Analysis of the Nigeria Data Protection Act 2023: Evolution from the NDPR Framework

The regulatory environment for data privacy in Nigeria underwent a fundamental transformation on 12 June 2023, when the Nigeria Data Protection Act (NDPA) was signed into law. This legislative milestone represents a transition from a subsidiary regulation—the Nigeria Data Protection Regulation (NDPR) 2019—to a substantive primary statute. For organisations operating within the Nigerian jurisdiction, understanding the distinctions between the previous regulatory regime and the current Act is not merely a matter of academic interest but a critical requirement for regulatory compliance and risk management.

The Legislative Hierarchy: From Regulation to Principal Act

The most significant change is the status of the law itself. The NDPR 2019 was issued by the National Information Technology Development Agency (NITDA) as a subsidiary regulation. While it provided a necessary framework, its enforceability was occasionally challenged in court on the grounds of legislative competence. The NDPA 2023 resolves these ambiguities by establishing a primary legislative framework passed by the National Assembly. This elevation ensures that data protection is now a standalone legal requirement with the full weight of federal law, providing a more robust basis for enforcement and the protection of constitutional rights to privacy as enshrined in Section 37 of the 1999 Constitution of the Federal Republic of Nigeria.

The Regulatory Authority: The Nigeria Data Protection Commission (NDPC)

Under the NDPR 2019, the Nigeria Data Protection Bureau (NDPB) was established as an interim measure to oversee data privacy matters, following the initial oversight by NITDA. The NDPA 2023 formalises this structure by establishing the Nigeria Data Protection Commission (NDPC). The Commission is a body corporate with perpetual succession and a common seal. It is headed by a National Commissioner who is responsible for the administration of the Act, the registration of data controllers and processors of major importance, and the oversight of the Data Protection Compliance Organisation (DPCO) model. The independence of the NDPC is more clearly defined under the 2023 Act than it was under the previous regulatory regime, granting it the power to issue regulations, guidelines, and directives without undue external interference.

What Stayed the Same: The Core Principles of Processing

Despite the comprehensive nature of the 2023 Act, several foundational principles from the NDPR 2019 have been retained to ensure continuity. The principles of data processing remain the bedrock of the Nigerian privacy framework. These include:

  • Lawfulness, Fairness, and Transparency: Personal data must be processed based on a valid legal ground, and the data subject must be informed of the processing activities.
  • Purpose Limitation: Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Data Minimisation: Organisations must only collect data that is adequate, relevant, and limited to what is necessary for the stated purpose.
  • Accuracy: Every reasonable step must be taken to ensure that personal data is accurate and kept up to date.
  • Storage Limitation: Personal data should not be kept longer than is necessary for the purposes for which it is processed.
  • Integrity and Confidentiality: Technical and organisational measures must be implemented to protect data against unauthorised or unlawful processing and accidental loss or damage.

Legal Bases for Processing: The Addition of Legitimate Interest

A notable evolution in the NDPA 2023 is the explicit introduction of 'Legitimate Interest' as a legal basis for processing personal data. Under the NDPR 2019, the legal bases were largely limited to consent, contract, legal obligation, vital interest, and public interest. The 2023 Act expands this to include processing that is necessary for the purposes of the legitimate interests pursued by the data controller or processor, or by a third party. However, the Act provides a safeguard: this basis cannot be used where such interests are overridden by the fundamental rights and freedoms of the data subject. This addition aligns the Nigerian framework more closely with international standards such as the GDPR, providing businesses with more flexibility in how they justify their data processing activities, particularly in the context of fraud prevention and direct marketing.

Rights of Data Subjects: Enhanced Control

The NDPA 2023 reinforces and expands the rights of data subjects. While the NDPR 2019 introduced the rights to access, rectification, and erasure, the 2023 Act provides more granular detail on the exercise of these rights. Data subjects now have the explicit right to object to processing, the right to data portability, and the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or significantly affects them. The timeline for responding to data subject access requests (DSARs) remains critical, and organisations must ensure they have internal mechanisms to verify identities and provide the requested information within the statutory period.

Data Protection Impact Assessments (DPIA)

While the NDPR 2019 alluded to the necessity of assessing risks, the NDPA 2023 makes the Data Protection Impact Assessment (DPIA) a mandatory requirement for processing activities that are likely to result in high risks to the rights and freedoms of data subjects. This includes large-scale processing of sensitive personal data or extensive monitoring of publicly accessible areas. A DPIA must include a systematic description of the envisaged processing, an assessment of the necessity and proportionality of the processing, and the measures envisioned to address the risks. Failure to conduct a DPIA where required is now a specific point of non-compliance that can lead to significant penalties.

The Role of Data Protection Compliance Organisations (DPCOs)

Nigeria continues its unique model of utilising Data Protection Compliance Organisations (DPCOs). This model, introduced by the NDPR 2019, involves the licensing of professional firms (such as audit and legal firms) to provide compliance services, training, and to conduct data protection audits on behalf of the Commission. The NDPA 2023 maintains this system, reinforcing the requirement for data controllers and processors to engage DPCOs for the filing of their annual audit reports. The annual audit deadline remains March 15 of every year. This system ensures that there is a layer of professional verification in the compliance ecosystem, reducing the administrative burden on the NDPC while promoting high standards of professional practice in the privacy sector.

Cross-Border Data Transfers

The rules governing the transfer of personal data outside Nigeria have been refined. Under the NDPR, transfers were largely dependent on the 'Adequacy List' issued by the Attorney General. The NDPA 2023 provides a more structured approach, allowing transfers based on adequacy decisions by the Commission, or in the absence of such decisions, through the use of Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or the explicit consent of the data subject. This clarification is vital for multinational corporations and Nigerian businesses utilising offshore cloud services, as it provides a clearer legal pathway for international data flows while ensuring that the protection afforded to Nigerian data subjects follows the data.

Enforcement, Fines, and Penalties

The enforcement regime has been significantly strengthened. Under the previous regulation, the maximum fine was 2% of annual gross revenue or 10 million Naira (whichever was greater) for data controllers with over 10,000 data subjects. The NDPA 2023 introduces a tiered penalty system based on whether the entity is a 'Data Controller or Processor of Major Importance'. For these entities, the maximum penalty is the greater of 10 million Naira or 2% of the previous year's annual gross revenue. For other entities, the penalty is the greater of 2 million Naira or 1% of the previous year's annual gross revenue. Furthermore, the Act grants the Commission the power to order the payment of compensation to data subjects who have suffered injury or loss due to a breach, and it introduces criminal liability for certain infractions, including the unauthorised disclosure of personal data.

Integration with Other Nigerian Laws

Compliance with the NDPA 2023 does not occur in a vacuum. It must be integrated with other statutory requirements. For instance, the Companies and Allied Matters Act (CAMA) 2020 requires proper corporate governance and annual returns, which now must reflect the organisation's status of data protection compliance. Furthermore, Designated Non-Financial Businesses and Professions (DNFBPs) must reconcile their data collection practices with Anti-Money Laundering (AML) requirements and Special Control Unit Against Money Laundering (SCUML) registrations. While AML laws require the collection of extensive Know Your Customer (KYC) data, the NDPA 2023 requires that this data be handled securely and only for the purposes mandated by law. Similarly, tax compliance with the Federal Inland Revenue Service (FIRS) involves the processing of sensitive financial data, necessitating robust internal controls to prevent unauthorised access.

Conclusion and Audit Preparedness

The transition from the NDPR 2019 to the NDPA 2023 signals a maturing of the Nigerian privacy sector. For organisations, the shift requires an immediate review of existing data protection policies, the update of privacy notices to include 'Legitimate Interest' where applicable, and the formal designation of a Data Protection Officer (DPO) for those qualifying as major data controllers. As the March 15 audit deadline approaches, it is imperative that firms conduct a gap analysis to ensure their practices align with the new statutory requirements. The focus of the NDPC is increasingly on accountability; documenting the 'why' and 'how' of data processing is no longer optional but a central pillar of corporate compliance in Nigeria.