Skip to the content
Global Data RulesData governance rules, country by country

Nigeria

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Active

Nigeria lets personal data leave the country, but only if you can show the place it is going protects it about as well as Nigeria does, and you must write down why. Some industries are far tighter. Card and cash machine payments have to be processed inside Nigeria, phone companies need written permission to move customer records abroad, and from 2027 banks' data must sit on Nigerian soil.

Data governance in Nigeria

The eight things that decide how you handle data about people in Nigeria. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office, staff or servers in Nigeria, as long as it handles the data of someone who is in Nigeria. There is no revenue or headcount floor to hide under. You do not have to appoint a Nigerian representative, but if you cross a very low size threshold you must register with the regulator and name a data protection officer.

High confidenceNational rulesRegister or notifyAppoint a data protection officer

Where the data is allowed to live

In general, yes, with conditions. You may send personal data out of Nigeria if the receiving side is covered by a law, a group-wide rulebook, a contract, a code of conduct or a certificate that gives protection as good as Nigeria's, or if one of a short list of special situations applies. That is the national answer. Four industries override it, and in those the honest answer is closer to 'no'.

Medium confidenceDepends on your industryApproval each timePaymentsTelecomsGovernment

Sending data out of the country

The model is: banned unless one of the listed grounds applies. There is no approved country list at all. The regulator has published none, and the law says that silence must not be read as approval. In practice you either write your own assessment showing the destination is safe enough, or you rely on the person's consent, a contract, a legal claim or another narrow exception. The regulator says it also expects to approve your transfer paperwork first, which is not obvious from the Act.

High confidenceApproval each timeOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractImportant public interestLegal claimsSomeone's life is at riskPut a transfer safeguard in place

The regulator, and whether it actually acts

The Nigeria Data Protection Commission, and it is genuinely working. It has a named chief executive, online systems for registration, breach reports and audit filings, and it published a detailed annual report in June 2026. It ran 146 investigations in 2025, has more than 38,000 registered organisations on its books, licensed 306 private compliance firms, and fined a pay television company about 766 million naira, roughly 560 thousand US dollars. Industry regulators for banking, telecoms and securities enforce their own rules alongside it.

High confidenceActiveRegulator

How long you must keep it — and when to delete it

Both a floor and a ceiling, and they pull in opposite directions. The unusual one is the ceiling: if no law tells you how long to keep something, the regulator says you must delete it within six months of finishing the job you collected it for. Against that, open banking data must be kept for at least seven years, telephone companies must keep proof of customer consent for two years, and organisations of major importance must file an audit return every year by the end of March.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep logsIndependent audit

If something goes wrong

One national clock, and it is 72 hours. If you are the organisation that decided what to do with the data, you have 72 hours from becoming aware of a break-in that puts people at risk to tell the regulator. If the risk to people is high you must also tell the affected people straight away, in plain language, with advice on what they should do. A supplier who suffers the breach must tell the organisation that hired it as soon as it knows, with no fixed number of hours.

High confidenceReport breaches to the regulatorTell affected peopleSecure the data

What catches people out

Five things that cost people their weekend. First, handling the data of just 200 people in six months makes you an organisation 'of major importance', with registration, a data protection officer and yearly audit filings. Second, a child in Nigeria is anyone under 18, so a parent must consent. Third, delete within six months by default. Fourth, ignoring a regulator's order is a crime, and directors are personally on the hook. Fifth, the biggest filers cannot file for themselves.

High confidenceRegister or notifyGet a parent's consent for childrenDelete data after a periodCriminal liabilityIndependent auditAppoint a data protection officer

What's changing next

The big date is 1 January 2027, when Nigeria's new national cloud rules are due to start. From then, data held by regulated financial institutions is meant to be hosted in Nigeria, and government and other sensitive data must have both its live copy and its backup inside the country. The central bank added its own data localisation circular in June 2026. Several powers already exist that could tighten things overnight with no consultation.

Medium confidencePassed, not yet fully in forceProposedKeep the data in the country

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Nigerian Communications Commission (Registration of Communications Subscribers) Regulations, 2022

Directly binding regulation · S.I. No. 86 of 2022, made 22 July 2022, Official Gazette No. 147 Vol. 109 of 15 August 2022

In forceYes, with paperwork

Phone and internet companies may not move subscriber information out of Nigeria without the regulator's prior written permission, and may not copy or store it for any purpose the regulations do not allow. The fine is charged per SIM card, so a database wide breach multiplies fast.

In force since 22 July 2022

Enforced by Nigerian Communications Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Payments

Guidelines on Operations of Electronic Payment Channels in Nigeria

Regulator guideline · Issued 31 May 2020, superseding the 2016 guidelines

In forceNo — it stays put

Every domestic card, cash machine and card terminal transaction must be switched by a Nigerian switch and must never be routed outside Nigeria. No card scheme may force a Nigerian bank to send such a transaction abroad for processing.

In force since 31 May 2020

Enforced by Central Bank of Nigeria

Transfer model: Not allowed

Medium confidence
Finance

Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures In The Nigeria Payments System

Regulator directive · PSS/DIR/PUB/CIR/001/004, 15 June 2026

In forceNot yet established

The central bank issued a payments system circular headed data localisation on 15 June 2026. Its existence, reference number and date are confirmed on the bank's own database, but the text is not publicly readable, so anyone in Nigerian payments should ask the bank for the copy rather than rely on any summary.

In force since 15 June 2026

Enforced by Central Bank of Nigeria

Transfer model: Approval each time

Low confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Nigeria Data Protection Act, 2023

Act of parliament · Act No. 37 of 2023

In forceYes, with paperwork

Nigeria's general privacy law. It reaches foreign companies with no Nigerian presence, bans sending personal data abroad unless a listed ground applies, requires a breach report within 72 hours, treats anyone under 18 as a child, and backs it all with fines measured against worldwide revenue plus a criminal offence for ignoring the regulator.

In force since 12 June 2023

Enforced by Nigeria Data Protection Commission

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

Nigeria Data Protection Act General Application and Implementation Directive (NDP Act-GAID) 2025

Government rules · NDPC/NDP ACT-GAID/01/2025, issued 20 March 2025

In forceYes, with paperwork

The directive that turns the Act into day to day duties: who must register, how much they pay, when audits are filed, what a data protection officer must be given, and a default rule that personal data is deleted six months after the job it was collected for is finished.

In force since 20 March 2025But only enforceable from 20 September 2025

Enforced by Nigeria Data Protection Commission

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct

High confidence

Who you would hear from

  • Nigeria Data Protection Commission (NDPC)

    General privacy law: registration, audits, complaints, breach reports, cross-border transfer instruments

    Fully operational. Led by National Commissioner and Chief Executive Dr Vincent Olatunji. Runs live online services for registration, breach reporting and audit filing, published an annual report in June 2026, and reports 146 investigations in 2025, 38,661 registered organisations, 306 licensed compliance firms and a 766.2 million naira fine on a pay television operator. It describes its own approach as restorative rather than punitive.

  • Cloud computing, government IT, data classification and localisation framework, IT project clearance

    Actively issuing binding guidelines; approved the National Cloud Computing Guideline and National Cloud Technical Guideline on 4 August 2026.

  • Telecoms licensing, subscriber registration, lawful interception, consumer code

    Active. Published new business rules for subscriber registration in 2026 and holds a draft data protection regulation still at consultation stage.

  • Banking, payments, financial technology, open banking

    Active and issuing circulars weekly. Its public file server blocks automated retrieval, so the text of its 15 June 2026 data localisation circular could not be read on this run even though the circular is listed in its own database.

  • Capital markets, digital assets, market operators

    Active. Agreed sector-wide data protection compliance work with the privacy regulator in August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The operative text, deadlines and covered firms of the Central Bank of Nigeria's data localisation circular of 15 June 2026

    The bank's file server answers automated requests with a bot check, and the Internet Archive's copy is the same bot check page. Only the title, reference number PSS/DIR/PUB/CIR/001/004 and date could be verified, from the bank's own circulars database. Anyone in Nigerian payments should request the file directly.

  • Whether the Nigeria Data Protection Commission has issued any adequacy decision for any country, or approved any cross-border transfer instrument

    None was found on the Commission's website, in the 2025 Directive or in the 2025 annual report, checked 18 August 2026. This is a negative that cannot be proved; the Commission does not publish a register of such decisions.

  • Whether a health-sector data storage or localisation rule exists in Nigeria

    No such instrument was located on a federal health domain, checked 18 August 2026. The Federal Ministry of Health website was found to be partly compromised with unrelated spam content, which makes negative findings there unreliable.

  • Incident reporting deadlines imposed on banks, payment firms and telecoms operators by their own regulators

    The central bank's cybersecurity framework documents could not be downloaded, and the telecoms consumer code was not opened on this run. Only the 72 hour national deadline is confirmed.

  • Minimum retention periods under Nigerian company and tax law

    The Corporate Affairs Commission website returned an access error and the tax authority site did not resolve, so no government backed figure for company or tax record floors is recorded here.

  • Whether NITDA has fixed 1 January 2027 as the binding start date of the National Cloud Computing Guideline

    The document's front matter states an effective date of 1 January 2027 but its operative commencement clause says it comes into effect on such date as NITDA may determine, and no separate commencement notice was found.

  • Whether any online gambling, mapping or defence specific storage rules exist

    Not researched to a conclusion. General web search was unavailable during this run, so these sectors were checked only by direct visits to regulator sites and nothing was found.

  • Current enforcement position on the National Data Protection Adequacy Programme Whitelist mentioned in the audit return form

    The 2025 Directive's audit template refers to organisations being on this whitelist, but no published list was found and the 2025 annual report does not mention it.

30-day cadence. Three things are in motion at once: the central bank's June 2026 localisation circular whose terms are not public, NITDA's cloud guidelines whose commencement date is at the agency's discretion despite a stated 1 January 2027 effective date, and the privacy regulator's still unissued cross-border transfer instrument. Any of the three can change the answer to 'can the data leave' within weeks.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Put this next to another country

Nigeria versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.