Middle East & Africa Nigeria

Nigeria NDPA Compliance: Data Protection Act 2023 Guide

Nigeria's Data Protection Act 2023: NDPC enforcement, lawful bases, data protection officers, DPCO audits, cross-border transfer rules, and fines up to 2% of revenue.

Regulation

Nigeria Data Protection Act, 2023 (signed June 12, 2023), with the NDPR 2019 framework it superseded and NDPC guidance including the 2025 General Application and Implementation Directive

Max Penalty

Data controllers of major importance: up to NGN 10 million or 2% of annual gross revenue, whichever is greater; others: up to NGN 2 million or 2% of annual gross revenue

Enforcing Authority

Nigeria Data Protection Commission (NDPC)

Official Source

ndpc.gov.ng

Executive Summary

  • The Nigeria Data Protection Act, signed June 12, 2023, replaced the regulation-based NDPR 2019 with primary legislation and created the Nigeria Data Protection Commission (NDPC) as an independent regulator.
  • It applies to processing in Nigeria and to foreign controllers processing Nigerians' data, with GDPR-family lawful bases including legitimate interest.
  • 'Data controllers and processors of major importance' must register with the NDPC, appoint DPOs, and file annual compliance audit returns through licensed Data Protection Compliance Organizations (DPCOs).
  • Fines scale to the greater of fixed naira amounts or 2% of annual gross revenue, and the NDPC enforces: it has run investigations and penalties against banks, fintechs, betting platforms, and a NGN 555.8 million fine against Meta-related infractions preceded the FCCPC's larger action.
  • Cross-border transfers require adequacy of the destination (assessed per NDPA criteria) or safeguards and derogations, with NDPC instruments and guidance completing the regime.

Nigeria built Africa’s most commercially significant data regime in two moves: the NDPR (2019) proved the market-based model, private DPCOs auditing controllers at scale, and the NDPA (2023) gave it statutory teeth, an independent commission, and revenue-scaled fines. The result is a system that supervises through paperwork you must generate annually: registration, DPO appointment, and a third-party audit return. For the largest consumer market in Africa, with fintech penetration to match, the NDPA is the compliance gateway, and the NDPC has shown it will use the 2%-of-revenue lever.

LawNigeria Data Protection Act, 2023
SignedJune 12, 2023 (NDPR 2019 superseded)
RegulatorNigeria Data Protection Commission (NDPC)
Major importanceRegistration + DPO + annual DPCO audit return
Max fineGreater of NGN 10M or 2% of annual gross revenue
TransfersAdequacy criteria, safeguards, derogations

Building the Nigeria module

Classify against ‘major importance’ first. Registration, DPO, and audit-return duties hinge on it; the NDPC’s directives set the categories, and misclassification is a visible gap.

Engage the DPCO relationship strategically. The annual audit is a standing external review, prepare the inventory, basis mapping, and breach log to survive it, and use findings as your remediation roadmap.

Paper transfers on the criteria model. Per-corridor adequacy/safeguards memos with NDPA-reflecting clauses; the POPIA comparison helps pan-African programs reconcile the two big regimes.

Watch the platform cases. The NDPC and FCCPC actions against global platforms signal Nigerian regulators’ willingness to enforce against foreign controllers, Kenya’s DPA and South Africa’s POPIA complete the regional picture.

Your Nigeria-facing pages’ consent and tracker behavior feeds both NDPC complaints and DPCO audits: check it with a free scan.

Frequently Asked Questions

Who counts as a data controller of major importance, and what extra duties attach?

The NDPA defines it around residency in Nigeria plus processing volume or sensitivity thresholds the NDPC specifies; the Commission's guidance (including the 2025 General Application and Implementation Directive) has set categories keyed to numbers of data subjects and sectors, banks, telecoms, insurance, fintechs, and large platforms land inside. Duties: register with the NDPC within the prescribed window, appoint a data protection officer, file annual compliance audit returns (via licensed DPCOs for the audit function), and face the higher fine band (greater of NGN 10 million or 2% of gross revenue). Smaller controllers keep the baseline duties without registration.

What are DPCOs and the audit-return system?

Data Protection Compliance Organizations are private firms licensed by the NDPC to provide audit, training, and compliance services, a deliberately market-based supervision model Nigeria pioneered under the NDPR and carried into the NDPA era. Controllers of major importance engage a DPCO to perform their annual data protection audit and file the return with the Commission (historically by March 15 each year). The DPCO ecosystem means Nigerian compliance has a standing third-party attestation layer: the audit file, findings, and remediation trail are regulator-visible artifacts your program must actually support.

Which lawful bases and rights does the NDPA recognize?

Bases: consent (informed, specific, withdrawable), contract performance, legal obligation, vital interests, public interest, and legitimate interest, the full GDPR set, with sensitive data (health, biometric, religious, political, and more) requiring heightened conditions. Rights: access, rectification, erasure, restriction, portability, objection (including to direct marketing), and protections around solely automated decisions. Time limits and procedures follow NDPC guidance. Children's data requires parental consent with age-verification expectations. A GDPR rights pipeline handles NDPA requests with addressee and template changes.

How do cross-border transfers work?

Transfers need either an adequate destination, adequacy is assessed against NDPA criteria (enforceable data subject rights, access to remedies, comparable protection), with the NDPC empowered to make adequacy findings and maintain instruments, or appropriate safeguards (contractual instruments, binding corporate rules) plus derogations: consent after being informed of risks, contract necessity, public interest, legal claims, vital interests. The old NDPR-era whitelist approach gave way to this criteria-based system. Practically: paper transfers with contract clauses reflecting NDPA requirements, document an adequacy/safeguards analysis per corridor, and watch NDPC guidance as its instrument set matures.

What does NDPC enforcement look like in practice?

Active and revenue-conscious. The Commission (and its NITDA-era predecessor) has investigated and penalized banks and fintechs over breaches and unlawful processing, sanctioned lending apps for contact-scraping practices, and pursued platform cases, Meta's Nigerian troubles span the NDPC and the consumer regulator FCCPC, whose USD 220 million penalty (upheld on appeal in 2025) included data-practice findings. The NDPC publicizes its enforcement, uses remediation orders and compliance fees, and coordinates with sector regulators. The audit-return system gives it a paper trail to check claims against: inconsistency between your DPCO filing and reality is an easy finding.

Regulatory Crosswalk

GDPRPOPIAKenya DPA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.