, leadership should execute five immediate actions:
- Build a Record of Processing Activities (RoPA): Document all data flows, databases, third-party vendor integrations, and retention periods.
- Update Public and Internal Privacy Notices: Ensure website privacy notices and employee handbooks reflect NDPA 2023 provisions.
- Execute Data Processing Agreements (DPAs): Ensure all third-party vendors and cloud software providers sign legally binding DPAs.
- Conduct Workforce Privacy Training: Train customer service, HR, and IT staff on handling data subject requests (SARs).
- Engage a Licensed DPCO: Retain a licensed Data Protection Compliance Organization to conduct your annual compliance audit.
About the ACE Privacy & Data Governance Practice
ACE ICT Consult provides end-to-end data protection advisory, DPIAs, DPO-as-a-service, and statutory annual audit filings. We help Nigerian enterprises achieve total compliance with the NDPA while streamlining digital operations.