Law / Nigeria

Nigeria

4 of 9 named instruments researched to a stage, across four of the six areas of law we track: 4 in force. As of 5 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (201 words)

Nigeria's comprehensive personal-data regime is the Nigeria Data Protection Act, 2023 (No. 37 of 2023), enforced by the Nigeria Data Protection Commission (NDPC) and implemented in detail by the NDPC's General Application and Implementation Directive (GAID) 2025.

The Act requires consent for processing sensitive personal data, for further processing incompatible with the original purpose, for transferring personal data to a country the Commission has not made an adequacy decision for, and before a data controller makes a decision based solely on automated processing that produces legal effects concerning a data subject.

A data controller must notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, and must notify affected data subjects immediately where the breach is likely to result in a high risk.

Cross-border transfer proceeds on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument such as binding corporate rules or standard contractual clauses, or another lawful ground including consent or a compelling legal or fiduciary duty. Data subjects hold rights to rectification, data portability, erasure (described as a right to be forgotten), and lodging a complaint with the Commission.

Comprehensive regime

Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Nigeria Data Protection Act, 2023 (No. 37 of 2023)General Application and Implementation Directive (GAID) 2025

In force since 12 June 2023. Binds public and private bodies.

What this law does

The Nigeria Data Protection Act, 2023 sets Nigeria's general rules for processing personal data, enforced by the Nigeria Data Protection Commission (NDPC) it establishes.

Consent is required for direct marketing, for processing sensitive personal data, for further processing incompatible with the original purpose, for processing a child's personal data, before transferring personal data to a country the Commission has not made an adequacy decision for, and before a data controller makes a decision based solely on automated processing that produces legal effects concerning or significantly affects a data subject.

A data controller must notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and personal data records concerned. It must also notify affected data subjects immediately where the breach is likely to result in a high risk to their rights and freedoms.

Cross-border transfer of personal data proceeds on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument (a code of conduct, certification, binding corporate rules, or standard contractual clauses), or another lawful basis including the data subject's consent or a compelling legal or fiduciary obligation.

Data subjects hold a right not to be subject to a decision based solely on automated processes or algorithms, together with rights to rectification, data portability, erasure (a right described as the right to be forgotten), and lodging a complaint with the Commission.

A data controller or data processor of major importance, determined by the Commission by reference to the number of data subjects whose personal data it processes, must register with the Commission and file compliance audit returns.

What it requires

Scraping law1 instrument, 1 in force

Research summary (252 words)

Nigeria has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 criminalises intentionally accessing a computer system or network without authorisation, but section 6(1)'s offence is conditioned on the access being for a fraudulent purpose and obtaining data vital to national security, so a plain reading does not reach ordinary scraping of a public, unauthenticated page absent that fraud and national-security element, and no reported Nigerian case has tested the provision against a scraper.

No Nigerian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act, 2022 permits fair dealing for private use, non-commercial research and private study, criticism, review, or the reporting of current events, and separately excepts news of the day for public broadcast or other public communication, but Nigeria has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general fair-dealing ground if it can be characterised as non-commercial research.

The Copyright Act confers no sui generis database right, and its related rights cover performers, sound recordings, broadcasts, and expressions of folklore, not databases as such. The Nigeria Data Protection Act, 2023 applies to processing personal data generally, and does not appear to state a general exemption for personal data a data subject has made publicly available.

No Nigerian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, unlawful access to a computer

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, s. 6 (unlawful access to a computer)Cybercrimes (Prohibition, Prevention, etc.) Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.cert.gov.ng/ngcert/resources/CyberCrime__Prohibition_Prevention_etc__Act__2015.pdf

In force. Binds public and private bodies.

What this law does

Section 6(1) makes it an offence for any person, without authorisation, to intentionally access in whole or in part a computer system or network for a fraudulent purpose and to obtain data vital to national security, punishable by imprisonment for not more than five years or a fine of not more than N5,000,000, or both.

Section 6(2) raises the penalty to imprisonment for not more than seven years or a fine of not more than N7,000,000, or both, where the access is committed with the intent of obtaining computer data, securing access to a program, or obtaining commercial, industrial, or classified information.

Section 6(1)'s own text conditions the offence on a fraudulent purpose and on the data obtained being vital to national security, so a plain reading of that subsection does not reach ordinary scraping of a public, unauthenticated page absent both elements; section 6(2)'s aggravated form reaches a wider set of intents but is only reached once subsection (1)'s unauthorised-access element is made out. No reported Nigerian decision has applied section 6 to a scraper.

What it requires

Age gating law1 instrument, 1 in force

Research summary (172 words)

Nigeria has no dedicated adult-content age-verification statute, social-media minor-access restriction, or app-store age-verification requirement. The Child's Rights Act, 2003 (Act No. 26 of 2003) sets Nigeria's general framework of children's rights and protections, including against sexual abuse and exploitation, but its text contains no reference to the internet or an online service.

The Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 criminalises producing, distributing, offering, or possessing child pornography by means of a computer or network, but this is a criminal prohibition on the content itself rather than an age-verification or age-gating duty on a service provider, and it does not impose a duty tied to the user's age.

The closest instrument to an age-appropriate design code is the National Information Technology Development Agency's Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, 2022, which requires a Platform to label, censor, redact, or otherwise control access so that content inappropriate for a child is not viewable to a child, and to inform users not to create, publish, or share content harmful to a child.

Age-appropriate design code

Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, child-content control duty

NITDA Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, 2022, Part IICode of Practice for Interactive Computer Service Platforms/Internet Intermediaries

In force since 26 September 2022. Binds private bodies.

What this law does

The Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, issued by the National Information Technology Development Agency (NITDA) under section 6 of the NITDA Act, 2007 in collaboration with the Nigerian Communications Commission and the National Broadcasting Commission, applies to all Interactive Computer Service Platforms and Internet Intermediaries operating in Nigeria, a term the Code defines broadly to include social media operators, websites, blogs, media-sharing sites, discussion forums, streaming platforms, and gaming platforms.

Part II requires a Platform to label, censor, redact, or otherwise apply access control so that content inappropriate for a child, such as sexually explicit content or images of violence, is not viewable to a child. Part II also requires a Platform to inform users through its terms of service not to create, publish, modify, transmit, store, or share content harmful to a child.

A Platform must also give consideration, in assessing whether content is harmful, to the risk that its dissemination could have a physical or psychological impact on a child or an adult, and must ensure its community rules specify how children will be protected from harmful content they may encounter.

The Code does not itself prescribe an age-verification mechanism, and non-compliance is stated to be a breach of the Nigerian Communications Act, 2003, the National Broadcasting Commission Act, 2004, and the NITDA Act, 2007, rather than a penalty set out in the Code itself.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (195 words)

Nigeria has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act, 2022 (Act No. 8 of 2022) is the only law reaching an aggregator's reproduction of news content.

Its fair dealing exceptions permit, among other things, quotations in the form of short excerpts from a work, criticism, review, or the reporting of current events subject to a fairness test, and separately except news of the day for public broadcast or other public communication; no reported Nigerian decision applies these exceptions to a systematic news aggregator as opposed to an individual quoting or reporting on a published work.

Related rights under the Act protect performers, sound recordings, broadcasts, and expressions of folklore, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or case law located addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was found. The Act contains no text-and-data-mining exception or machine-readable reservation mechanism.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.