---
title: "Nigeria Data Protection Act 2023: Key Features and Legal Framework"
url: https://planetweb.ng/key-features-of-the-nigeria-data-protection-act-2023/
date: 2024-12-02T13:02:15+00:00
modified: 2026-09-07T20:45:09+00:00
lang: en_US
---

# Nigeria Data Protection Act 2023: Key Features and Legal Framework

## Nigeria Data Protection Act 2023: What Every Business Needs to Know

The Nigeria Data Protection Act 2023 replaced the older NDPR with a more structured, rights-based framework for how personal data is collected, used, and protected in Nigeria. It applies to any organisation processing personal data connected to Nigeria, whether the organisation is based there or not. Most compliance problems start with a misunderstanding of what the Act asks for, not with any real intent to ignore it. An organisation that doesn't know it qualifies as a data controller or processor of major importance, or hasn't worked out which lawful basis applies to a given activity, ends up guessing at compliance rather than building it deliberately. This article covers what the Act requires. That means who it applies to, the lawful grounds for processing data, and the rights individuals hold. It also covers the regulator's role, what organisations are obligated to do, and what happens when something goes wrong. For turning those requirements into working processes, *[a starting-point guide for small organisations and NGOs](https://planetweb.ng/ndpa-compliance-for-small-businesses/)* and *[audit readiness](https://planetweb.ng/data-protection-compliance-in-nigeria-strategies/)* pick up where this one leaves off.

## Who the Act Applies To

The NDPA applies to public and private organisations domiciled, resident, or operating in Nigeria, and to organisations outside Nigeria that process the personal data of people in Nigeria. Physical presence in the country isn't the deciding factor; processing Nigerian data is.

### Data Controllers and Processors of Major Importance

A subset of organisations carry heavier obligations under the Act. The [General Application and Implementation Directive](https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf) (GAID), which became the operative implementation framework in September 2025, classifies these organisations into three tiers. Classification isn't based on data volume alone; it weighs the sensitivity of what's processed, cross-border transfers, reliance on third-party infrastructure, and the risk to data subjects, alongside the number of people whose data is processed within a six-month period.

| Tier | Data-Volume Indicator | Examples of Designated Sectors | Registration and Reporting |
| --- | --- | --- | --- |
| Ultra-High Level | Over 5,000 data subjects in 6 months, among other factors | Banks, telecoms, insurance, oil and gas, fintech, multinationals | Register once, file compliance audit returns annually |
| Extra-High Level | Over 1,000 in 6 months, among other factors | Government MDAs, microfinance banks, higher institutions, certain hospitals | Register once, file compliance audit returns annually |
| Ordinary High Level | Over 200 in 6 months, among other factors | Primary and secondary schools, primary health centres | Renew registration annually, no audit return required |

The sector examples are illustrative rather than exhaustive, and the volume figures are one factor among several rather than a standalone test. All three tiers have specific Data Protection Officer requirements, and the registration process itself is covered directly in *[GAID registration in Nigeria](https://planetweb.ng/gaid-registration-in-nigeria/)*. Smaller operations aren't automatically pulled into this classification. Traders with under 15 employees and certain artisans and community groups are treated as falling outside the major importance categories. Separately, processing done purely for personal or household purposes falls outside the Act's application entirely under Section 3, which is a different exclusion from not being classified as major importance.

## The Legal Grounds for Processing Personal Data

Every instance of collecting or using personal data needs a lawful basis behind it. The NDPA recognises six.

| Legal Basis | When an Organisation Would Rely on It |
| --- | --- |
| Consent | The individual has given clear, informed, freely given consent to the processing, such as signing up to a marketing mailing list |
| Contractual necessity | Processing is required to deliver something the person has agreed to, such as fulfilling an order or providing a service they signed up for |
| Legal obligation | Another law requires the processing, such as retaining certain financial records for tax purposes |
| Vital interest | The situation involves someone's life or physical safety and consent isn't practical to obtain in the moment |
| Public interest or official authority | Processing is necessary for a task carried out in the public interest, or under official authority vested in the organisation, which isn't limited to government bodies |
| Legitimate interest | An organisation has a genuine reason to process the data, provided that reason doesn't override the individual's own rights and interests |

Legitimate interest can be easier to misapply, since the organisation itself has to weigh up whether its reason for processing genuinely holds. Where it's relied upon, the GAID requires a documented assessment of that basis.

## Data Subject Rights

The Act gives people meaningful control over their own data: the right to know what's held about them, to correct inaccuracies, to request deletion, to move their data elsewhere, to object to certain uses, the right not to be subjected to decisions based solely on automated processing, and the right to lodge a complaint with the NDPC. These aren't rights an organisation can leave sitting in a privacy policy. An organisation with no defined process for receiving and actioning these requests has a clear gap between recognising the rights and being able to fulfil them in practice. Handling these requests in practice, including how to verify a requester's identity and what counts as a valid request, is covered in *[data subject rights in Nigeria](https://planetweb.ng/data-subject-rights-in-nigeria/)*.

## The Nigeria Data Protection Commission

The [NDPC](https://ndpc.gov.ng/) is the regulator responsible for enforcing the Act. It issues guidelines, investigates complaints, conducts audits, and has the power to impose fines and sanctions. Its role matters to organisations because it's the body responsible for implementing and enforcing the data protection framework, not just the body that penalises violations after the fact. The Commission's structure, enforcement powers, and how it conducts investigations are covered in *[the Nigeria Data Protection Commission](https://planetweb.ng/the-nigeria-data-protection-commission/)*.

## Obligations on Data Controllers and Processors

Beyond having a lawful basis for processing, the Act places a set of standing obligations on organisations handling personal data, whether or not they're classified as major importance.

### Security Measures

Organisations processing personal data are expected to put security measures in place that match the sensitivity of what's being processed and the risk of it being exposed. That can mean access controls and encryption for a healthcare provider handling medical records, and something considerably lighter for a business that only holds basic contact details for a mailing list. The Act doesn't prescribe one fixed standard; it expects the level of protection to be proportionate to what's genuinely at stake.

### Records of Processing

Organisations are expected to keep records of their processing activities: what's collected, why, and under what legal basis. That structured view is also what a regulator or auditor would expect to see if asked.

### Data Protection Impact Assessments

Where processing carries meaningful risk, such as large-scale processing of sensitive data or systematic monitoring, a data protection impact assessment is expected before the processing begins, not once something's already gone wrong.

### Data Protection Officer Appointment

Data controllers and processors of major importance are required to designate a Data Protection Officer under the GAID. Organisations outside that classification may also need to designate one where the nature of their processing makes it necessary. The DPO's role is to monitor compliance internally and act as the point of contact for both the NDPC and data subjects, which only works if the position carries enough independence to raise a problem without being overruled by whoever they report to.

### Processor-Specific Obligations

Processors carry obligations of their own, distinct from the controller's. A processor acting only on the controller's documented instructions is in a different position from one making its own decisions about how data gets used, and that distinction can shift where responsibility lands if something goes wrong.

## Breach Notification

Once an organisation becomes aware of a personal data breach, the clock starts immediately, not from when an internal investigation confirms exactly what happened. Where the breach is likely to result in a risk to the rights and freedoms of the people affected, the NDPA requires notification to the NDPC within 72 hours of becoming aware of it. If the breach creates a serious risk to those individuals, such as exposed financial details or health information, they generally need to be told as well, not just the regulator.

## Cross-Border Data Transfers

Sending personal data outside Nigeria, including through cloud services or tools hosted abroad, is permitted but conditional. The destination needs an adequate level of data protection as recognised by the NDPC, or the organisation needs appropriate safeguards in place, such as NDPC-approved standard contractual clauses or binding corporate rules. It's worth being precise about what this covers. Where a service provider physically hosts data is a separate question from whether an organisation's own processing activity constitutes a transfer requiring these safeguards. An organisation can be storing data with a provider that has servers in multiple regions while still needing to document the specific transfer mechanism that applies to its own processing. This mirrors the structure of frameworks like the GDPR in outline, though the specific mechanisms and thresholds differ; *[the NDPA vs. GDPR comparison](https://planetweb.ng/comparison-of-ndpa-2023-and-gdpr/)* covers where the two genuinely diverge.

## Penalties for Non-Compliance

Penalties also vary according to whether an organisation is classified as being of major importance. Under Section 48 of the NDPA, data controllers and processors of major importance can face a penalty of up to ₦10 million or 2% of the previous year's gross annual revenue, whichever is higher. Organisations outside that classification can face a penalty of up to ₦2 million or 2% of the previous year's gross annual revenue, whichever is higher. These are maximum amounts rather than fixed, automatic fines; the NDPC has discretion in how it applies them to a given case. The revenue-based calculation still means the potential exposure scales with the size of the organisation rather than being a flat figure applied regardless of scale.

## How the NDPA Replaced the NDPR

Before 2023, data protection in Nigeria ran on the Nigeria Data Protection Regulation, issued in 2019 by NITDA as subsidiary legislation rather than a standalone law. The NDPA replaced it with a full statute, established the NDPC as an independent regulator, and gave the framework clearer legal authority than the NDPR ever had on its own. The General Application and Implementation Directive formalised that transition: since it took effect in September 2025, the NDPC has operated the framework under the NDPA and the directive together, with actions properly taken under the earlier NDPR before that point remaining valid.

## Get Help Making Sense of Your NDPA Obligations

If it's still unclear which parts of the Act apply to your organisation, that's a reasonable place to start rather than a sign you're behind. Our [IT consulting](https://planetweb.ng/services/it-consulting-services/) work covers assessing where your organisation currently stands against NDPA requirements and building a practical plan to close the gaps. [Contact us](https://planetweb.ng/free-it-consultation/) to talk through your specific situation.

## Frequently Asked Questions

What is the Nigeria Data Protection Act?

The NDPA 2023 is Nigeria’s data protection law, replacing the earlier NDPR. It sets out how organisations must handle personal data, the rights individuals have over their own data, and the powers of the Nigeria Data Protection Commission to enforce compliance.

Who does the NDPA apply to?

Any organisation, public or private, that processes personal data connected to Nigeria, whether or not the organisation is physically based there. Certain organisations are further classified as data controllers or processors of major importance, which brings additional registration and compliance obligations.

What are the lawful bases for processing personal data under the NDPA?

Six: consent, contractual necessity, legal obligation, vital interest, public interest or official authority, and legitimate interest. Every processing activity needs to be tied to at least one of these, and the correct basis depends on the specific reason the data is being processed.

What are data controllers and processors of major importance?

A classification under the GAID that brings heavier registration, reporting, and Data Protection Officer obligations. It’s based on multiple factors, including the volume and sensitivity of personal data processed, cross-border transfers, and reliance on third-party infrastructure, not just a single data-subject count.

What is the difference between a data controller and a data processor?

A data controller decides why and how personal data is processed. A data processor handles that data on the controller’s behalf, following the controller’s documented instructions rather than making its own decisions about how the data gets used. Both carry obligations under the NDPA, but they’re not the same obligations.
