Customer, employee, supplier and client data is a governance issue, not only an IT issue. Nigeria’s current framework is built around the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive issued by the Nigeria Data Protection Commission in March 2025, which became effective in September 2025.
Know what personal data the business actually holds
Start with a practical data map. Identify the personal data collected through websites, onboarding forms, payroll, recruitment, customer records, CCTV, marketing lists, vendor files, cloud applications and physical documents. The business should be able to explain why each material category is collected, where it is stored, who can access it and how long it is retained.
Choose and document a lawful basis
The NDP Act recognises lawful bases including consent, contract, legal obligation, vital interests, public interest and legitimate interests. Consent is not the correct answer for every processing activity. The business should identify the basis that genuinely fits the purpose and document its reasoning, particularly where sensitive data, direct marketing, children’s data or other higher-risk processing is involved.
Give meaningful privacy information
People should be told, in clear language, who is processing their data, why it is being processed, relevant recipients, retention considerations, their rights and how to raise a concern. A generic website paragraph is not enough if the organisation processes employee, customer or client data in materially different ways.
Respect data-subject rights
The NDPC identifies rights including being informed, access, rectification, objection, restriction, portability, erasure in appropriate circumstances, withdrawal of consent where relevant, rights concerning qualifying automated decision-making, and the right to complain to the Commission. Organisations should have an internal process for receiving, verifying, tracking and responding to requests.
Control vendors and cross-border processing
Cloud software, payroll platforms, email tools, CRM systems, hosting providers and outsourced service providers can process personal data on the organisation’s behalf. Contracts and due diligence should address confidentiality, security, permitted processing, breach handling, return or deletion of data and any cross-border transfer requirements that apply.
Build security around the actual risk
Reasonable technical and organisational measures may include role-based access, strong authentication, backups, device controls, staff awareness, secure document sharing, logging, incident-response procedures and regular review of who still needs access. Security should be proportionate to the sensitivity, volume and business impact of the data involved.
Prepare for incidents before they happen
A privacy incident can arise from a cyberattack, lost device, misdirected email, exposed spreadsheet, unauthorised employee access or careless disclosure. Businesses should have a documented escalation route so that incidents are assessed quickly, evidence is preserved and regulatory or data-subject notification obligations are considered promptly.
What management should ask
- Do we know which personal data we collect and where it is stored?
- Can we explain the lawful basis and purpose for material processing activities?
- Are our privacy notices accurate for what we actually do?
- Do vendor contracts address personal-data responsibilities?
- Can we respond to a data-subject request without searching across disconnected systems?
- Do we have a workable breach-response process?
Source trail
Primary references include the Nigeria Data Protection Act 2023, the NDP Act General Application and Implementation Directive 2025 and guidance published by the Nigeria Data Protection Commission.
Publication note: Data-protection obligations depend on the nature, scale and risk of processing. Businesses should assess the requirements applicable to their own operations and seek specialist advice where necessary.