LegalDoc
Tax & Compliance

Data Protection

Data protection is the law governing how you collect, store and use other people's personal information. In Nigeria it is the Nigeria Data Protection Act 2023, and it applies to far smaller businesses than most owners assume.

Create a Privacy Policyfrom ₦5,000, ready in minutes
D

What data protection means

Data protection law says that personal information belongs, in a meaningful sense, to the person it describes.

Personal data is anything that identifies a living individual. A name, a phone number, an email address, a BVN, a photograph, a delivery address, a location, an IP address. If you can work out who somebody is from it, it is personal data.

The law then sets out what you may do with it. You need a lawful basis to process it at all. You must tell people what you are doing. You must collect only what you need, keep it only as long as you need it, keep it accurate, and keep it secure. And you must be able to demonstrate that you did all of that.

In Nigeria this is the Nigeria Data Protection Act 2023, which established the Nigeria Data Protection Commission and replaced the earlier regulatory framework with primary legislation.

How it is used

Every Nigerian business that keeps a customer list is processing personal data, and most of them do not realise the rules apply.

An online shop with delivery addresses. A gym with member records. A school with pupil files. A clinic with patient records. A fintech with BVNs. An Instagram seller with a WhatsApp list of buyers.

What compliance actually looks like is a short list. Know what personal data you hold and why. Identify a lawful basis for each use, which will usually be consent, performance of a contract, a legal obligation or a legitimate interest. Publish a privacy notice that says plainly what you collect, why, who you share it with, how long you keep it and what rights people have. Secure it, including access controls and encryption where appropriate. Have a process for responding when somebody asks for their data or asks you to delete it. Have a process for a breach.

Where you use a third party to process data on your behalf, such as a payment processor or a cloud service, there should be a written agreement covering it.

Key features

  • Governed by the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission
  • Applies to personal data, meaning anything identifying a living individual
  • Processing requires a lawful basis such as consent, contract, legal obligation or legitimate interest
  • Data subjects have rights of access, rectification, erasure, objection and portability
  • Personal data breaches must be notified to the Commission within seventy two hours
  • Data controllers of major importance must register and file compliance returns

How this works in Nigeria

The Act draws a line between ordinary data controllers and data controllers of major importance, and the obligations differ.

Controllers of major importance, determined by the volume and sensitivity of the data they handle and the sector they operate in, must register with the Commission, appoint a data protection officer, and file annual compliance returns. Banks, fintechs, telecoms, hospitals, schools and large e commerce operations typically fall here.

Smaller businesses are still bound by the principles and by data subject rights, even where the registration obligation does not apply to them. Being small is not an exemption from the law, only from some of the administrative steps.

Sanctions are real. The Act provides for remedial orders and financial penalties, with higher exposure for controllers of major importance, calculated by reference to gross annual revenue as well as a fixed sum. The Commission has been active, and enforcement has moved from theoretical to actual.

Consent also has to mean something. Bundling consent into terms nobody reads, or making a service conditional on consent for unrelated marketing, is not the consent the Act contemplates.

Data protection vs confidentiality vs cybersecurity

Three related obligations that businesses run together and should not.

Data protection is about personal data and the rights of the individuals it describes. It applies whether or not anybody promised confidentiality, because the obligation comes from the law rather than from an agreement.

Confidentiality is contractual. It arises from an NDA, an employment contract or the duty of confidence, and it can cover commercial information that has nothing to do with any individual.

Cybersecurity is technical. Firewalls, encryption, access controls and monitoring. It is one of the things data protection law requires, but it is a means rather than the obligation itself.

A business can have excellent cybersecurity and still breach data protection law by collecting information it does not need, keeping it forever, or failing to answer an access request.

Limits and risks

Awareness is the real limitation. Most Nigerian small businesses have never read the Act, do not know what a lawful basis is, and would not know what to do if somebody asked for their data.

Enforcement capacity is finite, and the Commission cannot examine every business. That produces a false sense of safety, particularly for businesses whose exposure only becomes visible after a breach.

The rules also sit awkwardly with common Nigerian practice. Buying phone number lists for marketing, sharing customer data between related businesses, and keeping records indefinitely are all normal and all difficult to justify under the Act.

And cross border transfers need care. Sending personal data outside Nigeria requires an adequate basis, which affects almost every business using foreign cloud services without thinking about it.

Worth knowing

Publish a real privacy notice and actually follow it. The most common Nigerian failure is not a hack, it is a business that collects data for one purpose, uses it for another, and has nothing in writing to point to when a customer or the Commission asks what it was allowed to do.

Questions people ask

What is the data protection law in Nigeria?

The Nigeria Data Protection Act 2023, which established the Nigeria Data Protection Commission and put the framework on a statutory footing. It governs how personal data is collected, stored, used and shared.

Does data protection law apply to small businesses?

Yes. The principles and data subject rights apply to anyone processing personal data. What differs is the administrative burden: only data controllers of major importance must register, appoint a data protection officer and file compliance returns.

What counts as personal data?

Anything that identifies a living individual, including names, phone numbers, email addresses, delivery addresses, photographs, BVNs, location data and IP addresses.

What rights do people have over their data?

Rights of access, rectification, erasure, restriction of processing, objection and portability. A business needs a process for responding to those requests within the timeframes the Act allows.

What do I do if there is a data breach?

Notify the Nigeria Data Protection Commission within seventy two hours, and inform affected individuals where the breach is likely to result in high risk to them. Document what happened and what you did about it.

What are the penalties for breaching the NDPA?

The Act provides for remedial orders and financial penalties, with higher exposure for data controllers of major importance, calculated by reference to gross annual revenue as well as a fixed sum. Enforcement has been active.

Documents that use this

Data Protection in Nigeria: NDPA 2023 — LegalDoc