Contact

Technical Brief · Legal

Data Protection for Nigerian Businesses in 2026: Practical Obligations Under the NDP Act and GAID

Customer, employee and client data is now a board-level compliance issue, not only an IT concern.

Customer, employee, supplier and client data is a governance issue, not only an IT issue. Nigeria’s current framework is built around the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive issued by the Nigeria Data Protection Commission in March 2025, which became effective in September 2025.

Know what personal data the business actually holds

Start with a practical data map. Identify the personal data collected through websites, onboarding forms, payroll, recruitment, customer records, CCTV, marketing lists, vendor files, cloud applications and physical documents. The business should be able to explain why each material category is collected, where it is stored, who can access it and how long it is retained.

Choose and document a lawful basis

The NDP Act recognises lawful bases including consent, contract, legal obligation, vital interests, public interest and legitimate interests. Consent is not the correct answer for every processing activity. The business should identify the basis that genuinely fits the purpose and document its reasoning, particularly where sensitive data, direct marketing, children’s data or other higher-risk processing is involved.

Give meaningful privacy information

People should be told, in clear language, who is processing their data, why it is being processed, relevant recipients, retention considerations, their rights and how to raise a concern. A generic website paragraph is not enough if the organisation processes employee, customer or client data in materially different ways.

Respect data-subject rights

The NDPC identifies rights including being informed, access, rectification, objection, restriction, portability, erasure in appropriate circumstances, withdrawal of consent where relevant, rights concerning qualifying automated decision-making, and the right to complain to the Commission. Organisations should have an internal process for receiving, verifying, tracking and responding to requests.

Control vendors and cross-border processing

Cloud software, payroll platforms, email tools, CRM systems, hosting providers and outsourced service providers can process personal data on the organisation’s behalf. Contracts and due diligence should address confidentiality, security, permitted processing, breach handling, return or deletion of data and any cross-border transfer requirements that apply.

Build security around the actual risk

Reasonable technical and organisational measures may include role-based access, strong authentication, backups, device controls, staff awareness, secure document sharing, logging, incident-response procedures and regular review of who still needs access. Security should be proportionate to the sensitivity, volume and business impact of the data involved.

Prepare for incidents before they happen

A privacy incident can arise from a cyberattack, lost device, misdirected email, exposed spreadsheet, unauthorised employee access or careless disclosure. Businesses should have a documented escalation route so that incidents are assessed quickly, evidence is preserved and regulatory or data-subject notification obligations are considered promptly.

What management should ask

  • Do we know which personal data we collect and where it is stored?
  • Can we explain the lawful basis and purpose for material processing activities?
  • Are our privacy notices accurate for what we actually do?
  • Do vendor contracts address personal-data responsibilities?
  • Can we respond to a data-subject request without searching across disconnected systems?
  • Do we have a workable breach-response process?

Source trail

Primary references include the Nigeria Data Protection Act 2023, the NDP Act General Application and Implementation Directive 2025 and guidance published by the Nigeria Data Protection Commission.

Publication note: Data-protection obligations depend on the nature, scale and risk of processing. Businesses should assess the requirements applicable to their own operations and seek specialist advice where necessary.

Professional note. This publication is general information only and does not by itself constitute legal, tax, audit, investment or other professional advice. The appropriate treatment depends on the facts, applicable law, regulatory guidance and the scope of the engagement.

Need the practical implication?

Apply the insight to your actual business position.

Speak with ADETAI