Nigeria NDPA 2023: Enforcement Is Active — What Enterprises Must Operationalise Now

OB
OpenBlockAI
Author
Nigeria NDPA 2023: Enforcement Is Active — What Enterprises Must Operationalise Now

Nigeria's Data Protection Act 2023 is in active enforcement. Consent, data subject rights, and DPCO filing are live obligations — most enterprises with Nigerian operations are not operationally ready.

NDPA enforcement is not a future event

Nigeria's Data Protection Act 2023 (NDPA) — one of Africa's most comprehensive privacy laws — passed into enforcement phase in 2024. The Nigeria Data Protection Commission (NDPC) is active, the Data Protection Compliance Organisation (DPCO) filing requirement is live, and the grace period that most multinational enterprises assumed they had is over.

For enterprises with Nigerian employees, customers, users, or operational data — including GCC companies with Nigerian office operations, Indian SaaS companies with West African expansion, and BFSI institutions with correspondent banking or insurance operations in Nigeria — the NDPA is a current compliance obligation.

DPCO filing — the most immediate enforcement trigger

Organisations that process personal data above a defined threshold in Nigeria must file an annual data processing audit with the NDPC via a registered DPCO (Data Protection Compliance Organisation). Failure to file is a direct enforcement trigger — and the NDPC has begun auditing organisations that process Nigerian data without a current DPCO filing. This is the most immediately actionable obligation for most enterprises.

Data subject rights — four that are operationally live

The NDPA provides data subjects with four rights that require documented, time-bound fulfilment workflows:

  • Right of access — personal data provided on request
  • Right to rectification — correction of inaccurate data with audit trail
  • Right to erasure — deletion in specified circumstances with processor propagation
  • Right to object to direct marketing — withdrawal from marketing processing specifically

Each right requires a documented, trackable, time-bound fulfilment workflow — not a generic support ticket queue.

Cross-border transfer restrictions under NDPA

NDPA restricts the transfer of Nigerian personal data to countries that do not provide an adequate level of data protection — unless specific safeguards are in place. For GCC organisations sending Nigerian employee or customer data to regional processing centres, this requires documented safeguards and contractual frameworks — not a standard cloud services agreement.

Breach notification — 72-hour window

NDPA requires notification to the NDPC within 72 hours of becoming aware of a data breach — mirroring GDPR's timeline. Individual notification is required when the breach poses high risk to affected persons. For enterprises managing simultaneous DPDPA and NDPA exposure, a single breach event can trigger parallel 72-hour notification obligations to both the Indian Data Protection Board and the Nigerian NDPC.

NDPA and DPDPA operational overlap for Indian enterprises

For Indian enterprises with Nigerian operations, NDPA and DPDPA create a dual accountability structure for the same cross-border data flows that India-Nigeria business generates. An Indian SaaS company processing Nigerian customer data in Indian cloud infrastructure is simultaneously accountable under NDPA for the outbound transfer and under DPDPA for the receiving entity's processing obligations.

How Consentica addresses NDPA compliance

Consentica by OpenBlockAI provides NDPA-configured consent flows for Nigerian users, data subject rights request tracking with a documented fulfilment trail, withdrawal propagation with NDPA-appropriate timelines, and audit reports structured for NDPC examination.

The NDPC's enforcement trajectory in 2026 mirrors where GDPR was in 2020 — building case precedent through early enforcement actions. The organisations that document their NDPA compliance proactively will not be those precedent cases.

Frequently Asked Questions

Yes — enforcement is active, and consent, data subject rights, and DPCO filing are live, not future, obligations for organisations operating in Nigeria.

3 months FREE.
Zero integration. Unlimited Consents. Live within 48 hours.

Start implementing DPDP-ready consent without long contracts, technical effort, or surprise billing. Launch fast, validate your consent flow, and scale when you’re ready.

What happens next:

1

A privacy specialist reaches out to understand your use case

2

We map your consent flow across app, web, offline and vendor access

3

We set up your consent workflow with zero integration required

4

Your consent system can go live within 48 hours