Nigeria flag

Nigeria

Nigeria Data Privacy Laws: NDPA 2023 and GAID 2025 Compliance Guide

Independently fact-checked against primary sources (last audited June 19, 2026). · 6 primary sources cited on this page. How we verify our legal content

Nigeria Data Privacy Laws: NDPA 2023 and GAID 2025 Compliance Guide

Frequently Asked Questions

What is the Nigeria Data Protection Act 2023?

The Nigeria Data Protection Act 2023 (NDPA) is Nigeria's first comprehensive data protection statute, enacted by the National Assembly and signed into law on June 12, 2023. It replaced the Nigeria Data Protection Regulation 2019 (NDPR), which was a secondary regulatory instrument rather than primary legislation. The NDPA establishes the Nigeria Data Protection Commission (NDPC), sets out data subject rights, defines obligations on data controllers and processors, and creates a tiered penalty structure for non-compliance.

What is the GAID 2025 and when did it take effect?

The General Application and Implementation Directive 2025 (GAID) is the NDPC's implementing directive for the NDPA. The NDPC issued it on March 20, 2025, and it became effective on September 19, 2025, after a six-month transition period. The GAID contains 52 articles and 10 schedules covering DCPMI registration, Compliance Audit Returns, DPO requirements, consent rules, cross-border transfers, cookie notices, and the SNAG system. The GAID retired the NDPR 2019 as a legal instrument.

Who must register with the NDPC as a DCPMI?

An organization must register as a Data Controller or Processor of Major Importance (DCPMI) if it processes personal data of 200 or more data subjects within any six-month period. The GAID 2025 defines three tiers: Ordinary High Level (OHL) covers 200-999 data subjects in six months; Extra High Level (EHL) covers 1,000-4,999; Ultra High Level (UHL) covers 5,000 or more. Organizations that provide commercial ICT services storing others' personal data, or that operate in any of the 14 designated sectors (including financial services, health, education, telecommunications, e-commerce, and insurance), also qualify regardless of data subject volume. Registration must occur within six months of first meeting any qualifying threshold.

Does the NDPA apply to foreign companies?

Yes. Under Section 2 of the NDPA, the Act applies to any organization, regardless of where it is based, that processes personal data of individuals in Nigeria or offers goods or services to people in Nigeria. A foreign company with no physical presence in Nigeria is still subject to the NDPA if it targets Nigerian data subjects. This extraterritorial reach has been applied in the Meta enforcement actions.

What is the breach notification deadline under the NDPA?

Data controllers must notify the NDPC of a personal data breach within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to data subjects' rights and freedoms, affected individuals must be notified without undue delay. Data processors must notify the relevant controller without undue delay so the controller can meet the 72-hour window.

What are the maximum penalties under the NDPA?

Data controllers or processors of major importance face fines of up to NGN 10 million or 2% of annual gross revenue, whichever is higher. Other organizations face fines of up to NGN 2 million or 2% of annual gross revenue, whichever is higher. Failure to comply with NDPC enforcement orders can also lead to imprisonment of up to one year for responsible individuals. The NDPC may also issue enforcement notices, order cessation of processing, and mandate independent compliance audits.

Can personal data be transferred out of Nigeria?

Yes, but only under conditions set out in Sections 41 to 43 of the NDPA and Schedule 5 of the GAID 2025. Transfers are permitted if the destination country has an NDPC adequacy decision; if the controller uses NDPC-approved Standard Contractual Clauses or Binding Corporate Rules; if the data subject gives explicit, informed consent to the specific transfer; or if the transfer is necessary for contract performance or vital interests. The NDPC has not yet published a formal adequacy list under the NDPA/GAID framework, so most organizations currently rely on contractual safeguards.

What happened to the Meta fine in Nigeria?

Two separate enforcement actions targeted Meta. The FCCPC, jointly with the NDPC, imposed a $220 million penalty in July 2024, upheld by the Competition and Consumer Protection Tribunal on April 25, 2025; those proceedings continue as of mid-2026. Separately, the NDPC imposed a $32.8 million NDPA penalty in February 2025. On October 30, 2025, the NDPC and Meta signed a confidential settlement, converted to a Federal High Court consent judgment on November 3, 2025, under which Nigeria waived the entire $32.8 million NDPA penalty and required Meta to pay only the government's legal fees.

What is a DCPMI Compliance Audit Return and who must file one?

A Compliance Audit Return (CAR) is an annual filing that Ultra-High Level (UHL) and Extra-High Level (EHL) DCPMIs must submit to the NDPC through a licensed Data Protection Compliance Organisation (DPCO). The CAR documents the organization's data protection practices, DPO details, processing activities, and security measures. The 2025 CAR deadline was extended to May 30, 2026. Ordinary-High Level (OHL) DCPMIs must register and appoint DPOs but are not required to engage a DPCO for CAR filing.

What is the constitutional basis for data protection in Nigeria?

Data protection in Nigeria is grounded in Section 37 of the Constitution of the Federal Republic of Nigeria 1999 (as amended), which guarantees the privacy of citizens' homes, correspondence, telephone conversations, and telegraphic communications. Section 37 is a justiciable fundamental right enforceable in the Federal High Court or State High Courts under Section 46(1) of the Constitution. The NDPA's preamble and Section 1 expressly state that the Act was enacted to safeguard data subjects' fundamental rights as guaranteed under the Constitution.

Updates

Independently fact-checked against the cited primary sources

Full audit-and-evolve refresh: added constitutional basis (Section 37), corrected DCPMI thresholds, expanded GAID 2025 coverage, updated Meta enforcement to reflect NDPC settlement waiver (October 2025), added 2026 enforcement actions including 649-institution education sector notice, expanded cross-border transfer section, added CAR deadline extension to 30 May 2026.

Initial publication covering NDPA 2023 framework, NDPC establishment, GAID 2025 issuance, penalty structure, and Meta/FCCPC enforcement action.

Sources and References

  1. Nigeria Data Protection Act, 2023 (Full Text)(cert.gov.ng).gov
  2. NDPA General Application and Implementation Directive (GAID) 2025(ndpc.gov.ng).gov
  3. Nigeria Data Protection Commission (NDPC) Official Website(ndpc.gov.ng).gov
  4. Nigeria Data Protection Regulation 2019 (NDPR)(nitda.gov.ng).gov
  5. NDPC Guidance Notice on Registration of DCPMIs (Updated 2024)(ndpc.gov.ng).gov
  6. FCCPC: Tribunal Upholds $220 Million Fine Against Meta/WhatsApp (April 2025)(fccpc.gov.ng).gov
  7. Meta, NDPC agree out-of-court settlement; $32.8M NDPA fine waived (Nov 2025)(techpoint.africa)
  8. NDPC fines Multichoice Nigeria NGN 766.2 million (Jun 2025)(dataguidance.com)
  9. NDPC Compliance Notices to 1,368 Organizations (Aug 2025)(techpoint.africa)
  10. NDPC Education Sector Compliance Notice, 649 Institutions (Feb 2026)(aluko-oyebode.com)
  11. NDPC Extends 2025 CAR Deadline to 30 May 2026(pavestoneslegal.com)
  12. Data Protection Laws and Regulations: Nigeria 2025-2026 (ICLG)(iclg.com)
  13. Nigeria Data Protection Landscape: 2026 Outlook (Mondaq)(mondaq.com)
Share: