KEY DEVELOPMENTS IN THE ADMINISTRATION OF NIGERIA’S PERSONAL DATA SECURITY LAWS

Table of Contents

Introduction:

 

The enactment of Nigeria’s Data Protection Act (the Act or NDPA) on June 12, 2023 provided the much-needed legislative imprimatur to the country’s almost decade-long efforts at safeguarding the privacy rights of natural persons in a global economy where personal data has hitherto become the fuel for commerce. Since its passage, the Nigeria Data Protection Commission (the Commission), the regulator charged with administering the Act has issued directives and compliance requirements aimed at ensuring adherence to its provisions. In this brief, we provide a brief overview of some key developments in the Commission’s administration of the Act and  related laws on the security of personal data.

 

 Guidance Notice on the Filing of Data Protection Compliance Audit Returns (CAR)

 

In November 2023, the Commission issued the Guidance Notice on the Filing of Data Protection Compliance Audit Returns (the Audits Guidance Notice). The Audits Guidance Notice, which was directed at Data Protection Compliance Organisations (DPCOs), outlined notable focus areas for compliance audits, including, the:

 

i.               implementation of Privacy Policies and directives for employees, contractors, and agents;

ii.              availability and designation of Data Protection Officers (DPOs);

iii.            categorization of Personal Data and their Lawful Basis;

iv.            application of Personal Data Protection Principles;

v.              technical measures for ensuring the confidentiality, integrity, and availability of Personal Data (‘Privacy by Design’ and ‘Privacy by Default’);

vi.            reporting requirement on redressing grievances;

vii.          disclosure of awareness and capacity-building efforts by Data Controllers and or Processors (DCPs); and

viii.        identification and NPDA-compliance of the agents or contractors of DCPs whose engagements include the processing of Personal Data.

 

It further set out compliance metrics designed for DCPs seeking inclusion in the National Data Protection Adequacy Programme Whitelist (the Whitelist). The metrics evaluate DCPs across major areas such as, their:

 

i.           adherence to Personal Data Protection Principles;

ii.          efforts at public sensitisations;

iii.        appointment of a DPO;

iv.         engagement of a DPCO;

v.          necessary or regular conduct of Data Protection Impact Assessments (DPIAs);

vi.         establishment of internal remediation mechanisms, etc.

 

Each criterion carries a maximum score of 10 points, with a total possible score of 100 points.

 

Notwithstanding the Commission’s promotion and reflection of DCPs accountability and transparency through the Whitelist, DCPs need be mindful that inclusion on the Whitelist does not equate to an exemption from investigation or sanctions arising from legitimate complaints of Data Subjects.

 

Classification and Registration of DCPMIs

 

In February 2024, the Commission published a Guidance Notice (the DCPMI Guidance Notice) designating DCPs of Major Importance (“DCPMIs”) required to register with the Commission. The Commission emphasized that registration is foundational evidence of an entity’s reliability in data processing activities, as well as its commitment to securing lives and the national and global economy.

 

It is noteworthy that the Act itself provides for DCPMIs. It recognised them as DCPs based in, residing in, or operating within Nigeria, who process or plan to process Personal Data of such treshhold or value as the Commission may prescribe.  Accordingly, the Commission proceeded to classify DCPMIs into the following:

 

i.               Ultra High Level (MDP-UHL):

Entities such as commercial banks, telecommunications companies, insurance companies, and organizations processing the Personal Data of +5,000 (above five thousand) individuals within six months fall into these category. They are are required to adhere to global and the highest attainable standards of Personal Data Protection.

 

ii.              Extra High Level (MDP-EHL):

These are government ministries, microfinance banks, hospitals, and institutions processing the Personal Data of over +1,000 (above one thousand) individuals within six months. They are are required to adhere to global with global best practices of Personal Data Protection.

 

iii.            Ordinary High Level (MDP-OHL):

These are Small and Medium Scale Enterprises (SMEs), primary and secondary schools, and organizations processing the Personal Data of + 200 (above two hundred)  individuals within six months. They are are required to adhere to adequate technical and organizational measures for Personal Data Protection.

 

This aspect of the DCPMI Guidance Notice recently came under judicial scrutiny in Frank Ijege v. Nigeria Data Protection Commission, where Mr. Ijege successfully challenged certain provisions of the DCPMI Guidance Notice, arguing that the NDPC exceeded its statutory powers. Nigeria’s Federal High Court proceeded to nullify several key paragraphs of the DCPMI Guidance Notice, including those mandating registration for fiduciaries, ultra-high compliance DCPs, and third-party agents or contractors. The Court held that these requirements were inconsistent with the classification criteria for DCPMIs under Section 65 of the NDPA.  While the judgment has curtailed registration obligations for certain entities, significant portions of the DCPMI Guidance Notice remain valid, for which professional advice needs be sought.

 

 

NDPA General Application and Implementation Directive (GAID)

 

In May 2024, the Commission published the draft NDPA General Application and Implementation Directive (GAID), which provides guidance on the implementation of the Act and operational requirements for Personal Data processing activities. When operative, GAID is to apply to the following categories of DCPs and Data Subjects:

 

i.           individuals within Nigeria, irrespective of their nationality or migration status;

ii.          individuals whose Personal Data have been transferred to Nigeria;

iii.        individuals whose Personal Data are in transit through Nigeria, with limited responsibility for the confidentiality, integrity, and availability of such Personal Data;

iv.         Nigerian citizens residing abroad; and

v.          DCPs that process or target the Personal Data of Data Subjects in Nigeria.

 

The draft GAID also specifies that DCPMIs in the MDP-UHL and MDP-EHL categories are mandated to register with the Commission and submit annual Compliance Audit Reports (CARs), while those in the MDP-OHL category only require annual registration renewal without the need for a CAR. It strengthens the role of DPOs by requiring semi-annual compliance reports to the management of their DCPs. Such reports must address Personal Data Protection Principles, lawful processing bases, and grievance resolutions. DPOs are also subject to annual credential assessments conducted by the Commission to ensure professionalism.

 

To enhance organizational compliance, the draft GAID mandates Data Controllers and Processors to maintain and publish schedules detailing technical and organizational measures such as training, software updates, and encryption reviews. These schedules must be overseen by certified information security officers. For emerging technologies such as Artificial Intelligence (AI) and blockchain, the draft GAID proposes rigorous testing in controlled environments, DPIAs, and mechanisms for ongoing monitoring.

 

The draft GAID outlines procedures for handling data breaches, emphasizing immediate notification by Data Controllers to relevant authorities, including the Commission, in cases of high-risk breaches. It also introduces a Standard Notice to Address Grievance (SNAG), enabling data subjects to formally notify entities of perceived violations without precluding other legal or administrative remedies.

 

By addressing key areas requiring clarification within Nigeria’s data protection legal framework, the draft GAID, if issued, will serve as a practical guide for implementing the NDPA and aligning Nigeria with global data privacy standards.

 

Investigation of DCPMI

 

Q3 and Q4, 2024 witness the Commission’s initiation of routine investigations to assess the DCPMIs compliances across the country. During these investigations, the Commission emphasized the necessity for Data Controllers to ensure that all vendors and third-party processors engaged are duly registered with the Commission. The Commission’s directive was also reinforced in its Public Notice dated October 4, 2024, which stipulated that DCPMIs must only engage agents and contractors who are duly registered with the Commission to maintain the integrity and security of data processing activities in Nigeria. Non-compliance with this directive attracts penalties as stipulated in the NDPA. To align with these requirements, organizations are encouraged to adopt policies that make evidence of Commission registration a mandatory part of their Know Your Customer (KYC) procedures.

 

Conclusion

The developments in Nigeria’s data protection landscape following the enactment of the NDPA represent a significant leap toward creating a stronger regulatory framework that prioritizes accountability, transparency, and compliance. The introduction of new compliance directives, and classification guidelines for Data Controllers and Data Processors, underscores the government’s commitment to fostering a secure and dynamic data protection ecosystem. However, it is worthy of note that as the Commission refines its processes, it must also address judicial challenges and align its directives with statutory provisions to avoid legal uncertainties.

 

About AO2LAW:

At AO2LAW, we are committed to providing cutting-edge legal and compliance solutions, including data protection advisory and compliance services. Through our affiliate, Taxaide Technologies Limited, a NITDA-licensed Data Protection Compliance Organization (DPCO), we assist businesses in navigating their obligations under the Nigeria Data Protection Act 2023. Our services include compliance audits, regulatory advisory, and implementation support, ensuring organizations meet the highest standards of data protection.

 

 

For further information on the foregoing or related matters, please generally contact us at info@ao2law.com, or specifically contact the key contacts:

 

Get the full article by subscribing to our newsletter


\"\"

Bidemi Olumide
Managing Partner
bidemi.olumide@ao2law.com


\"\"

Joseph Ajah
Senior Associate
joseph.ajah@ao2law.com


\"\"

Oghenekaro Isiorho
Associate
oghenekaro.isiorho@ao2law.com


\"\"

Oluseun Olayiwola
Associate
oluseun.olaiwola@ao2law.com

Share

Want to keep up with our Articles?

Get our most valuable tips right inside your inbox, every month!

Related Posts

Web Banner - business survival vs liquidation 1
COMPANY VOLUNTARY ARRANGEMENT UNDER CAMA 2020: A VIABLE OPTION FOR CORPORATE SUSTAINABILITY?
Under Nigeria's CAMA 2020, Company Voluntary Arrangements (CVAs) offer financially distressed companies...
Web Banner - Conversion Petroleum 22
CONVERSION AND RENEWAL OF PETROLEUM LICENCES AND LEASES IN NIGERIA: WHAT THE 2026 REGULATIONS MEAN FOR UPSTREAM PETROLEUM OPERATORS
The 2026 Conversion and Renewal Regulations introduce a clearer framework for transitioning Nigerian...
Corporate Rescue banner
CORPORATE RESCUE AND INSOLVENCY PROCEDURE IN NIGERIA: A CRITICAL REVIEW OF THE LEGAL REGIME
Nigeria's corporate insolvency framework has decisively shifted from inevitable liquidation to prioritizing...
Web Banner - Gas Flare
GAS FLARE COMMERCIALISATION IN NIGERIA: PROGRESS, GAPS, AND WHAT OPERATORS NEED TO KNOW
Nigeria’s gas flare commercialisation framework has entered its execution phase, with 28 permits issued...
payment ecosystem beyound compliance
BEYOND COMPLIANCE - CBN'S SHIFT FROM REGULATING MARKET PARTICIPANTS TO REGULATING MARKET STRUCTURE
The Central Bank of Nigeria is shifting from individual participant supervision to structural oversight...
NAATIONAL SINGLE WINDOW
NIGERIA'S NATIONAL SINGLE WINDOW: REFORM, RISK, AND THE PROMISE OF A PAPERLESS PORT
Nigeria has officially launched Phase One of the National Single Window (NSW), a centralized digital...
Free Zone Land
COLLATERALISING FREE ZONE LAND INTERESTS FOR DEBT FINANCING IN NIGERIA – REGULATORY FRAMEWORKS AND TITLE REGISTRATION CONSIDERATIONS
Nigeria's Free Zones are capital-intensive environments by design. The Nigeria Export Processing Zones...
Electricity sky
OPERATING IN THE LAGOS ELECTRICITY MARKET: A GUIDE TO LICENSING REQUIREMENTS UNDER THE LAGOS STATE ELECTRICITY LAW, 2024
The Lagos State Electricity Regulatory Commission has officially transitioned to an active market regulation...
BURDEN 1
TOXIC LOANS IN NIGERIA: LAX LENDING PRACTICES IN THE BANKING INDUSTRY AND THE COST OF FAILED DUE DILIGENCE
Toxic loans, also known as Non-Performing Loans (NPLs), are rising in Nigeria due to lax lending practices...