What is the New Name for NDPR? Understanding the Nigeria Data Protection Act (NDPA) 2023
I get asked this question almost every week during compliance workshops in Lagos and Abuja. Many business owners and legal officers are still searching for 'NDPR' updates. They want to know if the Nigeria Data Protection Regulation is still the law. The short answer is: the NDPR has changed. We have moved from a regulation to a substantive Act. The new name you are looking for is the Nigeria Data Protection Act (NDPA) 2023.
The Evolution: From Regulation to Statute
For years, we relied on the NDPR 2019. It was a subsidiary legislation issued by NITDA. It served its purpose. However, it lacked the 'teeth' of a full Act of Parliament. In June 2023, President Bola Ahmed Tinubu signed the NDPA into law. This wasn't just a name change. It was a total overhaul of the legal framework for privacy in Nigeria. We now have a solid legal foundation that ranks alongside the GDPR in Europe.
The NDPA 2023 established the Nigeria Data Protection Commission (NDPC). This body replaced the Nigeria Data Protection Bureau (NDPB). The NDPC is the primary regulator. If you are still addressing your compliance letters to NITDA, you are making a mistake. Your audit trail must reflect the new regulatory reality.
Why This Change Matters for Your Organisation
In my work as a compliance consultant, I see many firms treating data privacy as a 'tick-box' exercise. This is a dangerous gamble. The NDPA 2023 introduces stiffer penalties. It defines the roles of Data Controllers and Data Processors with surgical precision. If you handle any form of Personally Identifiable Information (PII), you are under its jurisdiction.
Defining PII Under the New Act
PII is any information that can identify a living individual. In the Nigerian context, this includes:
- Full names and residential addresses.
- Phone numbers and personal email addresses.
- Bank Verification Numbers (BVN) and National Identification Numbers (NIN).
- IP addresses and location data.
- Biometric data (fingerprints, facial recognition).
Note: If your organisation handles medical records or financial statements, this is flagged as High Sensitivity data. The NDPA requires even stricter controls for this category. You cannot treat a customer's blood group the same way you treat their favorite colour.
The March 15th Audit Deadline: The Non-Negotiable Date
One of the most critical carryovers from the old regime to the new Act is the annual audit requirement. Every organisation that processes the data of over 2,000 data subjects in six months (or 1,000 in a year) must file an audit report. The deadline is March 15th every year. There are no extensions. Missing this date signals to the NDPC that your organisation is a high-risk entity. I have seen companies face heavy fines simply because they started their audit in April. You must engage a licensed Data Protection Compliance Organisation (DPCO) to conduct this audit. We do not just look at your servers. We look at your culture.
Data Minimisation: The Golden Rule
I often tell my clients: 'If you don't need it, don't collect it.' This is the principle of data minimisation. Under the NDPA 2023, you must justify every piece of data you hold. Why are you asking for a client's date of birth for a simple newsletter subscription? If you cannot provide a legal basis (Consent, Contract, Legal Obligation, Vital Interest, Public Task, or Legitimate Interest), you are in breach. We help firms strip back their forms to the bare essentials. This reduces your liability. If you don't have the data, you can't lose it in a breach.
Intersections with CAMA 2020 and SCUML
Compliance does not exist in a vacuum. The NDPA 2023 works alongside other Nigerian laws. For instance, under CAMA 2020, companies must maintain a Register of Persons with Significant Control (PSC). This register contains PII. You must ensure that your filing with the Corporate Affairs Commission (CAC) complies with the NDPA. You are sharing sensitive data with a government agency; you must document the legal basis for this transfer.
Furthermore, if you are a Designated Non-Financial Business and Profession (DNFBP), you have SCUML (Special Control Unit against Money Laundering) obligations. You are required to perform Know Your Customer (KYC) checks. This involves collecting ID cards and utility bills. This is a high-risk data processing activity. Your SCUML compliance must be synchronised with your NDPA protocols. You cannot protect the financial system while exposing your clients' privacy.
Tax Compliance and the FIRS Link
The Federal Inland Revenue Service (FIRS) is increasingly digital. When you file your Value Added Tax (VAT) or Withholding Tax (WHT) returns, you are processing data. Employee Tax (PAYE) involves handling sensitive salary information. The NDPA 2023 requires that this data is stored securely. Any third-party consultant handling your tax filings must sign a Data Processing Agreement (DPA). Without a DPA, you are liable for any leak that happens on their end.
Practical Steps for Compliance Officers
If you are the designated Data Protection Officer (DPO), here is your checklist:
- Update Your Privacy Policy: Remove references to the 'NDPR 2019' and replace them with 'NDPA 2023'.
- Conduct a Data Mapping Exercise: Identify where every byte of data enters your organisation and where it leaves.
- Train Your Staff: Most breaches happen because of a clicked link in an email. Human error is your biggest risk.
- Review Third-Party Contracts: Ensure your vendors (cloud providers, security firms, HR consultants) are NDPA-compliant.
- Prepare for the Audit: Do not wait until February. Start gathering your evidence of compliance now.
The Penalty for Non-Compliance
The NDPC is not playing. Under the new Act, fines can reach up to 10 million Naira or 2% of your annual gross revenue, whichever is higher. For a major bank or a large FMCG, 2% of revenue is a staggering amount. Beyond the money, the reputational damage is often permanent. Nigerians are becoming more aware of their rights. A single data subject can file a petition with the NDPC that triggers a full-scale forensic investigation into your business.
Conclusion
The transition from NDPR to NDPA 2023 marks a new era of accountability in Nigeria. We are no longer in the 'grace period'. The NDPC is actively monitoring compliance. Whether you are a small startup in Yaba or a multinational in Port Harcourt, the law applies to you. My advice is simple: treat data like a toxic asset. It is useful, but if handled poorly, it can destroy your organisation. Secure your data, respect your customers' privacy, and ensure your March 15th filings are impeccable. That is the only way to thrive in this new regulatory environment.