Image: Jummy001 / Wikimedia Commons, CC BY-SA 4.0
MDAs must appoint and register data protection officers, budget for compliance and file annual audit returns by 31 March; vendors processing government data are affected.
The Nigeria Data Protection Commission announced on 4 August 2026 that the Federal Government had issued a compliance circular (Circular No. 59805/S.I/7) directing all Ministries, Departments and Agencies to comply with the Nigeria Data Protection Act 2023 and the Commission’s regulations, guidelines and directives.
Requirements
MDAs must designate qualified data protection officers and register them with the NDPC; may engage licensed Data Protection Compliance Organisations; must allocate budget for compliance, including training, technical safeguards and audits; and must file annual Data Protection Compliance Audit Returns by 31 March. Permanent secretaries, accounting officers and chief executives “shall be personally responsible for ensuring institutional compliance”. The NDPC has set up a regulatory clinic to support MDAs.
Why it matters to the private sector
Government institutions hold some of the largest personal data sets in Nigeria, including identity, tax, health and education records. Private contractors, technology vendors and cloud providers that process data for MDAs act as data processors under the NDPA. MDAs will now require data processing agreements, clear allocation of responsibilities and data protection impact assessments from vendors, and may audit them.
Vendors should expect procurement documents to include NDPA compliance warranties, breach notification obligations and restrictions on cross-border transfers, which interact with the National Digital Cloud Policy and NITDA’s sovereign cloud framework favouring hosting of government data in Nigeria. Personal liability of senior officials will make MDAs more demanding in contract negotiations.
Context
Courts are beginning to enforce the NDPA against private controllers. In Onimisi v Guaranty Trust Holding Company Plc, the Federal High Court found unlawful processing for direct marketing, and a Lagos High Court held in September 2026 that Truecaller could not rely on a user’s consent to process the data of people in that user’s contacts. Public sector compliance has lagged; the circular puts the public sector on the same footing.



Leave a Reply