An Examination of Data Protection Law and Corporate Compliance Obligations Under the Nigeria Data Protection Act 2023

📖 ABSTRACT/OVERVIEW

The Nigeria Data Protection Act 2023 replaced the Nigeria Data Protection Regulation 2019 and introduced a comprehensive framework for personal data governance, imposing significant compliance obligations on organisations that collect, process, or store personal data of Nigerian residents. This study examines the corporate compliance obligations under the NDPA 2023, focusing on the duties of data controllers, data processor accountability, data subjects rights, and the role of the Nigeria Data Protection Commission. A doctrinal methodology was adopted, supplemented by a compliance readiness survey of 40 companies in Lagos and Abuja. Results indicate that fewer than 35 percent of surveyed companies had appointed a data protection officer as required by the Act. Privacy impact assessments were conducted by only 18 percent of respondents before new data processing activities. Consent management mechanisms were found to be inadequate across most surveyed platforms. The NDPC enforcement record since Act commencement showed limited prosecutorial activity, reducing compliance incentives. The study concludes that NDPA 2023 corporate compliance in Nigeria is nascent and requires significant awareness-building, regulatory guidance from the NDPC, and proportionate enforcement to incentivise systematic compliance. Recommendations include a sector-specific compliance guide for financial institutions, telecoms, and healthcare companies, mandatory NDPC registration for large data processors, and a compliance grace period accompanied by structured NDPC advisory support.

Keywords: data protection, NDPA 2023, corporate compliance, data subjects rights, Nigeria Data Protection Commission

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬
Departments# Business Law