WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Africa

Nigeria Privacy & Data Protection Laws

Every regime below can apply to a business handling Nigeria residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

June 12, 2023 (Act); GAID issued March 20, 2025 and effective September 19, 2025
Nigeria Data Protection Act 2023
NDPA
Verify details

Section 2 gives the NDPA broad reach: it applies where the data controller or processor is domiciled, resident, or operating in Nigeria; where the processing occurs in Nigeria; and — extraterritorially — where a controller or processor not domiciled in Nigeria processes the personal data of data subjects in Nigeria. Africa's largest market therefore reaches foreign businesses serving Nigerian users. The General Application and Implementation Directive 2025, issued by the Nigeria Data Protection Commission on March 20, 2025 and effective September 19, 2025, is the operative compliance instrument: 52 articles and 10 schedules covering registration of data controllers and processors 'of major importance', Data Protection Officer requirements, annual audit filings, breach notification, cross-border transfer mechanisms, and consent standards. It supersedes the earlier NDPR 2019 and its 2020 Implementation Framework, which ceased to operate as data-protection regulation. Where the GAID and the Act conflict, the Act prevails.

Nigeria Data Protection Act 2023 (assented June 12, 2023), s. 2 (application); General Application and Implementation Directive 2025 (GAID)Read regulation →

Children & Minors Protections · 1

s. 31 requires the consent of a parent or legal guardian where the data subject is a child or otherwise lacks legal capacity to consent, and a child is anyone under 18, tracking the Child's Rights Act rather than any lower digital-consent age. Two details matter operationally. s. 31(5) provides that a child under 13 cannot give consent at all, so the under-13 and 13-to-17 groups are not treated identically even though both need a parent. And the Act does not leave age assurance to best efforts: a controller must apply appropriate mechanisms to verify age and consent taking available technology into account, with presentation of a government-approved identification document expressly named as an appropriate mechanism. Parental consent is not required where processing is necessary to protect the child's vital interests, is carried out for education, medical or social care by a professional owing a duty of confidentiality, or is necessary for court proceedings relating to the individual.

Nigeria Data Protection Act, 2023, s. 31; Child's Rights Act, 2003 (definition of a child)Read regulation →

Cross-Border Data Transfer · 1

s. 41(1) restricts transfer out of Nigeria by default and then supplies the ways through: the recipient must be subject to a law, binding corporate rules, contractual clauses, a code of conduct, or a certification mechanism that affords an adequate level of protection consistent with the Act. The Nigeria Data Protection Commission may issue adequacy decisions covering a country, a sector within a country, or a region, and may approve standard contractual clauses and cross-border data transfer instruments. Marked 'check': the operative detail now sits substantially in the GAID 2025 rather than the Act, and the Commission's adequacy and instrument-approval practice is still developing — a business should confirm which route the NDPC currently recognises rather than assuming the statutory list is self-executing.

Nigeria Data Protection Act, 2023, ss. 41-43; NDP Act General Application and Implementation Directive (GAID) 2025Read regulation →

Data Security & Breach Notification · 1

s. 40(2) gives data controllers 72 hours from becoming aware to notify the Nigeria Data Protection Commission of a reportable breach, with phased submission permitted where the full picture is not yet available. Where the breach is likely to result in a high risk to a data subject's rights and freedoms, the controller must communicate it to the data subject immediately, in plain and clear language, including mitigation steps. Processors must notify the controller or processor that engaged them on becoming aware. A sector caveat worth flagging: shorter, sector-specific breach deadlines exist in Nigeria outside the NDPA — internet access service providers face a 48-hour deadline under the telecoms Internet Code of Practice — so a 72-hour assumption is not safe for every regulated business.

Nigeria Data Protection Act, 2023, s. 40; NDP Act General Application and Implementation Directive (GAID) 2025Read regulation →

Other Africa jurisdictions