Nigeria: Privacy Protection

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
Faith-Based Organisations And Data Protection In Nigeria: Why Audit Obligations Should Not End With Registration Exemptions
The Nigeria Data Protection Act and the General Application and Implementation Directive provide a comprehensive legal framework for the protection of personal data in Nigeria. The Act applies its provisions to data controllers and processors domiciled, resident, or operating in Nigeria, with the principal exception being processing undertaken solely for personal or household purposes.
Nigeria Privacy
SA
S.P.A. Ajibade & Co.
Article
Updates On The Recent Activities And Other Developments In The Privacy Sector
The Federal High Court has affirmed the statutory powers of the Nigeria Data Protection Commission (NDPC) to register Data Controllers and Data Processors of Major Importance (DCPMIs) under the Nigeria Data Protection Act (NDPA), 2023. In a judgment delivered on 28 July 2026 by Honourable Justice F.N. Ogazi in Emmanuel Harunna v. Nigeria Data Protection Commission (FHC/L/CS/1116/2024), the court dismissed the applicant’s contention that Point of Sale (PoS) agents should not be classified as Data Controllers or Processors subject to the Commission’s registration regime.
Nigeria Privacy
SA
S.P.A. Ajibade & Co.
Article
Artificial Intelligence And The Right To Privacy Under Section 37 Of The Constitution Of The Federal Republic Of Nigeria, 1999 (As Amended).
Nigeria's adoption of AI-powered facial recognition at major airports and automated credit scoring by digital lenders raises urgent questions about constitutional privacy protections. With Section 37 of the 1999 Constitution drafted before modern biometric surveillance existed, can its guarantee of privacy extend to algorithmic profiling and mass data collection?
Nigeria Technology
A
Alliance Law Firm
Article
The New ISO 27701:2025; Practical Steps For Developing Your Breach Response Plan
ISO/IEC 27701:2025 introduces a standalone, certifiable privacy management standard that transforms how organisations handle data breaches. This article explores how Nigerian organisations can align the new international standard with the Nigeria Data Protection Act to develop robust, auditable breach response plans that move beyond reactive incident handling toward proactive privacy governance.
Nigeria Privacy
BC
Babalakin & Co.Legal Practitioners
Article
Regulatory Finality Or Rights Erosion? Reassessing The CBN’s One-Time Phone Number Update Rule Through The Lens Of Rectification And Proportionality
The Central Bank of Nigeria's new rule limiting BVN-linked phone number changes to just once raises critical questions about balancing financial security with data subject rights. As phone numbers serve as essential authentication tools yet remain inherently changeable due to theft, loss, or compromise, this regulatory restriction may conflict with statutory rectification rights under data protection law.
Nigeria Finance
SB
Stren & Blan Partners
See more