Skip to content
GRC, ISO 27001 and SOC 2

Nigeria's Data Protection Act 2023 (NDPA), explained for career starters

NDPA 2023 explained for cybersecurity beginners: who it covers, lawful bases, data subject rights, the 72-hour breach rule, DPOs, GAID and penalties.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 10 min read

The Nigeria Data Protection Act 2023 (NDPA) is Nigeria’s main law on how organisations collect, use, store and share personal data. It was signed on 12 June 2023, created the Nigeria Data Protection Commission (NDPC) as the regulator, and applies to any organisation processing the personal data of people in Nigeria, including organisations based abroad.

For anyone starting a career in cybersecurity, GRC or privacy in Nigeria, the NDPA isn’t optional background reading. It shapes incident response (there’s a 72-hour clock), access control, vendor management and much of the compliance work junior analysts actually do.

This article is an educational summary, not legal advice. Laws are interpreted by lawyers, regulators and courts, and the NDPC issues guidance that changes how the Act is applied. For any real decision, read the official text of the Act, check current guidance on ndpc.gov.ng, and get qualified legal advice.

Who does the NDPA apply to?

Section 2 says the Act applies to processing of personal data, by automated means or not, where:

  • the data controller or processor is domiciled in, resident in, or operating in Nigeria;
  • the processing happens in Nigeria; or
  • the controller or processor is outside Nigeria but is processing personal data of a data subject in Nigeria.

That third limb matters. A UK-based app with Nigerian users, or a foreign payroll provider handling Nigerian staff records, can fall within the Act.

Section 3 carves out processing done by individuals solely for personal or household purposes (your own phone contacts, for example), and gives limited exemptions for things like criminal investigation and national security, though some core duties still apply even then.

The key terms, in plain English

Term Meaning Example
Personal data Information about an identified or identifiable individual Name, phone number, BVN, NIN, IP address linked to a user
Sensitive personal data Special categories listed in the Act Genetic and biometric data (for identification), race or ethnic origin, religious beliefs, health, sex life, political opinions, trade union membership
Data subject The person the data is about A bank customer
Data controller Decides why and how the data is processed The bank
Data processor Processes data on the controller’s behalf The bank’s cloud or SMS provider
Controller/processor of major importance Organisations the Commission designates, by volume or by the value or significance of the data they process Banks, telcos, fintechs (see the GAID section below)

The principles (section 24)

Every controller and processor must make sure personal data is:

  1. processed fairly, lawfully and transparently;
  2. collected for specified, explicit and legitimate purposes, and not reused in incompatible ways;
  3. adequate, relevant and limited to the minimum necessary;
  4. kept no longer than necessary;
  5. accurate, complete and up to date; and
  6. processed with appropriate security, protecting against unauthorised access, loss, damage or breach.

Section 24 also requires appropriate technical and organisational measures to protect the confidentiality, integrity and availability of personal data, the CIA triad you’ll recognise from security fundamentals, and says controllers and processors owe a duty of care and must demonstrate accountability. “Demonstrate” is the word that creates GRC jobs: policies, records, assessments and evidence.

Lawful bases for processing (section 25)

Processing is lawful only if one of these applies:

  • Consent that has been given and not withdrawn, for a specific purpose;
  • necessary to perform a contract with the data subject (or take steps before one);
  • necessary to comply with a legal obligation;
  • necessary to protect vital interests of the data subject or another person;
  • necessary for a task in the public interest or exercise of official authority; or
  • necessary for legitimate interests of the controller, processor or a third party, but not where those interests override the person’s rights, conflict with the other bases, or go beyond what the person would reasonably expect.

Under section 26, the controller carries the burden of proving consent. Section 35 adds that withdrawing consent must be as easy as giving it. If a sign-up form takes one tap, unsubscribing shouldn’t need a branch visit.

Data subject rights (sections 34–38)

People whose data is processed have the right to:

  • access: confirmation of whether their data is processed, the purposes, recipients, retention, source, and the existence of automated decision-making, plus a copy in a commonly used electronic format;
  • rectification of inaccurate, out-of-date or misleading data;
  • erasure without undue delay where the data is no longer needed or there’s no lawful basis to keep it;
  • restriction of processing in certain circumstances;
  • withdraw consent at any time;
  • object to processing, with an absolute right to object to direct marketing;
  • not be subject to decisions based solely on automated processing, including profiling, with legal or similarly significant effects, subject to exceptions, and with rights to human intervention and to contest the decision; and
  • data portability: section 38 lets the Commission make regulations establishing this right.

For a security team, rights requests are an access-control problem: you must verify the requester’s identity before handing over anyone’s data. A careless “send me all my data” process is a gift to social engineers.

Security, DPIAs and processors

Section 39 requires appropriate technical and organisational measures for security, and gives pseudonymisation and encryption among the examples. It doesn’t prescribe a product list; it expects measures proportionate to the risk.

Section 28 requires a data privacy impact assessment (DPIA) before processing that is likely to result in high risk to people’s rights and freedoms. A DPIA describes the processing, assesses necessity and proportionality, assesses risks, and sets out the safeguards. If the risk stays high despite the measures, the controller must consult the Commission before processing.

Section 29 governs controllers' use of processors: a controller must make sure its processors also comply. That’s where vendor security questionnaires and contract clauses come from.

The 72-hour breach notification rule (section 40)

This is the part of the NDPA every incident responder in Nigeria should know by heart:

  • A processor that becomes aware of a breach must notify the controller that engaged it, describing the breach.
  • A controller must notify the Commission within 72 hours of becoming aware of a breach that is likely to result in a risk to people’s rights and freedoms.
  • Where a breach is likely to result in a high risk to data subjects, the controller must immediately communicate it to them in plain, clear language, including advice on how to protect themselves.
  • Notifications should include a point of contact, the likely consequences, and the measures taken or proposed.

Worked example: a fictional breach timeline

Acme Fintech (fictional) runs a savings app. Here’s how the clock works:

Time Event NDPA-relevant action
Mon 09:10 SOC alert: unusual bulk export from the customer database by a support account Open an incident; preserve logs
Mon 11:30 Investigation confirms about 4,000 customer records (names, phone numbers, account balances) were downloaded by an attacker using a phished support login Controller is now “aware” of a breach; the 72-hour clock is running
Mon 12:00 Account disabled, sessions revoked, MFA enforced for support staff Containment, recorded for the notification
Mon 14:00 DPO and legal assess risk: balances plus phone numbers enable targeted fraud calls High risk, so affected customers must be told immediately
Mon 17:00 Customers notified by in-app message and SMS with clear advice: “We will never call you to ask for your PIN or OTP” Section 40(3) communication
Wed 10:00 Notification filed with the Commission with the nature, categories and approximate numbers, contact point, consequences and measures Within 72 hours of awareness

Notice how security work feeds the legal duty. Without good logs, Acme couldn’t say how many records were affected or what kind of data, both of which the notification needs. Logging and monitoring are compliance controls as well as security ones.

Cross-border transfers (sections 41–43)

Personal data may only leave Nigeria if the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism giving an adequate level of protection, or if one of the exceptions in section 43 applies. The controller must record the basis for each transfer. Every Nigerian company using a foreign cloud, email or CRM platform has to think about this, which makes it a frequent GRC task.

Data controllers of major importance, DPOs and the GAID

The Act imposes extra duties on data controllers and processors of major importance (DCPMIs):

  • Register with the Commission (section 44).
  • Controllers of major importance must designate a Data Protection Officer (section 32) with expert knowledge of data protection law and practice. The DPO advises the organisation, monitors compliance and is the contact point for the Commission. The DPO can be an employee or engaged under a service contract.
  • Face a higher maximum penalty (see below).

In March 2025 the NDPC issued the NDP Act General Application and Implementation Directive (GAID), available on ndpc.gov.ng. It turns the Act’s duties into operational rules. Among other things, the GAID:

  • classifies DCPMIs into Ultra-High Level, Extra-High Level and Ordinary-High Level tiers, using factors such as data sensitivity, the number of data subjects processed and the type of organisation (it names, for example, commercial banks, telecoms companies, insurers and fintechs in the Ultra-High tier);
  • requires Ultra-High and Extra-High DCPMIs to file Compliance Audit Returns (CAR) with the Commission by 31 March each year; and
  • states that the Commission would stop applying the Nigeria Data Protection Regulation (NDPR) 2019 as a legal instrument once the GAID was issued, without affecting anything done under the NDPR before then.

Section 33 also lets the Commission license Data Protection Compliance Organisations (DPCOs) to monitor, audit and report on compliance. The NDPC publishes its DPCO requirements and registration portal online. Tier thresholds, fees and filing details are exactly the kind of thing the regulator updates, so always check the current guidance on ndpc.gov.ng.

Penalties (section 48)

After an investigation, the Commission can order an organisation to remedy the violation, pay compensation to people who suffered harm, account for profits made from the violation, or pay a penalty or remedial fee. The maximum fee is:

Organisation Maximum penalty or remedial fee
Controller or processor of major importance The greater of ₦10,000,000 or 2% of annual gross revenue in the preceding financial year
Controller or processor not of major importance The greater of ₦2,000,000 or 2% of annual gross revenue in the preceding financial year

Section 48 also tells the Commission what to weigh when deciding sanctions, including the nature, gravity and duration of the infringement and the number of data subjects involved. These administrative sanctions apply “notwithstanding any criminal sanctions” under the Act.

What the NDPA means for your career

The Act has created real, everyday work. Typical tasks you could be doing in a junior role:

  • Records of processing: mapping what personal data the organisation holds, why, where it lives and who it’s shared with.
  • DPIAs: helping assess a new product or system before launch.
  • Vendor reviews: checking processors' security and contract terms, and recording transfer bases.
  • Breach readiness: building the incident playbook step that starts the 72-hour clock, and running tabletop exercises.
  • Rights requests: designing a verification process so data goes to the right person.
  • Audit support: gathering evidence for compliance audit returns.

People coming from audit, law, banking operations or administration often already have half these skills. If that’s you, read moving into GRC from audit, legal, banking or admin. For the wider picture of the role, see what a GRC analyst does.

A study checklist

  1. Read sections 1–3, 24–26 and 28–48 of the Act. It’s shorter than you’d expect.
  2. Skim the GAID’s sections on DCPMI classification, compliance audit returns and breach notification.
  3. Draw a data map for a fictional company: what data, which systems, which suppliers, which countries.
  4. Write a one-page breach notification for the Acme scenario above.
  5. Compare the NDPA with the UK GDPR or EU GDPR on two points (lawful bases and breach notification). Diaspora employers value people who can work across both.

Questions

Is the NDPR still in force?

The GAID states that the NDPC ceased to apply the NDPR 2019 as a legal instrument on the GAID's issuance, without affecting things done under it before. The NDPA and the GAID are now the instruments to work from. Check ndpc.gov.ng for the latest position.

Does the NDPA apply to foreign companies?

It can. Section 2 covers controllers and processors outside Nigeria that process personal data of data subjects in Nigeria.

How fast must a breach be reported under the NDPA?

A controller must notify the Commission within 72 hours of becoming aware of a breach likely to risk people's rights and freedoms, and must inform affected people immediately where the risk to them is high.

Do I need a law degree to work in data protection?

No. Many privacy and GRC roles are filled by people from security, audit, risk and operations backgrounds. Legal knowledge helps, and you'll work alongside lawyers, but the day-to-day work is often process, evidence and technical controls.