Nigeria Data Protection Act, 2023, cross-border data transfer
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 12 June 2023.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Before transferring personal data outside Nigeria, rely on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument, or another lawful basis such as consent or a compelling legal or fiduciary duty.
- Obtain the data subject's consent before transferring their personal data to a country for which the Commission has made no adequacy decision.
- Where you rely on an approved instrument rather than an adequacy decision, use one of the four the Commission recognises: a code of conduct, a certification, binding corporate rules, or standard contractual clauses.
- File the cross-border transfer instrument the Commission approved for you as part of your evidence of compliance.
What it reaches
Obligation class
Transfer
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 45 states that Part VIII of the Act provides for cross-border data transfer and, by section 63, is the overarching governing provision for every transfer of personal data out of Nigeria; pending any further regulatory instrument, the explanatory note in Schedule 5 is used to evaluate countries for adequacy and for the other grounds the Act recognises, and the Commission is to weigh the enforcement of fundamental rights and the decisions of courts advancing fundamental freedoms in a jurisdiction it considers.
Schedule 5 lists the grounds for transfer as an adequacy decision by the Commission, a Cross-Border Data Transfer Instrument the Commission approves, and other lawful bases, and sets out what the Commission weighs in adjudging a country adequate under section 42(2) of the Act: enforceable data subject rights with administrative or judicial redress and the rule of law, any instrument between the Commission and a competent authority in the recipient jurisdiction, the terms on which a public authority there reaches personal data, the existence of an effective data protection law that is in force and not subject to an overriding law, and a functioning independent supervisory authority with adequate enforcement powers.
The instruments the Commission may approve in the absence of an adequacy decision are codes of conduct, certifications, binding corporate rules and standard contractual clauses. Consent is separately required before personal data may be transferred to a country for which the Commission has made no adequacy decision.
The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
General Application and Implementation Directive (GAID) 2025
an official regulatory instrument issued by the Nigeria Data Protection Commission under sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act, 2023, which quotes and implements the Act's provisions in detail a directly hosted copy of the Act's own gazetted text was not found among the sources reviewed
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.