Home › Law library › NDPA / GAID
NG
NDPA / GAID
Nigeria Data Protection Act 2023, with the NDPA General Application and Implementation Directive (GAID) 2025
Sourced. Last verified 9 October 2026
Nigeria Privacy
- Status
- NDPA in force (assented 13 June 2023). GAID issued 20 March 2025, effective 19 September 2025; it replaces the NDPR 2019 and its 2020 Implementation Framework.
- Who it applies to
- Controllers and processors domiciled, resident or operating in Nigeria. Under the GAID, 'operating in Nigeria' includes targeting Nigerian data subjects without a local presence (extraterritorial).
- Size thresholds
- 'Major importance' (must register): more than 200 data subjects in 6 months, or set sectors regardless of volume (finance, health, insurance, e-commerce, etc.). Tiers: >200, >1,000, >5,000 subjects.
- Regulator
- Nigeria Data Protection Commission (NDPC)
- Breach or incident reporting
- Notify the NDPC within 72 hours of becoming aware of a breach likely to risk individuals' rights; notify affected people immediately if high risk.
- Deadline to answer personal data requests
- Being verified
- Data protection officer
- Mandatory for data controllers/processors of major importance; may be an employee or contractor. GAID adds DPO credential assessment and certification.
- Local representative
- Being verified
- Sending data abroad
- Allowed to NDPC-assessed adequate jurisdictions, or using a Cross-Border Data Transfer Instrument, or exceptions (explicit consent, contract, legal claims).
- Cookies and consent
- Consent is one of six lawful bases; it must be specific, separately requested and withdrawable (notice alone is not consent). Privacy policies must disclose cookies and similar tracking tools.
- Maximum penalty
- Major importance: greater of 2% of prior-year gross revenue or NGN 10 million. Others: greater of 2% or NGN 2 million.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Count data subjects over 6 months to see if you are of major importance; register in the right tier.
- Pay the registration fee (NGN 10,000 / 100,000 / 250,000 by tier).
- File your annual Compliance Audit Return by 31 March if you are in the Extra-High or Ultra-High tier.
- Appoint a certified DPO if you are of major importance.
- Report breaches to the NDPC within 72 hours.
- Use a DPIA and meet GAID pre-deployment checks before using AI, IoT or blockchain.
- Record a legitimate-interest assessment before relying on that basis.
Recent changes
GAID issued March 2025, effective 19 Sept 2025: new registration tiers and fees, revised CAR thresholds, DPO certification, a standard DPIA template, emerging-tech rules and explicit extraterritorial targeting test.
Sources
- Primary source: https://ndpc.gov.ng/
- Second source: https://www.dlapiperdataprotection.com/index.html?t=law&c=NG
- Regulator: Nigeria Data Protection Commission (NDPC)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].