The Nigeria Data Protection Act 2023 has been signed into law by President Bola Tinubu, giving Nigeria its first comprehensive primary data protection legislation and placing the Nigeria Data Protection Commission (NDPC) on a statutory footing.
Key points
- Applies to controllers and processors processing the personal data of people in Nigeria, including those established abroad.
- Requires appropriate technical and organisational security measures and data protection impact assessments for high-risk processing.
- Personal data breaches must be reported to the NDPC within 72 hours.
- ‘Data controllers and processors of major importance’ must register with the NDPC and appoint a data protection officer.
- Cross-border transfers are restricted unless adequacy or other safeguards apply.
The Act’s extraterritorial reach means UK organisations with Nigerian customers, employees or partners may be directly in scope. Now is a good time to map Nigerian data flows and check whether registration and DPO requirements apply.
Source: Nigeria Data Protection Act 2023 (ngCERT, Federal Government of Nigeria)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.