WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Nigeria Data Protection Act, 2023 — personal data breach notification

NDPA s. 40

Nigeria · June 12, 2023

s. 40(2) gives data controllers 72 hours from becoming aware to notify the Nigeria Data Protection Commission of a reportable breach, with phased submission permitted where the full picture is not yet available. Where the breach is likely to result in a high risk to a data subject's rights and freedoms, the controller must communicate it to the data subject immediately, in plain and clear language, including mitigation steps. Processors must notify the controller or processor that engaged them on becoming aware. A sector caveat worth flagging: shorter, sector-specific breach deadlines exist in Nigeria outside the NDPA — internet access service providers face a 48-hour deadline under the telecoms Internet Code of Practice — so a 72-hour assumption is not safe for every regulated business.

Nigeria Data Protection Act, 2023, s. 40; NDP Act General Application and Implementation Directive (GAID) 2025Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.