---
title: "Data Subject Rights in Nigeria: Handling Requests the Right Way"
url: https://planetweb.ng/data-subject-rights-in-nigeria/
date: 2024-12-11T20:53:25+00:00
modified: 2026-09-07T15:26:25+00:00
lang: en_US
---

# Data Subject Rights in Nigeria: Handling Requests the Right Way

## Data Subject Rights in Nigeria: NDPA Requirements, Limits, and Business Compliance

Most Nigerian businesses treat data subject rights as a consumer protection issue, something that sits on the legal team's radar and rarely comes up in practice. That framing creates real risk. Data subject rights are enforceable legal rights under the Nigeria Data Protection Act 2023 (NDPA), administered by the Nigeria Data Protection Commission (NDPC). Respecting those rights is also an operational compliance obligation. Any business that collects personal data from customers, employees, website visitors, or others needs a process for handling data subject requests when they arrive. This article is part of PlanetWeb's NDPA compliance series. See our *[NDPA Compliance Guide for Nigerian Businesses](https://planetweb.ng/ndpa-compliance-for-small-businesses/)* and our breakdown of the *[Key Features of the NDPA 2023](https://planetweb.ng/key-features-of-the-nigeria-data-protection-act-2023/)* for broader context.

## What Data Subject Rights Are and Who Holds Them

Under the NDPA 2023, a data subject is any living individual whose personal data is being processed, including customers, job applicants, and newsletter subscribers. Employees are data subjects too, and can exercise their data protection rights over personal data held in HR records, payroll systems, performance reviews, and other employment records, subject to the same statutory limitations that apply to other data subjects. Organisations that have built a clear customer-facing data request process but ignored their internal HR obligations are only half-compliant. A former employee may still have valid rights over records the organisation continues to hold. The *[Nigeria Data Protection Commission](https://planetweb.ng/the-nigeria-data-protection-commission/)* is the enforcement authority for these rights.

## The Rights of Data Subjects Under the NDPA

### Right of Access

Any individual can request a copy of the personal data a business holds about them, along with information about how it is being used. This is called a Data Subject Access Request, or DSAR. Say Tolu applies for a loan at a Nigerian fintech, gets declined, and suspects the decision was based on incorrect information. He submits an access request. The fintech must respond with a copy of his data, the purposes for which it is being processed, and who it has been shared with. A valid access request does not need to cite the NDPA, and it does not need to be in writing. A spoken request made in person or over the phone counts too, provided the person makes clear they are asking for their own personal data. Requests that are manifestly unfounded or excessive, particularly where they are repetitive, may be refused or subject to a reasonable fee, depending on the circumstances.

### Right to Rectification

If a business holds inaccurate or incomplete data about an individual, that person can request a correction. This comes up frequently in credit records, employee files, and customer account profiles. Say Musa discovers his employer's HR system has his date of birth recorded incorrectly, affecting his pension contributions. He has the right to request a correction. The business can verify the requested correction before changing the record, particularly where the accuracy of the proposed correction is disputed.

### Right to Withdraw Consent

Where consent is the legal basis for processing, the individual can withdraw it at any time, and withdrawal has to be as easy as giving consent was in the first place. Once consent is withdrawn, the business must stop the processing that relied on it, though this does not automatically require deleting data already collected if another lawful basis or legal obligation applies to it. A newsletter subscriber who unsubscribes has withdrawn consent for marketing emails. If the business also holds their purchase history for tax record-keeping, that separate basis is unaffected by the withdrawal.

### Right to Erasure

Individuals can ask a business to delete their personal data when it is no longer needed for its original purpose, when consent has been withdrawn, or when it was processed unlawfully. Ada, a former customer of a logistics company who has not used the service in three years, wants her account and data deleted; the company has no continuing legal basis to hold it, so her request is valid. The critical limit: erasure can be refused when retaining the data is necessary to comply with a legal obligation, or to establish or defend a legal claim, such as an ongoing employment dispute.

### Right to Restrict Processing

Restriction is not deletion. The individual is asking that their data not be actively used while a dispute or investigation is pending. If Emeka is contesting the accuracy of his credit record with a financial institution, he can ask that processing of that data be restricted while the dispute is investigated. The data may remain stored, but its processing must be restricted while the relevant issue is being resolved, subject to the circumstances and limitations that apply under the NDPA. Operationally, this means businesses need a mechanism to flag records as restricted, not just a note in someone's inbox.

### Right to Data Portability

This right allows individuals to receive their personal data in a structured, commonly used, and machine-readable format and, where the applicable conditions are met, transfer it to another data controller. Section 38 empowers the Commission to prescribe the circumstances and conditions for exercising the right, and the General Application and Implementation Directive (GAID 2025) now provides operational rules for it. The right applies where the data subject provided the personal data on the basis of consent or where processing is necessary for the performance of a contract, and to processing carried out by automated means. GAID 2025 also sets out circumstances in which the right may not apply. For Nigerian fintechs and SaaS platforms, this has direct technical implications: systems may need to support the export and transfer of personal data in a usable, portable format.

### Right to Object

This right has two distinct contexts, and the distinction matters. Objecting to processing based on legitimate interests can be overridden if the business can demonstrate compelling grounds that outweigh the individual's interests. Objecting to direct marketing works differently: once a data subject objects, the personal data must no longer be processed for that purpose, with no argument for legitimate interests and no basis for asking them to justify the request. Businesses that apply the "we can override it" logic to direct marketing opt-outs are making a compliance error.

### Right to Be Informed

Individuals have the right to know, at the point their data is collected, who is collecting it, why, on what legal basis, how long it will be retained, and with whom it may be shared. This information is normally provided through a privacy notice and, where consent is required, an appropriate consent mechanism, and it is an ongoing obligation rather than a one-time policy exercise.

### Right in Relation to Automated Decision-Making and Profiling

The NDPA defines automated decision-making as a decision made solely by automated processing, without human involvement, that produces legal or similarly significant effects on an individual. A decision that involves genuine human involvement is not a decision made solely by automated processing, although whether that involvement is sufficient depends on how the decision is made in practice. The NDPA also carves out specific exceptions, including where the decision is necessary for a contract, authorised by written law with appropriate safeguards, or based on explicit consent. Where those exceptions apply, the NDPA requires suitable safeguards, including the ability to obtain human intervention, express a point of view, and contest the decision. Credit scoring systems, hiring filters, and fraud detection algorithms are commonly discussed in relation to this right, though whether a specific system falls within scope depends on meeting the statutory test rather than the category of tool alone. These systems are also frequently the ones that trigger a Data Protection Impact Assessment before deployment; *[data protection impact assessments in Nigeria](https://planetweb.ng/data-protection-impact-assessments-in-nigeria/)* covers when that assessment is required. For a comparison of how the NDPA approaches automated decision-making relative to the GDPR, see our *[NDPA vs GDPR analysis](https://planetweb.ng/comparison-of-ndpa-2023-and-gdpr/)*.

### Right to Lodge a Complaint

Where a data subject is dissatisfied with a business's decision, action, or inaction on any of the rights above, they can lodge a complaint directly with the NDPC for remedial action. This provides a regulatory route for redress through the Commission. What happens once this right is exercised is covered in *The NDPC Complaint Process* below.

## Rights That Are Absolute vs. Rights That Require Assessment

Not every data subject request produces an automatic outcome. Some rights are subject to specific conditions, exceptions, or balancing against other legal obligations.

| Right | Status |
| --- | --- |
| Access | Requires assessment (can be refused if manifestly unfounded or excessive) |
| Rectification | Requires assessment (the business should verify the requested correction where accuracy is disputed) |
| Erasure | Requires assessment (can be refused for legal obligation or to defend a claim) |
| Restriction | Requires assessment (available pending resolution of a request or objection, or to establish, exercise, or defend a legal claim) |
| Withdraw consent | Must be honoured where consent is the basis relied on, though it does not by itself erase data held under a separate legal basis |
| Portability | Requires assessment (only applies where the legal basis is consent or contract, and where the applicable conditions under GAID 2025 are met) |
| Object to legitimate-interest processing | Requires assessment (can be overridden by compelling grounds) |
| Object to direct marketing | Must be honoured |
| Being informed | Not request-dependent; an ongoing obligation regardless of assessment |
| Automated decision-making | Requires assessment (applies only where the statutory "solely automated" test is met, subject to specific exceptions) |

## When Erasure Meets Retention Rules

The right to erasure does not automatically override a legitimate legal or regulatory retention obligation. For businesses in financial services, healthcare, and other regulated sectors, that tension shows up in practice more often than the NDPA text alone would suggest. CBN guidelines require financial institutions to retain KYC documents and transaction records for defined periods, for anti-money-laundering and audit-trail purposes. Tax legislation also imposes record-keeping requirements that can limit the circumstances in which personal data can be erased. Healthcare differs because there is no single national statutory retention period equivalent to the defined periods that apply to some financial records; retention is instead governed by applicable professional, clinical, and institutional requirements. When a customer submits an erasure request and the business is legally required to retain the relevant data, the right approach is to refuse the erasure on the basis of legal obligation, communicate this in writing to the requester, and specify what data is being retained, why, and when it will be deleted once the retention period expires. This is legitimate only where the business is genuinely under that obligation and retains no more than what is legally required.

## How Businesses Must Handle Requests Operationally

### The Response Timeframe

Businesses should treat the date a request is received as the starting point for handling it, rather than waiting until someone internally identifies it as a data protection request. The NDPC's own Data Subject Access Request process states that it endeavours to respond within 30 days of receiving a written request and any further information required to process it. Businesses should treat this as a useful benchmark for prompt handling, while confirming the applicable requirements for the specific type of request involved.

### Identity Verification

Businesses can verify that a request comes from the person whose data it concerns. Asking someone to confirm their account email or answer a security question is proportionate; requiring notarised identity documents for a simple rectification request is not. The [ICO's guidance on handling DSARs](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/) provides a useful reference for what proportionate verification looks like, even though it is based on UK law.

### When a Request Involves Someone Else's Data

Fulfilling a request can expose personal data belonging to someone other than the requester: an email thread that names a colleague, a complaint file that identifies another employee, a shared document with several people's details in it. The business is not required to hand over a third party's personal data just because it happens to sit inside the requester's own file. The practical approach is to redact or withhold the third party's information while still fulfilling the request for the parts that genuinely concern the requester, rather than either refusing the whole request or disclosing everything unfiltered.

### Refusing a Request Properly

Any refusal must be in writing, cite the specific legal basis, inform the individual of their right to escalate to the NDPC, and be issued promptly. Failing to respond at all leaves the business exposed to a complaint and potential enforcement action.

### Record-Keeping

The NDPC can request evidence during an audit that requests were handled properly. A log of all incoming requests should record the date received, request type, action taken, response issued, and response date.

### Routing Requests Correctly

If a request sits unactioned in a general support inbox for two weeks before anyone realises what it is, those two weeks still count toward how quickly the business is expected to respond. The internal process needs to ensure requests are identified and routed to someone with authority to act on them from the moment they arrive.

## The NDPC Complaint Process: What to Expect

If an individual believes their rights have been violated, they can file a complaint with the [Nigeria Data Protection Commission](https://ndpc.gov.ng/). The Commission can also investigate suspected violations on its own initiative, separate from the complaint route. Where the NDPC completes an investigation and finds a violation, it can make an enforcement order or impose a sanction, which can include requiring the business to remedy the violation, requiring compensation to a data subject who has suffered loss or harm, an order to account for profits realised from the violation, or a penalty or remedial fee. When a business receives notice of an NDPC complaint, ignoring it or responding minimally is the worst approach. A prompt, documented, good-faith response that shows the original request was taken seriously, even if it was refused on legitimate grounds, is far more likely to produce a manageable outcome than silence.

## Employees as Data Subjects

An employee can submit a data subject access request for their own HR file, and the employer must respond on the same terms as any customer request. Inaccurate entries in a performance review can be challenged and corrected, and a former employee retains the right to ask what data the organisation continues to hold about them. Employers cannot delete employment records needed for tax and payroll compliance or to defend against a potential employment claim, but they cannot retain records indefinitely simply because it is convenient. The practical gap for most Nigerian employers is that they have built a process for handling customer data requests but have no equivalent for employee data, with clear ownership and a documented workflow. *[Employee data protection in Nigeria](https://planetweb.ng/employee-data-protection-in-nigeria/)* covers the broader obligations employers carry around HR data, beyond the specific rights and requests discussed here.

## Get Help With Data Subject Request Handling

Building a data subject request process from scratch, or fixing one that has never been tested against a real request, is exactly the kind of gap that surfaces at the worst possible time. Our [IT consulting](https://planetweb.ng/services/it-consulting-services/) work covers building the request-handling workflow, the identity-verification process, and the record-keeping behind it. [Contact us](https://planetweb.ng/free-it-consultation/) to talk through where your current process stands.

## Frequently Asked Questions

Can a business refuse a data subject request?

Yes, in specific circumstances, such as when the request is manifestly unfounded, excessive, or conflicts with a legal retention obligation. Any refusal must be in writing, cite the legal basis, and inform the individual of their right to complain to the NDPC.

Do employees have data subject rights over their HR records?

Yes. Employees can exercise data protection rights over their HR records, payroll data, and performance reviews on the same statutory terms that apply to any other data subject.

What happens if a business ignores a data subject request?

Ignoring a request can expose the business to a complaint and regulatory action. The NDPC can investigate violations and issue enforcement orders or sanctions, including orders requiring the organisation to remedy the violation, compensate an affected data subject, account for profits realised from the violation, or pay a penalty or remedial fee.

What is the difference between the right to object and the right to restrict processing?

The right to object challenges whether the business should be processing the data at all. The right to restrict accepts that the data may need to remain but asks that it not be actively used, typically while a dispute or investigation is pending.

Can a business rely on a GDPR-style privacy programme to meet NDPA data subject rights obligations?

Partly. Many of the underlying processes transfer, but some NDPA-specific requirements, including the rules governing data portability under GAID 2025 and the NDPC’s registration and complaint processes, need their own attention rather than being assumed to already be covered.
