Nigeria Data Regulators: What They Do & How to Comply

Nigeria data regulators privacy compliance guide in corporate meeting room with professionals reviewing tablet.

Nigeria Data Regulators: What Businesses Must Know

Nigeria does not have a single regulator for every aspect of a digital business. The NDPC oversees personal data protection specifically, while sector and technology regulators impose additional requirements depending on what the organisation does.

A fintech processing payments may have obligations involving the NDPC and the CBN. A hospital running a patient portal may have obligations involving the NDPC and health-sector bodies. A telecoms reseller collecting customer identity documents may have obligations involving the NDPC, NIMC, and the NCC.

Treating these as completely separate compliance problems can leave gaps between departments, particularly where the same data or process falls under more than one regulatory framework. This article covers the regulators most relevant to data, digital infrastructure, communications, identity, payments, and health, what each one governs, and how to stop overlapping obligations from becoming overlapping blind spots.

Other bodies may also apply depending on the organisation’s activities, among them the Securities and Exchange Commission (SEC), the Federal Competition and Consumer Protection Commission (FCCPC), the Corporate Affairs Commission (CAC), the Nigeria Deposit Insurance Corporation (NDIC), the Nigeria Revenue Service (NRS), and the National Office for Technology Acquisition and Promotion (NOTAP). The regulators covered here are the ones a data-focused business is most likely to encounter, not an exhaustive list.

It is part of PlanetWeb’s GAID compliance series. For the foundational data protection framework, see GAID Nigeria Data Protection Directive: What Every Business Must Know.

RegulatorPrimary FocusWhere It MattersKey Risk or Recent Development
NDPCPersonal data protection, generallyOrganisations processing personal data within the scope of the NDPAUp to ₦10 million or 2% of revenue under Section 48
NITDADigital economy policy, IT standardsBusinesses subject to NITDA’s technology, standards, or digital-economy requirementsAdministered the pre-GAID NDPR; now sits alongside the NDPC
NIMCNational identity data (NIN)Businesses authorised to collect, verify, or process NIN dataObligations apply on top of, not instead of, the NDPA
CBNPayment data localisationLicensed payment-system participants, and their unlicensed partners indirectlyCompliance deadline of 1 January 2027
NCCTelecoms regulatory complianceTelecoms operators, resellers, and agents₦1.04 trillion MTN fine (2015), a telecoms penalty, not a data protection one
NHIAHealth insurance oversightOrganisations within the health insurance system specificallyNo dedicated e-health law yet; NDPA is the current operative standard

Meet Nigeria’s Data Regulators: The NDPC

The Nigeria Data Protection Commission is the primary regulator for personal data in Nigeria, established under the Nigeria Data Protection Act 2023 and operationalised through GAID.

The NDPA applies to organisations domiciled, resident in, or operating in Nigeria, to processing that occurs in Nigeria, and in certain circumstances to organisations outside Nigeria processing personal data of data subjects in Nigeria.

The NDPC’s enforcement record shows this isn’t a regulator businesses can afford to treat lightly. Under Section 48 of the NDPA, the penalty structure is tiered: organisations classified as Data Controllers or Processors of Major Importance face a maximum penalty of the greater of ₦10 million or 2% of annual gross revenue, while other organisations face the greater of ₦2 million or 2%.

The Commission’s fines against MultiChoice Nigeria (₦766,242,500, July 2025) and Fidelity Bank (₦555.8 million, August 2024) illustrate the scale of financial exposure that can arise from broader NDPA non-compliance.

Sector-specific regulation does not displace those obligations. The NDPA applies across sectors even where a sector regulator has issued its own data protection requirements.

GAID Nigeria Data Protection Directive: What Every Business Must Know covers the full compliance framework and penalty structure in depth, and GAID Registration in Nigeria covers registration and classification specifically.

NITDA

The National Information Technology Development Agency administered the Nigeria Data Protection Regulation 2019, the NDPC’s predecessor framework, before the NDPA came into effect. Its broader mandate continues today across IT standards, digital economy policy, technology development, and related regulatory initiatives.

NITDA’s role today sits alongside the NDPC rather than replacing it: its mandate covers broader digital economy regulation, technology standards, and IT policy, while the NDPC is the dedicated regulator for personal data protection specifically. Its requirements come into play primarily where a technology activity also involves the processing of personal data.

NIMC

The National Identity Management Commission manages Nigeria’s National Identification Number system and the identity data behind it. Where a business is authorised to collect, verify, or otherwise process NIN information within an identity-management arrangement, NIMC requirements can apply alongside the NDPA.

Examples include bank-account opening, SIM registration, and KYC processes that require NIN verification.

Each of those activities is simultaneously a NIMC compliance question, how the data is verified and against what standard, and an NDPA compliance question, how it is stored, secured, and retained once collected. This is a useful illustration of how a sector-specific regulator can apply alongside general data protection law rather than instead of it, a pattern that repeats across several of the regulators below.

CBN: Data Localisation

The Central Bank of Nigeria‘s involvement in data regulation has changed substantially, and recently. On 15 June 2026, the CBN issued Circular PSS/DIR/PUB/CIR/001/004, introducing a data localisation requirement for the payments ecosystem.

What Was Issued

The CBN’s circular directs that payment transaction data generated within Nigeria must be stored and managed within Nigeria.

This must align with applicable Nigerian data protection law.

The same circular also introduces market concentration limits and beneficial-ownership disclosure requirements, but data localisation is the piece with the broadest compliance impact.

Who It Covers

The requirement applies to deposit money banks, microfinance banks, mobile money operators, switching companies, and payment solution providers, the organisations CBN licenses to facilitate payments.

Fintechs operating without a CBN licence aren’t named as primary obligors. This means the requirement can also affect unlicensed fintechs indirectly where they rely on covered payment-system participants.

What Data Is Affected

The scope is specifically payment transaction data, not an organisation’s financial data broadly. Primary databases, transaction ledgers, and disaster recovery backups all fall within it. The requirement extends beyond identifying a Nigerian storage location: the data itself has to genuinely reside and be managed within the country.

When Compliance Is Due

Full compliance is required from 1 January 2027. That date has not yet passed, and organisations still have time to plan for it, but the deadline is fixed. Organisations relying on cloud infrastructure hosted abroad will need time to assess their current architecture and make any necessary changes before the deadline.

NCC

The Nigerian Communications Commission regulates telecoms operators, and its enforcement history includes one of the largest regulatory fines in Nigerian corporate history: a ₦1.04 trillion fine against MTN Nigeria in 2015 for SIM registration non-compliance, later negotiated down to ₦330 billion.

That fine was a telecoms regulatory penalty, not a data protection one, and it predates the NDPA entirely. Its relevance here is what it demonstrates about the NCC’s willingness to use its enforcement powers, not a precedent for how NDPC penalties work.

Beyond that single case, the NCC’s ongoing relevance to data-handling businesses runs through SIM registration compliance and the data protection expectations it places on telecoms operators and their agents.

A business reselling SIM cards or operating as a telecoms agent may also be subject to NCC-specific requirements around identity verification and data handling that sit alongside, and are enforced separately from, its NDPA obligations.

Health Sector: NHIA and Digital Health Regulation

The National Health Insurance Authority, established under the NHIA Act 2022 and successor to the former National Health Insurance Scheme, oversees health insurance in Nigeria. Healthcare providers and health-tech platforms handling patient data sit within both the NDPA’s sensitive-data provisions and the health sector’s own regulatory expectations around patient confidentiality.

Nigeria does not yet have a dedicated, enacted legal framework for electronic health services specifically; legislative proposals covering electronic medical records, telemedicine, and digital prescriptions have been introduced but not yet passed into law. Businesses operating in this space should treat NDPA compliance, rather than any pending health-specific legislation, as the current operative standard.

International Cybercrime Cooperation

Nigeria ratified the Budapest Convention on Cybercrime on 6 July 2022, and it entered into force for Nigeria on 1 November 2022. Nigeria has not ratified the African Union’s Malabo Convention on Cyber Security and Personal Data Protection.

Neither convention is itself a Nigerian data protection law; both concern cybercrime cooperation and cybersecurity policy rather than personal data obligations directly. Their relevance to businesses is indirect: they provide frameworks for international cooperation in cybercrime investigations, separate from the NDPA’s own data protection requirements.

DPO Obligations Across Regulators

Organisations classified as Data Controllers or Processors of Major Importance are required to appoint a DPO under GAID. That requirement follows from DCPMI classification rather than a single data-volume figure in isolation.

Data Protection Officers in Nigeria covers the classification criteria, independence requirements, and certification process in full.

SNAG and the NDPC Complaint Process

When a data subject has a grievance with how a business is handling their data, GAID provides a standardised route for raising it directly with the organisation before, or alongside, escalating to the NDPC: the Standard Notice to Address Grievance.

A business that understands this process, and has a designated way to receive and respond to a SNAG, is better prepared to handle the complaint before it escalates. SNAG Process in Nigeria covers what triggers a SNAG and how to respond to one.

Vendor and Third-Party Risk Across Regulators

A single vendor relationship can create obligations across several regulatory regimes at once. A payment arrangement may bring CBN requirements into the same relationship that is already subject to NDPA requirements. A cloud infrastructure provider hosting patient records may bring health-sector expectations into the picture alongside NDPA ones.

A telecoms platform involved in customer identity verification may also bring NIMC and NCC requirements into the relationship, alongside the NDPA.

Vendor due diligence that only checks for a signed Data Processing Agreement misses this layering. A complete review asks which regulators apply to the underlying data and activity, beyond whether a standard contract clause exists. GAID Compliance Checklist: 24-Point Self-Audit covers vendor agreements and vendor registers as part of a broader audit process.

Navigating Overlapping Regulatory Obligations

Once the relevant regulators are identified, the practical work is avoiding duplicate compliance processes that each address the same underlying risk from a different angle.

Identify Every Applicable Regulator

A useful working model starts with listing every regulator that applies to the organisation’s actual activities, then mapping which data, process, or activity each one governs. The NIMC and NCC obligations discussed above, for instance, arise from specific activities such as NIN verification and SIM registration.

Find Where Requirements Overlap

Where two regulators’ requirements overlap, for instance, a payment provider needing to satisfy both CBN data localisation and NDPA lawful-basis documentation for the same transaction data, some controls can address both requirements, reducing duplication without treating the two obligations as identical.

Assign Ownership

Without a named person responsible for each regulatory relationship, overlapping obligations tend to fall into the gap between departments, IT assumes legal is tracking it, legal assumes compliance is tracking it, and none of them are.

Document Precedence Where Requirements Conflict

Where two regulators’ requirements genuinely conflict rather than overlap, the organisation should identify the legal basis for each requirement and document how the conflict is being resolved rather than assuming that one automatically takes precedence.

Maintain a Regulatory Calendar

A regulatory calendar helps more than any other single tool: CAR filing deadlines, the CBN’s 1 January 2027 compliance date, and any other sector-specific filing or renewal dates all sitting in one place, owned by one person, rather than scattered across departmental knowledge that leaves with whoever happens to hold it.

Get Help With Multi-Regulator Compliance

If it is unclear which regulators apply to your organisation, or how their requirements interact, that’s a reasonable place to start rather than a sign you’re behind.

Our IT consulting work covers mapping multi-regulator obligations and building a compliance structure that holds up across all of them. Get in touch to talk through where your organisation stands.

Frequently Asked Questions

Do I need to comply with the NDPC if I already comply with a sector regulator like the CBN?
Yes. Sector-specific requirements do not replace the NDPA. Organisations subject to a sector regulator may have to comply with both the sector-specific requirements and the NDPA’s data protection requirements.
When does the CBN's data localisation requirement take effect?
Full compliance is required from 1 January 2027, under Circular PSS/DIR/PUB/CIR/001/004 issued 15 June 2026. The deadline has not yet passed, but the requirement applies to the payment-system entities covered by the circular, including deposit money banks, microfinance banks, mobile money operators, switching companies, and payment solution providers.
Has Nigeria ratified the Budapest or Malabo Convention?
Nigeria ratified the Budapest Convention on Cybercrime in July 2022. It has not ratified the African Union’s Malabo Convention.
Which regulator handles patient data in Nigeria?
The NDPC’s data protection framework applies to patient data, while healthcare organisations may also face sector-specific requirements from bodies such as the NHIA. Dedicated e-health legislation is still under development and would add another layer once enacted.
What happens when two regulators' requirements overlap?
Often a single well-documented control can address both. Where requirements genuinely conflict rather than overlap, the organisation should document the legal basis for each and how the conflict is being resolved, rather than assuming one automatically takes precedence.
Share this article:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top