Nigeria Tightens Data Governance Rules Across Government Agencies

Nigeria is taking a significant step toward strengthening the protection of citizens’ personal data, with the Federal Government directing all Ministries, Departments, and Agencies (MDAs) to comply fully with the Nigeria Data Protection Act (NDP Act) 2023.

The new directive, issued through an official circular, introduces stricter governance requirements aimed at improving accountability, reducing data privacy risks, and ensuring that public institutions handle personal information in line with national regulations.

A New Standard for Public Sector Data Protection

Under the directive, every federal MDA is expected to implement the provisions of the NDP Act alongside all regulations and guidelines issued by the Nigeria Data Protection Commission (NDPC).

One of the most notable requirements is the mandatory appointment of qualified Data Protection Officers (DPOs). These officers will oversee compliance, advise management on lawful data processing, coordinate privacy initiatives, and serve as the primary liaison with the NDPC. Agencies are also expected to submit the details of their appointed officers to the commission and, where necessary, engage licensed Data Protection Compliance Organisations to support implementation.

Beyond appointing DPOs, MDAs are required to allocate budgets for data protection activities and submit mandatory data protection audit reports within regulatory timelines. Senior officials—including Permanent Secretaries, Accounting Officers, and Chief Executive Officers—will be held accountable for ensuring compliance within their institutions.

Why This Matters

The directive comes as Nigeria accelerates the digital transformation of public services. From digital identity systems and tax administration to healthcare, education, and social welfare programmes, government agencies are collecting and processing unprecedented volumes of personal data.

As digital government expands, so do the risks associated with data breaches, unauthorized access, and misuse of sensitive information. Strengthening governance frameworks is therefore becoming a critical component of building public trust in digital services.

The move also reinforces the implementation of the Nigeria Data Protection Act, signed into law in 2023, which established a comprehensive legal framework for the collection, storage, processing, and transfer of personal data in Nigeria. The legislation also strengthened the regulatory authority of the Nigeria Data Protection Commission.

Aligning with Global Best Practices

Nigeria’s latest directive mirrors a broader global shift toward stronger public-sector data governance. Governments worldwide are placing greater emphasis on privacy, cybersecurity, and responsible data management as digital public infrastructure becomes central to service delivery.

By institutionalizing dedicated privacy officers and making compliance the responsibility of agency leadership, Nigeria is moving beyond policy declarations toward operational enforcement. Industry observers note that consistent implementation will be essential to achieving the intended outcomes, particularly across agencies with varying levels of digital maturity.

Looking Ahead

While the directive raises compliance expectations for public institutions, it also presents an opportunity to modernize data governance across government. If effectively implemented, the reforms could strengthen citizen confidence in digital public services, improve regulatory compliance, and establish stronger safeguards for personal information as Nigeria’s digital economy continues to expand.

The success of the initiative, however, will depend on sustained enforcement, institutional capacity building, and adequate investment in privacy and cybersecurity capabilities across government.