Data Protection Officers in Nigeria: Role and Requirements

Data Protection Officers in Nigeria guide with professional woman at desk.

Data Protection Officers in Nigeria: Who Needs One and What the Role Involves

The Data Protection Officer (DPO) question often starts with whether an organisation is required to appoint one. A more useful question is who in the organisation is currently accountable for data protection, and whether that arrangement meets the applicable requirements.

Under GAID, the first question comes down to an organisation’s classification. The second requires an honest look at how the DPO role is structured in practice.

This article covers who is required to appoint a DPO, what independence means in practice, what the role involves day to day, and the options for organisations that cannot resource it internally.

This article is part of PlanetWeb’s GAID compliance series. For the foundational framework, see GAID Nigeria Data Protection Directive: What Every Business Must Know.

For the registration and classification framework, see GAID Registration in Nigeria. For the broader compliance programme context, see Data Protection Compliance Strategies.

Who Is Required to Appoint a DPO

The mandatory DPO requirement applies to organisations classified as Data Controllers or Processors of Major Importance (DCPMIs) under Article 11 of GAID. Classification is a broader question than any single number.

Data-subject volume is one entry point: over 200 data subjects within a six-month period is the OHL volume threshold, the lowest classification tier, with higher tiers at over 1,000 and over 5,000. DCPMI status depends on the wider classification framework, though, and the DPO requirement follows from DCPMI status rather than from the 200-data-subject figure alone.

Several other factors feed into how the Commission classifies an organisation as a DCPMI: sensitivity of the data processed, reliance on third-party or cloud infrastructure, cross-border data flows, and the value of the data-driven assets involved, which GAID sets out under Article 8.

The NDPC also maintains an official list of DCPMIs, which is updated as organisations are approved.

Classification FactorWhat It May Indicate
Data-subject volumeOver 200 individuals within any six-month period is the OHL volume threshold
Sensitivity of data processedHealth records, biometric data, or financial data processed at meaningful volume
Reliance on third-party infrastructureSubstantial use of cloud services or third-party servers for processing
Cross-border data flowsSubstantial transfer or processing of data outside Nigeria
Value of data-driven assetsData holdings material enough to affect the Commission’s risk assessment

A mid-size e-commerce platform, a marketing agency with an active client database, or a healthcare provider managing patient records can cross the 200-data-subject volume threshold without realising it, since the figure is lower than most business owners expect. Crossing it is one route into DCPMI status, not the only one.

Classification should rest on an organisation’s actual processing activities rather than any single metric in isolation. Where there is genuine uncertainty, the conservative position is to treat the requirement as mandatory and seek a formal assessment.

GAID Registration in Nigeria covers the full classification framework and what Major status commits an organisation to beyond the DPO requirement.

What the Independence Requirement Means in Practice

The NDPC does not simply require that someone be named as DPO. GAID requires the DPO to be demonstrably independent under Article 12: unable to be pressured, coerced, or covertly influenced, and protected from dismissal or penalty for performing their duties.

The DPO reports directly to the management level rather than through an intermediary who might filter concerns before they reach decision-makers.

GAID also binds the DPO to confidentiality, and permits other responsibilities only where doing so creates no conflict of interest. That last provision is the one most Nigerian organisations get wrong.

Why the Head of IT Is Usually the Wrong Choice

The most common appointment mistake is putting the Head of IT in the DPO role, on the assumption that data protection is fundamentally a technical problem. It is a governance and accountability problem with technical dimensions, not the reverse.

The Head of IT makes decisions about systems and data flows that the DPO is supposed to independently scrutinise. When one person holds both roles, the conflict-of-interest provision in Article 12(8) is directly compromised. Technical competence is useful in a DPO, but it does not substitute for independence.

Why Senior Executives Rarely Qualify

CFOs, COOs, legal directors, and CEOs will often face conflicts of interest that make them poor DPO candidates, particularly where their existing responsibilities involve decisions about the organisation’s data processing.

A DPO needs to be able to advise against a processing activity that carries compliance risk, even where it has commercial appeal, without fear that doing so affects their position. A senior executive whose remuneration is tied to those same commercial outcomes cannot credibly hold that position.

Who Typically Does Qualify

A dedicated compliance officer with no line management over data-handling teams is a strong internal candidate, as is legal counsel whose brief is narrowly defined around compliance.

In regulated industries such as financial services or healthcare, a compliance manager who already operates independently of commercial functions and reports directly to the board can also fit, though the job title itself is not what determines suitability.

The test in every case is the same: can the individual say no to a data processing decision and have that refusal respected, without risking their role.

What a DPO Does in Practice

Most descriptions of the DPO role list legal responsibilities: advise on data protection obligations, monitor compliance, act as a contact point for the NDPC. That is accurate but not particularly useful for a business owner trying to understand what they are resourcing. In practice, the role sits across operations, risk, and compliance.

Data Subject Request Handling

Under the NDPA, data subjects have the right to access their personal data, request corrections, ask for erasure, object to processing, and request data portability. The DPO is responsible for receiving these requests, logging them, routing them to the relevant department, and ensuring the response is accurate and timely, with records that demonstrate each request was handled correctly.

The NDPA does not fix a single statutory response window the way GAID does for breach notification. The process needs to exist regardless, though, since requests still need to be received, logged, and resolved within a reasonable time. Data Subject Rights in Nigeria covers each right and the operational steps for handling them.

Breach Response

The DPO is typically the first point of escalation when a potential data incident is identified. Their role is to assess whether the incident requires formal notification to the NDPC, which under GAID must happen within 72 hours of becoming aware of a personal data breach that requires notification.

That window is short. An organisation without a functioning DPO and a documented breach response process will almost certainly miss it, or make notification decisions without the framework to do so correctly.

The DPO does not manage the technical response to a breach; they manage the compliance response, assessment, notification, documentation, and communication with affected data subjects where required. Responding to Data Breaches in Nigeria covers what the notification process involves in detail.

Staff Training and Awareness

The DPO is responsible for ensuring that staff who handle personal data understand their obligations, which means designing training relevant to each role rather than running one generic annual session and recording attendance.

A customer service team handling data subject requests needs different training from a finance team processing payroll. The DPO owns both the content and the documentation: records showing training happened, who attended, and what was covered. Employee Data Protection in Nigeria covers the broader obligations employers carry around HR data specifically.

NDPC Correspondence and Registration

The DPO commonly serves as the organisation’s contact point with the NDPC, including correspondence relating to registration, compliance returns, complaints, audits, and investigations. Significant changes to information submitted to the Commission, a change in DPO among them, must be notified within the applicable 60-day period.

An organisation whose DPO has left, without the replacement having been notified to the NDPC, is in a poor position to respond effectively to correspondence in the meantime.

Vendor and Contract Review

A data controller must ensure that processors handling personal data on its behalf comply with applicable data protection requirements. The DPO’s role includes reviewing data processing agreements before contracts are signed and flagging gaps, breach notification timelines, audit rights, clear processing instructions, and termination provisions for non-compliance.

This is often the most neglected part of the DPO function; many Nigerian businesses sign vendor contracts without data protection provisions and only discover the gap when something goes wrong.

DPO Certification and Accreditation

The Commission maintains a database of certified DPOs and conducts an Annual Credential Assessment under Article 14, run against metrics in Schedule 3 of GAID, to evaluate whether the individual maintains the professionalism the role requires.

This is not a paperwork formality. Certification is verified as part of an organisation’s Compliance Audit Return (CAR) filing or registration, and the Commission can decline verification where the evidence submitted is unverifiable or lacks credibility.

It also carries a direct operational consequence: GAID Nigeria Data Protection Directive: What Every Business Must Know covers how a Data Protection Impact Assessment submitted to the Commission must be signed by a duly certified, accredited DPO.

An organisation needs to confirm the DPO responsible for a submitted DPIA meets that standard, and the Commission’s DPO verification portal can be used to check a certificate is genuine and current.

Semi-Annual Data Protection Reporting

A recurring obligation sits separate from the DPO’s day-to-day responsibilities: GAID’s Article 13 requires a semi-annual data protection report, compiled by the DPO and submitted to an officer of the organisation authorised to receive it.

The report covers compliance status in summary form: privacy notice adequacy, the types of data processed, the lawful bases relied on, whether a DPIA or Legitimate Interest Assessment applies, and how easily data subjects can exercise their rights, among other things.

Once submitted, the report is acknowledged by the receiving officer and forms part of the organisation’s Record of Processing Activities. It is also verified by a DPCO during the NDP Act compliance audit.

An organisation with no process for producing this report twice a year has a real gap, even with an otherwise qualified, independent DPO in place.

The Outsourced DPO Option

Organisations that qualify as Major but cannot resource a full-time internal DPO can engage an outsourced service. Article 11 permits the role to be fulfilled under a service contract rather than by a staff member. For some Nigerian SMEs, this can be a practical route where the compliance obligation is real but the volume of activity does not justify a full-time hire.

Two separate things need to be true here, and Nigerian businesses often conflate them. The individual acting as DPO needs to be certified under Article 14, the same requirement that applies to an internal appointment. Separately, where a licensed DPCO is engaged to provide regulated compliance services on the organisation’s behalf, that firm needs its own DPCO licence. Holding one does not substitute for the other.

Internal vs Outsourced: What to Weigh

Internal DPOOutsourced DPO
DPO certification requiredYesYes
DPCO licensing requiredNoWhere a licensed DPCO is providing the service
Independence obligationYesYes
CostSalary and trainingRetainer
Availability during incidentsImmediateDepends on agreement
Organisational knowledgeHighBuilds over time
Best suited forLarger DCPMIs with high data volumesMid-size organisations, first-time compliance

Verifying Both Before Engaging

Engaging a general compliance consultant or a legal firm with data protection experience does not satisfy either requirement on its own. The NDPC’s register of licensed DPCOs is the reference point for the firm side of that check, and DPO certification status can be confirmed directly with the Commission.

Independence Applies Equally

The engagement contract should specify the DPO’s authority, their right to report directly to the organisation’s board or governing body, and provisions protecting them from being directed to act against their professional judgement. An outsourced DPO who can be overruled by the client on compliance matters is not, in substance, independent.

Shared Arrangements Carry Risk

Shared DPO arrangements, where one practitioner serves multiple organisations simultaneously, are permissible but carry a practical risk: if the caseload is too heavy, the DPO may not give each organisation adequate attention.

It is worth understanding how many clients the practitioner currently serves and what their availability commitment looks like for each. A DPO managing thirty clients simultaneously is unlikely to respond within the breach notification window when an incident occurs at midnight.

The Designated Compliance Owner for Non-Major Organisations

Organisations that are not classified as DCPMIs do not face the mandatory DPO requirement under Article 11, but that is not the same as being exempt from accountability. This is a governance recommendation rather than a statutory obligation: every organisation processing personal data benefits from a named person responsible for compliance, data subject requests, breach response, and NDPC correspondence.

That role is less formally defined than a statutory DPO. It does not require NDPC certification or the same independence obligations, but it does require someone who understands the NDPA’s requirements, has the authority to act, and checks the privacy inbox regularly.

In a small organisation, this might be an office manager, a legal or compliance professional, or a founder who has invested time in understanding the obligations. What matters is that it is a specific, named person who knows what they are responsible for.

NDPA Compliance for Small Businesses covers that first stage in more depth, including for NGOs and small businesses with little prior NDPA exposure.

What Happens If a DPO Is Not Appointed

Failing to appoint a DPO when required is non-compliance under the NDPA. For a DCPMI, Section 48 provides for a maximum penalty of the greater of ₦10 million or 2% of annual gross revenue.

A missing DPO does not automatically produce that maximum figure on its own, but it removes a structural safeguard the Commission expects to see in place, and it compounds badly when combined with other gaps.

Recent enforcement actions show that financial exposure under the NDPA can be substantial. The NDPC fined MultiChoice Nigeria ₦766,242,500 in July 2025 and Fidelity Bank ₦555.8 million in August 2024. These are not DPO-specific penalties, but they illustrate the wider enforcement exposure facing organisations that fail to meet their data protection obligations.

The absence of a functioning DPO also weakens an organisation’s position in the event of a breach or a data subject complaint, since it signals a broader gap in the compliance programme rather than an isolated lapse.

Get Help With DPO Compliance

If it’s still unclear whether your current arrangement meets the standard, that’s a reasonable place to start rather than a sign you’re behind.

Our IT consulting work covers assessing DPO independence, certification status, and the broader compliance structure around the role. Get in touch and we can help you assess it.

Frequently Asked Questions

Who is legally required to appoint a DPO in Nigeria?
Organisations classified as Data Controllers or Processors of Major Importance under GAID. Data-subject volume is one classification factor, with more than 200 data subjects within six months forming the OHL volume threshold, though other factors also determine classification.
Can the same person be both DPO and Head of IT?
In most cases, no. GAID requires the DPO to be demonstrably independent, and the Head of IT typically makes the systems and data-flow decisions the DPO is meant to scrutinise. Combining the roles creates a conflict of interest.
Does an outsourced DPO satisfy the NDPC requirement?
Yes, provided the individual holds current DPO certification and the engagement is structured for genuine independence. Where a licensed DPCO provides the service, that firm also needs its own current licence.
What happens if a required DPO is not appointed?
It constitutes non-compliance under the NDPA and may be identified during an NDPC compliance review or investigation. Section 48 provides for a maximum penalty of the greater of ₦10 million or 2% of annual gross revenue for DCPMIs.
Can an organisation share a DPO with another company?
Yes, shared arrangements are permissible under GAID, but the practical risk is diluted attention. It is worth understanding how many organisations the practitioner already serves before entering the arrangement.
Share this article:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top