📖 ABSTRACT/OVERVIEW
The Nigeria Data Protection Act 2023 established a comprehensive statutory framework for personal data protection and created the Nigeria Data Protection Commission as the primary supervisory authority, replacing the 2019 Data Protection Regulation issued under the NITDA Act. The transition from regulatory guidelines to primary legislation represents a significant advance in Nigeria's data governance architecture, with implications for technology companies, financial institutions, healthcare providers, and government agencies processing personal data. This study professionally examines the NDPA 2023, evaluating its substantive provisions on data subject rights, data controller obligations, cross-border data transfers, enforcement powers of the NDPC, and the adequacy of its alignment with global data protection standards. A doctrinal methodology is applied, reviewing the NDPA 2023, the NDPR 2019, NDPC implementation guidelines, and comparative analysis from the European Union GDPR and Kenya's Data Protection Act 2019. The study evaluates consent requirements, purpose limitation principles, data breach notification obligations, and NDPC enforcement capacity. Available data governance literature from Nigeria identifies inadequate NDPC staffing, incomplete implementation regulations, and low public awareness of data rights as the primary regulatory gaps in the NDPA's first year of operation. The Accountability Principle in Data Protection Law and the OECD Privacy Guidelines provide the normative reference. Recommendations address NDPC regulatory capacity investment, mandatory data protection officer requirements for government agencies, and data literacy public campaigns. Keywords: data protection, NDPA 2023, privacy rights, NDPC, Nigeria.
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬