Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.
Nigeria
NGschema gdpri-v2trajectory: not yet assessedin transitionoverlaps: FIM, WPM, AIC
Last updated · 10 categories · 45
claims · 25 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
45Claimsbaseline..claims[]
18Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 28 September 2026.
Lead Signal
Nigeria's data-protection enforcement programme has escalated markedly through 2025 and 2026, positioning the Nigeria Data Protection Commission as one of the most active data-protection enforcers in the Global South. Two headline penalties anchor this cycle's lead signal: MultiChoice Nigeria was fined ₦766.2 million in July 2025 for data-privacy violations and illegal cross-border data transfers, and Meta Platforms was fined $220 million, reported as the largest penalty imposed by a Global South data-protection authority. These are not isolated incidents; they sit atop a broader enforcement programme that has, per NDPC's own account, collected approximately ₦7.2 billion, registered more than 38,000 companies, and completed 246 breach investigations.
The NDPC's enforcement statutory basis rests on the Nigeria Data Protection Act 2023, which sets tiered penalty ceilings: for Data Controllers and Processors of Major Importance, maximum fines are the higher of ₦10 million or 2 per cent of annual gross revenue, and for other organisations the higher of ₦2 million or 2 per cent of annual gross revenue. The Commission's active investigation of Temu, focused on data-processing practices and compliance, indicates this enforcement intensity is continuing rather than concluding with the MultiChoice and Meta actions.
Other Developments
A financial-sector overlay newly invokes the NDPA framework. The Central Bank of Nigeria's 2026 payments-data-localisation circular requires all financial institutions to ensure that Nigeria-generated payments transaction data is stored and managed within Nigeria, and does so explicitly in accordance with data protection law. This is a sectoral watch development of note: it is the financial sector's regulator, not the NDPC itself, reaching for the NDPA framework to justify a data-residency requirement, illustrating how the NDPA's reach is being extended through cross-sectoral regulatory cooperation rather than through the NDPC acting alone.
The compliance-audit regime tightened procedurally. Data Controllers and Processors of Major Importance are required to conduct an annual Data Protection Compliance Audit and file returns with the NDPC within the first quarter of each year; the 2025 filing window was extended to 30 May 2026, giving covered organisations additional time but also signalling heightened compliance-audit expectations for the 2026 audit season.
Cross-Monitor Connections
The CBN's payments-data-localisation circular is also covered by the world-payments monitor, which reads the same instrument primarily through its correspondent-banking and settlement-architecture implications; here it is read for its explicit invocation of the NDPA framework as the legal basis for data residency. The financial-integrity monitor separately reads the same underlying CBN circular activity for its beneficial-ownership and AML-surveillance dimensions. All three readings describe overlapping but analytically distinct facets of the same 2026 CBN regulatory action and should be read as complementary rather than duplicative.
Outlook
The NDPC's active investigation of Temu is the concrete near-term development to watch: whether it concludes in a further headline penalty, following the pattern set by MultiChoice and Meta, would further confirm the durability of Nigeria's high-enforcement-intensity posture rather than treating the 2025 actions as anomalies. The 2026 audit season, with its extended filing deadline of 30 May 2026, will also be a useful indicator of whether the NDPC's compliance-audit programme is achieving broader coverage across Data Controllers and Processors of Major Importance.
trust tier: ai_unverified
Standing brief, as of 28 September 2026.
Regulatory Status
Nigeria's data-protection enforcement activity escalated markedly through 2025-2026, with the Nigeria Data Protection Commission imposing headline fines against MultiChoice Nigeria (₦766.2 million, July 2025) and Meta Platforms ($220 million, reported as the largest Global South data-protection penalty), against a statutory backdrop of tiered penalty ceilings under the Nigeria Data Protection Act 2023. The NDPC's broader programme has, per its own figures, collected approximately ₦7.2 billion, registered more than 38,000 companies, and completed 246 breach investigations, and it is actively investigating Temu for NDPA violations. A new sectoral development this cycle sees the Central Bank of Nigeria's 2026 payments-data-localisation circular explicitly invoke the NDPA framework, requiring Nigeria-generated payments transaction data to be stored domestically.
Outlook
The NDPC's ongoing Temu investigation and the outcome of the 2026 compliance-audit season, following an extended 30 May 2026 filing deadline for Data Controllers and Processors of Major Importance, are the two developments most worth tracking into the next cycle.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Core statute and implementing directive are in force and actively enforced (registration, DPIA review, fines), but several operational details (e.g., full subsidiary regulations, sectoral harmonisation) remain under active development, consistent with the JID's in_transition designation.
Primary frameworkNigeria Data Protection Act, 2023 (NDPA)
Traffic-light rationale — AmberCore statute and implementing directive are in force and actively enforced (registration, DPIA review, fines), but several operational details (e.g., full subsidiary regulations, sectoral harmonisation) remain under active development, consistent with the JID's in_transition designation.
Sub-modules (5)
Regulator And AuthorityGreen
NDPC established under the NDPA as an independent statutory commission overseeing implementation.
Claims (1):
The NDPA established the Nigeria Data Protection Commission whose mandate is to oversee implementation of the NDP Act.
Act And InstrumentsGreen
NDPA 2023 is primary; GAID 2025 is the operative implementing directive, effective 19 Sept 2025, superseding NDPR 2019.
Claims (2):
The Federal Government of Nigeria signed the Nigeria Data Protection Act 2023 into law on 12 June 2023.
The NDPC published the General Application and Implementation Directive (GAID) of the NDPA in March 2025, which took effect 19 September 2025 and expressly replaced the Nigeria Data Protection Regulation 2019.
Material ScopeGreen
Act covers all sectors and all aspects of data privacy processing.
Claims (1):
The NDP Act covers all sectors and all aspects of data privacy, imposing a duty of care in respect of customers, employees, guests, visitors, and other data subjects.
Territorial ScopeGreen
Applies to domiciled/resident/operating entities in Nigeria and extraterritorially to processors of Nigeria-based data subjects' data.
Claims (1):
The NDP Act applies where the organisation is domiciled, resident, or operating in Nigeria, where processing occurs within Nigeria, or where a non-domiciled organisation processes personal data of a data subject in Nigeria.
Data controllers and data processors of major importance (DCPMI) must register with the NDPC, classified into Ultra-High, Extra-High and Ordinary-High Level tiers with corresponding registration fees.
Category narrative131 words
Nigeria's regime is anchored on the Nigeria Data Protection Act 2023 (NDPA), which established the Nigeria Data Protection Commission (NDPC) as a statutory independent authority, elevating the prior Nigeria Data Protection Regulation (NDPR 2019) — a lower-status regulatory instrument issued by NITDA — to a full comprehensive statute. The NDPC's General Application and Implementation Directive (GAID) 2025, published March 2025 and effective 19 September 2025, operationalises the Act and expressly supersedes the NDPR as the primary interpretive instrument. Material and territorial scope are broad: the Act applies to any entity domiciled, resident, or operating in Nigeria, to processing occurring within Nigeria, and extraterritorially to non-domiciled entities processing the data of Nigeria-based data subjects. Registration of Data Controllers/Processors of Major Importance (DCPMI) is mandatory and actively enforced via an online registration portal.
Sources and claims (6)
ProbableNDPC — The NDPA established the Nigeria Data Protection Commission whose mandate is to oversee implementation of the NDP Act.observed
ProbableNDPC — The Federal Government of Nigeria signed the Nigeria Data Protection Act 2023 into law on 12 June 2023.observed
ProbableIAPP — The NDPC published the General Application and Implementation Directive (GAID) of the NDPA in March 2025, which took effect 19 September 2025 and expressly replaced the Nigeria Data Protection Regulation 2019.observed
ProbableNDPC — The NDP Act covers all sectors and all aspects of data privacy, imposing a duty of care in respect of customers, employees, guests, visitors, and other data subjects.observed
ProbableNDPC — The NDP Act applies where the organisation is domiciled, resident, or operating in Nigeria, where processing occurs within Nigeria, or where a non-domiciled organisation processes personal data of a data subject in Nigeria.observed
ProbableNDPC — Data controllers and data processors of major importance (DCPMI) must register with the NDPC, classified into Ultra-High, Extra-High and Ordinary-High Level tiers with corresponding registration fees.observed
Core lawful-basis and consent framework is in force, but detailed sub-regulatory guidance on special categories, pseudonymisation/anonymisation safe-harbours and precise child-consent mechanics is not yet confirmed as published.
Primary frameworkNigeria Data Protection Act, 2023 (NDPA), Part V
Traffic-light rationale — AmberCore lawful-basis and consent framework is in force, but detailed sub-regulatory guidance on special categories, pseudonymisation/anonymisation safe-harbours and precise child-consent mechanics is not yet confirmed as published.
Sub-modules (4)
Lawful BasesGreen
Lawful bases include consent, legal obligation, contract, vital interest, and public interest.
Claims (1):
NDPC relies on and recognises lawful bases for data processing such as consent, legal obligation and contract, consistent with NDPA Part V provisions on lawful basis of personal data processing.
Consent ThresholdsGreen
Consent must be evidenced in writing, orally, electronically, or through other action demonstrating the data subject's knowledge and agreement.
Claims (1):
A data controller must seek consent either in writing, orally, through electronic means or by any other action through which the data subject knows he is giving consent.
Special CategoriesAmber
Sensitive personal data is addressed under Section 30 NDPA; GAID Article 28(8) imposes DPIA obligations for software processing sensitive data.
Claims (1):
A data controller or processor that deploys software for processing sensitive personal data must carry out a DPIA and submit it to the Commission within four months, per GAID Article 28(8).
Pseudonymisation And AnonymisationRed
No specific pseudonymisation/anonymisation safe-harbour provisions were located in this research pass.
Category narrative89 words
The NDPA (Part V, Sections 24-33) establishes principles and lawful bases for processing including consent, contract, legal obligation, vital interest and public interest. Consent must be freely given and evidenced in writing, orally, electronically or by other clear action. Sensitive personal data is addressed under Section 30, and processing of data belonging to children or persons lacking legal capacity to consent is addressed under Section 31, though granular thresholds (e.g., exact minimum age, verification mechanics) are not yet fully elaborated in public NDPC guidance located in this research pass.
Sources and claims (4)
ProbableNDPC — NDPC relies on and recognises lawful bases for data processing such as consent, legal obligation and contract, consistent with NDPA Part V provisions on lawful basis of personal data processing.observed
ProbableNDPC — A data controller must seek consent either in writing, orally, through electronic means or by any other action through which the data subject knows he is giving consent.observed
ProbableNDPC — A data controller or processor that deploys software for processing sensitive personal data must carry out a DPIA and submit it to the Commission within four months, per GAID Article 28(8).observed
UncertainNDPC — No confirmed statutory or GAID-level pseudonymisation/anonymisation safe-harbour definitions were identified for NG in this research pass.observed
Traffic-light rationale — AmberRights are enumerated and in force, but response-window deadlines are not confirmed from available sources.
Sub-modules (5)
Access RightAmber
General rights of a data subject are set out in Section 34 NDPA.
Claims (1):
Part VI of the NDPA (Section 34) sets out the general rights of a data subject, including withdrawal of consent under Section 35.
Rectification And ErasureAmber
Rectification/erasure rights fall within the general Section 34 rights bundle; no separately confirmed provision text located.
Claims (1):
Part VI of the NDPA (Section 34) sets out the general rights of a data subject, including withdrawal of consent under Section 35.
Restriction And ObjectionGreen
Right to object is set out in Section 36 NDPA.
Claims (1):
Section 36 of the NDPA provides data subjects a right to object to processing.
Data PortabilityGreen
Data portability right is set out in Section 38 NDPA.
Claims (1):
Section 38 of the NDPA provides for a data portability right, alongside Section 37's provisions on automated decision making.
Deadlines And Response WindowsRed
No confirmed statutory response-window deadline for data subject rights requests was located in this research pass.
Category narrative59 words
Part VI of the NDPA (Sections 34-38) enumerates data subject rights including general rights, withdrawal of consent, right to object, automated decision-making protections, and data portability. Specific statutory deadlines for controller response windows (analogous to GDPR's one-month SAR window) were not confirmed in the sources reviewed and should be verified against the full Act text or forthcoming NDPC guidance.
Sources and claims (4)
ProbableNational Assembly / hosted via DataGuidance — Part VI of the NDPA (Section 34) sets out the general rights of a data subject, including withdrawal of consent under Section 35.observed
ProbableNational Assembly / hosted via DataGuidance — Section 38 of the NDPA provides for a data portability right, alongside Section 37's provisions on automated decision making.observed
UncertainNDPC — No confirmed statutory deadline for controller response to data subject rights requests was located in the sources reviewed for NG.observed
Core accountability, DPIA, DPO, breach-notification and audit-filing obligations are confirmed in force and actively administered via NDPC's registration and DPCO ecosystem.
Primary frameworkNigeria Data Protection Act, 2023 (NDPA), Parts V & VII; GAID 2025
Traffic-light rationale — GreenCore accountability, DPIA, DPO, breach-notification and audit-filing obligations are confirmed in force and actively administered via NDPC's registration and DPCO ecosystem.
Sub-modules (7)
Accountability And DpiaGreen
DPIA obligations under Section 28 NDPA and GAID Article 28(3)/(8), including a 4-month submission window for sensitive-data-processing software DPIAs.
Claims (1):
A data controller or data processor who deploys software for processing of sensitive personal data must carry out a DPIA and submit same to the Commission within four months, per GAID Article 28(8).
Dpo RequirementsGreen
Section 32 NDPA requires Data Protection Officers; GAID sets DPO reporting duties on compliance status.
Claims (1):
Section 32 of the NDPA (Part V) provides for the appointment of Data Protection Officers, with GAID requiring DPO reports to include the compliance status of the data controller or processor.
Ropa RequirementsAmber
No dedicated Records of Processing Activities (ROPA) provision was separately confirmed; likely embedded within general accountability/registration obligations.
Joint Controller ArrangementsGreen
Section 29(1)(a) requires controllers engaging processors to ensure processor compliance with applicable principles/obligations; joint and vicarious liability applies to corporate officers and agents.
Claims (2):
Under Section 29(1)(a) of the NDPA, where a data controller or processor engages another processor, it must ensure the engaged processor complies with the principles and obligations applicable to the controller.
Where an offence has been committed by a body corporate or firm, principal officers are deemed culpable unless they prove the offence occurred without their consent/connivance and they exercised diligence to prevent it; controllers/processors are vicariously liable for acts of agents or employees.
Security MeasuresAmber
Part VII of the NDPA (Section 39) addresses security, integrity and confidentiality of processing.
Claims (1):
Part VII of the NDPA (Section 39, 'Security, integrity, and confidentiality') establishes security-of-processing obligations for controllers and processors.
Breach NotificationGreen
72-hour breach notification to the Commission required under Section 40(2); processor-to-controller notification obligations under Section 40(1).
Claims (2):
A data controller shall, within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals, notify the Commission of the breach, describing its nature including categories and approximate numbers of data subjects and records concerned.
Where a breach occurs with respect to data being processed by a data processor, the processor shall, on becoming aware of the breach, notify the engaging data controller/processor describing the nature of the breach and respond to information requests.
Retention And DisposalRed
No confirmed statutory retention-period or disposal-duty provisions were located in this research pass.
Category narrative103 words
The NDPA imposes accountability obligations including DPIAs (Section 28; GAID Article 28), DPO appointment (Section 32), and a 72-hour breach notification duty to the Commission for controllers (Section 40(2)), with processors required to notify controllers 'on becoming aware' of a breach (Section 40(1)). Data Protection Compliance Organisations (DPCOs) are licensed under Section 33 to provide compliance verification services. Annual Compliance Audit Returns (CAR) must be filed before 31 March each year via a licensed DPCO. Joint and vicarious liability for corporate officers and agents/employees is established under the Act's enforcement provisions. Explicit statutory retention/disposal duration limits were not confirmed in the sources reviewed.
Sources and claims (9)
ProbableNDPC — A data controller or data processor who deploys software for processing of sensitive personal data must carry out a DPIA and submit same to the Commission within four months, per GAID Article 28(8).observed
ProbableNDPC — Section 32 of the NDPA (Part V) provides for the appointment of Data Protection Officers, with GAID requiring DPO reports to include the compliance status of the data controller or processor.observed
ProbableNDPC — Under Section 29(1)(a) of the NDPA, where a data controller or processor engages another processor, it must ensure the engaged processor complies with the principles and obligations applicable to the controller.observed
ProbableNational Assembly / hosted via DataGuidance — Where an offence has been committed by a body corporate or firm, principal officers are deemed culpable unless they prove the offence occurred without their consent/connivance and they exercised diligence to prevent it; controllers/processors are vicariously liable for acts of agents or employees.observed
ProbableNational Assembly / hosted via DataGuidance — Part VII of the NDPA (Section 39, 'Security, integrity, and confidentiality') establishes security-of-processing obligations for controllers and processors.observed
ProbableNDPC — A data controller shall, within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals, notify the Commission of the breach, describing its nature including categories and approximate numbers of data subjects and records concerned.observed
ProbableOneTrust DataGuidance — Where a breach occurs with respect to data being processed by a data processor, the processor shall, on becoming aware of the breach, notify the engaging data controller/processor describing the nature of the breach and respond to information requests.observed
ProbableNDPC — Data controllers are expected to file annual Compliance Audit Returns (CAR) before 31 March each year, per GAID Articles 10.7 and 10.8, as a practical accountability/record-keeping mechanism.observed
UncertainNDPC — No confirmed statutory retention-period or disposal-duty provision was located for NG in this research pass.observed
Statutory transfer mechanism and adequacy-assessment framework are in force, but the practical adequacy list, SCC/BCR forms, and any localisation mandate remain unconfirmed/undeveloped from available sources.
Primary frameworkNigeria Data Protection Act, 2023 (NDPA), Part VIII
Traffic-light rationale — AmberStatutory transfer mechanism and adequacy-assessment framework are in force, but the practical adequacy list, SCC/BCR forms, and any localisation mandate remain unconfirmed/undeveloped from available sources.
Sub-modules (6)
Transfer MechanismsAmber
Sections 41-43 address cross-border transfer; a Cross-Border Data Transfer Instrument must be submitted for Commission approval prior to transfer.
Claims (2):
Sections 41-43 (Part VIII) of the NDP Act address the transfer of personal data to a foreign country, requiring an adequate level of protection be ensured by the controller or processor.
A data controller or processor must submit a Cross-Border Data Transfer Instrument to the Commission for approval and obtain that approval before engaging in cross-border data transfer.
Adequacy ReceivedRed
No confirmed adequacy decision received by Nigeria from another regime was located.
Adequacy GrantedAmber
No confirmed list of countries granted adequacy status by the NDPC was located; the Commission assesses adequacy per Section 42 on a substantially-similar-principles basis.
Claims (1):
A level of protection is deemed adequate under Section 42 of the NDPA if it upholds principles substantially similar to the conditions for processing personal data under the Act.
Sccs And BcrsRed
No confirmed standard contractual clauses or binding corporate rules templates specific to NG were located.
Transfer Impact AssessmentAmber
No dedicated Transfer Impact Assessment requirement distinct from the Cross-Border Data Transfer Instrument process was confirmed.
Data LocalisationRed
No confirmed general data-localisation mandate was located for NG in this research pass.
Category narrative92 words
Part VIII (Sections 41-43) of the NDPA governs cross-border transfer of personal data, requiring an adequate level of protection at the destination, assessed by the Commission against principles 'substantially similar' to Nigeria's own standards (Section 42). Controllers/processors may also rely on derogations (e.g., contractual necessity, vital interest, data subject's sole benefit) or must submit a Cross-Border Data Transfer Instrument to the Commission for approval prior to transfer. No confirmed list of adequacy decisions received or granted by/to Nigeria, nor confirmed SCC/BCR templates or a data-localisation mandate, were identified in this research pass.
Sources and claims (3)
ProbableNDPC — Sections 41-43 (Part VIII) of the NDP Act address the transfer of personal data to a foreign country, requiring an adequate level of protection be ensured by the controller or processor.observed
ProbableNDPC — A data controller or processor must submit a Cross-Border Data Transfer Instrument to the Commission for approval and obtain that approval before engaging in cross-border data transfer.observed
ProbableOneTrust DataGuidance — A level of protection is deemed adequate under Section 42 of the NDPA if it upholds principles substantially similar to the conditions for processing personal data under the Act.observed
Financial and telecoms sector overlays are confirmed and actively enforced; health, education, credit-scoring and insurance sector overlays are unconfirmed from available sources.
Primary frameworkNigeria Data Protection Act, 2023 (NDPA) with sectoral overlays (CBN, NCC)
Traffic-light rationale — AmberFinancial and telecoms sector overlays are confirmed and actively enforced; health, education, credit-scoring and insurance sector overlays are unconfirmed from available sources.
Sub-modules (7)
Financial Sector OverlayAmber
CBN Consumer Protection Regulation (Art. 5.4) and CBN risk-based cybersecurity framework (2022) apply alongside NDPA to financial institutions; NDPC has fined a major bank for data breach.
Claims (3):
NDPC recognises the Central Bank of Nigeria's Consumer Protection Regulation (Article 5.4) as a complementary instrument alongside the NDPA.
The Central Bank of Nigeria issued a risk-based cybersecurity framework and guidelines for other financial institutions on 29 June 2022, covering cybersecurity oversight, risk management and reporting.
NDPC fined Fidelity Bank NGN 555.8 million for data protection violations, evidencing active enforcement against financial-sector data controllers.
Health Sector OverlayRed
No confirmed health-sector-specific data protection overlay was located for NG.
Telecoms And EprivacyAmber
NCC's Consumer Code of Practice Regulations (Part IV) is referenced by NDPC as a complementary instrument for telecoms-sector personal data.
Claims (1):
NDPC recognises Part IV of the Nigerian Communications Commission's Consumer Code of Practice Regulations as a complementary instrument to the NDPA.
Employment DataRed
No confirmed employment-specific data protection overlay was located for NG.
Credit And ScoringRed
No confirmed credit-scoring-specific data protection overlay was located for NG.
EducationRed
No confirmed statutory education-sector data protection overlay was located; NDPC has pursued voluntary partnerships with universities.
InsuranceRed
No confirmed insurance-sector-specific data protection overlay was located for NG.
Category narrative79 words
The NDPA operates alongside sector regulators; NDPC explicitly recognises complementary instruments including the Central Bank of Nigeria's Consumer Protection Regulation and the Nigerian Communications Commission's Consumer Code of Practice Regulations. CBN separately issued a risk-based cybersecurity framework for financial institutions in June 2022. NDPC has actively enforced against financial-sector and media/telecom-sector entities, evidenced by fines against a major bank and a pay-TV operator. Confirmed sector-specific overlays for health, education, credit-scoring and insurance were not located in this research pass.
no periodic updates on record for this sub-brief
Sources and claims (4)
ProbableNDPC — NDPC recognises the Central Bank of Nigeria's Consumer Protection Regulation (Article 5.4) as a complementary instrument alongside the NDPA.observed
ProbableOneTrust DataGuidance — The Central Bank of Nigeria issued a risk-based cybersecurity framework and guidelines for other financial institutions on 29 June 2022, covering cybersecurity oversight, risk management and reporting.observed
ProbableOneTrust DataGuidance — NDPC fined Fidelity Bank NGN 555.8 million for data protection violations, evidencing active enforcement against financial-sector data controllers.observed
ProbableNDPC — NDPC recognises Part IV of the Nigerian Communications Commission's Consumer Code of Practice Regulations as a complementary instrument to the NDPA.observed
No dedicated adtech/commercial-privacy instrument (cookies, dark patterns, opt-out signals, clean rooms, direct marketing) was confirmed for NG beyond general NDPA consent principles.
Traffic-light rationale — RedNo dedicated adtech/commercial-privacy instrument (cookies, dark patterns, opt-out signals, clean rooms, direct marketing) was confirmed for NG beyond general NDPA consent principles.
Sub-modules (6)
Cookies And TrackersRed
No dedicated cookie/tracker consent statute identified; general NDPA consent principles apply by extension.
Claims (1):
No confirmed NG-specific statutory cookie/tracker consent regime distinct from general NDPA consent principles was located in this research pass.
Dark PatternsRed
No confirmed dark-pattern prohibition specific to NG was located.
Opt Out SignalsRed
No confirmed recognition of technical opt-out signals (e.g., GPC) was located for NG.
Clean Rooms And DcrRed
No confirmed clean-room/data-collaboration-room rules were located for NG.
Cross Context AdvertisingRed
No confirmed cross-context-advertising-specific rule (analogous to CPRA 'sale'/'share') was located for NG.
Direct MarketingRed
No confirmed direct-marketing-specific consent/suppression rule was located for NG beyond general consent principles.
Category narrative57 words
The NDPA does not contain a dedicated ePrivacy-style cookie/tracker consent regime, dark-pattern prohibition, opt-out signal recognition, clean-room framework, or direct-marketing suppression rule distinct from its general consent and lawful-basis provisions. NDPC's own website relies on general cookie-consent practices modelled on its statutory lawful-basis framework, but no NG-specific adtech statute or regulation was identified in this research pass.
Sources and claims (1)
UncertainNDPC — No confirmed NG-specific statutory cookie/tracker consent regime distinct from general NDPA consent principles was located in this research pass.observed
Automated decision-making right is confirmed in force; biometric, genetic, AI-risk-assessment and surveillance-carveout specifics remain largely unconfirmed or emergent.
Primary frameworkNigeria Data Protection Act, 2023 (NDPA), Section 37
Traffic-light rationale — AmberAutomated decision-making right is confirmed in force; biometric, genetic, AI-risk-assessment and surveillance-carveout specifics remain largely unconfirmed or emergent.
Sub-modules (6)
Profiling RestrictionsAmber
Profiling restrictions are addressed jointly with automated decision-making under Section 37 NDPA.
Claims (1):
Section 37 of the NDPA (Part VI) provides for protections in relation to automated decision-making.
Automated Decision Making TransparencyGreen
Section 37 (Part VI) of the NDPA addresses automated decision-making.
Claims (1):
Section 37 of the NDPA (Part VI) provides for protections in relation to automated decision-making.
Ai Risk AssessmentsRed
NDPC has begun exploratory AI-governance engagement (e.g., a National AI Scaling Hub partnership with Lagos Business School), but no binding AI-specific risk-assessment statute is confirmed in force.
Claims (1):
NDPC has partnered with Lagos Business School to establish a National Artificial Intelligence Scaling Hub, signalling emergent AI-governance engagement not yet codified as a binding risk-assessment requirement.
Biometric RegimeRed
No dedicated biometric-specific regime (facial recognition, fingerprint, gait) was confirmed distinct from general sensitive-personal-data treatment.
Genetic DataRed
No dedicated genetic-data-specific regime was confirmed distinct from general sensitive-personal-data treatment.
State Surveillance CarveoutsAmber
Constitutional exemptions (Sections 37 & 45, 1999 Constitution) are referenced generally in the GAID, but no detailed NDPA-specific surveillance carveout regime was confirmed.
Claims (1):
The GAID clarifies that nothing in the NDP Act or GAID authorises data processing without compliance with Sections 37 and 45 of the 1999 Constitution of the Federal Republic of Nigeria.
Category narrative97 words
The NDPA addresses automated decision-making under Section 37 (Part VI), giving data subjects protections analogous to GDPR Art 22. Biometric and genetic data likely fall within the Section 30 'sensitive personal data' category, though no dedicated biometric-specific regime (e.g., facial recognition governance) was confirmed. NDPC has begun engaging on AI governance, including a partnership with Lagos Business School on a national AI scaling hub, but no binding AI-specific risk-assessment statute was confirmed as in force. State-surveillance carveouts are referenced only generally via constitutional provisions (Sections 37 & 45, 1999 Constitution) rather than a detailed NDPA carveout regime.
SpeculativeNDPC — NDPC has partnered with Lagos Business School to establish a National Artificial Intelligence Scaling Hub, signalling emergent AI-governance engagement not yet codified as a binding risk-assessment requirement.observed
ProbableNDPC — The GAID clarifies that nothing in the NDP Act or GAID authorises data processing without compliance with Sections 37 and 45 of the 1999 Constitution of the Federal Republic of Nigeria.observed
Traffic-light rationale — AmberSection 31 confirms a children/incapacitated-persons category exists in force, but implementation specifics (age threshold, parental consent mechanics, profiling bans) remain unconfirmed.
Sub-modules (5)
Age VerificationRed
No confirmed statutory age-verification mechanism was located.
Parental ConsentAmber
Section 31 NDPA addresses children/persons lacking legal capacity to consent, implying a parental/guardian consent mechanism, but mechanics are unconfirmed.
Claims (1):
Section 31 of the NDPA (Part V) addresses processing of data belonging to children or persons lacking the legal capacity to consent, establishing a distinct consent-capacity category under the Act.
Minor Profiling BansRed
No confirmed minor-specific profiling ban was located distinct from general Section 37 automated-decision-making protections.
Education SettingsRed
No confirmed statutory education-settings-specific children's-data rule was located; NDPC pursues voluntary university partnerships.
Dependent AdultsAmber
Section 31's 'persons lacking legal capacity to consent' language extends coverage to dependent adults, though implementation specifics are unconfirmed.
Claims (1):
Section 31 of the NDPA (Part V) addresses processing of data belonging to children or persons lacking the legal capacity to consent, establishing a distinct consent-capacity category under the Act.
Category narrative100 words
Section 31 of the NDPA addresses 'Children or persons lacking the legal capacity to consent,' establishing a distinct legal basis category for processing data of minors and incapacitated persons. However, granular thresholds — the precise minimum age of consent, parental-consent verification mechanics, and any minor-specific profiling ban — were not confirmed from the sources reviewed and require verification against the full statutory text or forthcoming NDPC guidance. NDPC has pursued voluntary sector partnerships (e.g., with universities) but no confirmed statutory education-settings-specific children's-data rule, nor a dependent-adults-specific regime beyond the general 'persons lacking legal capacity' language in Section 31, was located.
Sources and claims (2)
ProbableNational Assembly / hosted via DataGuidance — Section 31 of the NDPA (Part V) addresses processing of data belonging to children or persons lacking the legal capacity to consent, establishing a distinct consent-capacity category under the Act.observed
UncertainNational Assembly / hosted via DataGuidance — No confirmed minimum-age threshold or age-verification mechanism under the NDPA/GAID was located in this research pass.observed
Enforcement powers are clearly codified and actively exercised, with multiple significant fines and ongoing investigations within the recent evidence window, plus judicial affirmation of NDPC's regulatory powers.
Primary frameworkNigeria Data Protection Act, 2023 (NDPA), Parts X-XI
Traffic-light rationale — GreenEnforcement powers are clearly codified and actively exercised, with multiple significant fines and ongoing investigations within the recent evidence window, plus judicial affirmation of NDPC's regulatory powers.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Sections 46-48 NDPA grant complaint-investigation, compliance-order and enforcement-order/penalty powers, with penalties up to the greater of NGN10m/NGN2m or 2% of annual gross revenue depending on DCPMI status.
Claims (3):
A data subject aggrieved by a controller/processor's decision, action or inaction in violation of the NDPA may lodge a complaint with the Commission, which may also investigate on its own accord under Section 46.
Under Section 47, the Commission may make a compliance order against a data controller or processor it is satisfied has violated or is likely to violate the NDPA or subsidiary legislation.
Under Section 48, a penalty or remedial fee for a DCPMI may reach the 'higher maximum amount' (the greater of NGN10,000,000 and 2% of annual gross revenue), while a non-major controller/processor faces a 'standard maximum amount' (the greater of NGN2,000,000 and 2% of annual gross revenue).
Enforcement Activity IndexGreen
NDPC has fined Fidelity Bank (NGN555.8m) and MultiChoice Nigeria (NGN766m) and initiated sectoral and specific-incident investigations.
Claims (3):
NDPC fined Fidelity Bank NGN 555.8 million for data protection violations.
NDPC fined MultiChoice Nigeria NGN 766 million for unlawful data transfers and privacy rights violations.
NDPC has commenced a sector-by-sector investigation of compliance with the NDPA and is investigating an alleged data breach at the Corporate Affairs Commission (CAC).
Regulator Funding And CapacityRed
No specific NDPC budget/headcount figures were confirmed in this research pass.
Collective Redress And Class ActionsAmber
No confirmed dedicated class-action mechanism specific to NDPA was located beyond individual civil remedies.
Private Right Of ActionGreen
Data subjects have the right to file civil actions in court against a data controller or data processor on the basis of the NDPA.
Claims (1):
Data subjects have the right to file civil actions in court against a data controller or data processor on the basis of the NDP Act.
Recent Developments 180DGreen
Within the last 180 days, sources indicate NDPC investigating an alleged CAC data breach and a court ruling backing NDPC's DCPMI registration power.
Claims (2):
NDPC is reported to be investigating an alleged data breach at the Corporate Affairs Commission (CAC), a development reported in April 2026, within the 180-day recent-developments window of this run.
A Nigerian court reportedly backed NDPC's power to require registration of Data Controllers/Processors of Major Importance (DCPMIs), reinforcing the Commission's registration and enforcement authority.
Category narrative141 words
The NDPC has express complaint-investigation powers (Section 46), compliance-order powers (Section 47), and enforcement-order/penalty powers (Section 48) under the NDPA. Penalties for DCPMI non-compliance can reach the 'higher maximum amount' — the greater of NGN10,000,000 or 2% of annual gross revenue in the preceding financial year — while non-major entities face a 'standard maximum amount' of the greater of NGN2,000,000 or 2% of annual gross revenue. The Commission has demonstrated active enforcement, including fines against Fidelity Bank (NGN555.8 million) and MultiChoice Nigeria (NGN766 million) for data protection violations, and is reported to have commenced a sector-by-sector compliance investigation and an investigation into an alleged breach at the Corporate Affairs Commission (CAC). Data subjects retain a private right of civil action in court against non-compliant controllers/processors (Section 51). A Nigerian court reportedly upheld NDPC's power to mandate DCPMI registration, reinforcing regulatory authority.
no periodic updates on record for this sub-brief
Sources and claims (9)
ProbableOneTrust DataGuidance — A data subject aggrieved by a controller/processor's decision, action or inaction in violation of the NDPA may lodge a complaint with the Commission, which may also investigate on its own accord under Section 46.observed
ProbableOneTrust DataGuidance — Under Section 47, the Commission may make a compliance order against a data controller or processor it is satisfied has violated or is likely to violate the NDPA or subsidiary legislation.observed
ProbableNDPC — Under Section 48, a penalty or remedial fee for a DCPMI may reach the 'higher maximum amount' (the greater of NGN10,000,000 and 2% of annual gross revenue), while a non-major controller/processor faces a 'standard maximum amount' (the greater of NGN2,000,000 and 2% of annual gross revenue).observed
ProbableOneTrust DataGuidance — NDPC fined Fidelity Bank NGN 555.8 million for data protection violations.observed
ProbableOneTrust DataGuidance — NDPC fined MultiChoice Nigeria NGN 766 million for unlawful data transfers and privacy rights violations.observed
ProbableOneTrust DataGuidance — NDPC has commenced a sector-by-sector investigation of compliance with the NDPA and is investigating an alleged data breach at the Corporate Affairs Commission (CAC).observed
ProbableNDPC — Data subjects have the right to file civil actions in court against a data controller or data processor on the basis of the NDP Act.observed
ProbableOneTrust DataGuidance — NDPC is reported to be investigating an alleged data breach at the Corporate Affairs Commission (CAC), a development reported in April 2026, within the 180-day recent-developments window of this run.observed
ProbableNDPC — A Nigerian court reportedly backed NDPC's power to require registration of Data Controllers/Processors of Major Importance (DCPMIs), reinforcing the Commission's registration and enforcement authority.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
waived
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
47.37
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Nigeria
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 45 claim(s) (45 category placement(s)), 25 source(s) in the cumulative register.
T1 (NDPC official) sourcing was obtained for regulator_and_framework, controller_processor_duties (breach notification, DPIA, DPO, registration), and portions of cross_border_and_adequacy and enforcement_and_redress (penalty structure, complaint/compliance-order powers via GAID and NDPC FAQs). T2 sourcing (statute-text hosts, IAPP analysis, NADPA) supplemented lawful_processing_and_special_data, data_subject_rights, sectoral_watch (financial/telecoms overlays), algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups. T3 sourcing (DataGuidance news summaries) was relied on for specific enforcement-activity claims (Fidelity Bank and MultiChoice fines, CAC investigation, sector-by-sector investigation) where full DataGuidance article bodies were paywalled and only headlines/metadata were retrievable — these claims carry Probable rather than Confirmed confidence accordingly. adtech_and_commercial_privacy returned largely negative findings (no dedicated NG-specific instrument located) and is emitted with red traffic_light and absent_field_provenance. Precise statutory deadlines for data-subject-rights response windows, pseudonymisation/anonymisation safe-harbours, retention/disposal duration limits, and exact children's-data age thresholds could not be confirmed from accessible excerpts and are flagged Uncertain with absent_field_provenance rather than fabricated.
Unresolved questions (7):
What is the exact statutory deadline (in days) for a controller to respond to a data subject access/rectification/erasure request under the NDPA?
What precise minimum age threshold and parental/guardian consent verification mechanism applies under NDPA Section 31 for children/persons lacking legal capacity?
Does the NDPA or GAID contain any pseudonymisation/anonymisation safe-harbour definition, and if so, what are its conditions?
Are there confirmed statutory retention-period limits or disposal-duty timelines for personal data under the NDPA?
Has the NDPC published or recognised any formal adequacy list (countries received/granted), SCC, or BCR templates for cross-border transfers?
Is there a confirmed NG-specific data-localisation mandate for any data category (e.g., financial, health, biometric)?
What are the exact dates and final resolution status of the Fidelity Bank and MultiChoice Nigeria fines, and are they under appeal?