AuditXYZ

Compliance Framework

Nigeria Data Protection Act 2023 (NDPA)

Nigeria's NDPA is Africa's largest economy's comprehensive data protection law, establishing the NDPC as the regulatory body, requiring annual audits for major data processors, and granting extensive data subject rights.

$5,000–$80,0003–9 monthsAudit Required2023
Issuing BodyNational Assembly of Nigeria / Nigeria Data Protection Commission (NDPC)
First Published2023-06-12
Latest Version2023
Typical Cost$5,000–$80,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyAnnual data protection audit required for data controllers and processors of major importance. Audit must be conducted by a licensed Data Protection Compliance Organization (DPCO).
Geographynigeria

NDPA: The Complete Guide

The Nigeria Data Protection Act 2023 is a landmark piece of legislation for Africa's largest economy and most populous nation. Signed into law on June 12, 2023, the NDPA replaces the earlier Nigeria Data Protection Regulation (NDPR) of 2019 and elevates Nigeria's data protection framework from regulatory guidance to primary legislation. The Act establishes the Nigeria Data Protection Commission (NDPC) as an independent statutory body with broad enforcement powers, introduces mandatory annual audits for significant data processors, and creates one of the most operationally demanding data protection compliance environments on the continent. With over 220 million people and a rapidly growing digital economy spanning fintech, e-commerce, and digital media, Nigeria's data protection posture has global significance.

What the NDPA Is and Who Issues It

The Nigeria Data Protection Act 2023 was enacted by the National Assembly of Nigeria and received presidential assent on June 12, 2023. It came into force immediately upon signing. The Act supersedes the Nigeria Data Protection Regulation (NDPR) 2019, which was issued by the National Information Technology Development Agency (NITDA) as subsidiary regulation rather than primary legislation. The NDPA's elevation to Act of Parliament gives it considerably more legal force and clarity of authority.

The Nigeria Data Protection Commission (NDPC) is established under Part II of the Act as an independent body corporate with perpetual succession. The Commission is led by a National Commissioner appointed by the President of Nigeria on the recommendation of the Council of State, subject to Senate confirmation. The NDPC's functions include:

  • Administering the Act and ensuring its implementation.
  • Receiving and investigating complaints from data subjects.
  • Conducting audits, investigations, and compliance assessments.
  • Licensing and regulating Data Protection Compliance Organizations (DPCOs).
  • Imposing administrative sanctions and referring criminal matters to prosecution authorities.
  • Promoting international cooperation on data protection.
  • Issuing guidelines, codes of practice, and determinations.

The NDPC operationalized the NDPR framework it inherited and has actively enforced the NDPA since its passage. By 2024-2025, the Commission had issued sector-specific guidelines for financial institutions, telecommunications operators, and health sector organizations; licensed dozens of DPCOs; concluded enforcement actions against multiple organizations for breach notification failures and unlawful processing; and published the Nigeria Data Protection Act Implementation Framework to guide organizations through compliance planning. The NDPC has stated that its enforcement posture will intensify through 2026, with particular focus on fintech, social media platforms, and cross-border data flows.

Who Must Comply

The NDPA applies to a broad range of organizations with a deliberately extraterritorial reach:

All organizations established in Nigeria — regardless of sector, size, or legal form — that process personal data of individuals. There is no minimum size or turnover threshold for general compliance obligations, though the intensity of specific obligations (notably the annual audit) is tiered by designation as a data controller or processor "of major importance."

Organizations outside Nigeria that process personal data of Nigerian residents in connection with:

  • Offering goods or services to Nigerian residents, whether or not payment is required.
  • Monitoring the behavior of Nigerian residents within Nigeria.

This extraterritorial provision captures global technology platforms, e-commerce companies, social media networks, and any organization that markets to or tracks Nigerian users online, regardless of where the organization is incorporated or headquartered.

The "major importance" designation: The NDPC designates certain data controllers and processors as being "of major importance" based on factors including the volume and nature of personal data processed, the scale of processing activities, the potential impact on data subjects, and the organization's role in critical infrastructure. Organizations so designated face the most stringent obligations, including mandatory annual audits by licensed DPCOs.

The NDPC has indicated that fintech companies, telecommunications operators, healthcare providers, large e-commerce platforms, and government contractors are among the categories likely to receive "major importance" designation. Organizations uncertain about their designation status should seek a formal determination from the NDPC.

Lawful Basis for Processing

The NDPA requires that all processing of personal data have a recognized lawful basis under Part III of the Act. The recognized bases are:

  • Consent: The data subject has given free, specific, informed, and unambiguous consent to the processing for one or more specific purposes. Consent may be withdrawn at any time, and withdrawal must be as easy as giving consent.
  • Contractual necessity: Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the data subject's request before entering into a contract.
  • Legal obligation: Processing is necessary for compliance with a legal obligation to which the controller is subject under Nigerian law.
  • Vital interests: Processing is necessary to protect the vital interests of the data subject or of another natural person.
  • Public interest: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official public mandate vested in the controller.
  • Legitimate interests: Processing is necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, rights, and freedoms of the data subject.

Organizations must identify and document the lawful basis for each processing activity before processing begins. Reliance on legitimate interests requires a balancing assessment demonstrating that the legitimate interest is not outweighed by the data subject's rights. The NDPC has issued guidance cautioning against routine reliance on legitimate interests for processing that data subjects would not reasonably expect.

Data Subject Rights in Depth

Part IV of the NDPA grants data subjects comprehensive rights that organizations must have operational systems to fulfill:

Right to be informed: Data subjects must be provided with clear, concise, and transparent information about how their personal data is processed, at the point of collection or as soon as practicable thereafter. Privacy notices must cover the controller's identity, processing purposes, lawful basis, retention periods, and data subject rights.

Right of access: Data subjects may request confirmation of whether their personal data is being processed and a copy of that data. Controllers must respond within one month of receiving the request, extendable by a further two months for complex or numerous requests with prior notice.

Right to rectification: Data subjects may request correction of inaccurate personal data and completion of incomplete data. Controllers must rectify without undue delay.

Right to erasure: Data subjects may request deletion of personal data when it is no longer necessary for the purposes for which it was collected, when consent is withdrawn and there is no other lawful basis, when the data has been unlawfully processed, or when erasure is required to comply with a legal obligation.

Right to restriction of processing: Data subjects may request that processing be restricted — effectively pausing processing while accuracy is contested, a legitimate interests objection is assessed, or data needed for legal claims is at issue.

Right to data portability: Data subjects have the right to receive personal data they have provided in a structured, commonly used, machine-readable format, and to have that data transmitted to another controller. The right applies where processing is based on consent or contract and is carried out by automated means.

Right to object: Data subjects may object to processing based on legitimate interests or public interest, including profiling based on those grounds. For direct marketing, objection must be honored immediately. For other grounds, the controller must cease processing unless it can demonstrate compelling legitimate grounds that override the data subject's interests, rights, and freedoms.

Rights related to automated decision-making: Data subjects have the right not to be subject to decisions based solely on automated processing — including profiling — that produce legal or similarly significant effects. Controllers using AI, machine learning, or algorithmic scoring for credit decisions, employment screening, or targeted advertising must implement meaningful human review mechanisms.

Special Personal Data

The NDPA establishes a protected category of special personal data that requires explicit consent or meets specific statutory conditions for processing. Special personal data includes:

  • Racial or ethnic origin
  • Political opinions
  • Religious or other beliefs of a similar nature
  • Trade union membership
  • Physical or mental health or condition
  • Sexual life or sexual orientation
  • Genetic data
  • Biometric data used for unique identification
  • Criminal records, allegations, or proceedings

Processing special personal data without explicit consent — or outside the narrow statutory exceptions — is a serious violation. Organizations in health, HR, fintech, and digital identity sectors must carefully assess their lawful basis for processing these categories and implement appropriate heightened safeguards.

The Annual Audit Requirement

The NDPA's most distinctive compliance feature is the mandatory annual data protection audit for data controllers and processors of major importance. This requirement — which has no direct parallel in the GDPR or most other data protection frameworks — creates a structured, third-party verification mechanism that significantly raises the compliance bar for designated organizations.

Under the Act and implementing framework:

  • Data controllers and processors of major importance must engage a licensed Data Protection Compliance Organization (DPCO) to conduct an annual audit of their data protection practices.
  • The DPCO must be licensed by the NDPC. The Commission maintains a public register of licensed DPCOs.
  • The audit must assess compliance with the NDPA across all key obligation areas: lawful processing, data subject rights, security safeguards, cross-border transfers, breach notification, DPO appointment, and record-keeping.
  • The audit report must be filed with the NDPC within the prescribed timeframe.
  • The NDPC may review audit reports as part of its supervisory function and may initiate enforcement action where the report reveals significant compliance gaps.

Organizations that process the personal data of more than 2,000 data subjects in a 12-month period, that process sensitive personal data at scale, or that are designated by the NDPC as of major importance should assume the annual audit obligation applies and engage a DPCO accordingly.

The DPCO framework is a unique feature of Nigeria's data protection ecosystem. DPCOs offer compliance auditing, advisory services, and ongoing monitoring — creating a regulated professional services market for data protection compliance.

Data Protection Officers

Organizations that process personal data on a large scale, process sensitive personal data regularly, or whose core activities involve systematic monitoring of data subjects must appoint a Data Protection Officer (DPO). The DPO must:

  • Have expert knowledge of the NDPA and data protection practice.
  • Be provided with resources necessary to carry out their tasks.
  • Report to the highest level of management.
  • Act independently and not receive instructions regarding the exercise of their tasks.
  • Serve as the point of contact for the NDPC and for data subjects.

The DPO may be an employee or external consultant. Where a DPO is appointed, their contact details must be published and communicated to the NDPC.

Cross-Border Transfer Restrictions

The NDPA restricts transfers of personal data outside Nigeria unless adequate safeguards are in place. Permitted transfer mechanisms include:

  • An adequacy determination by the NDPC that the destination country has adequate data protection standards.
  • Standard contractual clauses approved or issued by the NDPC.
  • Binding corporate rules for intra-group transfers, approved by the NDPC.
  • Consent of the data subject, after being informed of the risks.
  • Transfers necessary for contract performance or legal proceedings.

The NDPC has not yet published a formal adequacy list but has issued guidance indicating that countries with GDPR-equivalent frameworks may be treated as providing adequate protection. Organizations should document their transfer basis for each destination and build standard contractual clauses into data processing agreements with international partners.

Breach Notification

Data controllers must notify the NDPC of personal data breaches without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in risk to the rights and freedoms of natural persons. The notification must include:

  • The nature of the breach, including categories and approximate number of data subjects and records involved.
  • Contact details of the DPO or other contact point.
  • Likely consequences of the breach.
  • Measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

Where the breach is likely to result in a high risk to data subjects, the controller must also notify affected individuals without undue delay. Where the controller is a data processor, it must notify the controller without undue delay after becoming aware of a breach.

Enforcement and Penalties

The NDPC's enforcement toolkit includes:

  • Administrative sanctions: Fines of up to 2% of annual gross revenue or 10 million Naira (approximately $7,500), whichever is greater, for data controllers of major importance. For other controllers and processors, fines reach up to 2% of annual gross revenue or 2 million Naira, whichever is greater.
  • Criminal penalties: Individuals who knowingly and intentionally process personal data in contravention of the Act, or who obstruct the Commission, face criminal fines and imprisonment.
  • Enforcement notices: Requiring remediation within specified timeframes.
  • Suspension or prohibition: The NDPC may prohibit specific processing activities where ongoing harm to data subjects is found.

The NDPC has demonstrated enforcement intent: by 2025 it had concluded multiple enforcement actions, issued sector guidance with compliance deadlines, and made clear that the grace period that characterized the NDPR era is over.

Compliance Process and Timeline

PhaseActivitiesTypical Duration
AssessmentData inventory, gap analysis, "major importance" status review3–5 weeks
DesignPrivacy notices, lawful basis documentation, DPO appointment4–6 weeks
ImplementationNDPC registration, DPCO engagement, rights workflows, breach plan4–8 weeks
OngoingAnnual DPCO audit, NDPC filings, complaint handlingContinuous

Key compliance steps:

  1. NDPC registration — Register with the Nigeria Data Protection Commission.
  2. Major importance assessment — Determine whether the annual DPCO audit requirement applies.
  3. DPCO engagement — Engage a licensed Data Protection Compliance Organization for the annual audit where required.
  4. Lawful basis mapping — Document the legal basis for each processing activity, including balancing assessments for legitimate interests.
  5. DPO appointment — Designate a Data Protection Officer meeting the Act's requirements.
  6. Data subject rights workflows — Implement systems for handling all rights requests within the one-month response window.
  7. Breach notification procedure — Build a 72-hour NDPC notification workflow.
  8. Cross-border transfer safeguards — Review international data flows and implement approved transfer mechanisms.

The NDPA shares structural DNA with several major data protection frameworks, creating compliance efficiencies for multi-market organizations:

  • GDPR (approximately 60% overlap): The NDPA was modeled in significant part on the GDPR. Lawful bases, data subject rights, DPO requirements, breach notification, DPIA obligations, and cross-border transfer restrictions all mirror GDPR provisions. The primary differences are Nigeria's mandatory annual audit requirement (no GDPR equivalent) and the DPCO licensing framework. GDPR-compliant organizations will find most of their infrastructure adaptable.
  • POPIA (approximately 55% overlap): South Africa's POPIA and the NDPA share GDPR-aligned principles and an African regulatory context. Both require an equivalent of an information/data protection officer and impose cross-border transfer restrictions. POPIA does not have the NDPA's mandatory annual audit, and its enforcement body (the Information Regulator) has a longer track record than the NDPC.
  • Kenya DPA: Both are East/West African GDPR-aligned frameworks with registration requirements and similar data subject rights. The NDPA's annual audit obligation is its most distinctive differentiator. Organizations operating in both Nigeria and Kenya will find significant compliance overlap, particularly in documentation, rights workflows, and breach notification.
  • LGPD (Brazil): Both frameworks include data portability, breach notification, DPA oversight, and sanctions. LGPD's experience of phased enforcement offers a useful precedent for understanding how the NDPC's enforcement intensity may evolve.

How Privacy Automation Helps

Nigeria's NDPA creates a demanding and recurring compliance calendar: annual DPCO audits, 72-hour breach notifications, one-month access request responses, and NDPC registration maintenance. Privacy automation platforms reduce the manual burden significantly.

TruePrivacy covers the NDPA among its 12-plus supported frameworks and provides AI-powered data discovery across 128-plus sources — building the data inventory needed to respond accurately to access requests and assess breach scope across complex organizational data landscapes. DSR automation manages the one-month response window with escalation alerts and workflow tracking.

At $5,000 per year with 24-hour onboarding and an AuditXYZ score of 88/100, TruePrivacy is a practical fit for organizations managing NDPA alongside GDPR, POPIA, and other frameworks. As a newer platform, TruePrivacy's NDPA-specific DPCO audit preparation tooling is still maturing — organizations subject to the mandatory annual audit will still need to engage a licensed DPCO directly for the audit itself. See best privacy management tools for broader tool comparisons.

Frequently Asked Questions

Does the NDPA apply to a global company with no Nigerian office?

Yes. The NDPA applies to any data controller or processor that processes personal data of Nigerian residents in connection with offering goods or services to those residents or monitoring their behavior within Nigeria. A US company offering a subscription service to Nigerian users, a UK firm running targeted advertising to Nigerian audiences, or a South African company processing employment data of Nigerian staff are all within scope, regardless of where the company is incorporated.

What is a Data Protection Compliance Organization (DPCO) and how do I find one?

A DPCO is an organization licensed by the NDPC to provide data protection compliance services, including the mandatory annual audit for data controllers and processors of major importance. The NDPC maintains a public register of licensed DPCOs on its website. DPCOs offer a range of services beyond the annual audit, including gap assessments, policy development, DPO-as-a-service, and ongoing compliance monitoring. When selecting a DPCO, organizations should verify the DPCO's current license status with the NDPC and assess the DPCO's experience in the relevant sector.

What distinguishes a "data controller of major importance" from other organizations?

The NDPC determines "major importance" status based on factors including the volume of personal data processed (organizations processing personal data of 2,000 or more data subjects in a 12-month period are a threshold indicator), the sensitivity of data processed (regular processing of sensitive personal data), the organization's role in critical infrastructure or essential services, and the potential impact on data subjects of a compliance failure. Organizations that have not received a formal designation should conduct a self-assessment against these criteria and engage the NDPC for clarification where there is uncertainty.

How does the NDPA's consent standard differ from the GDPR's?

The NDPA's consent requirements closely mirror the GDPR's: consent must be freely given, specific, informed, and unambiguous; it must be as easy to withdraw as to give; and it cannot be bundled with terms and conditions as a condition of service. One area of additional emphasis in NDPA implementing guidance is the requirement that consent records demonstrate the specific information provided to the data subject before consent was obtained — not merely that a checkbox was ticked. Organizations should implement consent management systems that capture the specific privacy notice version displayed, the timestamp of consent, and the method by which consent was given.

What should organizations do if they previously relied on NDPR compliance and now need to transition to the NDPA?

The NDPA builds on the NDPR framework, so organizations with mature NDPR programs have a compliance foundation to work from. The transition priorities are: (1) reviewing lawful basis documentation against the NDPA's codified bases; (2) updating privacy notices to meet the NDPA's enhanced transparency requirements; (3) implementing the full data subject rights framework, including portability and automated decision-making rights that were less clearly defined under the NDPR; (4) assessing whether the annual DPCO audit obligation now applies; (5) establishing DPO appointment where required; and (6) reviewing cross-border transfer mechanisms against the NDPA's standard contractual clause requirements. NDPC implementation guidance published in 2023-2024 provides a transition roadmap.

Request a NDPA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

GDPRMedium60%
POPIAMedium55%

Related frameworks

Get matched with a NDPA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools