Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
NDPA
The NDPA (2023) is Nigeria's first primary data protection statute, creating the NDPC, GDPR-style rights and lawful bases, mandatory registration of major-importance controllers, DPOs, impact assessments and 72-hour breach notification.
The Nigeria Data Protection Act was signed into law in June 2023, superseding the Nigeria Data Protection Regulation (NDPR) issued by NITDA in 2019, and established the Nigeria Data Protection Commission (NDPC) as an independent regulator. It protects identified or identifiable individuals, applies to public and private entities including foreign entities targeting data subjects in Nigeria, and grants rights of access, rectification, erasure, portability, objection and protection from solely automated decisions. On 20 March 2025 the NDPC issued the General Application and Implementation Directive (GAID) 2025, which replaced the NDPR and its Implementation Framework and provides binding directives on lawful bases, registration of controllers of major importance (including any organisation processing personal data of more than 200 data subjects in six months), impact assessment templates and cross-border transfer guidance.
Enforcement has been assertive. In February 2025 the NDPC fined Meta Platforms USD 32.8 million with eight corrective orders for NDPA breaches including behavioural advertising without consent and cross-border transfer violations; a settlement was at an advanced stage before the Federal High Court by October 2025. The NDPC has also fined Multichoice Nigeria NGN 766.2 million for privacy violations and illegal cross-border transfers, opened investigations into TikTok and Truecaller in March 2025, and in early 2026 opened an investigation covering nearly 1,300 organisations for non-compliance. Penalties reach the higher of NGN 10 million or 2 percent of annual gross revenue for major-importance controllers.
Data controllers and processors of major importance must register with the NDPC; the GAID designates, among others, any organisation processing personal data of more than 200 data subjects in six months.
Processing requires consent, contract, legal obligation, vital interests, public interest or legitimate interests, and data must be minimal, accurate, securely processed and retained no longer than necessary.
Controllers of major importance must designate a DPO and file annual compliance audit returns, through licensed data protection compliance organisations, with the NDPC.
Breaches likely to risk individuals' rights and freedoms must be notified to the NDPC within 72 hours of awareness, with affected data subjects informed where the risk is high.
Read more
Anove scans your stack against NDPA and 260+ other frameworks in minutes.
High-risk processing requires a data protection impact assessment, and transfers abroad require adequacy (law, binding corporate rules, contract clauses, codes or certification) or specified derogations such as consent.