Nigeria’s Data Protection Act Creates a New Compliance Centre for Africa’s Largest Digital Market
Nigeria signed its Data Protection Act into law on 12 June 2023, creating an independent commission and moving national privacy requirements onto a statutory foundation.
Nigeria’s digital economy serves a large and rapidly growing population through financial technology, telecommunications, retail, health, identity and government services. The Nigeria Data Protection Act gives that processing a national legislative framework and establishes the Nigeria Data Protection Commission as regulator.
For international organisations, the Act is also a reminder that African privacy compliance cannot be reduced to South Africa’s POPIA or a copied European GDPR programme.
The Act follows the processing, not only the company
The framework applies to processing carried out in Nigeria and can reach processing relating to individuals in Nigeria in the circumstances set out by the Act. Providers should assess Nigerian users and operations even if core infrastructure sits elsewhere.
The Act distinguishes data controllers and processors. Controllers determine purposes and means; processors act on behalf of controllers. Contracts help allocate work, but they do not change the real role created by the service.
Processing needs a lawful basis
Personal data must be processed under a recognised lawful basis and in accordance with principles including fairness, lawfulness, transparency, purpose limitation, data minimisation, accuracy, storage limitation and security.
Consent is important but not the only basis. Contract, legal obligation, vital interests and other bases may apply in the circumstances provided by the law.
The organisation should select a basis before processing begins and ensure the user-facing explanation matches the actual operation. Retrofitting a basis after a complaint is not governance.
Significant Data Controllers carry additional expectations
The Commission may classify or regulate controllers and processors of major importance according to factors such as the number of data subjects, sensitivity and significance of processing. Registration and additional compliance steps may apply to Significant Data Controllers and Processors under the regulator’s current instruments.
Organisations should monitor classification guidance rather than assume size alone decides the issue. A smaller service handling national identity, health or financial data may present substantial risk.
International transfers require protection
The Act recognises cross-border processing but requires an adequate level of protection or another lawful transfer basis. The Commission’s guidance discusses approved instruments and limited exceptions.
Technical teams must map transfers broadly. Remote administration, fraud analytics, support tickets, backups and observability platforms can all make information available outside Nigeria.
Supplier due diligence should cover destination, onward transfer, security, deletion and regulator access—not merely the address of the primary data centre.
Security and breach governance
Controllers and processors must implement appropriate technical and organisational measures. The correct measures depend on volume, sensitivity, context and risk.
An effective programme combines access control, encryption where appropriate, resilient backups, monitoring, supplier management, secure development and incident response. It also defines how a suspected breach reaches the people responsible for notification decisions.
Build a Nigerian control map
Organisations should:
- Identify processing connected to individuals and operations in Nigeria.
- Record controller and processor roles.
- Map purposes, lawful bases and retention.
- Determine whether significant-controller registration applies.
- Review processor contracts and subprocessor chains.
- Document international-transfer mechanisms.
- Establish rights, complaint and regulatory-contact processes.
- Integrate Nigerian requirements into breach-response playbooks.
Africa’s privacy landscape is becoming local
The Act shares global privacy principles, which makes a common control framework possible. But regulatory registration, guidance, enforcement and transfer expectations are Nigerian.
Organisations that serve the market should build on a global baseline while treating the local regulator and law as first-class requirements.
Official sources
- Nigeria Data Protection Commission: Nigeria Data Protection Act 2023
- Nigeria Data Protection Commission: Frequently asked questions
This article provides general information and is not legal advice.
Continue the series: Africa Cyber & Digital Law Series index



