TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Nigeria TerraLex Guide to Data Protection Guide

Date posted:
18/07/2023
Last update:
18/07/2023

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

The list: 1. The constitution of the Federal Republic of Nigeria 1999 (as amended) 2. The Nigeria Data Protection Act, 2023 3. The Nigerian Data Protection Regulation, 2019 (“NDPR”) 4. The Nigerian Data Protection Implementation Framework 2020, issued by the National Information Technology Development Agency (“NITDA”) 5. The Central Bank of Nigeria (“CBN”) Consumer Protection Framework 2016 6. The National Health Act 2014 7. The Freedom of Information Act, 2011 (“FOI Act”) 8. The Child Rights Act 2003 9. The Consumer Code of Practice Regulations 2007 (“The NCC Regulations”) 10. The National Identity Management Commission (“NIMC”) Act 11. The Cybercrimes (Prohibition, Prevention Etc.) Act 2015 12. The HIV and AIDS (Anti-Discrimination) Act, 2014 13. The Registration of Telephone Subscribers Regulations 2011, Published by the Nigerian Communications Commission. 14. The Guidelines for the management of Personal Data by public institution in Nigeria 2020, issued by the NITDA

To whom do the laws apply?

The list: 1. All transactions intended for the processing of Personal Data. 2. All natural persons residing in Nigeria or residing outside Nigeria who are citizens of Nigeria.

Scope of protection

What type of data is covered by the law?

The list: 1. Personal data regarding natural persons residing in Nigeria or residing outside Nigeria who are citizens of Nigeria. 2. Transactions involving the exchange of Personal Data. 3. Characters, symbols, and binary on which operations are performed by a computer, which may be stored or transmitted in the form of electronic signals, stored in any format or any device.

What are the main exemptions (if any)?

The Nigerian Data Protection Act 2023 (“The Act”) provides that processing of personal data carried out by more persons solely for the purpose of personal and household purposes are exempt. The NDPR further provides that no consent shall be sought, given, or accepted in any circumstance that may engender direct or indirect propagation of atrocities, hate, child rights violation, criminal acts, and anti-social conducts.

What rights do the laws grant to the data owners?

Under The Act and the NDPR, Data owners/subject have the following rights: 1. RIGHT TO PROCURING CONSENT: No data shall be obtained except the specific purpose of collection is made known to the Data Subject. Where processing has been restricted such Personal Data shall, except for storage, only be processed with the Data Subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest in Nigeria. 2. RIGHT TO DUE DILIGENCE AND PROHIBITION OF IMPROPER MOTIVES: No consent shall be sought, given, or accepted in any circumstance that may engender direct or indirect propagation of atrocities, hate, child rights violation, criminal acts, and anti-social conducts. 3. RIGHT TO PUBLICITY AND CLARITY OF PRIVACY POLICY: Any medium through which Personal Data is being collected or processed shall display a simple and conspicuous privacy policy that the class of Data Subject being targeted can understand. 4. RIGHT TO DATA SECURITY: Anyone involved in data processing or the control of data shall develop security measures to protect data. 5. RIGHT TO THIRD PARTY DATA PROCESSING CONTRACT: Data processing by a third party shall be governed by a written contract between the third party and the Data Controller. 6. RIGHT TO OBJECTIONS: The right of a Data Subject to object to the processing of Personal Data relating to him which the Data Controller intends to process for the purpose of marketing. 7. RIGHT TO PRIVACY: The privacy right of a Data Subject shall be interpreted for the purpose of advancing and never for the purpose of restricting the safeguards Data Subject is entitled to under any data protection instrument made in furtherance of fundamental rights and the Nigerian laws. 8. RIGHT TO PENALTY FOR DEFAULT: The Data Controller would pay fines if found guilty of any data violations. 9. Right to information on foreign data protection safeguards: Where Personal Data are transferred to a foreign country or to an international organization, the Data Subject shall have the right to be informed of the appropriate safeguards for data protection in the foreign country. The Data Subject shall have the right to obtain from the Controller without undue delay the rectification of inaccurate Personal Data concerning him or her. Considering the purposes of the processing, the Data Subject shall have the right to have incomplete Personal Data completed, including by means of providing a supplementary statement. 10. Right to delete Personal Data: The Data Subject shall have the right to request the Controller to delete Personal Data without delay, and the Controller shall delete Personal Data where one of the following grounds applies: a) the Personal Data are no longer necessary in relation to the purposes for which they were collected or processed; b) the Data Subject withdraws consent on which the processing is based; c) the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing; d) the Personal Data have been unlawfully processed; and e) the Personal Data must be erased for compliance with a legal obligation in Nigeria. 11. Right to Data Portability: In exercising his right to Data Portability, the Data Subject shall have the right to have the Personal Data transmitted directly from one controller to another, where technically feasible. Provided that this right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller. 12. Right to an Effective Remedy: Data subjects have the right to an effective judicial remedy where they consider that their personal data was not processed in compliance with the law.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

The processing of Data shall be lawful if at least one of the following applies: 1. the Data Subject has given consent to the processing of his or her Personal Data for one or more specific purposes; 2. processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract; 3. processing is necessary for compliance with a legal obligation to which the Controller is subject; 4. processing is necessary in order to protect the vital interests of the Data Subject or of another natural person, and 5. processing is necessary for the performance of a task carried out in the public interest or in exercise of official public mandate vested in the controller;

What are the main obligations imposed by the law?

The following are the obligations imposed by the Act and the NDPR: 1. Personal Data shall be: a. collected and processed in accordance with specific, legitimate, and lawful purpose consented to by the Data Subject; provided that: i. a further processing may be done only for archiving, scientific research, historical research, or statistical purposes for public interest; ii. any person or entity carrying out or purporting to carry out data processing under the provision of this paragraph shall not transfer any Personal Data to any person; b. adequate, accurate and without prejudice to the dignity of human person; c. stored only for the period within which it is reasonably needed, and d. secured against all foreseeable hazards and breaches such as theft, cyberattack, viral attack, dissemination, manipulations of any kind, damage by rain, fire, or exposure to other natural elements. 2. Anyone who is entrusted with the Personal Data of a Data Subject or who is in possession of the Personal Data of a Data Subject owes a duty of care to the said Data Subject; 3. Anyone who is entrusted with Personal Data of a Data Subject or who is in possession of the Personal Data of a Data Subject shall be accountable for his acts and omissions in respect of data processing, and in accordance with the principles contained in this Regulation.

Do the laws establish a data retention period to be observed?

Yes, the NDPR provides that Data should be stored only for the period within which it is reasonably needed. However, a specific time frame is not provided.

Must the data processing activities be recorded under the law?

Yes, the data processing activities are to be recorded. 1. A Data Controller who processed the Personal Data of more than 2,000 Data Subjects in a period of 12 months shall, not later than the 15th of March of the following year, submit a summary of its data protection audit to the National Information Technology Development Agency. 2. Where a Data Controller processes the Personal Data of more than 1,000 in a period of six months, a soft copy of the summary of the audit should be submitted to the NITDA.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

The Nigerian Data Protection Commission serves as the National Authority for Data Protection in Nigeria. The Nigeria Data Protection Commission, is statutorily mandated by the Nigeria Data Protection Act of 2023 to, develop regulations for electronic governance and monitor the use of electronic data interchange and other forms of electronic communication transactions as an alternative to paper-based methods in government, commerce, education, the private and public sectors, labour and other fields, where the use of electronic communication may improve the exchange of data and information.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

Yes, the Nigeria Data Protection Act imposes the obligation of a designated Data Protection Officer (“DPO”). The DPO is empowered with the role of ensuring adherence to the Nigerian Data Protection Act 2023, relevant data privacy instruments and data protection directives of the Data Controller.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

Nigerian Data Protection Act 2023.

Is it necessary to notify the National Authority prior to the international transfer?

Yes, it is necessary. International transfer of data is under the supervision of the Nigeria Data Protection Commission. Note that no international, multi-national cross border data transfer codes, rules, or certification mechanisms shall be adopted in Nigeria without the approval of the National Assembly.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

Yes, the Nigeria Data Protection Act 2023 provides that anyone involved in the processing and/or the control of data shall develop security measures to protect the said data. Personal Data shall be secured against all foreseeable hazards and breaches such as theft, cyberattack, viral attack, dissemination, manipulations of any kind, damage by rain, fire, or exposure to other natural elements.

Do the laws establish any kind of mandatory notification duty?

Yes, the data Controller is saddled with the mandatory responsibility of notifying the data subject with all the following information: 1. the identity and the contact details of the Controller; 2. the contact details of the Data Protection Officer; 3. the purpose(s) of the processing for which the Personal Data are intended as well as the legal basis for the processing; 4. the legitimate interests pursued by the Controller or by a third party; 5. the recipients or categories of recipients of the Personal Data, if any; 6. where applicable, the fact that the Controller intends to transfer Personal Data to a third country or international organization; 7. the period for which the Personal Data will be stored, or if that is not possible, the criteria used to determine that period; 8. the existence of the right to request from the Controller access to and rectification or erasure of Personal Data or restriction of processing concerning the Data Subject or to object to processing as well as the right to Data Portability; 9. the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; 10. the right to lodge a complaint with a relevant authority; 11. whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the Data Subject is obliged to provide the Personal Data and of the possible consequences of failure to provide such data; 12. the existence of automated decision-making, including profiling and, at least, in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the Data Subject; 13. Where the Controller intends to further process the Personal Data for a purpose other than that for which the Personal Data were collected, the controller shall provide the Data Subject prior to that further processing with information on that other purpose, and with any relevant further information;

What are the sanctions for noncompliance with data protection laws?

Any person who is found to be in breach of the data privacy rights of any Data Subject shall be liable, in addition to any other criminal liability, to the following: 1. An order for the Data controller or Data processor to remedy the violation; 2. An order to pay compensation to the data subject, who has suffered injury, loss, or harm as a result of the violation; 3. An order to account for profit realized from the violation; 4. An order to pay a penalty or a remedial fee. The penalty or remedial fee is classified based on the whether or not the data controller or data processor is of “major importance” or “not of major importance.” i. For a data controller or processor of major importance, the penalty or remedial fee shall be the greater of either ₦10,000,000.00 (Ten Million naira) or 2% of its gross annual revenue in the preceding financial year. ii. For a data controller or processor not of major importance, the penalty or remedial fess shall be the greater of either ₦2,000,000.00 (two million naira) or 2% of its gross annual revenue in the preceding financial year.

Other comments

Other comments

N/A

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.