Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
NGMEDIUM coverage2 enforcement actions

Nigeria Data Protection Act 2023 (NDPA): AI Compliance Requirements

Nigeria's Data Protection Act 2023 (signed June 12, 2023) replaced the 2019 NDPR framework and established the Nigeria Data Protection Commission (NDPC) as the regulatory authority. The NDPA applies to any organization processing personal data of Nigerian residents, wherever the organization is located. This is Africa's most comprehensive data protection law and directly addresses AI-driven processing. Section 24 provides the right to object to automated processing. The NDPA explicitly recognizes AI as a key risk area and requires organizations deploying AI for significant decisions to conduct Data Protection Impact Assessments, obtain legal basis, and maintain processing records. The Act is modelled on GDPR principles.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

June 12, 2023

Maximum Penalty

Two-tier structure: Data Controllers/Processors of Major Importance face NGN 10,000,000 OR 2% of annual gross revenue, whichever is higher; other controllers/processors face NGN 2,000,000 OR 2% of revenue, whichever is higher. Up to 1 year imprisonment for willful violations; data subjects may separately recover civil damages.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Right to Object to Automated Processing (Section 24)

Critical

Nigeria NDPA Section 24: data subjects have the right to object to solely automated processing — including AI profiling — that produces decisions with legal or similarly significant effects. Implement: (1) Privacy notice disclosure of AI-driven significant decisions. (2) A clear mechanism to submit objections and request human review. (3) Timely response (NDPA requires compliance within reasonable time). Document all automated decision systems and objection handling procedures.

NDPA 2023, Section 24

Data Protection Impact Assessment (DPIA) for AI

High Priority

DPIAs are required for processing likely to result in high risk, including automated decision-making, large-scale profiling, biometric data processing, and novel technology deployments. Before deploying AI systems processing Nigerian residents' data: conduct a formal DPIA, document it, and retain records for NDPC inspection. High-risk DPIAs may require NDPC prior consultation.

NDPA 2023 (DPIA duty for high-risk processing)

NDPC Registration & Data Protection Officer

Medium Priority

Organizations processing personal data of Nigerian residents on a large scale, or processing sensitive personal data, must: (1) Register with the NDPC (ndpc.gov.ng). (2) Designate a Data Protection Officer. (3) Maintain records of processing activities. Unregistered organizations processing Nigerian data face enforcement action.

NDPA 2023 (registration + DPO duty for large-scale/sensitive processing)

Who Does This Apply To?

Applies to: any data controller or processor that processes the personal data of individuals resident in Nigeria, wherever the organisation itself is located (NDPA 2023 has extraterritorial reach where a controller/processor not in Nigeria processes the data of Nigerian data subjects). There is no blanket small-business exemption, but the most onerous duties attach to a "data controller/processor of major importance" — broadly, those processing the data of a large number of Nigerian data subjects (the NDPC has used a threshold in the order of 1,000+ data subjects for the annual-audit/registration duties) or processing data in sensitive sectors. Core in-scope obligations for AI: a documented lawful basis under Section 25 for every processing activity; the Section 24 right to object to solely automated decision-making with legal or similarly significant effects, with a human-review mechanism; DPIAs for high-risk processing (profiling, biometric AI, large-scale automated decisions); NDPC registration and a Data Protection Officer for large-scale or sensitive processing; and cross-border-transfer safeguards (Section 43). Enforced by the Nigeria Data Protection Commission (NDPC). NOTE: this entry (nigeria_ndpa) and nigeria_ndpr both describe the same NDPA 2023 regime — flagged for founder canonical-entry consolidation (RQ-54); nigeria_ndpr is the more complete, already-remediated entry.

Recent Enforcement Actions

Nigeria Data Protection Commission (NDPC)2025-07-06Source verified· as of 2026-08-22

Against: MultiChoice Nigeria Ltd

Nigeria Data Protection Commission (NDPC)2024-06Source verified· as of 2026-08-22

Against: Four banks + three other institutions

Recent Regulatory Guidance

guidance2024

Nigeria Data Protection Act 2023 + NDPC General Application & Implementation Directive (GAID); NAIS 2024 (federal policy)

Obligations for AI processing of Nigerian residents' personal data derive from the Nigeria Data Protection Act 2023 and the NDPC's General Application and Implementation Directive (GAID), not from a standalone AI guidelines instrument: document the lawful basis for each AI processing activity before deployment; honour the NDPA's right to object to solely-automated decisions with significant effects with a clear human-review mechanism; conduct DPIAs for high-risk AI processing (profiling, biometric AI, large-scale automated decisions); Data Controllers/Processors of Major Importance must file periodic data-audit reports. The National Artificial Intelligence Strategy (2024) is a federal policy document setting the country's AI direction.

Frequently Asked Questions

Does Nigeria Data Protection Act 2023 (NDPA) apply to my business?

Nigeria's Data Protection Act 2023 (signed June 12, 2023) replaced the 2019 NDPR framework and established the Nigeria Data Protection Commission (NDPC) as the regulatory authority. The NDPA applies to any organization processing personal data of… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Nigeria Data Protection Act 2023 (NDPA) is: Two-tier structure: Data Controllers/Processors of Major Importance face NGN 10,000,000 OR 2% of annual gross revenue, whichever is higher; other controllers/processors face NGN 2,000,000 OR 2% of revenue, whichever is higher. Up to 1 year imprisonment for willful violations; data subjects may separately recover civil damages.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Nigeria Data Protection Act 2023 (NDPA)?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://ndpc.gov.ng/media/NDPA_2023.pdf

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan