Nigeria: Data Protection

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
Faith-Based Organisations And Data Protection In Nigeria: Why Audit Obligations Should Not End With Registration Exemptions
The Nigeria Data Protection Act and the General Application and Implementation Directive provide a comprehensive legal framework for the protection of personal data in Nigeria. The Act applies its provisions to data controllers and processors domiciled, resident, or operating in Nigeria, with the principal exception being processing undertaken solely for personal or household purposes.
Nigeria Privacy
SA
S.P.A. Ajibade & Co.
Article
Updates On The Recent Activities And Other Developments In The Privacy Sector
The Federal High Court has affirmed the statutory powers of the Nigeria Data Protection Commission (NDPC) to register Data Controllers and Data Processors of Major Importance (DCPMIs) under the Nigeria Data Protection Act (NDPA), 2023. In a judgment delivered on 28 July 2026 by Honourable Justice F.N. Ogazi in Emmanuel Harunna v. Nigeria Data Protection Commission (FHC/L/CS/1116/2024), the court dismissed the applicant’s contention that Point of Sale (PoS) agents should not be classified as Data Controllers or Processors subject to the Commission’s registration regime.
Nigeria Privacy
SA
S.P.A. Ajibade & Co.
Article
Nigeria’s National Digital Cloud Policy: Key Provisions And Implications For Business
On 17 August 2026, Nigeria's Federal Government released its National Digital Cloud Policy, superseding the 2019 framework to establish a domestic cloud and data infrastructure ecosystem. The Policy introduces fiscal and regulatory incentives for qualifying investors, mandates cloud-first adoption across government agencies, and implements a four-tier sovereign data classification system that confines data residency requirements to specific categories rather than imposing blanket localisation.
Nigeria Technology
T
Templars
Article
Exemption From NDPC Registration Does Not Mean Exemption From Data Protection Compliance: Understanding The GAID Framework
The introduction of registration requirements for certain data controllers and data processors under the General Application and Implementation Directive (GAID) has significantly altered the compliance landscape of Nigeria's data protection regime. However, the registration framework has also given rise to a common misconception among organisations that fall below the prescribed registration thresholds or otherwise qualify for an exemption: namely, that exemption from registration translates into exemption from data protection obligations.
Nigeria Privacy
SA
S.P.A. Ajibade & Co.
Article
Confidentiality Role Of Paralegals In The Nigerian Legal Sector
In the legal profession, maintaining confidentiality in the course of practice is not just a principle, it is a daily ethical conduct. This is not unconnected to the sensitivity of the legal sector and the fact that legal practitioners and paralegals handle sensitive information of clients which carries significant implications if exposed or leaked. Ethically, client information is expected to be kept confidential, hence the attorney-client privilege serving as the legal pillar underpinning that obligation.
Nigeria Law Performance
SA
S.P.A. Ajibade & Co.
Article
Open Banking And Digital Lending In Nigeria: Opportunities, Risks And Regulatory Readiness
Nigeria's open banking framework promises to transform digital lending through secure, consent-driven financial data sharing. As the phased rollout approaches mid-2026, lenders face both opportunity and obligation: faster credit decisions, better risk assessment, and new product possibilities, alongside stricter compliance requirements and infrastructure dependencies that will reshape competitive dynamics across the sector.
Nigeria Finance
TA
Tope Adebayo LP
Article
Beyond The Pitch: Balancing Data-Driven Success With Performance And Data Privacy
Modern sports organizations increasingly rely on data analytics to enhance athlete performance and gain competitive advantages. However, this data-driven approach raises critical questions about how to protect athletes' personal information while maximizing the benefits of performance tracking. The intersection of sports technology and privacy law creates complex challenges that require careful navigation by teams, leagues, and legal professionals.
Nigeria Privacy
AP
Advocaat Law Practice
Article
Poisoned At The Source: Securing Nigeria’s AI Supply Chain Against Data Poisoning
Nigerian technology businesses face a critical challenge in AI governance: data poisoning attacks that embed harmful patterns during model training, before traditional guardrails can detect them. This analysis examines how adversarial manipulation of training data creates legal, cybersecurity, and procurement risks that existing controls may miss. Understanding where poisoning enters the AI pipeline and how Nigerian law applies to these threats is essential for organizations deploying AI systems.
Nigeria Privacy
TA
Tope Adebayo LP
Article
Anita Joseph vs Caramel Plug: Who Actually Owns Your Photos Under Nigeria’s Copyright Act
When actress Anita Joseph used AI to swap her face onto content creator Caramel Plug's birthday photograph, it sparked a viral controversy that exposed critical gaps in how Nigeria's creative industry understands copyright ownership. Under the Copyright Act 2022, the photographer—not the subject—typically owns the image, while AI-generated derivatives exist in a legal gray zone that may leave no one with enforceable rights.
Nigeria IP
OA
Olisa Agbakoba Legal (OAL)
Article
CBN’S Data Localisation Directive – Compliance Considerations For Payment System Participants
Nigeria's Central Bank has introduced sweeping data localisation requirements that will fundamentally reshape how payment service providers, banks, and financial institutions handle transaction data. With a January 2027 compliance deadline, these new rules mandate that all payment transaction data generated within Nigeria must be stored and managed locally, raising critical questions about cloud infrastructure, vendor relationships, and operational readiness. This analysis examines the scope of the requirem
Nigeria Finance
PL
Pavestones Legal
Article
The NIMC Act 2026 Explained: What Nigeria’s New Identity Law Means For You
Nigeria's new National Identity Management Commission Act 2026 introduces sweeping reforms to the country's digital identity infrastructure, making the National Identification Number mandatory for essential services while designating NIMC as the nation's Root Certificate Authority. The legislation imposes significantly harsher penalties for identity offences and reconstitutes NIMC's governance structure, but questions remain about data protection safeguards and the concentration of power within a single ins
Nigeria Government
OA
Olisa Agbakoba Legal (OAL)
Article
Nigeria's 48-Hour Data Breach Notification Requirement: Regulatory Implications And Comparative Analysis
Nigeria's Internet Code of Practice 2026 introduces a 48-hour breach notification requirement for Internet Access Service Providers, creating a shorter timeline than the Nigeria Data Protection Act 2023 and raising questions about overlapping regulatory obligations. This development reflects a broader global trend toward sector-specific cyber resilience requirements that demand earlier visibility into cyber incidents.
Nigeria Privacy
Syntegral Legal Practice
See more