Nigeria Forces Every Government Agency to Appoint a Data Protection Officer

Nigeria · TECHNOLOGY

The circular that changed government compliance

On 7 November 2022, the Office of the Secretary to the Government of the Federation issued a service-wide circular with reference number SGF/OP/I/S.3/XII/186. It instructed every federal ministry, department and agency to comply with the Nigeria Data Protection Regulation 2019 and its Implementation Framework.

The circular required each MDA to designate an appropriate officer as a Data Protection Officer, forward that person’s name and contact details to the then Nigeria Data Protection Bureau, and allocate budget for annual audit compliance and capacity-building. It also set a deadline of 30 March each year for filing annual Data Protection Audit reports.

Under the NDPR Implementation Framework, a government organ must appoint a DPO within six months, and the same duty applies to any entity that processes personal data of more than 10,000 data subjects per year, regularly handles sensitive personal data, or holds critical national information infrastructure. In practice, that threshold captured virtually every federal MDA.

From regulation to Act: the NDPA sharpens the obligation

President Bola Ahmed Tinubu signed the Nigeria Data Protection Act into law on 12 June 2023, replacing the earlier NDPR as the country’s primary data privacy legislation. The Act established the Nigeria Data Protection Commission as the national regulator and introduced the category of Data Controllers and Data Processors of Major Importance.

Section 32(1) of the NDPA requires every data controller of major importance to designate a Data Protection Officer with expert knowledge of data protection law and practices. While the statutory language targets large or critical entities, NDPC guidance and the General Application and Implementation Directive that became fully effective on 19 September 2025 have extended the obligation across public-sector bodies.

Specialist law firms note that public-sector bodies are almost universally required to appoint a DPO under the post-NDPR regime. Practical compliance guidance for 2026 specifies that federal, state and local government MDAs processing personal data must appoint a DPO, publish their contact details, and register the appointment on the NDPC portal with supporting documents.

Enforcement shifts from warnings to fines

Nigeria’s data protection enforcement has moved through three explicit phases. Phase one, from 2019 to 2023, focused on warnings and education.

Phase two, spanning 2024 and 2025, brought systematic investigations and sanctions. Phase three, now underway in 2026, is described by the NDPC as full enforcement mode.

By early 2026 the commission had collected about ₦7.2 billion from company registrations, compliance revenues and fines. It had concluded over 240 investigations into data breaches, resulting in 11 major enforcement actions.

Administrative fines under the NDPA can reach up to ₦10 million or 2 per cent of annual gross revenue of the preceding financial year, whichever is greater.

The enforcement drive is not confined to the private sector. On 19 February 2026, the NDPC issued compliance notices to 649 higher education institutions, ordering them to submit evidence of DPO appointments and 2024 audit returns within 21 days.

Failure, the commission warned, could lead to enforcement orders, administrative fines and criminal prosecution.

Data Protection Officers as a lever of state power

The service-wide circular embeds privacy oversight directly under the chief executives and permanent secretaries of MDAs, altering internal power dynamics. A DPO inside a government agency can become a gatekeeper around data sharing, procurement of foreign technology solutions and surveillance practices.

Nigeria’s cybersecurity architecture reinforces this role. The Cybercrimes Act 2015, amended in 2024, imposes a 72-hour incident reporting requirement and raised the cybersecurity levy on electronic transactions from 0.005 per cent to 0.5 per cent.

The National Cybersecurity Policy and Strategy, updated in 2021, calls for minimum standards for handling personal information and safeguards for citizen data on government systems.

Academic and policy analyses point out that this cybersecurity-plus-privacy model is partly about asserting control over data flows and critical digital infrastructure. Yet there are documented concerns that broad interception and surveillance powers may undermine citizens’ digital rights, creating tension between security and privacy goals.

Revenue, industry and the Brussels effect

The DPO mandate is also a fiscal and industrial policy tool. The NDPC and industry observers estimate Nigeria’s data-protection and compliance ecosystem at ₦16.2 billion, driven by licensed Data Protection Compliance Organisations, training providers, audit firms and legal consultancies.

Nigeria’s regime is explicitly inspired by the European Union’s General Data Protection Regulation. The NDPA adopts familiar GDPR concepts including lawful bases for processing, data subject rights, DPOs, cross-border transfer rules and controller-processor categories.

This alignment facilitates data flows with European partners and positions Nigeria as a regional regulatory leader.

Global technology and payment firms operating in Nigeria must now register as controllers or processors of major importance where thresholds are met, appoint DPOs capable of interfacing with the NDPC, and file Compliance Audit Returns via licensed compliance organisations. The 72-hour incident-reporting requirement effectively puts major foreign firms under quasi-continuous regulatory visibility, as explored in Africa: The New Scramble.

What to watch as enforcement deepens

The NDPC has signalled that 2026 marks the start of aggressive enforcement, with more frequent fines and litigation risk. In April 2026 the commission began investigations into alleged large-scale data breaches involving Remita Payment Services Limited and Sterling Bank, focusing on possible compromise of sensitive personal and financial data.

For government MDAs, the immediate pressure point is the annual 30 March audit filing deadline. Agencies that fail to appoint DPOs, file returns or register on the NDPC portal face enforcement orders and potential personal liability for officials under broader cybercrime and administrative law frameworks.

The broader geopolitical read-through is clear. Nigeria is building one of West Africa’s most structured data-protection frameworks, backed by active enforcement and a growing compliance industry.

By hosting African regulators and pushing cross-border cooperation, it seeks to become a norm-setter in continental debates over data sovereignty and digital infrastructure.

Frequently Asked Questions

What does the Nigerian government require MDAs to do about data protection?

A service-wide circular from November 2022 ordered all federal ministries, departments and agencies to appoint a Data Protection Officer, forward their details to the then Data Protection Bureau (now the NDPC), and file annual audit reports by 30 March each year.

What penalties can Nigerian MDAs face for non-compliance?

Under the Nigeria Data Protection Act 2023, administrative fines can reach up to ₦10 million or 2 per cent of annual gross revenue, whichever is greater, and officials may face personal liability under cybercrime and administrative law frameworks.

How much has Nigeria collected from data protection enforcement so far?

By early 2026 the Nigeria Data Protection Commission had collected about ₦7.2 billion from company registrations, compliance revenues and fines since intensifying enforcement under the 2023 Act.

Sources

This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error

LatAm Markets: Live Signals → — real-time movers, turnover leaders and FX across Latin America.