Law / Nigeria

Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Nigeria Data Protection Act 2023 (No. 37 of 2023), general duties (ss. 1-3, 24-29, 32-33, 39 and 63-65; GAID 2025, arts. 1-17, 19-32, 34-35 and 41-42)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 12 June 2023.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Register with the Commission as a data controller or data processor of major importance where the Commission so determines, conduct a compliance audit within fifteen months of commencing business and annually thereafter, and file Compliance Audit Returns by 31 March each year in the Ultra-High and Extra-High Level categories.
  • Tell the Commission of any significant change to the information in your most recent registration submission within sixty days of the change.
  • Designate a Data Protection Officer as section 32 of the Act mandates, give the officer the position the Directive prescribes, and have the officer prepare semi-annual data protection reports.
  • Process personal data on one of the lawful bases section 25 recognises, and hold to the section 24 principles of fairness, lawfulness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, confidentiality, integrity and availability.
  • Take consent for cookies and other tracking tools freely, informed and specific, display a conspicuous cookie banner at the first part of the page, and let a data subject reject every cookie other than the necessary ones that carry security, network stability and accessibility.
  • Carry out a Data Privacy Impact Assessment where required, including where deploying software to process sensitive personal data, and file it with the Commission.
  • Before deploying data processing software that tracks a data subject or opens a communication link with one, carry out an impact assessment, design it for privacy by design and by default, put a data privacy policy inside the software, and give a prospective user a privacy statement before installation.
  • Put a Data Processing Agreement in place with any data processor you engage, setting out the obligations of both parties under section 29 of the Act.
  • Follow schedules for monitoring, evaluating and maintaining the data security system, and for organisation-wide internal sensitisation and training on data privacy.

What it reaches

Obligation class

Consent, Security, Governance, DPIA, Reporting

Who checks it

Audit expectation

periodic

Who audits it

Self, Registered or designated auditor

Where the report goes

Filed with regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 7 of the Directive lists the general compliance measures the Act expects of every data controller and data processor: registering with the Commission as one of major importance where the Commission so determines, conducting a compliance audit within fifteen months of commencing business and annually thereafter, filing Compliance Audit Returns by 31 March each year in the Ultra-High and Extra-High Level categories, identifying every obligation under the Act and scheduling compliance with it, keeping semi-annual data protection reports, and following schedules for monitoring, evaluating and maintaining the data security system and for internal sensitisation and training.

Article 9 governs registration as a data controller or data processor of major importance, requires the Ultra-High and Extra-High Level categories to register once and file Returns annually, requires the Ordinary-High Level category to renew registration annually instead, and requires notice to the Commission of any significant change to registered information within sixty days.

Articles 11 to 14 govern the designation, position, semi-annual reporting and credential assessment of the Data Protection Officer that section 32 of the Act mandates. Articles 15 to 17 and 20 to 26 carry the principles of section 24 and the lawful bases of section 25, and article 19 governs consent to cookies and other tracking tools.

Article 28 carries the Data Privacy Impact Assessment that section 28 of the Act mandates where processing may result in high risk, article 29 the monitoring, evaluation and maintenance of the data security system that section 39 requires, article 31 the duties that attach to deploying data processing software, and article 34 the Data Processing Agreement that section 29(2) requires between a controller and its processor.

The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.

When LexLint raises it

  • high_risk_decisions
  • automated_outreach
  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

General Application and Implementation Directive (GAID) 2025
an official regulatory instrument issued by the Nigeria Data Protection Commission under sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act, 2023, which quotes and implements the Act's provisions in detail a directly hosted copy of the Act's own gazetted text was not found among the sources reviewed

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app