Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
AfricaMEDIUM coverage2 enforcement actions

Nigeria Data Protection Regulation (NDPR 2019) + Nigeria Data Protection Act 2023: AI Compliance Requirements

Nigeria has Africa's most comprehensive data protection framework. The Nigeria Data Protection Regulation (NDPR 2019) was superseded by the Nigeria Data Protection Act (NDPA 2023), administered by the Nigeria Data Protection Commission (NDPC). Nigeria is the most populous African country and its largest economy, making compliance critical for any Africa-focused AI deployment. Organizations processing data of over 1,000 Nigerian individuals must file annual data audit reports. AI systems processing Nigerian data must comply with NDPA consent, transparency, and data subject rights requirements.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 25, 2019

Enforcement Begins

June 14, 2023

Maximum Penalty

Two-tier structure under NDPA 2023: Data Controllers/Processors of Major Importance face a fine of NGN 10,000,000 OR 2% of annual gross revenue from the preceding year, WHICHEVER IS HIGHER (so 2% can exceed ₦10M for a large company); other controllers/processors face NGN 2,000,000 OR 2% of annual gross revenue, whichever is higher. Imprisonment for up to 1 year may also apply. Data subjects may separately recover damages for injury/loss/harm in civil proceedings.

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Lawful Basis and Consent Framework

Critical

NDPA 2023 Section 25 requires a documented lawful basis for all personal data processing: consent, contract, legal obligation, vital interests, public interest, or legitimate interest. AI systems processing Nigerian residents' data must document their basis prior to processing. Consent must be freely given, specific, informed, and unambiguous — pre-ticked boxes and bundled consent are prohibited.

NDPA 2023, Section 25

Data Subject Rights (Access, Correction, Deletion)

Critical

NDPA 2023 Sections 34-43 grant Nigerian residents rights to access, rectify, erase, restrict, and port their personal data. AI automated decision-making must be disclosed and human review provided on request. Data controllers must respond within 30 days. A designated Data Protection Officer (DPO) is required for high-risk processing.

NDPA 2023, Sections 34-43

Annual Data Protection Audit Filing

High Priority

NDPR 2019 (and transitional NDPA 2023 obligations) require organizations processing data of more than 1,000 Nigerian individuals to submit an annual data audit report to the NDPC before 15 March each year. The report must cover categories of data processed, security measures, breach incidents, and AI-specific processing activities.

Deadline: March 15, 2027

NDPR 2019 (transitional obligation under NDPA 2023)

Cross-Border Data Transfer Safeguards

Medium Priority

NDPA 2023 Section 43 restricts transfer of Nigerian personal data outside Nigeria to countries with an adequate level of data protection or with NDPC-approved transfer mechanisms (BCRs, standard contractual clauses). Cloud AI services processing Nigerian data must document transfer controls and maintain records available for NDPC inspection.

NDPA 2023, Section 43

Recent Enforcement Actions

Nigeria Data Protection Commission2024-06Source verified· as of 2026-08-22

Against: Four banks + three other institutions

Source
Nigeria Data Protection Commission2025-07Source verified· as of 2026-08-22

Against: MultiChoice Nigeria Ltd

Source

Recent Regulatory Guidance

guidance2024-05

NDPC + NITDA — AI Ethics Code and Nigeria Data Protection Act 2023 implementation (2023-2024)

NITDA published the Nigeria National AI Ethics Code (2024) covering responsible AI deployment alongside NDPC guidance on the Nigeria Data Protection Act (NDPA) 2023. Key obligations: (1) controllers must register with NDPC as Data Controllers/Processors of Major Importance where annual processing thresholds are met; (2) DPIA required for AI processing likely to result in high risk; (3) AI-driven automated decisions affecting Nigerian residents trigger transparency and human-review rights; (4) cross-border transfers require NDPC adequacy or appropriate safeguards. CBN AI Policy for Banks (2024) and SEC Nigeria's AI guidance for capital markets impose sectoral overlays.

Key Case Law & Precedent

NDPC v. MultiChoice Nigeria (2025)

Nigeria Data Protection Commission · 2025

CORRECTION of a prior fabricated "NDPC v. Truecaller ₦220M" citation — no such fine exists; the Truecaller/TikTok matter is an open NDPC probe. The real leading NDPC enforcement precedent is the ₦766,242,500 fine on MultiChoice Nigeria (July 2025) for NDP Act violations, alongside the ₦400 million in aggregate remediation fees paid by seven companies (June 2024) — together establishing the NDPC's active penalty practice for processing Nigerian personal data without documented lawful basis, transparency, and data-subject rights mechanisms.

Outcome: ₦766,242,500 fine on MultiChoice Nigeria (July 2025)

Case reference

Frequently Asked Questions

Does Nigeria Data Protection Regulation (NDPR 2019) + Nigeria Data Protection Act 2023 apply to my business?

Nigeria has Africa's most comprehensive data protection framework. The Nigeria Data Protection Regulation (NDPR 2019) was superseded by the Nigeria Data Protection Act (NDPA 2023), administered by the Nigeria Data Protection Commission (NDPC).… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Nigeria Data Protection Regulation (NDPR 2019) + Nigeria Data Protection Act 2023 is: Two-tier structure under NDPA 2023: Data Controllers/Processors of Major Importance face a fine of NGN 10,000,000 OR 2% of annual gross revenue from the preceding year, WHICHEVER IS HIGHER (so 2% can exceed ₦10M for a large company); other controllers/processors face NGN 2,000,000 OR 2% of annual gross revenue, whichever is higher. Imprisonment for up to 1 year may also apply. Data subjects may separately recover damages for injury/loss/harm in civil proceedings.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Nigeria Data Protection Regulation (NDPR 2019) + Nigeria Data Protection Act 2023?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://ndpc.gov.ng/NDPA2023.pdf

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan