The Regulatory Framework: From NDPR 2019 to the Nigeria Data Protection Act 2023

The regulatory environment for data privacy in Nigeria has undergone a significant transformation. What began as the Nigeria Data Protection Regulation (NDPR) in 2019 has now matured into a robust primary legislation: the Nigeria Data Protection Act (NDPA) 2023. This evolution signals a clear message from the Nigeria Data Protection Commission (NDPC): data privacy is no longer a discretionary 'best practice' but a mandatory statutory obligation for every organisation operating within the Nigerian borders. As a Senior Data Protection and Compliance Officer, I have observed numerous organisations struggling to align their operations with these stringent requirements. The transition from a regulation to a full-fledged Act has increased the severity of penalties and the breadth of oversight, making it imperative for Nigerian companies to identify and rectify common compliance errors before they attract the attention of the regulator.

1. The 'Copy-Paste' Privacy Policy Syndrome

One of the most frequent mistakes made by Nigerian startups and established firms alike is the adoption of generic privacy policies. Many companies simply copy policies from international tech giants or foreign websites, failing to realise that Nigerian law has specific requirements that differ from the GDPR or the CCPA. A privacy policy under the NDPA 2023 must be specific, transparent, and accessible. It must clearly state the lawful basis for processing, the specific categories of data collected, and the contact details of the Data Protection Officer. Furthermore, it must address the specific rights of Nigerian data subjects, such as the right to lodge a complaint with the NDPC. A generic policy often fails to mention the 'Administrative Redress Panel' or the specific timelines for data retention required by Nigerian financial or telecommunications laws, rendering the document legally insufficient during a compliance audit.

2. Misunderstanding the Role and Necessity of a Data Protection Officer (DPO)

There is a widespread misconception that only large multinational corporations require a Data Protection Officer. Under the NDPA 2023, the requirement to designate a DPO is based on the nature, scale, and complexity of the data processing activities. Many Nigerian companies fail to appoint a DPO or, worse, appoint an individual with a clear conflict of interest, such as the Head of IT or the Chief Technology Officer. The DPO must function with a degree of independence, reporting directly to the highest level of management. Their role is to monitor compliance, provide advice, and act as a point of contact for the NDPC. Failing to appoint a qualified DPO—or appointing one who lacks the requisite knowledge of Nigerian data protection laws—is a critical failure that can lead to significant fines during the annual audit process.

3. Missing the Mandatory March 15th Audit Deadline

The Nigerian data protection framework is unique due to its outsourced oversight model involving Data Protection Compliance Organisations (DPCOs). Every organisation that processes the personal data of more than 2,000 data subjects in a period of 12 months (or 1,000 in 6 months) is required to conduct an annual audit and file a report with the NDPC by the 15th of March each year. A common mistake is the assumption that this deadline is flexible. It is not. Failure to file this audit report is often the first red flag that triggers a formal investigation by the Commission. Many companies wait until late February to engage a DPCO, leading to rushed, inaccurate audits that do not reflect the true state of their data processing activities. This lack of preparation leaves the organisation vulnerable to 'High Sensitivity' flags regarding their handling of financial or medical records.

4. Inadequate Identification of Lawful Bases for Processing

Many Nigerian businesses operate under the false impression that 'Consent' is the only lawful basis for processing personal data. This leads to 'consent fatigue' where users are bombarded with unnecessary checkboxes. Conversely, some organisations process data without any identifiable legal basis at all. The NDPA 2023 provides several bases: consent, contract performance, legal obligation, vital interests, public interest, and legitimate interests. A common mistake is relying on consent for employee data, where the power imbalance makes truly 'freely given' consent difficult to prove. Companies must carefully map their data flows and document which legal basis applies to each processing activity. Failure to do so means that any data processing performed is effectively illegal under the Act.

5. Neglecting Third-Party Vendor Due Diligence

In the modern Nigerian business ecosystem, companies rely heavily on third-party service providers for cloud storage, payroll management, and marketing. A significant compliance gap exists where companies fail to sign Data Processing Agreements (DPAs) with these vendors. Under the NDPA, the 'Data Controller' (the company) is held responsible for the actions of the 'Data Processor' (the vendor). If a third-party cloud provider suffers a breach, the Nigerian company could be held liable if they failed to conduct due diligence or failed to include mandatory contractual clauses regarding data security and breach notification. Companies must ensure that their contracts with vendors are compliant with Section 29 of the NDPA, ensuring that the processor only acts on documented instructions.

6. Failure to Implement a Data Breach Response Protocol

Many Nigerian organisations operate on the 'hope for the best' principle regarding cyber-attacks. They lack a documented, tested Data Breach Response Plan. The NDPA 2023 requires that data breaches that are likely to result in a risk to the rights and freedoms of individuals must be reported to the NDPC within 72 hours of the organisation becoming aware of the breach. Without a clear protocol, companies often spend those first 72 hours in a state of internal confusion, missing the regulatory window. A 'High Sensitivity' flag is often raised when medical or financial data is involved, as the impact on the data subject is immediate and severe. Failure to report a breach is a separate, punishable offence from the breach itself.

7. Mismanagement of Data Subject Access Requests (DSARs)

Nigerian citizens are becoming increasingly aware of their rights. They have the right to ask an organisation what data is held about them, why it is being processed, and to request its rectification or erasure. A common mistake is the lack of a formalised process for handling these requests. Employees at the front desk or in customer service often do not know how to identify a DSAR, leading to ignored requests and subsequent complaints to the NDPC. Organisations must have clear internal guidelines on how to verify the identity of the requester and how to provide the data in a structured, commonly used electronic format within the statutory timelines.

8. Lack of Regular Staff Sensitisation and Training

Data protection is not merely an IT issue; it is a cultural and organisational requirement. A common mistake is treating NDPR compliance as a one-time project rather than an ongoing process. Even the most sophisticated technical security measures can be bypassed by a single employee falling for a phishing scam or improperly sharing an Excel sheet containing customer Bank Verification Numbers (BVN) or National Identification Numbers (NIN). Regular training is a mandatory requirement under the NDPA. Companies that fail to document their staff training sessions often find themselves unable to prove 'accountability' during a regulatory inspection, which is a core principle of the Nigerian data protection framework.

9. Improper Handling of International Data Transfers

With the rise of remote work and global software-as-a-service (SaaS) platforms, personal data of Nigerians is constantly being transferred across borders. The NDPA 2023 places strict limitations on transferring data to countries that do not have 'adequate' data protection laws. Many Nigerian companies fail to assess whether the destination country (e.g., the USA or India) meets the criteria set by the NDPC or if they need to implement 'Appropriate Safeguards' such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules. Transferring data without a legal mechanism is a direct violation of the Act and can lead to the suspension of the company's ability to transfer data internationally, effectively crippling their operations.

10. Violation of the Data Minimisation Principle

The principle of data minimisation dictates that an organisation should only collect the data it absolutely needs for a specific purpose. In Nigeria, there is a historical tendency for companies to collect excessive information 'just in case'—requesting NINs, home addresses, and next-of-kin details for simple newsletter signups or basic service enquiries. This excessive collection increases the risk profile of the company. If you do not have the data, you cannot lose it. A common compliance mistake is failing to conduct a Data Protection Impact Assessment (DPIA) for new projects to determine the minimum amount of data required. Over-collection is a direct violation of the NDPA and is often viewed by the Commission as evidence of poor data governance.

Enforcement and the Cost of Non-Compliance

The NDPC has been empowered to impose heavy sanctions. For 'Data Controllers of Major Importance,' fines can reach up to 2% of their annual gross revenue of the preceding year or 10 million Naira, whichever is greater. For other controllers, the fine can be 1% of revenue or 2 million Naira. Beyond the financial penalties, the reputational damage and the potential for class-action lawsuits from data subjects can be catastrophic. Companies must also remember their obligations under the Companies and Allied Matters Act (CAMA) 2020 and FIRS requirements, as data protection often intersects with corporate governance and tax records. Compliance is not merely about avoiding fines; it is about building trust in the Nigerian digital economy.

Conclusion: The Path to Robust Compliance

Rectifying these common mistakes requires a proactive approach. Nigerian companies must move beyond a 'tick-box' exercise and integrate data protection into their core business processes. This begins with engaging a licensed DPCO to conduct a thorough gap analysis, appointing a competent DPO, and ensuring that the March 15th audit deadline is met with a high-quality, honest report. In an era where data is the most valuable asset, protecting that asset is not just a legal requirement—it is a competitive advantage. The Nigeria Data Protection Commission is becoming increasingly vigilant, and the window for 'ignorance' as a defence has firmly closed. Organisations must act now to ensure their operations are fully aligned with the Nigeria Data Protection Act 2023.