By Mide Alabi, Esq
If your business collects, stores, or processes personal data about Nigerian residents, you are subject to the Nigeria Data Protection Act 2023 (NDPA).1 That covers a wider range of businesses than most founders and executives initially assume. A fintech collecting BVN numbers, a logistics company storing delivery addresses, a hospital maintaining patient records, an e-commerce platform tracking purchase history: all of them are caught. So is any foreign company that processes the personal data of people in Nigeria, regardless of where the company itself is based.
The NDPA came into force on 14 June 2023 and is administered by the Nigeria Data Protection Commission (NDPC), which has regulatory authority to investigate complaints, conduct audits, and impose sanctions. Maximum penalties under the Act reach the higher of ₦2,000,000 or 2% of annual gross revenue for most violations, rising to ₦10,000,000 or 2% of annual gross revenue for the most serious breaches.2 Those figures are large enough to be material for any company at scale, and the enforcement appetite of the NDPC has grown steadily since the Act commenced.
What follows is a plain-language guide to the five compliance obligations that every company operating in Nigeria should understand and have in place.
1. You Need a Lawful Basis for Every Processing Activity
The NDPA prohibits processing personal data unless you have a lawful basis for doing so. Section 25 of the Act sets out the recognised bases: consent of the data subject, performance of a contract to which the data subject is a party, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest, and the legitimate interests of the data controller or a third party, provided those interests are not overridden by the rights of the data subject.
Consent, which many businesses treat as the default answer, carries specific requirements under the Act. It must be freely given, specific, informed, and unambiguous. A pre-ticked box does not constitute valid consent. Neither does burying a consent clause in terms and conditions that no reasonable person would read in full. Where consent is the basis relied upon, the data subject must also be able to withdraw it as easily as it was given, and withdrawal must not be made a condition for receiving a service.
The practical implication is that every data collection point in your business, your website sign-up form, your customer onboarding flow, your employee contracts, your vendor agreements, needs to be mapped to a specific lawful basis. “We collect data because we need it” is not a lawful basis. Getting this right at the foundation level is considerably easier than retrofitting it after a complaint has been filed.
2. Your Privacy Notice Must Actually Say Something
Section 24 of the NDPA requires data controllers to provide data subjects with clear, accessible information about how their data is being processed. This is commonly delivered through a privacy policy, but the Act’s requirements go beyond the generic boilerplate that most Nigerian websites currently carry.
A compliant privacy notice must include: the identity and contact details of the data controller; the purposes for which personal data is being processed and the lawful basis for each purpose; the categories of data being collected; whether data will be transferred to third parties or outside Nigeria, and on what basis; how long the data will be retained; and the rights available to data subjects, including the right to access, correct, delete, and object to processing.
The NDPC has made clear in its guidelines that privacy notices are expected to be written in plain language that an ordinary person can understand, not in the dense legal prose that characterises most privacy policies currently in circulation. A document that technically discloses everything but is functionally incomprehensible does not satisfy the Act’s transparency requirements. If your privacy policy has not been reviewed since the NDPA commenced, it almost certainly needs updating.
3. Cross-Border Data Transfers Require Specific Authorisation
Many businesses transfer personal data outside Nigeria without realising that the NDPA regulates this specifically. Section 43 of the Act provides that personal data may only be transferred to a foreign country or international organisation where adequate protection is guaranteed for the rights of data subjects.
Adequacy can be established in several ways: the destination country may have been designated as providing adequate protection by the NDPC; the transfer may be covered by standard contractual clauses approved by the NDPC; or the data subject may have given explicit, informed consent to the specific transfer. Using a cloud storage provider whose servers are located outside Nigeria, sending customer data to a foreign parent company, or sharing employee records with an offshore HR platform are all transfers that require one of these mechanisms to be in place.
This obligation catches businesses that have not thought carefully about where their data actually goes once it leaves their own systems. A review of your vendor contracts and your technology stack, specifically which tools process or store personal data and where those tools are hosted, is the starting point for assessing your cross-border transfer exposure.
4. Data Breaches Must Be Reported, and Quickly
Section 40 of the NDPA requires data controllers to notify the NDPC of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of data subjects. Where the breach is likely to result in a high risk to those rights and freedoms, affected data subjects must also be notified without undue delay.
Seventy-two hours is a short window, particularly for companies that do not have an established incident response process. Meeting the deadline requires knowing, in advance, who in the organisation is responsible for identifying and escalating a breach, what information needs to be gathered before a notification can be filed, and where the NDPC notification portal is and how it works. These are not decisions that can be made sensibly in the middle of an active incident.
A data breach, under the Act, is not limited to a cyberattack or a hacking incident. Accidental disclosure, unauthorised access by an employee, loss of a device containing personal data, and sending personal data to the wrong recipient all qualify. Companies that process significant volumes of personal data should have a written breach response procedure in place before one occurs, not after.
5. Certain Companies Must Appoint a Data Protection Officer and Register with the NDPC
The NDPA and the NDPC’s Data Protection Compliance Organisations (DPCO) Framework impose registration and appointment obligations on companies that process personal data above certain thresholds. Data controllers and data processors who process the personal data of more than 2,000 data subjects within a 12-month period are required to file an annual data protection audit with the NDPC and to engage a licensed Data Protection Compliance Organisation to conduct that audit.3
Additionally, section 32 of the Act requires certain categories of data controller to designate a Data Protection Officer (DPO). The obligation applies where processing is carried out by a public authority, where processing requires regular and systematic monitoring of data subjects on a large scale, or where the core activities of the controller involve large-scale processing of sensitive personal data. The DPO must have expert knowledge of data protection law and practice, and must be given the resources and independence necessary to perform the role effectively.
For many Nigerian startups and mid-size companies, the DPO obligation will not be triggered immediately. But the audit filing requirement, which turns on the 2,000 data subjects threshold, will apply to most companies of any meaningful scale. Missing the annual filing deadline is a straightforward enforcement exposure that is easily avoided with the right systems in place.
What This Means for Your Business
The NDPA is not aspirational legislation waiting to be taken seriously. The NDPC has conducted investigations, issued enforcement notices, and made clear through its public communications that compliance is expected and that non-compliance has consequences. The companies most at risk are not necessarily the ones committing the most egregious violations; they are often the ones that simply have not turned their attention to the issue at all.
The five obligations described above are not the entirety of what the Act requires, but they represent the areas where enforcement exposure is most immediate and where the gap between current practice and legal requirement tends to be widest. A structured compliance review, starting with a data audit to understand what personal data your business processes and on what basis, is the logical first step for any company that has not yet engaged seriously with the NDPA.
Enebeli and Partners Legal advises businesses on data protection compliance, privacy policy drafting, NDPC registration, and data breach response. If you have questions about your obligations under the NDPA, our team is available to assist.
To retain Enebeli & Partners Legal for Data Protection advisory contact us at info@goenebeli.com or call +234 802 255 7029. Visit www.goenebeli.com.
Author
Mide Alabi, Esq – Deputy Managing Partner, Enebeli & Partner Legal
NOTES
1 Nigeria Data Protection Act 2023 (Federal Republic of Nigeria), assented to 12 June 2023 and commenced 14 June 2023.
2 NDPA 2023, s 48.
3 Nigeria Data Protection Commission, Data Protection Compliance Organisation (DPCO) Framework (2023).





