Nigeria built Africa’s most commercially significant data regime in two moves: the NDPR (2019) proved the market-based model, private DPCOs auditing controllers at scale, and the NDPA (2023) gave it statutory teeth, an independent commission, and revenue-scaled fines. The result is a system that supervises through paperwork you must generate annually: registration, DPO appointment, and a third-party audit return. For the largest consumer market in Africa, with fintech penetration to match, the NDPA is the compliance gateway, and the NDPC has shown it will use the 2%-of-revenue lever.
| Law | Nigeria Data Protection Act, 2023 |
|---|---|
| Signed | June 12, 2023 (NDPR 2019 superseded) |
| Regulator | Nigeria Data Protection Commission (NDPC) |
| Major importance | Registration + DPO + annual DPCO audit return |
| Max fine | Greater of NGN 10M or 2% of annual gross revenue |
| Transfers | Adequacy criteria, safeguards, derogations |
Building the Nigeria module
Classify against ‘major importance’ first. Registration, DPO, and audit-return duties hinge on it; the NDPC’s directives set the categories, and misclassification is a visible gap.
Engage the DPCO relationship strategically. The annual audit is a standing external review, prepare the inventory, basis mapping, and breach log to survive it, and use findings as your remediation roadmap.
Paper transfers on the criteria model. Per-corridor adequacy/safeguards memos with NDPA-reflecting clauses; the POPIA comparison helps pan-African programs reconcile the two big regimes.
Watch the platform cases. The NDPC and FCCPC actions against global platforms signal Nigerian regulators’ willingness to enforce against foreign controllers, Kenya’s DPA and South Africa’s POPIA complete the regional picture.
Your Nigeria-facing pages’ consent and tracker behavior feeds both NDPC complaints and DPCO audits: check it with a free scan.