What Is Nigeria Data Protection Act, 2023?
The Nigeria Data Protection Act, 2023 (NDPA), assented 12 June 2023, is Nigeria's comprehensive data-protection statute, replacing the earlier NITDA-issued 2019 Nigeria Data Protection Regulation (NDPR) as the primary legal instrument. The NDPA created the Nigeria Data Protection Commission (NDPC) as the independent regulator. The most significant post-enactment development is the NDP Act General Application and Implementation Directive 2025 (GAID), issued 20 March 2025 and in force 19 September 2025. GAID expressly states the 2019 NDPR ceased to apply as a legal instrument on GAID's issuance (though actions already taken under the NDPR were not invalidated), and it supplies the operative complaint procedure, registration categories, and exemption qualifications that the Act itself leaves to subsidiary rules. A Nigeria Data Protection Act (Amendment) Bill, 2025 (HB.2436) was at first reading in the National Assembly in the official Order Paper record dated 23 July 2025; no enacted amendment to the NDPA itself has been located, so the Bill remains proposed, not current law.
At a glance
- Full name
- Nigeria Data Protection Act, 2023
- Short code
- NDPA
- Jurisdiction
- Nigeria
- Enacted
- 2023
- Last major update
- NDP Act General Application and Implementation Directive 2025 (GAID), issued 20 March 2025, in force 19 September 2025 — the prior 2019 NDPR ceased to apply as a legal instrument on GAID's issuance
- Regulator
- Nigeria Data Protection Commission (NDPC)
- Private right of action
- Yes
- Statutory citation
- Nigeria Data Protection Act, 2023 (Act No. 37)
Scope, who NDPA covers
Protected data
Data subject rights
Confirmation of processing and access to personal data
Detailed processing information (purposes, categories, recipients, retention)
A machine-readable copy of personal data, subject to an unreasonable-cost limitation
Rectification of inaccurate or incomplete data
Erasure without undue delay in specified circumstances
Restriction of processing
Withdrawal of consent at any time
Objection to processing, subject to overriding lawful or public-interest grounds
An absolute right to object to direct marketing
Safeguards against solely automated decision-making
Data portability, with conditions to be prescribed by the NDPC
Complaint to the NDPC and judicial review of Commission orders
Notable features
GAID's Article 5 sets a floor under every statutory exemption: even exempted processing remains subject to the Act's core principles, lawful-basis rules, DPO duties, breach duties, and data-subject-rights provisions — exemptions narrow obligations, they do not remove the Act's baseline protections. GAID's complaint procedure runs on stage-specific deadlines (7-day acknowledgment, 21-day respondent response, 7-day post-determination decision communication) rather than a single end-to-end resolution deadline, and its Schedule 9 SNAG mechanism lets a complainant ask a controller to resolve a matter within 30 days without that being a precondition to filing directly with the NDPC or going to court.
Enforcement & penalties
Regulator: Nigeria Data Protection Commission (NDPC)
Penalties: Two-tier statutory maximum: for controllers/processors of "major importance," the greater of ₦10,000,000 or 2% of prior-year annual gross revenue; for other controllers/processors, the greater of ₦2,000,000 or 2% of prior-year annual gross revenue. The NDPC may also order remedies, compensation, or disgorgement, weighing gravity, duration, subject count, harm, mitigation, intent, cooperation, and data sensitivity. Non-compliance with a Commission order may separately be an offence carrying up to one year's imprisonment, the applicable fine, or both. A distinct GAID late-annual-audit-filing penalty (50% of the filing fee) is a compliance-filing penalty, not the general violation maximum.
Private right of action: Section 46 lets a data subject lodge a complaint with the NDPC over a controller's or processor's violating decision, action, or inaction, and civil proceedings for injury, loss, or harm remain available alongside the administrative route. Judicial review of a Commission order is generally available within 30 days; no separate internal NDPC appeal tribunal was located in the reviewed materials.
Relevance to data brokers
No Nigeria-specific data-broker, people-search-service, or public-record-aggregator complaint or deletion route has been located in official NDPC materials; the only mechanisms found are the general access/rectification/erasure request route, the NDPC's online breach/privacy-violation reporting portal, and the Section 46 complaint process. A broker processing the data of a Nigerian data subject would ordinarily be subject to the Act's general controller obligations, but an individual request does not establish the outcome in advance.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Nigeria have a comprehensive data-protection law?+
Yes. The Nigeria Data Protection Act, 2023 is the omnibus statute, implemented through the 2025 General Application and Implementation Directive (GAID), which replaced the earlier 2019 NDPR as the operative implementing instrument.
How do I file a complaint with the NDPC?+
Submit a complaint electronically or by other reasonable means under Section 46 of the Act and GAID's complaint procedure. The NDPC's electronic platform should acknowledge receipt within 7 days, and a respondent generally has 21 days to reply once a complaint proceeds — but no single overall resolution deadline is stated in the Act or GAID.
Does the NDPA cover a foreign data broker outside Nigeria?+
Potentially. GAID clarifies that a foreign controller or processor processing the data of a subject located in Nigeria can fall within the Act's scope, with narrower treatment for data merely transiting Nigeria. No dedicated data-broker registration or deletion route exists beyond the Act's general rights and complaint mechanisms.
Official sources & citations
Other international privacy regimes
NDPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
