Nigeria
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Nigeria — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Nigeria lets personal data leave the country, but only if you can show the place it is going protects it about as well as Nigeria does, and you must write down why. Some industries are far tighter. Card and cash machine payments have to be processed inside Nigeria, phone companies need written permission to move customer records abroad, and from 2027 banks' data must sit on Nigerian soil.
Data governance in Nigeria
The eight things that decide how you handle data about people in Nigeria. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office, staff or servers in Nigeria, as long as it handles the data of someone who is in Nigeria. There is no revenue or headcount floor to hide under. You do not have to appoint a Nigerian representative, but if you cross a very low size threshold you must register with the regulator and name a data protection officer.
- What you have to do here:
- Register or notify · Appoint a data protection officer
The Nigeria Data Protection Act 2023 applies in three cases. First, where you are based, resident or operating in Nigeria. Second, where the data is handled in Nigeria. Third, where an organisation with no Nigerian presence at all handles the data of a person in Nigeria. The Commission's 2025 Directive says 'operating in Nigeria' includes simply targeting people in Nigeria. The registration threshold is unusually low. You count as an organisation 'of major importance' if you handle the data of more than 200 people within any six months. You also count if you work in one of thirteen listed sectors. Those include finance, health, education, communications, insurance, oil and gas, hospitality and e-commerce. If you count, you must register. The Act also protects Nigerian citizens who are outside Nigeria. In that case your duties go only as far as mutual legal assistance arrangements cover.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023 (Act No. 37 of 2023), section 2
ndpc.gov.ng
“This Act shall apply, where the — (a) data controller or data processor is domiciled in, resident in, or operating in Nigeria ; (b) processing of personal data occurs within Nigeria ; or (c) the data controller or the data processor is not domiciled in, resident in, or operating in Nigeria, but is processing personal data of a data subject in Nigeria.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act General Application and Implementation Directive 2025, Articles 1 and 8, and Schedule 7
ndpc.gov.ng
“Processes the personal data of more than Two-Hundred (200) data subjects in six (6) months”
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, with conditions. You may send personal data out of Nigeria if the receiving side is covered by a law, a group-wide rulebook, a contract, a code of conduct or a certificate that gives protection as good as Nigeria's, or if one of a short list of special situations applies. That is the national answer. Four industries override it, and in those the honest answer is closer to 'no'.
Industry overrides, strictest first. PAYMENTS: every domestic card, cash machine and point-of-sale transaction must be switched by a Nigerian switch. In the central bank's words, it must not 'under any circumstance' be routed outside Nigeria. BANKING AND OTHER REGULATED FINANCE: the central bank issued a circular on 15 June 2026 on market structure, keeping data in Nigeria, beneficial ownership disclosure and oversight of the Nigeria Payments System. From 1 January 2027 the technology agency's cloud rules say all financial data created, handled, sent or stored by regulated financial institutions must be mainly hosted and stored inside Nigeria. TELECOMS: no subscriber information may leave Nigeria without the telecoms regulator's prior written consent. Phone companies may not copy or store subscriber records for any purpose beyond what the rules allow. GOVERNMENT AND CRITICAL DATA: from 2027, government and regulated sector data at classification Level 2 and above must be hosted in Nigeria by default. Both the live site and the backup site must be inside the country. The most sensitive class may never leave a Nigerian government facility. SECURITIES: the markets regulator does not require storage in Nigeria. But a digital asset business must have a Nigerian office, and must justify to the regulator any work it outsources abroad. HEALTH: we found no health-specific storage rule on a federal health site, checked 18 August 2026. Health records sit at Level 2 of the cloud classification, where hosting in Nigeria is described as highly recommended rather than compulsory.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, sections 41 to 43
ndpc.gov.ng
“A data controller or data processor shall not transfer or permit personal data to be transferred from Nigeria to another country, unless — (a) the recipient of the personal data is subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism that affords an adequate level of protection with respect to the personal data in accordance with this Act ; or (b) one of the conditions set out in section 43 of this Act applies.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaGuidelines on Operations of Electronic Payment Channels in Nigeria, 31 May 2020, paragraph 2.4.4.8
cbn.gov.ng
“All domestic transactions, including, but not limited to POS and ATM transactions must be switched, using the services of a local switch, and shall not, under any circumstance, be routed outside Nigeria for switching.”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionRegistration of Communications Subscribers Regulations, 2022 (S.I. No. 86 of 2022), regulation 9(4)
ncc.gov.ng
“No subscriber information shall be transferred outside the Federal Republic of Nigeria without the prior written consent of the Commission.”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNational Cloud Computing Guideline 2026, paragraphs 9.2 and 9.3
nitda.gov.ng
“Notwithstanding any other provision of this Guideline, all financial data generated, processed, transmitted or stored by regulated financial institutions shall be primarily hosted, processed and stored within the territorial boundaries of the Federal Republic of Nigeria.”
Link checked 18 August 2026
- Official sourceSecurities and Exchange Commission, NigeriaRules on Issuance, Offering Platforms and Custody of Digital Assets, rules 4.3, 24.9 and 38.8
sec.gov.ng
“A VASP shall have an office in Nigeria managed by a Director of the company.”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
The rule is: you cannot send data abroad unless one of the listed grounds applies. There is no approved country list at all. The regulator has published none, and the law says that silence must not be read as approval. So you either write your own assessment showing the destination is safe enough, or you rely on the person's consent, a contract, a legal claim or another narrow exception. The regulator also says it expects to approve your transfer paperwork first. That is not obvious from the Act.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life
Section 41 of the Act allows a transfer where the recipient is covered by a law, group-wide rules, contract clauses, a code of conduct or a certification that gives adequate protection. Section 42 lets the Commission declare a country, region, sector or set of standard clauses safe enough. Section 42(6) says that the absence of such a decision does not mean a destination is safe. As of 18 August 2026 we found no such decision on the Commission's own site, in the 2025 Directive or in the Commission's 2025 annual report. So the list is empty and the burden sits entirely with you. Schedule 5 of the 2025 Directive lists the grounds as an official decision that a country is safe enough, a cross-border transfer document approved by the Commission, or 'other lawful bases'. It says the approved-document route covers codes of conduct, certifications, group-wide rules and standard contract clauses. The Commission's 2025 annual report goes further. It lists unauthorised cross-border transfer of personal data as a live enforcement theme. It says some organisations seem unaware that they must get the Commission's approval before sending data abroad. So expect to need approval, even though the Act reads as though you assess it yourself. You must also record the basis for every transfer, and answer for it in your annual audit filing, which asks which countries you send data to.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, section 42(6)
ndpc.gov.ng
“The absence of a determination by the Commission under subsection (4) or (5) with respect to a country, territory, sector, binding corporate rules, contractual clause, code of conduct, or certification mechanism shall not imply the adequacy of the protections afforded by it.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Article 45 and Schedule 5
ndpc.gov.ng
“Pending the issuance of any regulatory instrument by the Commission on cross-border data transfer, the explanatory note in Schedule 5 of this GAID shall be used for the evaluation of countries for the purposes of determining their level of adequacy.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Commission Annual Report 2025, section 4.2 (Investigation and Enforcement Actions)
ndpc.gov.ng
“There are cases where data controllers seem oblivious of their obligations in seeking the approval of the Commission before carrying out cross-border transfer of personal data.”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Nigeria Data Protection Commission, and it is clearly working. It has a named chief executive, online systems for registration, breach reports and audit filings, and it published a detailed annual report in June 2026. It ran 146 investigations in 2025. It has more than 38,000 registered organisations on its books. It has licensed 306 private compliance firms. And it fined a pay television company about 766 million naira, roughly 560 thousand US dollars. Industry regulators for banking, telecoms and securities enforce their own rules alongside it.
Enforcement is rated active rather than aggressive on the Commission's own description of its approach: the 2025 annual report says it has 'adopted a restorative rather than punitive approach', leaning on warnings, compliance orders and 'remedial fees in lieu of strict penalties' under section 48(2)(d) of the Act. The numbers it publishes for itself are investigations of 117 in 2022, 177 in 2023, 213 in 2024 and 146 in 2025; compliance revenue of 94.4 million naira in 2022 rising to 4.99 billion naira in 2025; registered organisations of major importance of 36,052 in 2024 and 38,661 in 2025; and 306 licensed Data Protection Compliance Organisations. Open investigations span health, social media, telecommunications, banking and financial technology, and hospitality, and named recurring problems include opening bank accounts without consent, copied and pasted privacy notices, cookie-based data mining and unauthorised cross-border transfers. The report also says the Commission is 'now transitioning into a phase of full enforcement'. The chief executive is Dr Vincent Olatunji, National Commissioner, who signed the 2025 Directive and appears in Commission news through August 2026.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Commission Annual Report 2025 (published June 2026) — enforcement statistics and approach
ndpc.gov.ng
“The Commission is currently handling multiple investigations into alleged violations of privacy rights across key sectors, including health, social media, telecommunications, banking/fintech, and hospitality.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNigeria a Model in Data Protection, Ranked 1st in Africa, Says NDPC National Commissioner (10 July 2025)
ndpc.gov.ng
“the recent fine of ₦766.2 million on MultiChoice”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC privacy breach reporting portal (live, checked 18 August 2026)
services.ndpc.gov.ng
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both a floor and a ceiling, and they pull in opposite directions. The unusual one is the ceiling: if no law tells you how long to keep something, the regulator says you must delete it within six months of finishing the job you collected it for. Against that, open banking data must be kept for at least seven years, telephone companies must keep proof of customer consent for two years, and organisations of major importance must file an audit return every year by the end of March.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep logs · Independent audit
The six month default in Article 49(3) of the 2025 Directive is the rule people miss most often in Nigeria. Most global retention schedules assume that silence means you may keep data forever. Article 49(4) softens it. You may keep data longer, with proper safeguards, to defend a legal claim or for due diligence. On the keep side: the central bank's open banking rules require data obtained for open banking to be kept for a minimum of seven years. A security annex in the same rules says open banking data must be kept for reference for a minimum of ten years. So one document sets two different minimums. Telecoms business rules require evidence and logs of subscriber consent to be stored for at least two years, and biometric verification logs for at least two years. Intercepted communications held by security agencies may be archived for three years and must then be destroyed. Timing: you must run a data protection audit within fifteen months of starting business, and every year afterwards. An organisation of major importance in the top two tiers must file its audit return by 31 March each year, with a late fee of half the filing fee. We could not verify the general company and tax record retention periods from government sources.
Sources
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Articles 7 and 49
ndpc.gov.ng
“In circumstances requiring storage limitation, where no timebound obligation has been provided by law, the storage time for the purpose of data processing shall lapse not later than six (6) calendar months when the original purpose of the processing has been accomplished.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaOperational Guidelines for Open Banking in Nigeria, 8 March 2023, section 4.1 and security annex
cbn.gov.ng
“Ensure that data obtained for the purposes of open banking is retained for a minimum period of seven (7) years, except when legally bound”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionBusiness Rules for the Registration of Communications Subscribers Regulations 2026 — consent log and biometric log retention
ncc.gov.ng
“Data Retention: Evidence/logs of consent received shall be stored for a minimum period of 2 years and shall be retrievable when required.”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionLawful Interception of Communications Regulations, 2019 (S.I. No. 14 of 2019), regulation 6
ncc.gov.ng
“may be archived for three years and thereafter be destroyed”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
One national clock, and it is 72 hours. If you are the organisation that decided what to do with the data, you have 72 hours from becoming aware of a break-in that puts people at risk to tell the regulator. If the risk to people is high you must also tell the affected people straight away, in plain language, with advice on what they should do. A supplier who suffers the breach must tell the organisation that hired it as soon as it knows, with no fixed number of hours.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Secure the data
The duty sits in section 40 of the Act and is expanded in Article 33 of the 2025 Directive. The Directive adds a duty of care overlay: whatever the 72 hour limit says, you must give immediate information to all relevant authorities, including the Commission, where that could help contain a breach on a national or sector scale. It also lists eight things the notification must contain, including when the breach happened, how many people are at real risk of significant harm, and a named contact who can answer the Commission's questions. Reports are filed through the Commission's online breach portal. Watch for extra sector clocks: banks, payment firms and telecoms operators sit under their own incident reporting rules, and those deadlines were not verified from primary regulator documents on this run because the central bank blocks automated downloads of its circulars.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, section 40
ndpc.gov.ng
“A data controller shall, within 72 hours of becoming aware of a breach which is likely to result in a risk to the rights and freedoms of individuals, notify the Commission of the breach”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Article 33
ndpc.gov.ng
“a data controller shall notify affected data subjects immediately after becoming aware of the breach in order to ensure that data subjects are not unlawfully targeted as a result of the breach”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC online privacy breach reporting service
services.ndpc.gov.ng
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that cost people their weekend. First, handling the data of just 200 people in six months makes you an organisation 'of major importance', with registration, a data protection officer and yearly audit filings. Second, a child in Nigeria is anyone under 18, so a parent must consent. Third, delete within six months by default. Fourth, ignoring a regulator's order is a crime, and directors are personally on the hook. Fifth, the biggest filers cannot file for themselves.
- What you have to do here:
- Register or notify · Get a parent's consent for children · Delete data after a period · Independent audit · Appoint a data protection officer
- What it costs if you get it wrong:
- Criminal liability
(1) The 200 person threshold in Schedule 7 of the 2025 Directive is far below the level most companies expect, and thirteen listed sectors are caught regardless of size. Registration fees run from 10,000 naira to 250,000 naira, and the annual audit return fee runs up to 1,000,000 naira, about 735 US dollars, for the largest filers, with a 50 percent surcharge for filing late. (2) 'Child' takes its meaning from the Child's Rights Act 2003, so the age is 18, not 13 or 16, and the Act says presenting a government approved identity document is an acceptable way to check age. (3) The six month default deletion rule in Article 49(3) applies wherever no other law sets a period. (4) Section 49 makes failure to comply with an enforcement order a criminal offence carrying up to one year in prison, and section 53 deems the principal officers of a company culpable unless they prove the offence happened without their consent or connivance and that they exercised diligence. (5) Under Article 10(14) of the Directive, organisations in the top two tiers must file their audit returns through a Data Protection Compliance Organisation licensed by the Commission, so an in-house team cannot simply file for itself. A sixth to watch: the Commission's own reading is that cross-border transfers need its approval, which is stricter than the plain words of the Act.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, sections 31, 49, 53 and 65 (definition of child)
ndpc.gov.ng
“Where an offence has been committed by a body corporate or firm, the body corporate or firm, as well as principal officers of the body corporate or firm shall be deemed culpable, unless the principal officers prove that — (a) the offence was committed without their consent or connivance ; and (b) they exercised diligence to prevent the commission of the offence.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Articles 10 and 49, Schedules 7 and 10
ndpc.gov.ng
“Except as otherwise approved by the Commission, a data controller or a data processor within the categories of UHL and EHL shall file CAR through a Data Protection Compliance Organisation (DPCO) licensed by the Commission in line with Section 33 of the NDP Act.”
Link checked 18 August 2026
What's changing next
The big date is 1 January 2027, when Nigeria's new national cloud rules are due to start. From then, data held by regulated financial institutions is meant to be hosted in Nigeria. Government and other sensitive data must have both its live copy and its backup inside the country. The central bank added its own circular in June 2026 requiring data to stay in Nigeria. Several powers already exist that could tighten things overnight with no consultation.
- What you have to do here:
- Keep the data in the country
Dated items. 1 January 2027: the National Cloud Computing Guideline 2026 and the National Cloud Technical Guideline 2026 are stated to take effect. Both were approved on 4 August 2026 and both are marked mandatory. There is a transition period for existing deployments, which the technology agency has yet to publish. 15 June 2026: the central bank issued its payments system circular on market structure and keeping data in Nigeria. Its practical deadlines are unverified, because the bank blocks public downloads of the file. Powers already held, any of which can move without a public consultation. (1) Section 41(4) of the Act lets the Commission name types of personal data that get extra transfer restrictions. None has been named yet. (2) The 2025 Directive says a dedicated cross-border transfer document is still to be issued, and Article 50 lets the Commission make extra rules that override the Directive. (3) The cloud guideline says it starts 'on such date as may be determined by NITDA', despite the 1 January 2027 date on its own front pages. So the start date is at the agency's discretion. (4) The telecoms regulator holds a draft Data Protection Regulations 2023 and a draft Internet Code of Practice. Both are still drafts with no legal effect. (5) The technology agency can give foreign cloud providers temporary waivers from the rule that data stays in Nigeria, if they promise investment in Nigerian data centres. So the rule is negotiable for large players and not for small ones.
Sources
- Official sourceNational Information Technology Development AgencyNational Cloud Computing Guideline 2026 — approval date 4 August 2026, effective date 1 January 2027, enforcement status mandatory
nitda.gov.ng
“The Guideline shall come into effect on such date as may be determined by NITDA.”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNational Cloud Technical Guideline 2026 — primary and secondary sites within Nigeria for Level 2 data and above
nitda.gov.ng
“Primary and Secondary Sites within Nigeria: For data at Level 2 and above, both the primary production site and the secondary (failover) disaster recovery site must be located within Nigeria's territorial boundaries.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaCircular PSS/DIR/PUB/CIR/001/004, 15 June 2026 — Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures In The Nigeria Payments System
cbn.gov.ng
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionNCC Regulations index listing the Draft Data Protection Regulations 2023 and the Consultation Paper on the Internet Code of Practice
ncc.gov.ng
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data must stay in the country
Official name: Nigerian Communications Commission (Registration of Communications Subscribers) Regulations, 2022 · S.I. No. 86 of 2022, made 22 July 2022, Official Gazette No. 147 Vol. 109 of 15 August 2022 · Directly binding regulation
Phone and internet companies may not move subscriber information out of Nigeria without the regulator's prior written permission, and may not copy or store it for any purpose the regulations do not allow. The fine is charged per SIM card, so a database wide breach multiplies fast.
Enforced by Nigerian Communications Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countrySubscriber information may leave Nigeria only with the telecoms regulator's prior written consent. We found no published way to apply and no list of approvals, so this works as a ban.
- Secure the data
- Keep logs — 2 yearsUnder the 2026 business rules, evidence of subscriber consent and biometric verification logs must be kept for at least two years.
What it costs if you get it wrong
- Fixed maximum fine: NGN 200,000 per subscription medium — about $147A licensee retaining, duplicating or dealing in subscriber information in breach of the regulations; the per SIM basis makes the total unbounded
Sources
- Official sourceNigerian Communications CommissionRegistration of Communications Subscribers Regulations, 2022, regulations 9 and 20 (gazette copy)
ncc.gov.ng
“No subscriber information shall be transferred outside the Federal Republic of Nigeria without the prior written consent of the Commission.”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionNCC Regulations index confirming the 2022 Regulations and the 2026 Business Rules are current
ncc.gov.ng
Link checked 18 August 2026
Payment data rules
Official name: Guidelines on Operations of Electronic Payment Channels in Nigeria · Issued 31 May 2020, superseding the 2016 guidelines · Regulator guideline
Every domestic card, cash machine and card terminal transaction must be switched by a Nigerian switch, and must never be routed outside Nigeria. No card scheme may force a Nigerian bank to send such a transaction abroad to be handled.
Enforced by Central Bank of Nigeria
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThis covers the routing, authorisation and switching of domestic transactions, rather than the storage of records. Card details must not be stored on unauthorised servers.
- Secure the data
Sources
- Official sourceCentral Bank of NigeriaGuidelines on Operations of Electronic Payment Channels in Nigeria 2020, paragraphs 1.2, 2.4.1.6, 2.4.4.8 and 3.4.3.6
cbn.gov.ng
“No card or payment scheme shall compel any issuer or acquirer to send any transaction outside Nigeria for the purpose of processing, authorization or switching, if the transaction is at an ATM or at any acceptance device in Nigeria and the issuer is a Nigerian bank.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaCBN circulars index, entry dated 31/05/2020 for these Guidelines
cbn.gov.ng
Link checked 18 August 2026
- Secondary sourceInternet ArchiveInternet Archive capture of the same document, used to read the text the bank's own site refuses to serve to automated clients
web.archive.org
Link checked 18 August 2026
Finance data must stay in the country
Official name: Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures In The Nigeria Payments System · PSS/DIR/PUB/CIR/001/004, 15 June 2026 · Regulator directive
The central bank issued a payments system circular on 15 June 2026 requiring data to stay in Nigeria. Its existence, reference number and date are confirmed on the bank's own database. The text is not publicly readable. So if you work in Nigerian payments, ask the bank for a copy rather than rely on any summary.
Enforced by Central Bank of Nigeria
How this country controls where data goes: Approval each time
What you have to do
- Keep the data in the country — from 15 June 2026We confirmed the heading and the issuing department on the bank's own circulars database. We could not read the actual wording, the deadlines or exactly which firms are covered. The bank's file server rejects automated requests, and the Internet Archive copy is the same rejection page.
Sources
- Official sourceCentral Bank of NigeriaCBN circulars database entry: PSS/DIR/PUB/CIR/001/004, Payments System Supervision, 15/06/2026
cbn.gov.ng
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaThe circular itself (file rejects automated retrieval with a bot check, 18 August 2026)
cbn.gov.ng
Link checked 18 August 2026
Government data needs a copy kept in the country
Official name: National Cloud Computing Guideline 2026 and National Cloud Technical Guideline 2026 · Issued under sections 6 and 32 of the NITDA Act 2007; approved 4 August 2026 · Regulator guideline
Nigeria's new cloud rulebook. From 2027 government and other sensitive data must be hosted in Nigeria by default, both the live and the backup copy, and all data held by regulated financial institutions must sit inside the country. Foreign providers can buy a temporary waiver by investing in Nigerian data centres.
Enforced by National Information Technology Development Agency
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the country — from 1 January 2027Sovereign data at classification Level 2 and above hosted in Nigeria by default; all financial data of regulated financial institutions hosted, processed and stored in Nigeria; Level 4 classified data never leaves a Nigerian government or certified facility.
- Prove the data stays under local control — from 1 January 2027Both the live site and the disaster recovery site must be inside Nigeria for Level 2 data and above, in different geopolitical zones.
- Hold a security certificate — from 1 January 2027Providers must be certified and listed on the agency's Digital Regulatory Platform to sell to federal public institutions.
- Do not hand data to foreign authorities on demandForeign government access to sovereign data only through mutual legal assistance channels; direct requests must not be granted.
What it costs if you get it wrong
- Order to stopSuspension of a provider's services from the Digital Regulatory Platform, forced recertification audits, remediation notices and compliance directives under the NITDA Act
Sources
- Official sourceNational Information Technology Development AgencyNational Cloud Computing Guideline 2026, document information table, paragraphs 9.2, 9.3, 13.2 and Schedules A and D
nitda.gov.ng
“All sovereign data classified as Level 2 and above, as defined and categorised in Schedule A: National Data Classification Framework, shall be hosted within Nigeria by default, subject to temporary waivers as provided below.”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNational Cloud Technical Guideline 2026 — Nigeria-First disaster recovery principle
nitda.gov.ng
“Under no circumstances shall data classified as LEVEL 4”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNITDA regulations and policies index listing the 2026 cloud instruments
nitda.gov.ng
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Nigeria Data Protection Act, 2023 · Act No. 37 of 2023 · Act of parliament
Nigeria's general privacy law. It reaches foreign companies with no Nigerian presence, bans sending personal data abroad unless a listed ground applies, requires a breach report within 72 hours, treats anyone under 18 as a child, and backs it all with fines measured against worldwide revenue plus a criminal offence for ignoring the regulator.
Enforced by Nigeria Data Protection Commission
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Get consent
- Tell people what you do
- Secure the data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Report breaches to the regulator — within 72 hours
- Tell affected peopleImmediately, where the breach is likely to result in a high risk to the person.
- Get a parent's consent for children — applies at: under 18, following the Child's Rights Act 2003
- Appoint a data protection officer — applies at: Data controllers of major importance
- Register or notify — applies at: Data controllers and processors of major importance, within six months of qualifying
- Put a transfer safeguard in place
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: Greater of NGN 10,000,000 or 2% of annual gross revenue in the preceding financial year — about $7 thousandViolation by a data controller or processor of major importance (the 'higher maximum amount'); the percentage limb has no cap
- Percentage of global turnover: Greater of NGN 2,000,000 or 2% of annual gross revenue in the preceding financial year — about $1 thousandViolation by any other data controller or processor (the 'standard maximum amount')
- Criminal liability: Up to one year imprisonment, or a fine, or bothFailure to comply with a compliance order made by the Commission
- Claims by individualsA person who suffers injury, loss or harm may recover damages in civil proceedings
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023 (Act No. 37 of 2023), commencement 12 June 2023
ndpc.gov.ng
“The "higher maximum amount" shall be the greater of — (a) N10,000,000, and (b) 2% of its annual gross revenue in the preceding financial year.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC Resources page hosting the official text of the Act
ndpc.gov.ng
Link checked 18 August 2026
General data protection law
Official name: Nigeria Data Protection Act General Application and Implementation Directive (NDP Act-GAID) 2025 · NDPC/NDP ACT-GAID/01/2025, issued 20 March 2025 · Government rules
The directive that turns the Act into day to day duties: who must register, how much they pay, when audits are filed, what a data protection officer must be given, and a default rule that personal data is deleted six months after the job it was collected for is finished.
Enforced by Nigeria Data Protection Commission
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct
What you have to do
- Register or notify — applies at: More than 200 people's data in six months, or any organisation in one of thirteen listed sectors
- Independent audit — 1 yearFirst audit within 15 months of starting business; top two tiers must file audit returns by 31 March each year, and must file through a licensed compliance organisation.
- Keep records of how you use data
- Assess high-risk projectsYou had to assess data you were already handling within six months of the Directive being issued.
- Appoint a data protection officerMust report to management level, must not be dismissed or penalised for doing the job, and must undergo credential assessment.
- Delete data after a period — 6 monthsDefault deletion point where no other law sets a period.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Written vendor contract
- Put a transfer safeguard in place
- Get consentSeparate article on consent to cookies and other tracking tools.
What it costs if you get it wrong
- Fixed maximum fine: NGN 1,000,000 audit return filing fee for the largest filers, plus a 50% surcharge for late filing — about $735Failure to file compliance audit returns on time
Sources
- Official sourceNigeria Data Protection CommissionNDP Act-GAID 2025, signed by the National Commissioner on 20 March 2025
ndpc.gov.ng
“Upon the issuance of the GAID, the Commission shall cease to apply the Nigeria Data Protection Regulation (NDPR) 2019 as a legal instrument for regulating data privacy and protection.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC Annual Report 2025, section 4.1 on implementing the GAID
ndpc.gov.ng
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The operative text, deadlines and covered firms of the Central Bank of Nigeria's keeping data in the country circular of 15 June 2026
We could not read the circular's text. The bank's file server answers automated requests with a bot check, and the Internet Archive's copy is the same bot check page. We verified only the title, the reference number PSS/DIR/PUB/CIR/001/004 and the date, from the bank's own circulars database. If you work in Nigerian payments, ask the bank for the file directly.
Whether the Nigeria Data Protection Commission has issued any official “this country is safe” decision for any country, or approved any cross-border transfer instrument
We found no official decision that any country is safe enough. We checked the Commission's website, the 2025 Directive and the 2025 annual report on 18 August 2026. The Commission does not publish a register of such decisions, so we could not confirm this against a government source.
Whether a health-sector data storage or localisation rule exists in Nigeria
We found no health-specific rule about where data must be stored on a federal health site, checked 18 August 2026. The Federal Ministry of Health website was partly compromised with unrelated spam content, so we cannot rely on that search. If you work in health, check with the Ministry before you rely on this.
Incident reporting deadlines imposed on banks, payment firms and telecoms operators by their own regulators
We could not confirm the industry breach reporting deadlines. We could not download the central bank's cybersecurity documents, and we did not open the telecoms consumer code. Only the 72 hour national deadline is confirmed. If you are a bank, a payment firm or a telecoms operator, check your own regulator's deadline.
Minimum retention periods under Nigerian company and tax law
We could not confirm how long company and tax records must be kept. The Corporate Affairs Commission website returned an access error and the tax authority site did not load. Check with your accountant before you set a retention schedule.
Whether NITDA has fixed 1 January 2027 as the binding start date of the National Cloud Computing Guideline
We could not confirm the start date. The document's front pages give an effective date of 1 January 2027. Its own commencement clause says it comes into effect on a date NITDA decides. We found no separate commencement notice.
Whether any online gambling, mapping or defence specific storage rules exist
We could not check these sectors to a conclusion. General web search was unavailable, so we checked only by visiting regulator sites directly, and found nothing. If you work in one of these sectors, check with your regulator before you rely on this.
Current enforcement position on the National Data Protection Adequacy Programme Whitelist mentioned in the audit return form
We could not confirm that this whitelist exists in published form. The 2025 Directive's audit template refers to organisations being on it, but we found no published list, and the 2025 annual report does not mention it. Ask the Commission whether it keeps one.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.