Policy brief

Nigeria’s data protection law at three: many regulators, few remedies

Three years after the Nigeria Data Protection Act, enforcement is shaped by overlapping regulators, a funding model tied to fees and fines, and little action against the state. The review now under way can fix all three.

Author
ACTPOL
Published
Topics
Data protection and privacy, Online platforms and speech
Region
West Africa
Region: West Africa

Key points

  • Nigeria’s regulator has built a large registration and audit system, reporting ₦4.99 billion in compliance revenue in 2025, and describes its enforcement as “restorative rather than punitive”.
  • Two regulators claim supremacy over the same conduct. A tribunal upheld the competition regulator’s US$220 million penalty on Meta, while the data regulator’s US$32.8 million penalty ended in a settlement that set it aside.
  • We found no published sanction against a government agency. Courts are filling the gap through the constitutional right to privacy.
  • The National Assembly’s review should settle each regulator’s role, separate the regulator’s funding from its fines, and require every decision and settlement to be published.

Why Nigeria matters

The Nigeria Data Protection Act, 2023 took effect on 12 June 2023 and replaced a regulation issued in 2019 with a full statute and an independent Nigeria Data Protection Commission.1 Nigeria is Africa’s most populous country and one of its largest digital markets, so how the Act is enforced shapes the experience of a very large share of the continent’s internet users, and the expectations of every company that serves them.

Three years on, the Act has produced an active regulator and an unusually busy courtroom. It has also exposed three structural problems: overlapping regulators with competing claims to supremacy, a funding model that ties the regulator to the money it collects, and very little visible enforcement against the state. The National Assembly began a formal review of the Act on 12 May 2026.2 This brief sets out what that review should address.

A regulator built around registration

The Act requires data controllers and processors “of major importance” to register with the Commission and allows it to charge them fees.3 The Commission’s General Application and Implementation Directive, issued on 20 March 2025 and in force since 19 September 2025, fills in the detail.4 It sorts organisations into three tiers with annual fees of ₦250,000, ₦100,000 and ₦10,000, lists “Public Service” among the sectors that qualify, and requires annual compliance audit returns, data protection officers and, in defined high-risk cases, impact assessments filed with the Commission.5

The system has scale. The Commission reported compliance revenue of ₦4.99 billion in 2025, 213 investigations in 2024 and 146 in 2025, and describes its approach as “restorative rather than punitive”.6 In January 2026 it said that its 246 concluded investigations had produced 11 enforcement actions.7

Some of those actions were substantial. The Commission was reported to have fined Fidelity Bank ₦555.8 million in August 2024, a finding the bank disputed, and MultiChoice Nigeria ₦766,242,500 in July 2025, in part for unlawful cross-border transfers.8 But the design matters as much as the record. The Act caps fines for the largest organisations at the greater of ₦10 million or 2 per cent of annual gross revenue, and the Commission’s fund keeps the “levies, fees, penalties, and fines” it collects.9 A regulator whose budget grows with its collections has an incentive to favour the enforcement that pays.

A regulator funded by what it collects will always be tempted to register first and investigate second.

Two regulators, two supremacy clauses

Section 63 of the Act says it prevails over any inconsistent law on the processing of personal data.10 The Federal Competition and Consumer Protection Act, 2018 says that in “all matters relating to competition and consumer protection” it “shall override the provisions of any other law”, and gives the Federal Competition and Consumer Protection Commission precedence over sector regulators.11 Both clauses now reach the same conduct.

The case of Meta shows the consequences. In July 2024 the competition regulator imposed a US$220 million penalty on Meta and WhatsApp, in a final order framed as the result of a joint investigation with the Data Protection Commission and grounded partly in the 2019 data protection regulation.12 On 25 April 2025 the Competition and Consumer Protection Tribunal upheld the penalty and held that the competition regulator “acted within its statutory mandate” on data protection.13 Meta told the court it might have to shut down Facebook and Instagram in Nigeria, which the regulator called a threat that “does not absolve Meta of liabilities”, and in July 2026 the regulator said Meta had appealed.14

The Data Protection Commission’s own case against Meta took a different course. It fined Meta US$32.8 million in February 2025. Meta challenged the decision, and on 3 November 2025 the Federal High Court adopted the parties’ terms of settlement as its judgment.15 According to certified copies obtained by Premium Times, the Commission set aside its final orders, neither side admitted liability, and Meta paid the Commission’s legal fees.16 Two weeks before the settlement was signed, the Commission announced that it had translated the Act into Hausa, Igbo and Yoruba “in collaboration with Meta”.17 A group of data privacy lawyers has since threatened to challenge the consent judgment.18

The overlap is spreading. In February 2026 the Commission signed a memorandum of understanding with the Nigerian Communications Commission on data protection in telecommunications.19 In June 2026 the Central Bank issued rules requiring payment transaction data generated in Nigeria to be stored in Nigeria by 1 January 2027, a localisation mandate that sits awkwardly beside the Act’s transfer regime, which allows data to leave the country on the basis of adequate protection, contractual clauses or consent.20

Independence, and the state as a data controller

The Act declares the Commission independent, but also lets the Minister issue policy directives that it must obey, and provides for its head to be appointed by the President on the Minister’s recommendation.21 That arrangement matters most when the organisation in breach is part of government.

Public institutions process some of the most sensitive data in the country, from national identity numbers to bank verification data. Yet we found no published sanction by the Commission against a government agency. The Foundation for Investigative Journalism reached the same conclusion in November 2025, and in July 2026 reported three high-profile cases, including one involving the National Identity Management Commission, with no published outcome.22

The courts are filling part of the gap. The Lagos High Court held in September 2025 that rights under the Act form part of the constitutional right to privacy and can be enforced through the fundamental rights procedure, and in July 2026 the High Court of the Federal Capital Territory awarded ₦15 million in damages against a bank that kept using former customers’ data without a lawful basis.23 The Federal High Court has also policed the Commission’s own rule-making, striking down a registration criterion that went beyond the Act.24 Court enforcement is welcome, but it depends on individuals who can afford to litigate. It is no substitute for a regulator that acts.

What the review should do

The review is also considering a private member’s amendment bill that would require platforms to open physical offices in Nigeria and let the Commission shut down non-compliant entities within 30 days, which the Socio-Economic Rights and Accountability Project has asked the National Assembly to reject.25 Stronger enforcement does not require such blunt tools. It requires clearer roles, cleaner incentives and more transparency.

  1. Settle who leads on personal data. The National Assembly should amend both Acts so that the Data Protection Commission leads on the processing of personal data, the competition regulator leads on market conduct, and joint cases are decided jointly, with one penalty for one wrong.
  2. Separate funding from fines. Penalties should be paid into the Consolidated Revenue Fund, and the Commission funded by appropriation, so that its enforcement choices never depend on what they earn.
  3. Publish every decision and settlement. The Act should require the Commission to publish its enforcement decisions, the reasons for them and the terms of any settlement, including with global platforms.
  4. Enforce against the state, and report on it. The Commission should publish an annual account of investigations into public institutions and their outcomes, and the Act should let it order remedial measures against them directly.
  5. Keep shutdowns in the courts. Any power to suspend or shut down a service should require a court order, and localisation rules such as the Central Bank’s should be reconciled with the Act’s transfer regime rather than issued alongside it.

Notes

  1. Nigeria Data Protection Act, 2023 (Act No. 37 of 2023), Official Gazette No. 119, Vol. 110. ↩

  2. Nigeria Anti-Corruption and Legislative Task Force, “National Assembly initiates review of National Data Protection Act”, May 2026. ↩

  3. Nigeria Data Protection Act, 2023, sections 44, 45 and 65. ↩

  4. Nigeria Data Protection Commission, Annual Report 2025. ↩

  5. Nigeria Data Protection Commission, General Application and Implementation Directive, 2025, articles 10 to 12 and 28, and schedule 7. ↩

  6. Nigeria Data Protection Commission, Annual Report 2025. ↩

  7. BusinessDay, “NDPC concludes 246 investigations, generates N5.2bn revenue”, 29 January 2026. ↩

  8. Sahara Reporters, report on the Fidelity Bank fine, 21 August 2024; Fintech Magazine Africa, “Fidelity Bank denies data breach allegations”, 22 August 2024; Nairametrics, “NDPC fines MultiChoice Nigeria N766.2 million”, 6 July 2025. ↩

  9. Nigeria Data Protection Act, 2023, sections 19 and 48. ↩

  10. Nigeria Data Protection Act, 2023, section 63. ↩

  11. Federal Competition and Consumer Protection Act, 2018, sections 104 and 105(2). ↩

  12. Federal Competition and Consumer Protection Commission, final order against Meta and WhatsApp, 18 July 2024, and executive summary of the investigation, 13 November 2023. ↩

  13. Federal Competition and Consumer Protection Commission, “Tribunal upholds FCCPC’s $220 million fine against Meta/WhatsApp”, April 2025. ↩

  14. BusinessDay, “Meta threatens exit from Nigeria”, 3 May 2025; Federal Competition and Consumer Protection Commission, “Quitting Nigeria does not absolve Meta of liability”, 3 May 2025, and statement of 6 July 2026. ↩

  15. Nairametrics, report on the Commission’s decision against Meta, 16 July 2025; BusinessDay, “Meta, NDPC resolve $32.8m privacy dispute out of court”, November 2025. ↩

  16. Premium Times, “Inside Nigeria’s deal to write off $32.8 million fine against Meta”, April 2026. ↩

  17. Nigeria Data Protection Commission, announcement of the translations, 16 October 2025. ↩

  18. Sahara Reporters, report on the pre-action notice, 22 December 2025. ↩

  19. ThisDay, “NCC, NDPC sign MoU to enhance data protection in telecoms sector”, 6 February 2026. ↩

  20. Central Bank of Nigeria, circular PSS/DIR/PUB/CIR/001/004, 15 June 2026, as summarised by G. O. Enebeli; Nigeria Data Protection Act, 2023, sections 41 to 43. ↩

  21. Nigeria Data Protection Act, 2023, sections 7, 14(1)(a) and 60. ↩

  22. Foundation for Investigative Journalism, “How Nigeria’s data protection law created a regulator, then weakened it”, 3 November 2025, and report of 14 July 2026. ↩

  23. Bonje v Guaranty Trust Bank Plc, High Court of Lagos State, 18 September 2025, as analysed on Mondaq; Sahara Reporters, report on Ogundipe and Ibrahim v Stanbic IBTC, 1 August 2026. ↩

  24. Frank Ijege v Nigeria Data Protection Commission, Federal High Court, 22 November 2024, as analysed on Mondaq. ↩

  25. Lawyard, “SERAP urges National Assembly to reject data protection amendment bill”, July 2026. ↩