Nigerian and African tech news: startups, fintech, telecoms, gadgets, AI and policy.

Policy & Regulation

Nigeria’s Data Protection Act explained for small businesses

If your business collects customers' names, phone numbers or payment details, the Nigeria Data Protection Act applies to you. Here is what it requires, in plain language.

Nigeria's Data Protection Act explained for small businesses

The Nigeria Data Protection Act 2023 (NDPA) sets the rules for how organisations collect, use, store and share personal data. It also created the Nigeria Data Protection Commission (NDPC), which enforces the law. If your business keeps customers’ names, phone numbers, addresses, emails, photos or payment details, the Act applies to you, even if you are small.

This is a general guide, not legal advice. For your specific situation, speak to a data protection professional or lawyer.

Key ideas in the law

  • Personal data is any information that identifies a person.
  • Sensitive personal data, such as health, religion, ethnicity, biometrics and financial details, needs extra care.
  • A data controller decides why and how data is used (usually your business). A data processor handles data on your behalf, such as a cloud or payroll provider.

The main principles

  • Have a lawful reason for using personal data, such as consent, a contract, a legal duty or legitimate interest.
  • Collect only what you need for a clear purpose, and do not use it for unrelated purposes.
  • Keep it accurate and up to date.
  • Do not keep it longer than necessary.
  • Keep it secure against loss, theft and unauthorised access.
  • Be transparent: tell people what you collect and why.

People’s rights

Your customers and staff have the right to be informed, to access the data you hold about them, to have it corrected or deleted in many cases, to object to some uses such as direct marketing, and to withdraw consent. You should have a simple way for people to make these requests and respond promptly.

A practical checklist for small businesses

  1. List what data you collect, where it is stored (phones, WhatsApp, spreadsheets, apps) and who can access it.
  2. Publish a clear privacy notice on your website and forms.
  3. Get clear consent for marketing messages, and make it easy to opt out.
  4. Secure your devices and accounts with passwords, two-step verification and up-to-date software.
  5. Limit access so staff only see what they need.
  6. Check your service providers, and have agreements with those who handle data for you.
  7. Have a plan for data breaches. The Act requires serious breaches to be reported to the NDPC quickly, generally within 72 hours of becoming aware, and affected people may need to be informed.
  8. Delete data you no longer need.

Registration and penalties

Organisations that process large amounts of personal data, or data that is especially sensitive, may be classed as data controllers or processors of major importance and must register with the NDPC. Check the NDPC’s current guidance to see whether this applies to you.

Breaking the law can lead to significant fines. For organisations of major importance, penalties can reach the higher of ₦10 million or 2% of annual gross revenue; other organisations face smaller maximum amounts. Beyond fines, a data breach can seriously damage customer trust.

Further reading: Nigeria Data Protection Commission.

Leave a Reply

Your email address will not be published. Required fields are marked *