Comprehensive regime
Nigeria Data Protection Act, 2023 (NDPA), general data protection duties
Nigeria Data Protection Act, 2023 (No. 37 of 2023)General Application and Implementation Directive (GAID) 2025
In force since 12 June 2023. Binds public and private bodies.
What this law does
The Nigeria Data Protection Act, 2023 sets Nigeria's general rules for processing personal data, enforced by the Nigeria Data Protection Commission (NDPC) it establishes.
Consent is required for direct marketing, for processing sensitive personal data, for further processing incompatible with the original purpose, for processing a child's personal data, before transferring personal data to a country the Commission has not made an adequacy decision for, and before a data controller makes a decision based solely on automated processing that produces legal effects concerning or significantly affects a data subject.
A data controller must notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, describing the nature of the breach and, where feasible, the categories and approximate numbers of data subjects and personal data records concerned. It must also notify affected data subjects immediately where the breach is likely to result in a high risk to their rights and freedoms.
Cross-border transfer of personal data proceeds on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument (a code of conduct, certification, binding corporate rules, or standard contractual clauses), or another lawful basis including the data subject's consent or a compelling legal or fiduciary obligation.
Data subjects hold a right not to be subject to a decision based solely on automated processes or algorithms, together with rights to rectification, data portability, erasure (a right described as the right to be forgotten), and lodging a complaint with the Commission.
A data controller or data processor of major importance, determined by the Commission by reference to the number of data subjects whose personal data it processes, must register with the Commission and file compliance audit returns.
What it requires