NDPA
Nigeria Data Protection Act 2023
What it is
The Nigeria Data Protection Act 2023 elevated data protection to primary legislation, replacing the 2019 Nigeria Data Protection Regulation (NDPR). It created the NDPC as a standalone regulator and harmonised Nigerian data protection with international norms, while preserving local enforcement priorities.
What it requires
All data controllers and processors handling personal data of Nigerian residents, including offshore entities targeting the Nigerian market. Requires lawful basis, data subject rights, breach notification, DPO appointment for organisations processing data of major importance, and compliance audit filing with the NDPC.
Key facts
- Supervisor
- Nigeria Data Protection Commission (NDPC), reporting to the National Commissioner for Data Protection
- Maximum fine
- Up to 2% of annual gross revenue or NGN 10 million (whichever is higher) for data controllers of major importance
- Official text
- https://ndpc.gov.ng/
DSI services for NDPA
DSI Advisory Services helps covered entities translate NDPA obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.
See the service →Related briefings
Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.
On the night of January 30, 2026, 3,421 ATM withdrawals against the United Bank for Africa drained 1.143 billion CFA francs from 91 customer accounts. The transactions happened in three Senegalese cities — Dakar, Thiès, Kaolack — and were mirrored simultaneously against UBA subsidiaries in nine other African countries. The attackers had what they always have in this pattern: privileged access to the card-authorization infrastructure. FASTCash, the eight-year-old North Korean cash-out playbook, has landed in West Africa at pan-African banking scale — and ngCERT's advisory came five months after the night the money walked.
From a conference stage, Claus Balslev, head of digitalisation at Denmark's STAR labour-market agency, said the sentence everyone hedges around: if you put data in a US cloud, you share it directly with the US intelligence service. Then he acted on it, migrating STAR's systems off Microsoft and onto European cloud in roughly nine months, and saving money doing it. My assessment: the statement is not rhetoric, it is the precise legal architecture. The CLOUD Act attaches jurisdiction to the US entity, not the data; FISA 702 authorises bulk collection from US providers with no warrant and a gag order; RISAA (2024) extends reach toward the silicon itself; and the 12 June 2026 Fable/Mythos AI suspension proved Washington can switch off the capability globally by letter. Asked under oath before the French Senate in 2025 whether Microsoft could guarantee EU data is never sent to US authorities, Microsoft France's legal-affairs director answered: no. This is not a governance gap but a governance collision, two irreconcilable legal systems applied to the same data, which is why Safe Harbor, Privacy Shield, and soon the current framework all fall. Residency is where the bits sit; sovereignty is who controls access. STAR removed the last excuse, and the AI layer is the next Schrems ruling.
In June 2024, Paradigm Initiative proved the largest data leak in Nigerian history by buying it: for 100 naira a record, rogue sites were selling the NIN, BVN, passport, and phone number of 104 million Nigerians from NIMC's database, including the slips of the digital-economy minister and the national data regulator. On 27 June 2026, President Tinubu signed the NIMC Act 2026, replacing a 19-year-old law, and named that same commission the Root Certification Authority for Nigeria's national PKI. My assessment: the Act hardens the cryptography, but the 2024 breach was never cryptographic. It leaked through custody and access, third-party agents with legitimate credentials, the exact layer a certificate hierarchy does not fix. The new 14-agency board (INEC, DSS, EFCC, CBN, the population commission, the national security adviser) concentrates the state's coercive machinery around one dataset. For every Nigerian fintech, identity verification now chains to a single sovereign root you cannot switch away from, held by a custodian with a demonstrated breach history. The law is overdue and much of it is sound. But a root of trust is the one credential that cannot be reissued, and it now sits on the custody layer that already failed once, at the scale of a nation. What to watch: the secondary regulations, the data regulator's enforcement teeth, the access-governance layer, and whether any redress ever reaches the 104 million.
985,000 passports and driver's licences sat on public URLs with no password, no access control, nothing. No hack, no exploit chain. The custodian was not a government agency or a bank but Nefos Solutions, a two-person Irish startup that built membership software for Spanish cannabis clubs, with a Stripe key in plain text inside its app. My assessment: this is not one breach. France Titres (national identity agency, IDOR found by a 15-year-old, 11.7M records), the UK Visa Portal (guessable URL, 100,000+ passports), the Texas hunting-licence vendor (third-party breach, 3.09M Texans), and Nefos (public URL, 985,000 passports) are four expressions of one structural reality. From the most capable national agency to a two-person startup, the security outcome is identical: government identity documents on the open internet. The EU's age-verification mandate will create thousands more Nefos-scale custodians collecting the one category of data that cannot be reset. Identity documents are only as secure as the weakest custodian in the chain that now holds them. Extends the DSI EU regulatory series: France Titres, the EUDI Wallet, and the age-verification oxymoron.
Atlassian terminated sixteen hundred employees on the eleventh of March 2026. Six weeks later an eight-year veteran of the edge infrastructure team uploaded a thirty-eight-minute YouTube video walking through the company's entire production architecture. Some viewers called it the best free system design lesson on the platform. They were also describing, in different words, a complete operational security disclosure for any actor that wanted to attack the company. The AI replacement doctrine has produced the largest involuntary supply of high-context insider threats in the history of the industry, and the demographic concentration is in the cohort that holds the most institutional memory. The DSI reading of what comes next.
Read more on this
Other data protection frameworks in the DSI registry: