Understanding the Nigeria Data Protection Act (NDPA) 2023: A Comprehensive Guide to Data Privacy Principles

In the contemporary Nigerian business environment, data has emerged as one of the most significant assets an organisation can possess. However, with the increasing reliance on digital information comes a heightened responsibility to protect the privacy and rights of individuals. The transition from the Nigeria Data Protection Regulation (NDPR) 2019 to the Nigeria Data Protection Act (NDPA) 2023 represents a pivotal shift in our legal framework. As a Senior Data Protection and Compliance Officer, I observe many organisations struggling to interpret these legal requirements into actionable business processes. This guide aims to clarify the core principles of data privacy in Nigeria, ensuring your organisation remains compliant with the Nigeria Data Protection Commission (NDPC) mandates.

1. Lawfulness, Fairness, and Transparency

The first and perhaps most vital principle under the NDPA 2023 is the requirement that data processing must be conducted lawfully, fairly, and in a transparent manner. This is not merely a suggestion; it is a mandatory legal standard that dictates how every piece of personal information must be handled from the moment of collection.

Lawfulness: For any processing of personal data to be considered lawful, it must be grounded in one of the specific legal bases provided by the Act. These include obtaining the clear consent of the data subject, the performance of a contract, compliance with a legal obligation, the protection of vital interests, the performance of a task in the public interest, or the pursuit of legitimate interests (provided these do not override the individual's fundamental rights). Organisations must document which legal basis they are relying upon for every processing activity.

Fairness: Fairness dictates that you should not process data in a way that is detrimental, unexpected, or misleading to the individual. If a Nigerian bank collects data for a loan application, it would be unfair to use that data to market unrelated third-party real estate services without explicit disclosure and a valid legal basis.

Transparency: This requires organisations to be open and honest about who they are and why they are processing data. This is typically achieved through a Privacy Policy or Privacy Notice. Under the NDPA, these notices must be easily accessible, written in clear and plain language, and provided at the point where data is collected. You must inform individuals about their rights, the identity of the data controller, and the duration for which their data will be stored.

2. Purpose Limitation

The principle of purpose limitation ensures that organisations do not collect data for one reason and then use it for another unrelated purpose. This prevents what is known in the compliance industry as 'function creep'.

When an organisation decides to collect personal data, the purpose must be 'specified, explicit, and legitimate'. For example, if a healthcare provider in Lagos collects a patient's phone number to send appointment reminders, they cannot suddenly decide to sell that contact list to a pharmaceutical marketing firm. The secondary use is incompatible with the original purpose for which the data was collected. If an organisation wishes to use data for a new purpose, they must generally seek fresh consent or ensure the new purpose is legally compatible with the original one.

3. Data Minimisation

The NDPA 2023 strictly enforces the principle of data minimisation, which states that personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. In simpler terms: do not collect more data than you actually need.

Many Nigerian startups have a habit of asking for excessive information—such as home addresses or marital status—when a simple email address would suffice for the service offered. This creates unnecessary risk. If your organisation suffers a data breach, the more data you have unnecessarily stored, the higher your legal and financial liability. A rigorous audit of all data collection forms is essential to ensure that every data field is justified by a specific business requirement.

4. Accuracy and Data Quality

Organisations are legally obligated to ensure that the personal data they hold is accurate and, where necessary, kept up to date. This is the principle of accuracy. Inaccurate data can lead to significant real-world harm, such as a credit bureau reporting incorrect debt information or a hospital having the wrong blood type on a patient's record.

The NDPA 2023 grants data subjects the right to rectification. This means if an individual informs your organisation that their information is incorrect, you must take every reasonable step to ensure the data is erased or rectified without delay. Regular data cleansing exercises and providing self-service portals where customers can update their own information are excellent ways to maintain compliance with this principle.

5. Storage Limitation

How long should your organisation keep personal data? The principle of storage limitation states that data should not be kept for longer than is necessary for the purposes for which it was collected. There is no 'one size fits all' rule for retention periods, as they are often dictated by other Nigerian laws—such as the Money Laundering (Prevention and Prohibition) Act, which requires financial records to be kept for specific periods.

However, once the legal or business necessity has expired, the data must be securely deleted or anonymised. Anonymisation means the data is stripped of all identifying markers so that the individual can no longer be identified. Keeping 'dark data'—information that is no longer useful but hasn't been deleted—is a major compliance failure and a target for cybercriminals.

6. Integrity and Confidentiality (Security)

Often referred to as the 'Security Principle', this requires organisations to process data in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage. This involves both technical and organisational measures.

Technical Measures: These include encryption, multi-factor authentication (MFA), firewalls, and regular vulnerability assessments. For Nigerian companies handling sensitive financial or medical data, encryption is not optional; it is a fundamental requirement.

Organisational Measures: This involves staff training, clear internal data protection policies, and physical security measures like locked filing cabinets and secure server rooms. Under the NDPA, if a data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, the organisation must notify the NDPC within 72 hours of becoming aware of the breach. Failure to have a robust incident response plan is a breach of the integrity and confidentiality principle.

7. Accountability: The Pillar of the NDPA 2023

The principle of accountability is the most significant addition to the modern data protection framework. It is no longer enough to simply follow the rules; you must be able to demonstrate that you are following the rules. This moves compliance from a passive state to an active, documented process.

To meet the accountability requirement, Nigerian organisations must:

  • Appoint a Data Protection Officer (DPO) where required by the Act.
  • Engage a Data Protection Compliance Organisation (DPCO) to conduct annual audits.
  • Maintain a Record of Processing Activities (ROPA).
  • Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
  • Implement 'Data Protection by Design and by Default' into all new products and services.

The NDPC requires that organisations file their annual data protection audit report by the 15th of March every year. This audit is a critical component of the accountability framework and serves as an official record of your organisation's compliance status.

The Rights of the Data Subject

While the principles guide the behaviour of the organisation, the NDPA also empowers the individual (the data subject). Every Nigerian citizen and resident has the right to access their data, the right to object to processing for marketing purposes, the right to data portability, and the right to be forgotten (erasure). Your organisation must have internal processes to respond to these requests within the statutory timeframe, which is generally 30 days.

Conclusion: Building a Culture of Compliance

Compliance with the NDPA 2023 should not be viewed as a mere 'box-ticking' exercise. In the current regulatory environment, it is a fundamental aspect of corporate governance. By adhering to these seven principles—Lawfulness, Purpose Limitation, Data Minimisation, Accuracy, Storage Limitation, Security, and Accountability—your organisation can build trust with its customers, avoid the heavy fines imposed by the NDPC, and ensure the long-term sustainability of its operations. The journey to full compliance begins with a single step: understanding the data you hold and respecting the rights of those to whom it belongs.