Understanding the Transition: From the NDPR 2019 to the NDPA 2023

In the evolving regulatory environment of Nigeria, the transition from the Nigeria Data Protection Regulation (NDPR) 2019 to the Nigeria Data Protection Act (NDPA) 2023 represents the most significant milestone in the nation's digital rights history. For many organisations, Data Protection Officers, and legal counsel, a primary question persists: Has the NDPR been repealed or replaced by the NDPA? The answer is nuanced and requires a technical examination of the transitional provisions contained within the primary legislation. This post provides a comprehensive analysis of the current legal status of both instruments, the implications for compliance, and the structural changes introduced by the new Act.

The Historical Context: Why the NDPR was Necessary

Before the enactment of the NDPA in June 2023, Nigeria relied on the NDPR, which was issued by the National Information Technology Development Agency (NITDA) in January 2019. The NDPR was a subsidiary piece of legislation—a regulation—created to fill a void in a country rapidly digitising its economy without a dedicated data privacy law. While the NDPR was revolutionary and successfully introduced Nigerians to the concepts of data subjects' rights and the obligations of data controllers, it faced certain limitations. As a regulation, its enforcement powers were often questioned in court, and its scope was tied to the parent NITDA Act. The need for a robust, independent, and primary piece of legislation led to the drafting and eventual signing of the Nigeria Data Protection Act 2023.

Section 64: The Legal Answer to the 'Repeal' Question

To determine whether the NDPR has been repealed, one must look directly at Section 64 of the Nigeria Data Protection Act 2023. This section provides the transitional provisions that bridge the gap between the old regulatory framework and the new statutory regime. Specifically, the Act does not summarily abolish the NDPR. Instead, it states that all existing regulations, directives, and orders issued by NITDA or the Nigeria Data Protection Bureau (NDPB) prior to the commencement of the Act remain in force. However, this is subject to a critical condition: such regulations remain valid only to the extent that they are consistent with the provisions of the new Act. Therefore, the NDPR has not been 'repealed' in the sense of being rendered null and void; rather, it has been 'superseded' and 'validated' as a subsidiary instrument under the authority of the new Act until the Nigeria Data Protection Commission (NDPC) issues new regulations that may explicitly replace it.

The Emergence of the Nigeria Data Protection Commission (NDPC)

One of the most significant changes introduced by the NDPA is the formal establishment of the Nigeria Data Protection Commission (NDPC). Under the NDPR, data protection was overseen by NITDA and later the NDPB (a bureau created by executive action). The NDPA 2023 elevates this oversight by creating a statutory Commission with independent powers to regulate, monitor, and enforce compliance. The NDPC now possesses the legal authority to impose much heavier sanctions than those previously available under the NDPR. This institutional shift ensures that data protection in Nigeria is no longer an 'add-on' to information technology development but a dedicated regulatory pillar of the digital economy.

Key Differences in Compliance Requirements

While the NDPR laid the foundation, the NDPA expands the obligations for organisations. Understanding these differences is vital for an audit trail and for maintaining a high standard of data privacy.

  • Scope of Application: The NDPR applied to 'Nigerians within and outside Nigeria'. The NDPA provides a more precise jurisdictional scope, applying to data controllers and processors domiciled in, resident in, or operating in Nigeria, as well as those outside Nigeria processing the personal data of data subjects who are in Nigeria.
  • Lawful Basis for Processing: The NDPA introduces 'Legitimate Interest' as a formal lawful basis for processing personal data, a concept that was notably absent or poorly defined in the NDPR. This aligns Nigeria more closely with the General Data Protection Regulation (GDPR) standards.
  • Data Protection Impact Assessments (DPIA): While the NDPR encouraged DPIAs, the NDPA makes them a mandatory requirement for processing activities that are likely to result in high risks to the rights and freedoms of data subjects.
  • Data Protection Officers (DPO): The NDPA mandates the appointment of a DPO for data controllers and processors of 'major importance'. This is a more defined category than the broad requirements found in the NDPR.

High Sensitivity: Processing Medical and Financial Data

Under the NDPA 2023, the processing of sensitive personal data—which includes medical records, genetic data, biometric data, and financial information—is subject to stricter controls. These categories are flagged as 'High Sensitivity'. Organisations must ensure they have a specific legal basis for processing such data beyond mere general consent. For instance, medical data processing is often restricted to health professionals under a duty of confidentiality, or where it is necessary for reasons of public interest in the area of public health. Financial data must be protected with the highest levels of encryption and access control to prevent fraud and identity theft. Failure to implement enhanced security measures for sensitive data now carries significantly higher penalties under the Act.

The Audit Cycle and the March 15th Deadline

A unique feature of the Nigerian data protection framework, carried over from the NDPR and reinforced by the NDPC, is the requirement for an annual Data Protection Compliance Audit. Data controllers and processors who process the data of a certain number of subjects must engage a Data Protection Compliance Organisation (DPCO) to conduct an audit and file a report with the Commission. The deadline for this filing remains March 15th of every year. This audit process provides a structured mechanism for organisations to demonstrate their adherence to the principles of data minimisation, purpose limitation, and storage limitation. It also serves as a critical component of the audit trail required during regulatory investigations.

Penalties and Enforcement under the NDPA

The enforcement regime under the NDPA 2023 is considerably more rigorous than the NDPR. The Act introduces a two-tier penalty system for infringements:

  • Standard Levy: For data controllers or processors not classified as being of 'major importance', the fine can be up to 2 million Naira or 2% of their annual gross revenue from the preceding year, whichever is greater.
  • Higher Maximum Levy: For data controllers or processors of 'major importance', the fine can reach up to 10 million Naira or 2% of their annual gross revenue, whichever is greater.
These penalties demonstrate that the Nigerian government is serious about data privacy. The Commission also has the power to issue enforcement notices and seek judicial intervention to ensure compliance, making it imperative for organisations to move beyond 'paper compliance' to actual, demonstrable data protection practices.

Cross-Border Data Transfers

The NDPA 2023 provides a more structured framework for transferring personal data outside Nigeria. While the NDPR required the approval of the Attorney General of the Federation for certain transfers, the NDPA empowers the Commission to determine the adequacy of data protection laws in recipient countries. In the absence of an adequacy decision, organisations must rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or the explicit consent of the data subject after being informed of the risks. This ensures that the protection afforded to Nigerian data subjects follows their data, regardless of where in the world it is processed.

Immediate Steps for Organisations

Given that the NDPA 2023 is now the primary law, organisations must take proactive steps to align their operations with its requirements. First, every organisation should conduct a gap analysis to identify areas where their current NDPR-aligned policies fall short of the NDPA standards. This includes updating privacy notices to include the new lawful bases and ensuring that data subject access request (DSAR) procedures are robust. Second, organisations must determine if they qualify as a 'Data Controller or Processor of Major Importance' and register with the NDPC accordingly. Third, the internal culture must shift towards 'Privacy by Design and Default', ensuring that every new project or product considers data protection from the outset.

Conclusion

In summary, the NDPR has not been discarded; it has been integrated into a more powerful statutory framework. The NDPA 2023 provides the legal teeth that the NDPR lacked, creating a mandatory and enforceable environment for data privacy in Nigeria. As a Senior Data Protection & Compliance Officer, I advise all entities to treat the NDPA not merely as a legal hurdle but as a fundamental component of corporate governance. By adhering to the principles of transparency, accountability, and data minimisation, organisations can build trust with their customers and avoid the severe financial and reputational consequences of non-compliance. The transition from regulation to Act marks Nigeria's commitment to the global standards of data protection, and it is incumbent upon all stakeholders to ensure this transition is handled with the required professional diligence.