Law / Nigeria

Nigeria

10 of 15 named instruments researched to a stage, across five of the six areas of law we track: 10 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (201 words)

Nigeria's comprehensive personal-data regime is the Nigeria Data Protection Act, 2023 (No. 37 of 2023), enforced by the Nigeria Data Protection Commission (NDPC) and implemented in detail by the NDPC's General Application and Implementation Directive (GAID) 2025.

The Act requires consent for processing sensitive personal data, for further processing incompatible with the original purpose, for transferring personal data to a country the Commission has not made an adequacy decision for, and before a data controller makes a decision based solely on automated processing that produces legal effects concerning a data subject.

A data controller must notify the Commission of a personal data breach likely to result in a risk to individuals' rights and freedoms within 72 hours of becoming aware of it, and must notify affected data subjects immediately where the breach is likely to result in a high risk.

Cross-border transfer proceeds on an adequacy decision by the Commission, a Commission-approved cross-border data transfer instrument such as binding corporate rules or standard contractual clauses, or another lawful ground including consent or a compelling legal or fiduciary duty. Data subjects hold rights to rectification, data portability, erasure (described as a right to be forgotten), and lodging a complaint with the Commission.

Breach notification

Nigeria Data Protection Act, 2023, data breach notification

Nigeria Data Protection Act, 2023, data breach notification (s. 40; GAID 2025, art. 33)General Application and Implementation Directive (GAID) 2025

In force since 12 June 2023. Binds public and private bodies.

What this law does

Article 33(1) quotes section 40(2) of the Act: a data controller shall, within 72 hours of becoming aware of a breach which is likely to result in a risk to the rights and freedoms of individuals, notify the Commission of the breach and, where feasible, describe its nature including the categories and approximate numbers of data subjects and personal data records concerned.

Article 33(2) fixes when a breach is likely to result in a high risk: where, considering its nature, the personal data involved and the probability of reaching the data subject's other personal data through it, the data subject may become a victim of fraud, identity theft or exposure of sensitive personal data. Article 33(3) requires the controller to notify affected data subjects immediately after becoming aware of the breach, so that they are not unlawfully targeted as a result of it.

Article 33(4) requires immediate information to the Commission and every other relevant authority, whatever the time otherwise allowed, where that may help contain an imminent breach on a national scale or where containment may be needed nationally, sectorally or individually, or where the breach may affect the general public.

Article 33(5) fixes the content of the notification: the circumstances of the loss or unauthorised access or disclosure, the date or time period it occurred over, a description of the personal information involved, an assessment of the risk of harm, an estimate of the number of individuals at real risk of significant harm, the steps taken to reduce that harm, the steps taken to notify individuals, and the name and contact details of a person who can answer for the organisation.

The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.

What it requires

Comprehensive regime

Nigeria Data Protection Act, 2023 (NDPA), general data protection duties

Nigeria Data Protection Act 2023 (No. 37 of 2023), general duties (ss. 1-3, 24-29, 32-33, 39 and 63-65; GAID 2025, arts. 1-17, 19-32, 34-35 and 41-42)General Application and Implementation Directive (GAID) 2025

In force since 12 June 2023. Binds public and private bodies.

What this law does

Article 7 of the Directive lists the general compliance measures the Act expects of every data controller and data processor: registering with the Commission as one of major importance where the Commission so determines, conducting a compliance audit within fifteen months of commencing business and annually thereafter, filing Compliance Audit Returns by 31 March each year in the Ultra-High and Extra-High Level categories, identifying every obligation under the Act and scheduling compliance with it, keeping semi-annual data protection reports, and following schedules for monitoring, evaluating and maintaining the data security system and for internal sensitisation and training.

Article 9 governs registration as a data controller or data processor of major importance, requires the Ultra-High and Extra-High Level categories to register once and file Returns annually, requires the Ordinary-High Level category to renew registration annually instead, and requires notice to the Commission of any significant change to registered information within sixty days.

Articles 11 to 14 govern the designation, position, semi-annual reporting and credential assessment of the Data Protection Officer that section 32 of the Act mandates. Articles 15 to 17 and 20 to 26 carry the principles of section 24 and the lawful bases of section 25, and article 19 governs consent to cookies and other tracking tools.

Article 28 carries the Data Privacy Impact Assessment that section 28 of the Act mandates where processing may result in high risk, article 29 the monitoring, evaluation and maintenance of the data security system that section 39 requires, article 31 the duties that attach to deploying data processing software, and article 34 the Data Processing Agreement that section 29(2) requires between a controller and its processor.

The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.

What it requires

Cross border transfer

Nigeria Data Protection Act, 2023, cross-border data transfer

Nigeria Data Protection Act, 2023, cross-border data transfer (Part VIII; GAID 2025, art. 45 and Schedule 5)General Application and Implementation Directive (GAID) 2025

In force since 12 June 2023. Binds public and private bodies.

What this law does

Article 45 states that Part VIII of the Act provides for cross-border data transfer and, by section 63, is the overarching governing provision for every transfer of personal data out of Nigeria; pending any further regulatory instrument, the explanatory note in Schedule 5 is used to evaluate countries for adequacy and for the other grounds the Act recognises, and the Commission is to weigh the enforcement of fundamental rights and the decisions of courts advancing fundamental freedoms in a jurisdiction it considers.

Schedule 5 lists the grounds for transfer as an adequacy decision by the Commission, a Cross-Border Data Transfer Instrument the Commission approves, and other lawful bases, and sets out what the Commission weighs in adjudging a country adequate under section 42(2) of the Act: enforceable data subject rights with administrative or judicial redress and the rule of law, any instrument between the Commission and a competent authority in the recipient jurisdiction, the terms on which a public authority there reaches personal data, the existence of an effective data protection law that is in force and not subject to an overriding law, and a functioning independent supervisory authority with adequate enforcement powers.

The instruments the Commission may approve in the absence of an adequacy decision are codes of conduct, certifications, binding corporate rules and standard contractual clauses. Consent is separately required before personal data may be transferred to a country for which the Commission has made no adequacy decision.

The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.

What it requires

Data subject rights

Nigeria Data Protection Act, 2023, rights of a data subject

Nigeria Data Protection Act, 2023, rights of a data subject (ss. 27 and 46; GAID 2025, arts. 27 and 36-40)General Application and Implementation Directive (GAID) 2025

In force since 12 June 2023. Binds public and private bodies.

What this law does

Article 27 requires the information given to a data subject under section 27 of the Act to be clear and to take the data subject's circumstances into account.

Article 36 makes the right to rectification part of the accuracy principle, requires the platform through which personal data is processed to give an effective opportunity to rectify, bars requiring an affidavit or a newspaper publication where the correction aligns the data with the data subject's National Identification Number, and bars charging a data subject to correct an error that was not their fault.

Article 37 gives a right to data portability where the data subject supplied the personal data on the basis of consent or where the processing is necessary to perform a contract, without prejudice to the rights of other data subjects in the same set or to the right of erasure.

Article 38 gives a right to be forgotten where the data is no longer necessary for the purpose it was collected for, where consent is withdrawn and was the lawful basis, where the data subject objects to processing founded on legitimate interest and no overriding ground exists, where the processing is for direct marketing and the data subject objects, where the processing was unlawful, or where erasure is needed to comply with a legal ruling or obligation.

Article 39 makes the right to lodge a complaint with the Commission a threshold right of redress under section 37 of the 1999 Constitution and section 46 of the Act, and requires every instrument about processing personal data to carry a clause on it. Article 40 provides the Standard Notice to Address Grievance in Schedule 9, which an aggrieved data subject may serve directly on a controller or processor without it being a condition of complaining to the Commission.

Article 43(2)(a) carries the right of a data subject not to be subject to a decision solely based on automated processes or algorithms. The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.

What it requires

Enforcement supervision

Nigeria Data Protection Act, 2023, complaints, enforcement and redress

Nigeria Data Protection Act, 2023, complaints and enforcement (ss. 46 and 48; GAID 2025, arts. 39, 47 and 48)General Application and Implementation Directive (GAID) 2025

In force since 12 June 2023. Binds public and private bodies.

What this law does

Article 39 makes the right to lodge a complaint with the Nigeria Data Protection Commission a threshold right of redress under section 37 of the 1999 Constitution and section 46 of the Act, requires the Commission to run an electronic platform for complaints and to acknowledge one within seven days while continuing to accept complaints by any reasonable means, and requires it to carry out a preliminary evaluation of each complaint; a Pre-Action Conference may be held as often as a complaint or an investigation under section 46(3) needs.

Article 47 confirms that a data subject may seek redress for a violation of their data privacy rights in court, and treats proximity and access to courts as part of what national adequacy means.

Article 48 governs how the Commission weighs evidence of compliance: registration, annual Compliance Audit Returns, a filed impact assessment and an approved cross-border transfer instrument show accountability and prima facie good faith, but do not replace concrete evidence in defence of a complaint about any other provision, and the Commission treats accountability as partial fulfilment of the cooperation section 48(6)(f) of the Act requires.

Article 49 makes the safeguarding of a data subject's constitutional privacy right the overriding consideration in judging whether an obligation was met in time. The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.

What it requires

Sensitive categories

Nigeria Data Protection Act, 2023, sensitive personal data and a child's data

Nigeria Data Protection Act, 2023, sensitive personal data and a child's data (GAID 2025, arts. 18 and 43)General Application and Implementation Directive (GAID) 2025

In force since 12 June 2023. Binds public and private bodies.

What this law does

Article 18(1) makes consent a requirement, on top of anything else the Act demands, for any direct marketing activity, for processing sensitive personal data, for further processing incompatible with the original purpose, for processing the personal data of a child, before personal data may be transferred to a country the Commission has made no adequacy decision for, and before a data controller makes a decision based solely on automated processing that produces legal effects concerning or significantly affecting the data subject; article 18(2) makes the Compliance Audit Returns state whether the controller or processor relies on consent for any of those activities.

Article 20(2) bars consent from being sought, given or accepted in any circumstance that may propagate atrocities, hate, child rights violations or criminal acts.

Article 43 binds a controller or processor deploying an emerging technology such as artificial intelligence, the Internet of Things or blockchain to set technical and organisational parameters for the processing that take account of the data subject's right not to be subject to a solely automated decision, the right to be forgotten, safeguards for processing sensitive personal data, safeguards for child rights and other vulnerable groups, the regulation of cross-border data flows, and privacy by design and by default; those parameters are documented and filed with the Commission as part of the Returns, and an impact assessment must weigh disparate outcomes and the Data Subjects' Vulnerability Indexes in Schedule 6.

The General Application and Implementation Directive 2025, which carries the text quoted here, is made under section 37 of the 1999 Constitution and sections 1(a), 6(c), 61 and 62 of the Nigeria Data Protection Act 2023, an Act in force since 12 June 2023.

What it requires

Scraping law1 instrument, 1 in force

Research summary (252 words)

Nigeria has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 criminalises intentionally accessing a computer system or network without authorisation, but section 6(1)'s offence is conditioned on the access being for a fraudulent purpose and obtaining data vital to national security, so a plain reading does not reach ordinary scraping of a public, unauthenticated page absent that fraud and national-security element, and no reported Nigerian case has tested the provision against a scraper.

No Nigerian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act, 2022 permits fair dealing for private use, non-commercial research and private study, criticism, review, or the reporting of current events, and separately excepts news of the day for public broadcast or other public communication, but Nigeria has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general fair-dealing ground if it can be characterised as non-commercial research.

The Copyright Act confers no sui generis database right, and its related rights cover performers, sound recordings, broadcasts, and expressions of folklore, not databases as such. The Nigeria Data Protection Act, 2023 applies to processing personal data generally, and does not appear to state a general exemption for personal data a data subject has made publicly available.

No Nigerian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, unlawful access to a computer

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, s. 6 (unlawful access to a computer)Cybercrimes (Prohibition, Prevention, etc.) Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.cert.gov.ng/ngcert/resources/CyberCrime__Prohibition_Prevention_etc__Act__2015.pdf

In force. Binds public and private bodies.

What this law does

Section 6(1) makes it an offence for any person, without authorisation, to intentionally access in whole or in part a computer system or network for a fraudulent purpose and to obtain data vital to national security, punishable by imprisonment for not more than five years or a fine of not more than N5,000,000, or both.

Section 6(2) raises the penalty to imprisonment for not more than seven years or a fine of not more than N7,000,000, or both, where the access is committed with the intent of obtaining computer data, securing access to a program, or obtaining commercial, industrial, or classified information.

Section 6(1)'s own text conditions the offence on a fraudulent purpose and on the data obtained being vital to national security, so a plain reading of that subsection does not reach ordinary scraping of a public, unauthenticated page absent both elements; section 6(2)'s aggravated form reaches a wider set of intents but is only reached once subsection (1)'s unauthorised-access element is made out. No reported Nigerian decision has applied section 6 to a scraper.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (412 words)

Nigeria's one confirmed standalone security duty reaching a general operator of a computer system is section 21 of the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015: any person or institution, whether public or private, that operates a computer system or network in Nigeria must immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of an attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network, and a person or institution that fails to report such an incident to the National CERT within 7 days of its occurrence commits an offence, punishable by denial of internet services and a mandatory fine of N2,000,000 payable into the National Cyber Security Fund.

No product-security-requirements statute was found: NITDA's Certification and Licensing of Original Equipment Manufacturers scheme and its National Software Testing Guideline require registration, sample-model testing, and a fee before an IT product or device may be sold in Nigeria, but NITDA's own published description states the scheme's purpose as curbing piracy and substandard goods and promoting local software, not as a security, vulnerability-handling, or update-support requirement, so it is not filed here.

NITDA's Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, this jurisdiction's other topics' instrument, is a content-moderation and platform-governance code with no vulnerability-handling or incident-reporting clause of its own.

The Central Bank of Nigeria is understood to maintain a sector-specific risk-based cybersecurity framework for deposit money banks and payment service providers, but cbn.gov.ng returned a Cloudflare CAPTCHA challenge rather than the framework's text, so its terms are not confirmed here; being bound to a licensed financial-sector status no LexLint activity can express, it would be deferred rather than flagged even if confirmed.

No standalone reasonable-security baseline statute binding a general business with no sector gate was found.

The Nigeria Data Protection Act, 2023 and its General Application and Implementation Directive (GAID) 2025 impose their own security-of-processing duty, Article 29's schedules for monitoring, evaluation, and maintenance of a data security system, but that is a comprehensive data-protection regime's own safeguards article and stays with this jurisdiction's privacy row rather than being re-filed here.

Likewise, the Cybercrimes Act's section 6 offence of unauthorised access to a computer system binds the intruder, not the operator or manufacturer, and stays with this jurisdiction's scraping row. Project research notes reference a 2024 amendment to the Cybercrimes Act, but no checked publisher served its text, so nothing about its content is asserted here beyond the 2015 Act text quoted below.

Vulnerability and incident reporting

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT

Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, section 21, Reporting of Cyber ThreatsCybercrimes (Prohibition, Prevention, etc.) Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2023. Publisher's page: https://www.cert.gov.ng/ngcert/resources/CyberCrime__Prohibition_Prevention_etc__Act__2015.pdf

In force. Binds public and private bodies.

What this law does

Section 21 of the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 requires any person or institution, whether public or private, that operates a computer system or network in Nigeria to immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network, so that the National CERT can take the necessary measures to address the issue.

The National CERT Coordination Center may propose isolating an affected computer system or network pending resolution. A person or institution that fails to report such an incident to the National CERT within 7 days of its occurrence commits an offence and is liable to denial of internet services, and must in addition pay a mandatory fine of N2,000,000 into the National Cyber Security Fund.

The Office of the National Security Adviser is the Act's own coordinating body for all security and enforcement agencies under it.

What it requires

Age gating law1 instrument, 1 in force

Research summary (172 words)

Nigeria has no dedicated adult-content age-verification statute, social-media minor-access restriction, or app-store age-verification requirement. The Child's Rights Act, 2003 (Act No. 26 of 2003) sets Nigeria's general framework of children's rights and protections, including against sexual abuse and exploitation, but its text contains no reference to the internet or an online service.

The Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 criminalises producing, distributing, offering, or possessing child pornography by means of a computer or network, but this is a criminal prohibition on the content itself rather than an age-verification or age-gating duty on a service provider, and it does not impose a duty tied to the user's age.

The closest instrument to an age-appropriate design code is the National Information Technology Development Agency's Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, 2022, which requires a Platform to label, censor, redact, or otherwise control access so that content inappropriate for a child is not viewable to a child, and to inform users not to create, publish, or share content harmful to a child.

Age-appropriate design code

Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, child-content control duty

NITDA Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, 2022, Part IICode of Practice for Interactive Computer Service Platforms/Internet Intermediaries

In force since 26 September 2022. Binds private bodies.

What this law does

The Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries, issued by the National Information Technology Development Agency (NITDA) under section 6 of the NITDA Act, 2007 in collaboration with the Nigerian Communications Commission and the National Broadcasting Commission, applies to all Interactive Computer Service Platforms and Internet Intermediaries operating in Nigeria, a term the Code defines broadly to include social media operators, websites, blogs, media-sharing sites, discussion forums, streaming platforms, and gaming platforms.

Part II requires a Platform to label, censor, redact, or otherwise apply access control so that content inappropriate for a child, such as sexually explicit content or images of violence, is not viewable to a child. Part II also requires a Platform to inform users through its terms of service not to create, publish, modify, transmit, store, or share content harmful to a child.

A Platform must also give consideration, in assessing whether content is harmful, to the risk that its dissemination could have a physical or psychological impact on a child or an adult, and must ensure its community rules specify how children will be protected from harmful content they may encounter.

The Code does not itself prescribe an age-verification mechanism, and non-compliance is stated to be a breach of the Nigerian Communications Act, 2003, the National Broadcasting Commission Act, 2004, and the NITDA Act, 2007, rather than a penalty set out in the Code itself.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (195 words)

Nigeria has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act, 2022 (Act No. 8 of 2022) is the only law reaching an aggregator's reproduction of news content.

Its fair dealing exceptions permit, among other things, quotations in the form of short excerpts from a work, criticism, review, or the reporting of current events subject to a fairness test, and separately except news of the day for public broadcast or other public communication; no reported Nigerian decision applies these exceptions to a systematic news aggregator as opposed to an individual quoting or reporting on a published work.

Related rights under the Act protect performers, sound recordings, broadcasts, and expressions of folklore, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or case law located addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law was found. The Act contains no text-and-data-mining exception or machine-readable reservation mechanism.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.