Nigeria Data Protection Act, 2023, data breach notification
Nigeria Data Protection Act, 2023, data breach notification (s. 40; GAID 2025, art. 33)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 12 June 2023.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and records concerned.
- Notify affected data subjects immediately after becoming aware of a breach likely to result in a high risk to their rights and freedoms.
- Give the Commission and every other relevant authority immediate information about a breach, whatever time you otherwise have, where that may help contain an imminent breach on a national scale, where containment may be needed nationally, sectorally or individually, or where the breach may affect the general public.
- Put in the notification the circumstances of the loss or unauthorised access or disclosure, the date or time period it occurred over, the personal information involved, an assessment of the risk of harm, an estimate of the number of individuals at real risk of significant harm, the steps you took to reduce that harm and to notify individuals, and the name and contact details of someone who can answer for you.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 33(1) quotes section 40(2) of the Act: a data controller shall, within 72 hours of becoming aware of a breach which is likely to result in a risk to the rights and freedoms of individuals, notify the Commission of the breach and, where feasible, describe its nature including the categories and approximate numbers of data subjects and personal data records concerned.
Article 33(2) fixes when a breach is likely to result in a high risk: where, considering its nature, the personal data involved and the probability of reaching the data subject's other personal data through it, the data subject may become a victim of fraud, identity theft or exposure of sensitive personal data. Article 33(3) requires the controller to notify affected data subjects immediately after becoming aware of the breach, so that they are not unlawfully targeted as a result of it.
Article 33(4) requires immediate information to the Commission and every other relevant authority, whatever the time otherwise allowed, where that may help contain an imminent breach on a national scale or where containment may be needed nationally, sectorally or individually, or where the breach may affect the general public.
Article 33(5) fixes the content of the notification: the circumstances of the loss or unauthorised access or disclosure, the date or time period it occurred over, a description of the personal information involved, an assessment of the risk of harm, an estimate of the number of individuals at real risk of significant harm, the steps taken to reduce that harm, the steps taken to notify individuals, and the name and contact details of a person who can answer for the organisation.
The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachoperates_essential_service
Read the law
General Application and Implementation Directive (GAID) 2025
an official regulatory instrument issued by the Nigeria Data Protection Commission under sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act, 2023, which quotes and implements the Act's provisions in detail a directly hosted copy of the Act's own gazetted text was not found among the sources reviewed
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.