Law / Nigeria

Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Nigeria Data Protection Act, 2023 (No. 37 of 2023)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 12 June 2023.

A comprehensive regime rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Obtain a data subject's consent before any direct marketing activity, before processing sensitive personal data, before further processing that is incompatible with the original purpose, before processing a child's personal data, before transferring personal data to a country the Commission has not made an adequacy decision for, and before making a decision based solely on automated processing that produces legal effects concerning or significantly affects the data subject.
  • Notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and records concerned.
  • Notify affected data subjects immediately after becoming aware of a breach likely to result in a high risk to their rights and freedoms.
  • Before transferring personal data outside Nigeria, rely on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument, or another lawful basis such as consent or a compelling legal or fiduciary duty.
  • Give a data subject the right not to be subject to a decision based solely on automated processes or algorithms, and give effect to their rights to rectification, data portability, erasure, and lodging a complaint with the Commission.
  • Carry out a Data Privacy Impact Assessment where required, including where deploying software to process sensitive personal data, and file it with the Commission.

Who enforces it

Enforcement body

Nigeria Data Protection Commission (NDPC)

What it reaches

Obligation class

Consent, Breach notice, Transfer, Data subject rights, DPIA

Who checks it

Audit expectation

periodic

Who audits it

Self, Registered or designated auditor

Where the report goes

Filed with regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Nigeria Data Protection Act, 2023 sets Nigeria's general rules for processing personal data, enforced by the Nigeria Data Protection Commission (NDPC) it establishes.

Consent is required for direct marketing, for processing sensitive personal data, for further processing incompatible with the original purpose, for processing a child's personal data, before transferring personal data to a country the Commission has not made an adequacy decision for, and before a data controller makes a decision based solely on automated processing that produces legal effects concerning or significantly affects a data subject.

A data controller must notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and personal data records concerned. It must also notify affected data subjects immediately where the breach is likely to result in a high risk to their rights and freedoms.

Cross-border transfer of personal data proceeds on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument (a code of conduct, certification, binding corporate rules, or standard contractual clauses), or another lawful basis including the data subject's consent or a compelling legal or fiduciary obligation.

Data subjects hold a right not to be subject to a decision based solely on automated processes or algorithms, together with rights to rectification, data portability, erasure (a right described as the right to be forgotten), and lodging a complaint with the Commission.

A data controller or data processor of major importance, determined by the Commission by reference to the number of data subjects whose personal data it processes, must register with the Commission and file compliance audit returns.

When LexLint raises it

  • high_risk_decisions
  • automated_outreach

Read the law

General Application and Implementation Directive (GAID) 2025
an official regulatory instrument issued by the Nigeria Data Protection Commission under sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act, 2023, which quotes and implements the Act's provisions in detail a directly hosted copy of the Act's own gazetted text was not found among the sources reviewed

Back to the example  ·  Lint your app