Nigeria Data Protection Compliance in 2026: A Practical Guide to the NDPA and GAID

IOC Law / Insight

Nigeria Data Protection Compliance in 2026 A Practical Guide to the NDPA and GAID

Legal and commercial analysis for businesses operating across African markets

The Nigeria Data Protection Act 2023 created the statutory framework. The General Application and Implementation Directive 2025 provides much of the operating detail. GAID took effect on 19 September 2025, so organisations are now expected to demonstrate implementation rather than future intention.

Data protection is a market-entry issue. A UK or other overseas business may be within scope while it is still selling remotely, before any Nigerian company is incorporated.

When does Nigerian data protection law apply

The Act applies where an organisation is domiciled, resident or operating in Nigeria, where processing takes place in Nigeria, or where an organisation outside Nigeria processes personal data of a data subject in Nigeria.

Personal data is not limited to identity documents or financial records. Names, contact details, online identifiers, device information, location, customer histories, recordings, employee files and recruitment records can all be personal data. Sensitive personal data attracts additional concern, but ordinary personal data is still regulated.

The starting point is a data map showing the individual, data fields, collection point, purpose, system, access, recipient, retention period and country. Without that map, privacy notices, vendor terms and transfer assessments are likely to be generic and inaccurate.

Identify controller, processor and joint controller roles

A controller determines the purposes and means of processing. A processor acts on behalf of a controller. Parties that jointly determine the purpose and means may be joint controllers. The role is decided by facts, not by the label in a contract.

A Nigerian subsidiary may be a separate controller for employees but a processor for group customer support. A cloud provider may be a processor for hosted data and an independent controller for security logs or billing information. Each processing activity should be assessed rather than assigning one global label to an organisation.

Contracts should reflect the role. Processor terms should address instructions, confidentiality, security, subprocessors, rights requests, incidents, deletion or return and audit. Controller-to-controller sharing needs a clear purpose, lawful basis, transparency and allocation of responsibilities.

Determine whether the organisation is a DCPMI

GAID and NDPC guidance require organisations to assess whether they are a Data Controller or Processor of Major Importance and the applicable category. Volume, the number and class of data subjects, sensitivity, risk and sector can be relevant. A small workforce does not necessarily mean the organisation is outside the regime if it operates a high-volume digital service.

DCPMIs must register and maintain the required status with the Nigeria Data Protection Commission. The assessment and conclusion should be documented. Registration is not a substitute for substantive compliance.

Compliance Audit Returns are an annual accountability process

Article 10 of GAID 2025 requires controllers and processors to carry out periodic compliance audits using a risk-based approach. A DCPMI must file an annual Compliance Audit Return. For a DCPMI established before 12 June 2023, the stated deadline is 31 March each year.

The audit should test real controls across people, process and technology. A completed questionnaire unsupported by system evidence provides limited protection. Organisations should preserve records of decisions, data-flow diagrams, policies, notices, contracts, security testing, training, incidents, rights requests and remediation.

The NDPC’s April 2026 public materials continued to describe CARs as a tool for accountability and corporate risk management. A licensed Data Protection Compliance Organisation may be involved in the filing process where required.

Choose a lawful basis before collecting data

Consent is only one lawful basis. Contract, legal obligation, vital interests, public interest and legitimate interests may apply depending on the processing. The chosen basis should match the actual purpose.

Consent should not be bundled into terms or used where refusal is not realistic. It should be specific, informed and withdrawable. Legitimate interests require a documented assessment of the purpose, necessity and impact on individuals. Processing necessary for a contract must be genuinely necessary, not merely convenient.

New uses of existing data need review. A broad sentence saying data may be used “to improve services” does not automatically justify unrelated profiling, marketing or sharing.

Write privacy notices that describe the real service

A useful notice explains what is collected, the purposes and lawful bases, recipients, transfers, retention, rights, complaint route and controller identity. Separate notices may be needed for website visitors, customers, employees, applicants and monitored premises.

Notices should match the product and system configuration. If analytics, cookies, call recordings, credit checks, location permissions or automated decisions are used, they should be addressed with sufficient clarity. Product teams should involve privacy owners before launch, not after the interface is built.

Conduct DPIAs before high risk processing

A data privacy impact assessment should be completed before processing likely to create high risk. Relevant examples can include large-scale sensitive data, systematic monitoring, biometrics, children’s data, credit scoring, location tracking, novel technology or decisions with significant effects.

The DPIA should describe the proposal, necessity and proportionality, risks to individuals, mitigations, residual risk and decision owner. It should be revisited when the product, dataset, recipient or technology changes.

Manage data rights and incidents operationally

Rights requests need an intake route, identity-verification standard, search process, exemption review and response owner. Customer support, HR and IT staff should recognise a rights request even when the individual does not use legal terminology.

Incident response should connect security, privacy, legal, communications, insurance and senior management. The playbook should cover preservation, containment, risk assessment, notification decisions, communications and lessons learned. Tabletop exercises expose gaps more effectively than a policy stored unread.

International transfers require evidence

Sections 41 to 43 of the Act and GAID govern transfers outside Nigeria. The exporter should identify the country, recipient, purpose, categories of personal data, onward transfers and legal protection, then document the applicable transfer basis.

For UK-to-Nigeria transfers there is a second layer. Nigeria is not a UK adequacy destination. A UK exporter may need the UK’s International Data Transfer Agreement or UK Addendum and a transfer risk assessment unless another lawful route applies. The Nigerian and UK analyses can use the same data map, but they apply different legal tests.

Remote access can itself be a transfer issue. If a Nigerian support team can access a UK customer database, the arrangement should not be ignored merely because the server remains in Europe.

Vendors and cloud services need continuing control

Vendor diligence should cover security, location, subprocessors, incident history, certifications, deletion, business continuity and government-access risk. The contract should provide the rights and information needed to demonstrate compliance.

After signature, the organisation should track subprocessor changes, assurance reports, incidents and termination. A promise that data will be deleted is not credible if backups, logs and derived datasets are not addressed.

Data protection in investment and M And A

A buyer should review DCPMI status, registration, CARs, data maps, notices, lawful bases, marketing lists, processor agreements, international transfers, DPIAs, complaints, rights requests, security incidents and regulatory correspondence.

The buyer must also establish whether it can lawfully use the target’s data after completion. Transaction documents may need warranties, indemnities, remediation covenants, incident notification between signing and completion, and rules for data-room access. Integration plans should prevent the uncontrolled combination of databases.

Enforcement and practical exposure

The Act provides a maximum remedial fee for a DCPMI of the greater of NGN10 million and 2% of prior-year gross revenue. For another controller or processor, the maximum is the greater of NGN2 million and 2%. Orders, compensation, loss of customer trust and operational restrictions can be more significant than the monetary amount.

A 30 day implementation sprint

Week 1 discover

  • Map systems, data, purposes, recipients and countries.

  • Determine controller, processor and joint-controller roles.

  • Record sensitive, children’s and high-risk processing.

  • Assess DCPMI status and registration.

Week 2 repair the public and contractual layer

  • Update privacy and cookie notices.

  • Put processor and sharing agreements in place.

  • Record lawful bases and legitimate-interest assessments.

  • Identify and document international transfer mechanisms.

Week 3 make compliance operational

  • Launch rights-request and complaint procedures.

  • Set retention and deletion rules.

  • Test the incident plan.

  • Complete priority DPIAs and vendor reviews.

Week 4 evidence and govern

  • Prepare the CAR workstream and evidence set.

  • Train customer, HR, marketing, product and security teams.

  • Assign actions, owners and dates.

  • Put privacy metrics and high risks into management reporting.

Compliance is not a privacy notice. It is the ability to explain and evidence why data is processed, how it is protected, where it goes and what happens when something goes wrong.

Discuss the practical implications

Speak with IOC Law about how these issues affect your proposed market entry, transaction or operations.

Start a Conversation →

Leave a Reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Importing Goods into…

    IOC Law / Insight Importing Goods into Nigeria in 2026…

  • Bringing Capital In…

    IOC Law / Insight Bringing Capital In and Taking Profits…

  • Foreign Land and…

    IOC Law / Insight Foreign Land and Business Premises in…

  • Schedule a Consultation

    Tell us what you're working on.