NigeriaIn ForceData Protection

Nigeria Data Protection Act, 2023

ng-ndpa-2023 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Nigeria Data Protection Act, 2023 (NDPA) is Nigeria's primary federal statute governing the collection, processing, storage, and transfer of personal data. Signed into law by President Bola Tinubu on 12 June 2023 and published in the Federal Republic of Nigeria Official Gazette on 1 July 2023, the Act entered into force on the date of signing. The NDPA applies to any data controller or processor that is domiciled, resident, or operating in Nigeria, and, by extraterritorial reach, to any controller or processor that processes the personal data of individuals who are in Nigeria regardless of where that controller or processor is located. This means foreign companies with Nigerian users must comply. The Act establishes the Nigeria Data Protection Commission (NDPC) as Nigeria's independent statutory supervisory authority, replacing the former Nigeria Data Protection Bureau. The NDPC is empowered to issue regulations, register data controllers and processors, investigate complaints, conduct audits, and impose administrative sanctions. Six lawful bases are recognised for processing personal data: consent, contractual necessity, legal obligation, vital interests, a public task, and legitimate interests. Sensitive personal data, including health, biometric, genetic, political opinion, religious, and ethnic data, attracts stricter requirements and limited lawful grounds. Data controllers and processors classified as being 'of major importance' must register with the NDPC, file annual data protection audits through a licensed Data Protection Compliance Organisation (DPCO), and appoint a Data Protection Officer. All controllers conducting high-risk processing must carry out a Data Protection Impact Assessment before commencing that processing. Data subjects are granted comprehensive rights: the right to be informed, to access their personal data, to rectification, to erasure, to restrict or object to processing, and to data portability. Controllers must respond within defined timeframes. Cross-border data transfers outside Nigeria are permitted only to jurisdictions with adequate protection or where appropriate safeguards, such as standard contractual clauses or binding corporate rules, are in place. Breach notification is mandatory: controllers must notify the NDPC within 72 hours of becoming aware of a personal data breach and must inform affected data subjects where there is a high risk to their rights and freedoms. Administrative fines of up to 2% of annual global gross revenue (or ₦10 million for natural persons) apply for serious violations, with higher penalties and criminal liability for deliberate breaches.

Key provisions
  1. Establishes the Nigeria Data Protection Commission (NDPC) as Nigeria's independent supervisory authority for data protection, replacing the former Nigeria Data Protection Bureau.
  2. Applies extraterritorially to any controller or processor processing the personal data of individuals in Nigeria, regardless of the controller's country of domicile or operation.
  3. Requires data controllers and processors of major importance to register with the NDPC, appoint a Data Protection Officer, and file annual compliance audits through a licensed Data Protection Compliance Organisation (DPCO).
  4. Mandates a Data Protection Impact Assessment (DPIA) before commencing any high-risk processing activity, such as large-scale profiling or processing of sensitive personal data.
  5. Grants data subjects rights including access, rectification, erasure, restriction of processing, data portability, and the right to object to processing.
  6. Permits cross-border data transfers only to adequately protective jurisdictions or where appropriate safeguards such as standard contractual clauses are in place.
  7. Requires breach notification to the NDPC within 72 hours of becoming aware of a personal data breach, with further notification to affected data subjects where high risk exists.
  8. Provides for administrative fines of up to 2% of annual global gross revenue (or ₦10 million for natural persons) for serious violations, with additional criminal liability for deliberate breaches.
Cases citing this instrument
Related instruments
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from Nigeria Data Protection Commission official resources and Federal Republic of Nigeria Official Gazette