Nigeria
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Nigeria lets personal data leave the country, but only if you can show the place it is going protects it about as well as Nigeria does, and you must write down why. Some industries are far tighter. Card and cash machine payments have to be processed inside Nigeria, phone companies need written permission to move customer records abroad, and from 2027 banks' data must sit on Nigerian soil.
Data governance in Nigeria
The eight things that decide how you handle data about people in Nigeria. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office, staff or servers in Nigeria, as long as it handles the data of someone who is in Nigeria. There is no revenue or headcount floor to hide under. You do not have to appoint a Nigerian representative, but if you cross a very low size threshold you must register with the regulator and name a data protection officer.
The Nigeria Data Protection Act 2023 applies where the organisation is based, resident or operating in Nigeria, where the processing happens in Nigeria, or where an organisation with no Nigerian presence at all processes the data of a person in Nigeria. The Commission's 2025 Directive spells out that 'operating in Nigeria' includes simply targeting people in Nigeria. The registration threshold is unusually low: an organisation handling the data of more than 200 people within any six months, or working in one of thirteen listed sectors including finance, health, education, communications, insurance, oil and gas, hospitality and e-commerce, is treated as being 'of major importance' and must register. The Act also protects Nigerian citizens who are outside Nigeria, though in that case the organisation's duties are limited to what mutual legal assistance arrangements cover.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023 (Act No. 37 of 2023), section 2
ndpc.gov.ng
“This Act shall apply, where the — (a) data controller or data processor is domiciled in, resident in, or operating in Nigeria ; (b) processing of personal data occurs within Nigeria ; or (c) the data controller or the data processor is not domiciled in, resident in, or operating in Nigeria, but is processing personal data of a data subject in Nigeria.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act General Application and Implementation Directive 2025, Articles 1 and 8, and Schedule 7
ndpc.gov.ng
“Processes the personal data of more than Two-Hundred (200) data subjects in six (6) months”
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, with conditions. You may send personal data out of Nigeria if the receiving side is covered by a law, a group-wide rulebook, a contract, a code of conduct or a certificate that gives protection as good as Nigeria's, or if one of a short list of special situations applies. That is the national answer. Four industries override it, and in those the honest answer is closer to 'no'.
Sector overrides, most restrictive first. PAYMENTS: every domestic card, cash machine and point-of-sale transaction must be switched by a Nigerian switch and, in the central bank's words, must not 'under any circumstance' be routed outside Nigeria. BANKING AND OTHER REGULATED FINANCE: the central bank issued a circular on 15 June 2026 headed 'Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System', and from 1 January 2027 the technology agency's cloud rules say all financial data generated, processed, transmitted or stored by regulated financial institutions must be primarily hosted, processed and stored inside Nigeria. TELECOMS: no subscriber information may be moved out of Nigeria without the telecoms regulator's prior written consent, and phone companies may not copy or store subscriber records for any purpose beyond what the rules allow. GOVERNMENT AND CRITICAL DATA: from 2027 government and regulated sector data at classification Level 2 and above must be hosted in Nigeria by default, with both the live site and the backup site inside the country, and the most sensitive class may never leave a Nigerian government facility. SECURITIES: the markets regulator does not impose storage in Nigeria, but a digital asset business must have a Nigerian office and must justify to the regulator any function it outsources abroad. HEALTH: no health specific storage rule was found on a federal health domain, checked 18 August 2026; health records sit at Level 2 of the cloud classification, where hosting in Nigeria is described as highly recommended rather than mandatory.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, sections 41 to 43
ndpc.gov.ng
“A data controller or data processor shall not transfer or permit personal data to be transferred from Nigeria to another country, unless — (a) the recipient of the personal data is subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism that affords an adequate level of protection with respect to the personal data in accordance with this Act ; or (b) one of the conditions set out in section 43 of this Act applies.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaGuidelines on Operations of Electronic Payment Channels in Nigeria, 31 May 2020, paragraph 2.4.4.8
cbn.gov.ng
“All domestic transactions, including, but not limited to POS and ATM transactions must be switched, using the services of a local switch, and shall not, under any circumstance, be routed outside Nigeria for switching.”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionRegistration of Communications Subscribers Regulations, 2022 (S.I. No. 86 of 2022), regulation 9(4)
ncc.gov.ng
“No subscriber information shall be transferred outside the Federal Republic of Nigeria without the prior written consent of the Commission.”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNational Cloud Computing Guideline 2026, paragraphs 9.2 and 9.3
nitda.gov.ng
“Notwithstanding any other provision of this Guideline, all financial data generated, processed, transmitted or stored by regulated financial institutions shall be primarily hosted, processed and stored within the territorial boundaries of the Federal Republic of Nigeria.”
Link checked 18 August 2026
- Official sourceSecurities and Exchange Commission, NigeriaRules on Issuance, Offering Platforms and Custody of Digital Assets, rules 4.3, 24.9 and 38.8
sec.gov.ng
“A VASP shall have an office in Nigeria managed by a Director of the company.”
Link checked 18 August 2026
Sending data out of the country
The model is: banned unless one of the listed grounds applies. There is no approved country list at all. The regulator has published none, and the law says that silence must not be read as approval. In practice you either write your own assessment showing the destination is safe enough, or you rely on the person's consent, a contract, a legal claim or another narrow exception. The regulator says it also expects to approve your transfer paperwork first, which is not obvious from the Act.
Section 41 of the Act allows a transfer where the recipient is covered by a law, binding corporate rules, contractual clauses, a code of conduct or a certification that gives adequate protection. Section 42 lets the Commission declare a country, region, sector or set of standard clauses adequate, and section 42(6) states that the absence of such a decision does not imply adequacy. As of 18 August 2026 no adequacy decision could be found on the Commission's own site, in the 2025 Directive or in the Commission's 2025 annual report, so the list is empty and the burden sits entirely with the organisation. Schedule 5 of the 2025 Directive describes the grounds as an adequacy decision, a Cross-Border Data Transfer Instrument approved by the Commission, or 'other lawful bases', and says that instrument route covers codes of conduct, certifications, binding corporate rules and standard contractual clauses. The Commission's 2025 annual report goes further, listing 'Unauthorised Cross-Border Transfer of Personal Data' as a live enforcement theme and saying some controllers 'seem oblivious of their obligations in seeking the approval of the Commission before carrying out cross-border transfer'. Treat approval as expected in practice even though the statute reads as self-assessment. You must also record the basis for every transfer, and answer for it in your annual audit filing, which asks which countries you send data to.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, section 42(6)
ndpc.gov.ng
“The absence of a determination by the Commission under subsection (4) or (5) with respect to a country, territory, sector, binding corporate rules, contractual clause, code of conduct, or certification mechanism shall not imply the adequacy of the protections afforded by it.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Article 45 and Schedule 5
ndpc.gov.ng
“Pending the issuance of any regulatory instrument by the Commission on cross-border data transfer, the explanatory note in Schedule 5 of this GAID shall be used for the evaluation of countries for the purposes of determining their level of adequacy.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Commission Annual Report 2025, section 4.2 (Investigation and Enforcement Actions)
ndpc.gov.ng
“There are cases where data controllers seem oblivious of their obligations in seeking the approval of the Commission before carrying out cross-border transfer of personal data.”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Nigeria Data Protection Commission, and it is genuinely working. It has a named chief executive, online systems for registration, breach reports and audit filings, and it published a detailed annual report in June 2026. It ran 146 investigations in 2025, has more than 38,000 registered organisations on its books, licensed 306 private compliance firms, and fined a pay television company about 766 million naira, roughly 560 thousand US dollars. Industry regulators for banking, telecoms and securities enforce their own rules alongside it.
Enforcement is rated active rather than aggressive on the Commission's own description of its approach: the 2025 annual report says it has 'adopted a restorative rather than punitive approach', leaning on warnings, compliance orders and 'remedial fees in lieu of strict penalties' under section 48(2)(d) of the Act. The numbers it publishes for itself are investigations of 117 in 2022, 177 in 2023, 213 in 2024 and 146 in 2025; compliance revenue of 94.4 million naira in 2022 rising to 4.99 billion naira in 2025; registered organisations of major importance of 36,052 in 2024 and 38,661 in 2025; and 306 licensed Data Protection Compliance Organisations. Open investigations span health, social media, telecommunications, banking and financial technology, and hospitality, and named recurring problems include opening bank accounts without consent, copied and pasted privacy notices, cookie-based data mining and unauthorised cross-border transfers. The report also says the Commission is 'now transitioning into a phase of full enforcement'. The chief executive is Dr Vincent Olatunji, National Commissioner, who signed the 2025 Directive and appears in Commission news through August 2026.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Commission Annual Report 2025 (published June 2026) — enforcement statistics and approach
ndpc.gov.ng
“The Commission is currently handling multiple investigations into alleged violations of privacy rights across key sectors, including health, social media, telecommunications, banking/fintech, and hospitality.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNigeria a Model in Data Protection, Ranked 1st in Africa, Says NDPC National Commissioner (10 July 2025)
ndpc.gov.ng
“the recent fine of ₦766.2 million on MultiChoice”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC privacy breach reporting portal (live, checked 18 August 2026)
services.ndpc.gov.ng
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both a floor and a ceiling, and they pull in opposite directions. The unusual one is the ceiling: if no law tells you how long to keep something, the regulator says you must delete it within six months of finishing the job you collected it for. Against that, open banking data must be kept for at least seven years, telephone companies must keep proof of customer consent for two years, and organisations of major importance must file an audit return every year by the end of March.
The six month default in Article 49(3) of the 2025 Directive is the single most easily missed rule in Nigeria, because most global retention schedules assume that silence means you may keep data indefinitely. Article 49(4) softens it: you may keep data longer with proper safeguards to defend a legal claim or for due diligence. On the floor side: the central bank's open banking rules require data obtained for open banking to be kept for a minimum of seven years, and a security annex in the same document says open banking data must be retained for reference for a minimum of ten years, so the same instrument contains two different minimums. Telecoms business rules require evidence and logs of subscriber consent to be stored for at least two years and biometric verification logs for at least two years. Intercepted communications held by security agencies may be archived for three years and then must be destroyed. Compliance timing: an organisation must run a data protection audit within fifteen months of starting business and every year afterwards, and an organisation of major importance in the top two tiers must file its audit return by 31 March each year, with a late fee of half the filing fee. General company and tax record floors were not verified from government sources on this run.
Sources
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Articles 7 and 49
ndpc.gov.ng
“In circumstances requiring storage limitation, where no timebound obligation has been provided by law, the storage time for the purpose of data processing shall lapse not later than six (6) calendar months when the original purpose of the processing has been accomplished.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaOperational Guidelines for Open Banking in Nigeria, 8 March 2023, section 4.1 and security annex
cbn.gov.ng
“Ensure that data obtained for the purposes of open banking is retained for a minimum period of seven (7) years, except when legally bound”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionBusiness Rules for the Registration of Communications Subscribers Regulations 2026 — consent log and biometric log retention
ncc.gov.ng
“Data Retention: Evidence/logs of consent received shall be stored for a minimum period of 2 years and shall be retrievable when required.”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionLawful Interception of Communications Regulations, 2019 (S.I. No. 14 of 2019), regulation 6
ncc.gov.ng
“may be archived for three years and thereafter be destroyed”
Link checked 18 August 2026
If something goes wrong
One national clock, and it is 72 hours. If you are the organisation that decided what to do with the data, you have 72 hours from becoming aware of a break-in that puts people at risk to tell the regulator. If the risk to people is high you must also tell the affected people straight away, in plain language, with advice on what they should do. A supplier who suffers the breach must tell the organisation that hired it as soon as it knows, with no fixed number of hours.
The duty sits in section 40 of the Act and is expanded in Article 33 of the 2025 Directive. The Directive adds a duty of care overlay: whatever the 72 hour limit says, you must give immediate information to all relevant authorities, including the Commission, where that could help contain a breach on a national or sector scale. It also lists eight things the notification must contain, including when the breach happened, how many people are at real risk of significant harm, and a named contact who can answer the Commission's questions. Reports are filed through the Commission's online breach portal. Watch for extra sector clocks: banks, payment firms and telecoms operators sit under their own incident reporting rules, and those deadlines were not verified from primary regulator documents on this run because the central bank blocks automated downloads of its circulars.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, section 40
ndpc.gov.ng
“A data controller shall, within 72 hours of becoming aware of a breach which is likely to result in a risk to the rights and freedoms of individuals, notify the Commission of the breach”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Article 33
ndpc.gov.ng
“a data controller shall notify affected data subjects immediately after becoming aware of the breach in order to ensure that data subjects are not unlawfully targeted as a result of the breach”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC online privacy breach reporting service
services.ndpc.gov.ng
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. First, handling the data of just 200 people in six months makes you an organisation 'of major importance', with registration, a data protection officer and yearly audit filings. Second, a child in Nigeria is anyone under 18, so a parent must consent. Third, delete within six months by default. Fourth, ignoring a regulator's order is a crime, and directors are personally on the hook. Fifth, the biggest filers cannot file for themselves.
(1) The 200 person threshold in Schedule 7 of the 2025 Directive is far below the level most companies expect, and thirteen listed sectors are caught regardless of size. Registration fees run from 10,000 naira to 250,000 naira, and the annual audit return fee runs up to 1,000,000 naira, about 735 US dollars, for the largest filers, with a 50 percent surcharge for filing late. (2) 'Child' takes its meaning from the Child's Rights Act 2003, so the age is 18, not 13 or 16, and the Act says presenting a government approved identity document is an acceptable way to check age. (3) The six month default deletion rule in Article 49(3) applies wherever no other law sets a period. (4) Section 49 makes failure to comply with an enforcement order a criminal offence carrying up to one year in prison, and section 53 deems the principal officers of a company culpable unless they prove the offence happened without their consent or connivance and that they exercised diligence. (5) Under Article 10(14) of the Directive, organisations in the top two tiers must file their audit returns through a Data Protection Compliance Organisation licensed by the Commission, so an in-house team cannot simply file for itself. A sixth to watch: the Commission's own reading is that cross-border transfers need its approval, which is stricter than the plain words of the Act.
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023, sections 31, 49, 53 and 65 (definition of child)
ndpc.gov.ng
“Where an offence has been committed by a body corporate or firm, the body corporate or firm, as well as principal officers of the body corporate or firm shall be deemed culpable, unless the principal officers prove that — (a) the offence was committed without their consent or connivance ; and (b) they exercised diligence to prevent the commission of the offence.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionGeneral Application and Implementation Directive 2025, Articles 10 and 49, Schedules 7 and 10
ndpc.gov.ng
“Except as otherwise approved by the Commission, a data controller or a data processor within the categories of UHL and EHL shall file CAR through a Data Protection Compliance Organisation (DPCO) licensed by the Commission in line with Section 33 of the NDP Act.”
Link checked 18 August 2026
What's changing next
The big date is 1 January 2027, when Nigeria's new national cloud rules are due to start. From then, data held by regulated financial institutions is meant to be hosted in Nigeria, and government and other sensitive data must have both its live copy and its backup inside the country. The central bank added its own data localisation circular in June 2026. Several powers already exist that could tighten things overnight with no consultation.
Dated items. 1 January 2027: the National Cloud Computing Guideline 2026 and the National Cloud Technical Guideline 2026, both approved on 4 August 2026 and both marked mandatory, are stated to take effect, subject to a transition period for existing deployments that the technology agency has yet to publish. 15 June 2026: the central bank's payments system circular on market structure and data localisation was issued, with its practical deadlines unverified because the bank blocks public downloads of the file. Dormant switches, any of which can move without a public consultation. (1) Section 41(4) of the Act lets the Commission designate categories of personal data that get extra transfer restrictions, and none has been designated yet. (2) The 2025 Directive says a dedicated cross-border transfer instrument is still to be issued, and Article 50 lets the Commission issue supplementary rules that override the Directive. (3) The cloud guideline says it commences 'on such date as may be determined by NITDA', despite the 1 January 2027 date in its own front matter, so the start date is at the agency's discretion. (4) The telecoms regulator holds a draft Data Protection Regulations 2023 and a draft Internet Code of Practice that remain drafts with no legal effect. (5) The technology agency can grant temporary localisation waivers to foreign cloud providers that promise investment in Nigerian data centres, which makes the localisation wall negotiable for large players and not for small ones.
Sources
- Official sourceNational Information Technology Development AgencyNational Cloud Computing Guideline 2026 — approval date 4 August 2026, effective date 1 January 2027, enforcement status mandatory
nitda.gov.ng
“The Guideline shall come into effect on such date as may be determined by NITDA.”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNational Cloud Technical Guideline 2026 — primary and secondary sites within Nigeria for Level 2 data and above
nitda.gov.ng
“Primary and Secondary Sites within Nigeria: For data at Level 2 and above, both the primary production site and the secondary (failover) disaster recovery site must be located within Nigeria's territorial boundaries.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaCircular PSS/DIR/PUB/CIR/001/004, 15 June 2026 — Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures In The Nigeria Payments System
cbn.gov.ng
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionNCC Regulations index listing the Draft Data Protection Regulations 2023 and the Consultation Paper on the Internet Code of Practice
ncc.gov.ng
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Nigerian Communications Commission (Registration of Communications Subscribers) Regulations, 2022
Directly binding regulation · S.I. No. 86 of 2022, made 22 July 2022, Official Gazette No. 147 Vol. 109 of 15 August 2022
Phone and internet companies may not move subscriber information out of Nigeria without the regulator's prior written permission, and may not copy or store it for any purpose the regulations do not allow. The fine is charged per SIM card, so a database wide breach multiplies fast.
Enforced by Nigerian Communications Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countrySubscriber information may leave Nigeria only with the telecoms regulator's prior written consent. No published application route or approval list was found, so in practice this behaves as a wall.
- Secure the data
- Keep logs — 2 yearsUnder the 2026 business rules, evidence of subscriber consent and biometric verification logs must be kept for at least two years.
What it costs if you get it wrong
- Fixed maximum fine: NGN 200,000 per subscription medium — about $147A licensee retaining, duplicating or dealing in subscriber information in breach of the regulations; the per SIM basis makes the total unbounded
Sources
- Official sourceNigerian Communications CommissionRegistration of Communications Subscribers Regulations, 2022, regulations 9 and 20 (gazette copy)
ncc.gov.ng
“No subscriber information shall be transferred outside the Federal Republic of Nigeria without the prior written consent of the Commission.”
Link checked 18 August 2026
- Official sourceNigerian Communications CommissionNCC Regulations index confirming the 2022 Regulations and the 2026 Business Rules are current
ncc.gov.ng
Link checked 18 August 2026
Guidelines on Operations of Electronic Payment Channels in Nigeria
Regulator guideline · Issued 31 May 2020, superseding the 2016 guidelines
Every domestic card, cash machine and card terminal transaction must be switched by a Nigerian switch and must never be routed outside Nigeria. No card scheme may force a Nigerian bank to send such a transaction abroad for processing.
Enforced by Central Bank of Nigeria
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryApplies to the routing, authorisation and switching of domestic transactions rather than to storage of records. Card details must not be stored on unauthorised servers.
- Secure the data
Sources
- Official sourceCentral Bank of NigeriaGuidelines on Operations of Electronic Payment Channels in Nigeria 2020, paragraphs 1.2, 2.4.1.6, 2.4.4.8 and 3.4.3.6
cbn.gov.ng
“No card or payment scheme shall compel any issuer or acquirer to send any transaction outside Nigeria for the purpose of processing, authorization or switching, if the transaction is at an ATM or at any acceptance device in Nigeria and the issuer is a Nigerian bank.”
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaCBN circulars index, entry dated 31/05/2020 for these Guidelines
cbn.gov.ng
Link checked 18 August 2026
- Secondary sourceInternet ArchiveInternet Archive capture of the same document, used to read the text the bank's own site refuses to serve to automated clients
web.archive.org
Link checked 18 August 2026
Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures In The Nigeria Payments System
Regulator directive · PSS/DIR/PUB/CIR/001/004, 15 June 2026
The central bank issued a payments system circular headed data localisation on 15 June 2026. Its existence, reference number and date are confirmed on the bank's own database, but the text is not publicly readable, so anyone in Nigerian payments should ask the bank for the copy rather than rely on any summary.
Enforced by Central Bank of Nigeria
Transfer model: Approval each time
What it makes you do
- Keep the data in the country — from 15 June 2026The heading and the issuing department are confirmed on the bank's own circulars database. The operative wording, the deadlines and the exact population of firms covered could not be read because the bank's file server rejects automated requests and the Internet Archive copy is the same rejection page.
Sources
- Official sourceCentral Bank of NigeriaCBN circulars database entry: PSS/DIR/PUB/CIR/001/004, Payments System Supervision, 15/06/2026
cbn.gov.ng
Link checked 18 August 2026
- Official sourceCentral Bank of NigeriaThe circular itself (file rejects automated retrieval with a bot check, 18 August 2026)
cbn.gov.ng
Link checked 18 August 2026
National Cloud Computing Guideline 2026 and National Cloud Technical Guideline 2026
Regulator guideline · Issued under sections 6 and 32 of the NITDA Act 2007; approved 4 August 2026
Nigeria's new cloud rulebook. From 2027 government and other sensitive data must be hosted in Nigeria by default, both the live and the backup copy, and all data held by regulated financial institutions must sit inside the country. Foreign providers can buy a temporary waiver by investing in Nigerian data centres.
Enforced by National Information Technology Development Agency
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the country — from 1 January 2027Sovereign data at classification Level 2 and above hosted in Nigeria by default; all financial data of regulated financial institutions hosted, processed and stored in Nigeria; Level 4 classified data never leaves a Nigerian government or certified facility.
- Prove the data stays under local control — from 1 January 2027Both the live site and the disaster recovery site must be inside Nigeria for Level 2 data and above, in different geopolitical zones.
- Hold a security certificate — from 1 January 2027Providers must be certified and listed on the agency's Digital Regulatory Platform to sell to federal public institutions.
- Do not hand data to foreign authorities on demandForeign government access to sovereign data only through mutual legal assistance channels; direct requests must not be granted.
What it costs if you get it wrong
- Order to stopSuspension of a provider's services from the Digital Regulatory Platform, forced recertification audits, remediation notices and compliance directives under the NITDA Act
Sources
- Official sourceNational Information Technology Development AgencyNational Cloud Computing Guideline 2026, document information table, paragraphs 9.2, 9.3, 13.2 and Schedules A and D
nitda.gov.ng
“All sovereign data classified as Level 2 and above, as defined and categorised in Schedule A: National Data Classification Framework, shall be hosted within Nigeria by default, subject to temporary waivers as provided below.”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNational Cloud Technical Guideline 2026 — Nigeria-First disaster recovery principle
nitda.gov.ng
“Under no circumstances shall data classified as LEVEL 4”
Link checked 18 August 2026
- Official sourceNational Information Technology Development AgencyNITDA regulations and policies index listing the 2026 cloud instruments
nitda.gov.ng
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Nigeria Data Protection Act, 2023
Act of parliament · Act No. 37 of 2023
Nigeria's general privacy law. It reaches foreign companies with no Nigerian presence, bans sending personal data abroad unless a listed ground applies, requires a breach report within 72 hours, treats anyone under 18 as a child, and backs it all with fines measured against worldwide revenue plus a criminal offence for ignoring the regulator.
Enforced by Nigeria Data Protection Commission
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Get consent
- Tell people what you do
- Secure the data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Report breaches to the regulator — within 72 hours
- Tell affected peopleImmediately, where the breach is likely to result in a high risk to the person.
- Get a parent's consent for children — applies at: under 18, following the Child's Rights Act 2003
- Appoint a data protection officer — applies at: Data controllers of major importance
- Register or notify — applies at: Data controllers and processors of major importance, within six months of qualifying
- Put a transfer safeguard in place
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: Greater of NGN 10,000,000 or 2% of annual gross revenue in the preceding financial year — about $7 thousandViolation by a data controller or processor of major importance (the 'higher maximum amount'); the percentage limb has no cap
- Percentage of global turnover: Greater of NGN 2,000,000 or 2% of annual gross revenue in the preceding financial year — about $1 thousandViolation by any other data controller or processor (the 'standard maximum amount')
- Criminal liability: Up to one year imprisonment, or a fine, or bothFailure to comply with a compliance order made by the Commission
- Claims by individualsA person who suffers injury, loss or harm may recover damages in civil proceedings
Sources
- Official sourceNigeria Data Protection CommissionNigeria Data Protection Act, 2023 (Act No. 37 of 2023), commencement 12 June 2023
ndpc.gov.ng
“The "higher maximum amount" shall be the greater of — (a) N10,000,000, and (b) 2% of its annual gross revenue in the preceding financial year.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC Resources page hosting the official text of the Act
ndpc.gov.ng
Link checked 18 August 2026
Nigeria Data Protection Act General Application and Implementation Directive (NDP Act-GAID) 2025
Government rules · NDPC/NDP ACT-GAID/01/2025, issued 20 March 2025
The directive that turns the Act into day to day duties: who must register, how much they pay, when audits are filed, what a data protection officer must be given, and a default rule that personal data is deleted six months after the job it was collected for is finished.
Enforced by Nigeria Data Protection Commission
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct
What it makes you do
- Register or notify — applies at: More than 200 people's data in six months, or any organisation in one of thirteen listed sectors
- Independent audit — 1 yearFirst audit within 15 months of starting business; top two tiers must file audit returns by 31 March each year, and must file through a licensed compliance organisation.
- Keep records of processing
- Assess high-risk projectsExisting processing had to be assessed within six months of the Directive being issued.
- Appoint a data protection officerMust report to management level, must not be dismissed or penalised for doing the job, and must undergo credential assessment.
- Delete data after a period — 6 monthsDefault deletion point where no other law sets a period.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Written vendor contract
- Put a transfer safeguard in place
- Get consentSeparate article on consent to cookies and other tracking tools.
What it costs if you get it wrong
- Fixed maximum fine: NGN 1,000,000 audit return filing fee for the largest filers, plus a 50% surcharge for late filing — about $735Failure to file compliance audit returns on time
Sources
- Official sourceNigeria Data Protection CommissionNDP Act-GAID 2025, signed by the National Commissioner on 20 March 2025
ndpc.gov.ng
“Upon the issuance of the GAID, the Commission shall cease to apply the Nigeria Data Protection Regulation (NDPR) 2019 as a legal instrument for regulating data privacy and protection.”
Link checked 18 August 2026
- Official sourceNigeria Data Protection CommissionNDPC Annual Report 2025, section 4.1 on implementing the GAID
ndpc.gov.ng
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The operative text, deadlines and covered firms of the Central Bank of Nigeria's data localisation circular of 15 June 2026
The bank's file server answers automated requests with a bot check, and the Internet Archive's copy is the same bot check page. Only the title, reference number PSS/DIR/PUB/CIR/001/004 and date could be verified, from the bank's own circulars database. Anyone in Nigerian payments should request the file directly.
Whether the Nigeria Data Protection Commission has issued any adequacy decision for any country, or approved any cross-border transfer instrument
None was found on the Commission's website, in the 2025 Directive or in the 2025 annual report, checked 18 August 2026. This is a negative that cannot be proved; the Commission does not publish a register of such decisions.
Whether a health-sector data storage or localisation rule exists in Nigeria
No such instrument was located on a federal health domain, checked 18 August 2026. The Federal Ministry of Health website was found to be partly compromised with unrelated spam content, which makes negative findings there unreliable.
Incident reporting deadlines imposed on banks, payment firms and telecoms operators by their own regulators
The central bank's cybersecurity framework documents could not be downloaded, and the telecoms consumer code was not opened on this run. Only the 72 hour national deadline is confirmed.
Minimum retention periods under Nigerian company and tax law
The Corporate Affairs Commission website returned an access error and the tax authority site did not resolve, so no government backed figure for company or tax record floors is recorded here.
Whether NITDA has fixed 1 January 2027 as the binding start date of the National Cloud Computing Guideline
The document's front matter states an effective date of 1 January 2027 but its operative commencement clause says it comes into effect on such date as NITDA may determine, and no separate commencement notice was found.
Whether any online gambling, mapping or defence specific storage rules exist
Not researched to a conclusion. General web search was unavailable during this run, so these sectors were checked only by direct visits to regulator sites and nothing was found.
Current enforcement position on the National Data Protection Adequacy Programme Whitelist mentioned in the audit return form
The 2025 Directive's audit template refers to organisations being on this whitelist, but no published list was found and the 2025 annual report does not mention it.
30-day cadence. Three things are in motion at once: the central bank's June 2026 localisation circular whose terms are not public, NITDA's cloud guidelines whose commencement date is at the agency's discretion despite a stated 1 January 2027 effective date, and the privacy regulator's still unissued cross-border transfer instrument. Any of the three can change the answer to 'can the data leave' within weeks.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Put this next to another country
Nigeria versus
Compare