Act 2023
Nigeria Data Protection Act 2023
Issued by Nigeria Data Protection Commission
Effective: 12 Jun 2023
Plain-English summary
The Nigeria Data Protection Act 2023 is a key privacy legislation enacted on June 12, 2023, that ensures the protection of citizens' data by establishing the Nigeria Data Protection Commission as the primary regulatory authority. Citizens are provided the right to govern their personal data, such as requesting access to or removal of the same. Data controllers are required to process data securely, report data breaches within 72 hours, and face heavy fines of up to two percent of their total annual gross revenue.
Who it applies to
Banking · Insurance · Telecom & Tech · Healthcare & Pharma
Topics
Data Protection & Privacy
Obligations arising from this law or regulation
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| Lawful basis, notice and data subject rights | Ongoing | NDPC | source | |
Legally Binding Basis, Privacy Notice and Data Subject Rights in Nigeria is a mandatory requirement that requires organizations to collect and process personal information according to the Nigeria Data Protection Act 2023 in a legally binding framework. The Nigeria Data Protection Commission (NDPC), together with the GAID 2025 rules, enforces Section 25, which states that the organization will be prohibited from processing personal data unless it is established under one of the six statutory bases: consent, contract, legal obligation, vital interests, public task, and legitimate interest [NDPA 2023]. It is necessary for the data controller to provide a Privacy Notice of the data usage purpose and period of time of retention, along with details of third-party sharing at the moment of data collection. It is also obligatory for organizations to have dedicated channels for ensuring enforcement of enforceable Data Subject Rights and to allow access, rectification, restriction, and complete deletion (erasure) of their personal data. The violation of the legal basis, failure to publish a privacy notice, or ignoring the rights request will lead to administrative sanctions, including fines up to ₦10,000,000 or up to 2% of annual gross revenue. |
||||
| Personal data breach notification | Deadline Event-based | NDPC | source | |
The duty to notify of personal data breaches in Nigeria is a mandatory statutory requirement provided for under Section 40 of the Nigeria Data Protection Act 2023 that compels data controllers to inform the Nigeria Data Protection Commission (NDPC) within 72 hours of being aware of any security incidents [NDPA 2023]. Based on the operational guidelines set out by the GAID 2025, it states that whenever there is likelihood of risk of breach resulting into risk to individual rights and freedoms, the organization is obliged to formally notify NDPC about the nature of the hack, number of records compromised, and steps taken as remedy. Additionally, if there is a high risk to individuals as a consequence of the security incident, the data controller will be required to notify the affected individuals immediately and without unreasonable delays using clear and plain language. Data processors have a legal duty to immediately notify their respective data controllers in case of any unauthorized access. Any failure to comply with the 72 hours deadline, or cover-up of an active data breach leads to serious punitive actions by NDPC through mandatory audit checks and imposition of hefty administrative fines not exceeding ₦10,000,000 or 2% of annual |
||||
| No obligations match these filters. | ||||
Latest news
No related news yet. We publish updates as regulators act.