NigeriaSupersededData Protection

Nigeria Data Protection Regulation, 2019

ng-ndpr-2019 · Regulation

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Nigeria Data Protection Regulation, 2019 (NDPR) was Nigeria's first substantive data protection instrument. Issued on 25 January 2019 by the National Information Technology Development Agency (NITDA) pursuant to its powers under the NITDA Act 2007, the NDPR was a subsidiary regulation rather than an Act of Parliament. It preceded and was superseded by the Nigeria Data Protection Act, 2023 (NDPA), which placed Nigeria's data protection framework on primary legislative footing. The NDPR applied to natural persons resident in Nigeria, Nigerian citizens outside Nigeria, and to any person or organisation that processes the personal data of such persons. It imposed obligations on data controllers to process personal data lawfully, collect data only for specified purposes, maintain data quality, and implement security safeguards. The Regulation required data controllers above specified thresholds to engage a licensed Data Protection Compliance Organisation (DPCO) to conduct annual data protection audits and submit compliance reports to NITDA. This audit mechanism was among the most distinctive features of Nigeria's pre-2023 regime. Data subjects were granted rights of access, rectification, and objection. Cross-border data transfers were restricted to countries with adequate protection or subject to contractual safeguards. Breach notification obligations also applied. The NDPR was administered by NITDA's Nigeria Data Protection Bureau (NDPB). When the NDPA 2023 came into force, it established the NDPC as the successor authority and superseded the NDPR, though certain regulatory continuity provisions were retained during the transition period. Entries in this Library relating to the NDPR are provided for historical and comparative reference only; the NDPA 2023 (ng-ndpa-2023) is the current operative instrument.

Key provisions
  1. Issued by NITDA on 25 January 2019 as a subsidiary regulation under the NITDA Act 2007, providing Nigeria's first operational data protection framework.
  2. Required data controllers above prescribed thresholds to engage a licensed Data Protection Compliance Organisation (DPCO) to conduct annual audits and file compliance reports with the regulator.
  3. Obliged data controllers to process personal data lawfully, collect only for specified purposes, maintain data accuracy, and implement appropriate security safeguards.
  4. Granted data subjects rights of access, rectification, and objection to processing.
  5. Restricted cross-border data transfers to countries providing an adequate level of protection or where contractual safeguards were in place.
  6. Breach notification obligations required controllers to notify affected individuals and the regulator of data security incidents.
  7. Superseded by the Nigeria Data Protection Act, 2023, which replaced the NDPR with primary legislation and the NDPC succeeded NITDA's NDPB as the supervisory authority.
Cases citing this instrument
Related instruments
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from NITDA official resources; instrument confirmed superseded by NDPA 2023