← Back to Insights

Nigeria

Nigeria Data Protection Act 2023: What Your Business Must Do Now

Michael K. Onyekwere··10 min read

I've spent the last decade working in data protection across financial services: Royal Bank of Scotland, Fidelity, TMF Group. Most of that was GDPR. But the Nigeria Data Protection Act 2023 is the law I keep getting asked about now, because Nigerian businesses are waking up to it and realising they're not ready.

This guide is written for founders, CTOs, and compliance leads who need to know what the law actually requires so they can build systems that comply from the start.

Who the NDPA applies to

If your business touches data belonging to people in Nigeria, it applies to you. Specifically:

  • Your business is domiciled, resident or operating in Nigeria
  • The processing itself happens in Nigeria
  • You process the personal data of a data subject in Nigeria, wherever you are

Those are the three limbs of section 2(2), and the third is broader than GDPR's equivalent. GDPR asks whether you target or monitor people in the EU; the NDPA catches any processing of someone in Nigeria by a foreign business, full stop. Running analytics on Nigerian users from Dublin puts you in scope.

The GAID: the rulebook under the Act

One document sits under the NDPA that most summaries skip: the General Application and Implementation Directive (GAID) 2025, issued by the NDPC in March 2025 and fully in effect since 19 September 2025. It replaced the old NDPR, and it is where the operating detail lives: the registration tiers, the CAR template and fee bands, the DPIA filing requirement, the legitimate-interest assessment template, and the cross-border transfer framework. When this guide cites a procedure, the GAID is usually the instrument behind it. The full text is on the NDPC's site.

The principles, quickly

These mirror GDPR but enforcement is Nigerian, which changes the practical calculation. In short:

Have a reason for every piece of data you process. A real, named legal basis, well beyond "we might need it". More on that below.

Tell people what you're doing with their data. Before you do it, in language they understand, somewhere they will actually see it rather than a 40-page privacy policy nobody reads.

Only collect what you need. If your chatbot doesn't need someone's date of birth to answer a support question, don't collect it. This sounds obvious but I've seen countless systems hoovering up data "just in case."

Don't keep it forever. Set retention periods. Actually delete things when the period expires. CBN's 5-year AML retention requirement doesn't mean you keep everything for 5 years, just the transaction records they specifically require.

Protect it. Encryption, access controls, the basics. If you lose it or someone steals it, there are consequences.

Prove it. This is the one that separates paper compliance from real compliance. Documentation, audit trails, impact assessments. The NDPC wants evidence rather than assurances, and documentation is the evidence.

Lawful bases: which one to use

Every processing activity needs a legal basis. Six options:

Consent: the one everyone defaults to. Person agrees, you process. Has to be specific and freely given. Can be withdrawn. For AI systems, this is often a bad choice because withdrawing consent mid-processing creates operational chaos. Use it for marketing, not for core service delivery.

Contract: processing is necessary to deliver a service someone signed up for. Customer joins your fintech app, you process their data to provide the service. Usually the strongest basis for customer-facing AI.

Legal obligation: the law requires it. CBN AML monitoring is a clear example. The NDPA recognises that some processing is mandatory.

Vital interests: protecting someone's life. Rare outside healthcare.

Public interest: mostly government. You're probably not using this.

Legitimate interest: you have a genuine business reason that doesn't override individual rights. Fraud detection fits here. But you need a documented balancing test showing you've weighed your interest against the person's privacy. The NDPC guidance on this is still developing, which means the safe play is documenting thoroughly.

For AI: contract and legitimate interest cover most cases. Don't lean on consent unless you genuinely need it.

What you need to document

The NDPA is a documentation-heavy regime. Here's what you actually need:

Privacy notices. Before you collect data, people need to know who you are, what you're collecting, why, who sees it, how long you keep it, and how they can exercise their data subject rights. If your AI chatbot processes conversation data, the customer needs to see a privacy notice before the first message.

Records of processing. A register of every processing activity: what data, what subjects, what purpose, what legal basis, who receives it, retention periods, security measures. Sounds tedious. It is. But it's also the first thing the NDPC asks for in an investigation.

Data Protection Impact Assessments. Required when processing is high-risk, and most AI systems qualify: automated decision-making, new technology, large-scale processing. Under the GAID there is a second step people miss: for triggers like profiling, automated decisions with legal effects and systematic monitoring, the DPIA must also be filed with the Commission, which turns an internal document into a regulatory submission. Write the DPIA before you deploy, because retrofitting one after launch is expensive and visible.

Data Processing Agreements. Any third party that touches personal data on your behalf gets a DPA. Your AI provider (OpenAI, Anthropic, whoever), your cloud host, your analytics platform. The DPA covers what they can do with the data, how they secure it, and what happens when the relationship ends. Using ChatGPT API or Claude API? You need a DPA with them.

The NDPC: who's watching

The Nigeria Data Protection Commission replaced the old arrangement where NITDA handled privacy alongside everything else in IT regulation. The NDPC is dedicated, focused, and building capacity fast.

They can investigate, audit, issue compliance orders, and fine. Fines for a controller of major importance run to whichever is higher of ₦10 million or 2% of annual gross revenue for the preceding year. Those numbers are in the Act itself.

Two things you need to know about NDPC compliance:

The Compliance Audit Return. Annual filing, made through a licensed DPCO for the Extra-High and Ultra-High tiers; Ordinary-High Level entities renew their NDPC registration directly instead. You're a controller or processor of major importance if you process the data of more than 200 data subjects in six months, provide commercial ICT services, or operate in a listed sector, and fintechs are Ultra-High Level by name. The standing deadline is 31 March each year; the 2026 cycle was extended once to 30 May 2026, and that date has now passed.

The Data Protection Officer. If you're classified as a DCMI/DPMI, you need one. Can be an internal hire or outsourced.

AI and the NDPA

This is the part I care about most, because it's where I see the most confusion.

Automated decisions. Section 37 bites where a decision about someone is made on a solely automated basis with legal or similarly significant effects: credit approvals, fraud blocks, loan pricing, insurance terms. The person then has the right to human intervention, to put their point of view, and to contest the decision, and your privacy notice has to disclose that this kind of decision-making exists. Keeping a human meaningfully in the loop takes you outside section 37, and is good practice even then. On explanations, source code stays private; "the model considers these factors and weighs them roughly like this" is the level required.

Training data. Personal data used to train models counts as processing. You need a lawful basis for it. And it should show up in your records of processing. The tricky part: once personal data is embedded in model weights, you can't easily honour a deletion request. Document this limitation upfront.

Cross-border transfers. Every API call to OpenAI sends data to the US. Every AWS backup may be stored in Ireland. Nigerian personal data leaving Nigeria needs documented safeguards under the GAID's transfer framework (adequacy evaluation under Schedule 5, or a transfer instrument approved by the Commission): standard contractual clauses, adequacy decisions (rare), or explicit consent for the transfer. Document every route.

WhatsApp bots. Nigeria runs on WhatsApp. If you're building a WhatsApp AI chatbot, every conversation is personal data processing. Consent or another lawful basis, privacy notice, retention policy. The informality of WhatsApp doesn't make the NDPA go away.

The CBN overlap

Financial services companies get hit from both sides. The NDPA governs your data processing. CBN directives govern your banking operations. They don't always agree.

Data retention conflict. CBN wants 5 years of transaction records for AML. The NDPA says don't keep data longer than necessary. Resolution: keep what CBN specifically requires for 5 years, apply NDPA minimisation to everything else. Document why you're keeping what you're keeping.

The June 2026 AML deadline. CBN mandates automated transaction monitoring. The NDPA requires a DPIA for that kind of large-scale automated processing. You need to satisfy both.

KYC data. CBN requires you to collect a lot of personal data for customer due diligence. The NDPA says minimise. The answer: collect exactly what CBN requires, not a byte more, and document the legal obligation as your lawful basis.

EU AI Act intersection

If your AI system's output reaches EU residents (diaspora customers, European business partners, anyone in the EU, the EU AI Act may also apply. It reaches beyond the EU, though on its own Article 2 tests rather than GDPR's.

The overlaps: AI Act requires risk classification, NDPA requires a DPIA. AI Act requires technical documentation, NDPA requires records of processing. Similar exercises, not identical ones. If you're a Nigerian fintech serving diaspora, you're potentially under three regulatory frameworks simultaneously.

We've written about managing the full regulatory stack, covering NDPA, CBN, GDPR and the AI Act in one programme.

What I'd tell you to do right now

If you're building or running AI systems in Nigeria:

Map your data. What personal data do you hold? Where did it come from? Where does it go? This exercise is unglamorous and nobody wants to do it. It's also the foundation of everything else.

Check your legal bases. For every processing activity, can you name the lawful basis? If the answer is "consent" for everything, rethink. Consent works, but it is fragile for AI.

Write DPIAs for your AI systems. Before deployment. The cost of a DPIA is a fraction of the cost of retrofitting compliance after a complaint.

Get DPAs in order. Every AI provider, every cloud host. Most of them have DPAs ready to sign. The failure is usually that nobody at the company has actually signed them.

Appoint a DPO. Internal or outsourced. If you're above the threshold, this isn't optional.

Engage a DPCO if your tier files through one. Extra-High and Ultra-High Level entities file the annual CAR through a licensed DPCO; Ordinary-High Level entities renew registration directly. Build the relationship now rather than the week before the deadline.

The NDPA isn't going away and enforcement is ramping up. The businesses that build compliance into their systems from the start will spend less, stress less, and never have to explain to a regulator why they didn't bother.

Start with an NDPA Readiness Diagnostic

If you need NDPA compliance advice or a compliant AI build, the first step is a written diagnostic. You get a written assessment with priced next steps.

NDPANigeriaData ProtectionComplianceAI