IOC Law / Africa Intelligence / Nigeria

Data Protection and Privacy in Nigeria

← Back to the Nigeria guide

The Nigeria Data Protection Act 2023 applies where an organisation is domiciled, resident or operating in Nigeria, processing occurs in Nigeria, or an overseas organisation processes personal data of an individual in Nigeria. A foreign platform can therefore be in scope before incorporating locally.

The General Application and Implementation Directive 2025 took effect on 19 September 2025 and gives operating detail on registration, audits, lawful bases, accountability, impact assessments and international transfers.

Build the compliance system

Map individuals, data, purposes, systems, recipients, retention and countries. Identify controller, processor and joint-controller roles. Determine whether the business is a Data Controller or Processor of Major Importance and complete registration or renewal with the Nigeria Data Protection Commission where required.

Choose a lawful basis for each purpose. Consent is not the default answer where it is not freely given or processing will occur regardless. Legitimate interests should be assessed and documented. Privacy notices for customers, website users, employees and applicants should describe the real service.

Put processor and data-sharing agreements in place; conduct DPIAs for high-risk processing; establish data-rights, complaint, retention, deletion and incident procedures; govern cookies and direct marketing; and train relevant staff.

Compliance Audit Returns and transfers

GAID requires a DCPMI to file an annual Compliance Audit Return. For an organisation established before 12 June 2023, GAID states a 31 March annual deadline. Audit evidence should cover people, processes and technology, not merely a completed template.

International transfers require an identified legal basis and documented protection. A UK business transferring personal data to Nigeria must also apply UK GDPR transfer rules. Nigeria is not a UK adequacy destination, so an International Data Transfer Agreement or UK Addendum and transfer risk assessment may be needed unless another lawful route applies.

The maximum remedial fee under the Act for a DCPMI is the greater of NGN10 million and 2% of prior-year gross revenue. For another controller or processor, it is the greater of NGN2 million and 2%.