Skip to the content
Global Data RulesData governance rules, country by country

Nigeria

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Nigeria — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Nigeria lets personal data leave the country, but only if you can show the place it is going protects it about as well as Nigeria does, and you must write down why. Some industries are far tighter. Card and cash machine payments have to be processed inside Nigeria, phone companies need written permission to move customer records abroad, and from 2027 banks' data must sit on Nigerian soil.

Data governance in Nigeria

The eight things that decide how you handle data about people in Nigeria. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office, staff or servers in Nigeria, as long as it handles the data of someone who is in Nigeria. There is no revenue or headcount floor to hide under. You do not have to appoint a Nigerian representative, but if you cross a very low size threshold you must register with the regulator and name a data protection officer.

What you have to do here:
Register or notify · Appoint a data protection officer

Where the data is allowed to live

In general, yes, with conditions. You may send personal data out of Nigeria if the receiving side is covered by a law, a group-wide rulebook, a contract, a code of conduct or a certificate that gives protection as good as Nigeria's, or if one of a short list of special situations applies. That is the national answer. Four industries override it, and in those the honest answer is closer to 'no'.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

The rule is: you cannot send data abroad unless one of the listed grounds applies. There is no approved country list at all. The regulator has published none, and the law says that silence must not be read as approval. So you either write your own assessment showing the destination is safe enough, or you rely on the person's consent, a contract, a legal claim or another narrow exception. The regulator also says it expects to approve your transfer paperwork first. That is not obvious from the Act.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Nigeria Data Protection Commission, and it is clearly working. It has a named chief executive, online systems for registration, breach reports and audit filings, and it published a detailed annual report in June 2026. It ran 146 investigations in 2025. It has more than 38,000 registered organisations on its books. It has licensed 306 private compliance firms. And it fined a pay television company about 766 million naira, roughly 560 thousand US dollars. Industry regulators for banking, telecoms and securities enforce their own rules alongside it.

How long you must keep it — and when to delete it

Both a floor and a ceiling, and they pull in opposite directions. The unusual one is the ceiling: if no law tells you how long to keep something, the regulator says you must delete it within six months of finishing the job you collected it for. Against that, open banking data must be kept for at least seven years, telephone companies must keep proof of customer consent for two years, and organisations of major importance must file an audit return every year by the end of March.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs · Independent audit

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

One national clock, and it is 72 hours. If you are the organisation that decided what to do with the data, you have 72 hours from becoming aware of a break-in that puts people at risk to tell the regulator. If the risk to people is high you must also tell the affected people straight away, in plain language, with advice on what they should do. A supplier who suffers the breach must tell the organisation that hired it as soon as it knows, with no fixed number of hours.

What you have to do here:
Report breaches to the regulator · Tell affected people · Secure the data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that cost people their weekend. First, handling the data of just 200 people in six months makes you an organisation 'of major importance', with registration, a data protection officer and yearly audit filings. Second, a child in Nigeria is anyone under 18, so a parent must consent. Third, delete within six months by default. Fourth, ignoring a regulator's order is a crime, and directors are personally on the hook. Fifth, the biggest filers cannot file for themselves.

What you have to do here:
Register or notify · Get a parent's consent for children · Delete data after a period · Independent audit · Appoint a data protection officer
What it costs if you get it wrong:
Criminal liability

What's changing next

The big date is 1 January 2027, when Nigeria's new national cloud rules are due to start. From then, data held by regulated financial institutions is meant to be hosted in Nigeria. Government and other sensitive data must have both its live copy and its backup inside the country. The central bank added its own circular in June 2026 requiring data to stay in Nigeria. Several powers already exist that could tighten things overnight with no consultation.

What you have to do here:
Keep the data in the country

What to do: Diarise 1 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Nigerian Communications Commission (Registration of Communications Subscribers) Regulations, 2022 · S.I. No. 86 of 2022, made 22 July 2022, Official Gazette No. 147 Vol. 109 of 15 August 2022 · Directly binding regulation

In forceYes, with paperwork

Phone and internet companies may not move subscriber information out of Nigeria without the regulator's prior written permission, and may not copy or store it for any purpose the regulations do not allow. The fine is charged per SIM card, so a database wide breach multiplies fast.

In force since 22 July 2022

Enforced by Nigerian Communications Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Payments

Payment data rules

Official name: Guidelines on Operations of Electronic Payment Channels in Nigeria · Issued 31 May 2020, superseding the 2016 guidelines · Regulator guideline

In forceNo — it stays put

Every domestic card, cash machine and card terminal transaction must be switched by a Nigerian switch, and must never be routed outside Nigeria. No card scheme may force a Nigerian bank to send such a transaction abroad to be handled.

In force since 31 May 2020

Enforced by Central Bank of Nigeria

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Finance

Finance data must stay in the country

Official name: Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures In The Nigeria Payments System · PSS/DIR/PUB/CIR/001/004, 15 June 2026 · Regulator directive

In forceNot yet established

The central bank issued a payments system circular on 15 June 2026 requiring data to stay in Nigeria. Its existence, reference number and date are confirmed on the bank's own database. The text is not publicly readable. So if you work in Nigerian payments, ask the bank for a copy rather than rely on any summary.

In force since 15 June 2026

Enforced by Central Bank of Nigeria

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Nigeria Data Protection Act, 2023 · Act No. 37 of 2023 · Act of parliament

In forceYes, with paperwork

Nigeria's general privacy law. It reaches foreign companies with no Nigerian presence, bans sending personal data abroad unless a listed ground applies, requires a breach report within 72 hours, treats anyone under 18 as a child, and backs it all with fines measured against worldwide revenue plus a criminal offence for ignoring the regulator.

In force since 12 June 2023

Enforced by Nigeria Data Protection Commission

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

General data protection law

Official name: Nigeria Data Protection Act General Application and Implementation Directive (NDP Act-GAID) 2025 · NDPC/NDP ACT-GAID/01/2025, issued 20 March 2025 · Government rules

In forceYes, with paperwork

The directive that turns the Act into day to day duties: who must register, how much they pay, when audits are filed, what a data protection officer must be given, and a default rule that personal data is deleted six months after the job it was collected for is finished.

In force since 20 March 2025Enforced from 20 September 2025

Enforced by Nigeria Data Protection Commission

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct

Who you would hear from

  • Nigeria Data Protection Commission (NDPC)

    General privacy law: registration, audits, complaints, breach reports, cross-border transfer instruments

    Fully operational. Led by National Commissioner and Chief Executive Dr Vincent Olatunji. Runs live online services for registration, breach reporting and audit filing, published an annual report in June 2026, and reports 146 investigations in 2025, 38,661 registered organisations, 306 licensed compliance firms and a 766.2 million naira fine on a pay television operator. It describes its own approach as restorative rather than punitive.

  • Cloud computing, government IT, data classification and localisation framework, IT project clearance

    Actively issuing binding guidelines; approved the National Cloud Computing Guideline and National Cloud Technical Guideline on 4 August 2026.

  • Telecoms licensing, subscriber registration, lawful interception, consumer code

    Active. Published new business rules for subscriber registration in 2026 and holds a draft data protection regulation still at consultation stage.

  • Banking, payments, financial technology, open banking

    Active and issuing circulars weekly. Its public file server blocks automated retrieval. So we could not read the text of its 15 June 2026 circular requiring data to stay in Nigeria, even though the circular is listed in its own database.

  • Capital markets, digital assets, market operators

    Active. Agreed sector-wide data protection compliance work with the privacy regulator in August 2026.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The operative text, deadlines and covered firms of the Central Bank of Nigeria's keeping data in the country circular of 15 June 2026

    We could not read the circular's text. The bank's file server answers automated requests with a bot check, and the Internet Archive's copy is the same bot check page. We verified only the title, the reference number PSS/DIR/PUB/CIR/001/004 and the date, from the bank's own circulars database. If you work in Nigerian payments, ask the bank for the file directly.

  • Whether the Nigeria Data Protection Commission has issued any official “this country is safe” decision for any country, or approved any cross-border transfer instrument

    We found no official decision that any country is safe enough. We checked the Commission's website, the 2025 Directive and the 2025 annual report on 18 August 2026. The Commission does not publish a register of such decisions, so we could not confirm this against a government source.

  • Whether a health-sector data storage or localisation rule exists in Nigeria

    We found no health-specific rule about where data must be stored on a federal health site, checked 18 August 2026. The Federal Ministry of Health website was partly compromised with unrelated spam content, so we cannot rely on that search. If you work in health, check with the Ministry before you rely on this.

  • Incident reporting deadlines imposed on banks, payment firms and telecoms operators by their own regulators

    We could not confirm the industry breach reporting deadlines. We could not download the central bank's cybersecurity documents, and we did not open the telecoms consumer code. Only the 72 hour national deadline is confirmed. If you are a bank, a payment firm or a telecoms operator, check your own regulator's deadline.

  • Minimum retention periods under Nigerian company and tax law

    We could not confirm how long company and tax records must be kept. The Corporate Affairs Commission website returned an access error and the tax authority site did not load. Check with your accountant before you set a retention schedule.

  • Whether NITDA has fixed 1 January 2027 as the binding start date of the National Cloud Computing Guideline

    We could not confirm the start date. The document's front pages give an effective date of 1 January 2027. Its own commencement clause says it comes into effect on a date NITDA decides. We found no separate commencement notice.

  • Whether any online gambling, mapping or defence specific storage rules exist

    We could not check these sectors to a conclusion. General web search was unavailable, so we checked only by visiting regulator sites directly, and found nothing. If you work in one of these sectors, check with your regulator before you rely on this.

  • Current enforcement position on the National Data Protection Adequacy Programme Whitelist mentioned in the audit return form

    We could not confirm that this whitelist exists in published form. The 2025 Directive's audit template refers to organisations being on it, but we found no published list, and the 2025 annual report does not mention it. Ask the Commission whether it keeps one.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.