07011011237  |  info@aceictconsult.comOffices in Abuja and Lagos, Nigeria
ACE ICT Consult logoACE ICT ConsultBook a Consultation

NDPA 2023 Compliance for Nigerian Businesses: What the Commission Expects

Navigating the statutory mandates of the Nigeria Data Protection Act 2023, avoiding costly regulatory sanctions, and embedding privacy into daily corporate operations.

Data Protection & Legal CompliancePublished: February 3, 20268 Min ReadBy ACE Privacy & Data Governance Practice

With the passage of the Nigeria Data Protection Act 2023 (NDPA) and the active regulatory enforcement campaigns led by the Nigeria Data Protection Commission (NDPC), data privacy in Nigeria has evolved from voluntary corporate guidelines into an aggressively audited statutory obligation.

Organizations that process personal records—ranging from commercial banks, fintechs, and insurance carriers to telecommunications companies, retail chains, and private hospitals—now face severe financial penalties (up to ₦10,000,000 or 2% of annual gross revenue, whichever is greater) and potential personal criminal liability for corporate directors who fail to protect data subjects.

1. Are You a "Data Controller or Processor of Major Importance" (DCMI)?

Under Section 65 of the NDPA, the Commission categorizes organizations based on the sensitivity, volume, and commercial value of data processed. Organizations classified as DCMIs must fulfill heightened statutory duties:

  • Mandatory Registration: Formal registration with the NDPC and payment of prescribed statutory fees.
  • Designation of a Certified DPO: Appointing a dedicated Data Protection Officer with direct access to executive management.
  • Annual Compliance Audit Filing: Engaging an accredited Data Protection Compliance Organization (DPCO) to audit operations and submit verified compliance returns to the Commission annually.

2. Establishing Lawful Bases for Processing

Under Section 25 of the Act, organizations cannot process personal data without establishing and documenting at least one of six recognized lawful bases:

3. Data Protection Impact Assessments (DPIAs)

Section 28 of the NDPA mandates that whenever processing involves "high risk to the rights and freedoms of data subjects" by virtue of its nature, scope, context, or automated technologies, the controller must conduct a formal Data Protection Impact Assessment (DPIA) prior to launch.

Triggers that legally require a DPIA include:

  • Deploying AI-driven automated credit scoring or risk profiling algorithms.
  • Introducing facial recognition or biometric authentication in mobile apps or premises access.
  • Migrating core customer databases to multi-tenant foreign cloud providers.
  • Mass collection of children's data or sensitive biometric/financial information.

4. Strict 72-Hour Data Breach Notification Window

In the event of a security breach involving unauthorized access, exfiltration, or loss of personal data, the organization has exactly 72 hours from becoming aware of the incident to formally notify the NDPC. The notification must outline:

  1. The nature and estimated scale of the breach (number of records and categories).
  2. The name and contact details of the Data Protection Officer.
  3. Likely consequences and risks to the affected data subjects.
  4. Measures taken or proposed to contain the breach and mitigate its harmful impact.

5. Practical Action Plan for Corporate Compliance

To avoid enforcement notices and public sanctions from the Commission, leadership should execute five immediate actions:

  1. Build a Record of Processing Activities (RoPA): Document all data flows, databases, third-party vendor integrations, and retention periods.
  2. Update Public and Internal Privacy Notices: Ensure website privacy notices and employee handbooks reflect NDPA 2023 provisions.
  3. Execute Data Processing Agreements (DPAs): Ensure all third-party vendors and cloud software providers sign legally binding DPAs.
  4. Conduct Workforce Privacy Training: Train customer service, HR, and IT staff on handling data subject requests (SARs).
  5. Engage a Licensed DPCO: Retain a licensed Data Protection Compliance Organization to conduct your annual compliance audit.

Need advice on meeting NDPA 2023 compliance requirements?

Speak to our certified data protection consultants today.

Book an NDPA Consultation