Nigeria: Data Protection

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
Nigeria’s National Digital Cloud Policy: Key Provisions And Implications For Business
On 17 August 2026, Nigeria's Federal Government released its National Digital Cloud Policy, superseding the 2019 framework to establish a domestic cloud and data infrastructure ecosystem. The Policy introduces fiscal and regulatory incentives for qualifying investors, mandates cloud-first adoption across government agencies, and implements a four-tier sovereign data classification system that confines data residency requirements to specific categories rather than imposing blanket localisation.
Nigeria Technology
T
Templars
Article
Registration Of Data Controllers And Data Processors – A Legal Conundrum Clarified In The Case Of Emmanuel Haruna v. Nigeria Data Protection Commission
The Nigeria Data Protection Commission's controversial Guidance Notice requiring registration of Data Controllers and Processors of Major Importance sparked legal challenges and widespread debate over regulatory authority, privacy rights, and compliance obligations. A landmark Federal High Court ruling has now clarified the scope and validity of these registration requirements, establishing binding precedent on who must register and under what circumstances.
Nigeria Privacy
A
Alliance Law Firm
Article
Artificial Intelligence And The Right To Privacy Under Section 37 Of The Constitution Of The Federal Republic Of Nigeria, 1999 (As Amended).
Nigeria's adoption of AI-powered facial recognition at major airports and automated credit scoring by digital lenders raises urgent questions about constitutional privacy protections. With Section 37 of the 1999 Constitution drafted before modern biometric surveillance existed, can its guarantee of privacy extend to algorithmic profiling and mass data collection?
Nigeria Technology
A
Alliance Law Firm
Article
Open Banking And Digital Lending In Nigeria: Opportunities, Risks And Regulatory Readiness
Nigeria's open banking framework promises to transform digital lending through secure, consent-driven financial data sharing. As the phased rollout approaches mid-2026, lenders face both opportunity and obligation: faster credit decisions, better risk assessment, and new product possibilities, alongside stricter compliance requirements and infrastructure dependencies that will reshape competitive dynamics across the sector.
Nigeria Finance
TA
Tope Adebayo LP
Article
Confession, Counselling And Confidentiality: Managing Legal Risk For Religious Leaders
Religious leaders routinely receive sensitive personal disclosures during spiritual counselling, creating expectations of confidentiality rooted in faith traditions and pastoral trust. Yet the legal landscape presents a complex web of competing obligations, from safeguarding laws and mandatory reporting requirements to data protection regulations and criminal investigations. This analysis examines how clergy must balance their religious duty of confidentiality against evolving legal obligations that may com
Nigeria Privacy
Syntegral Legal Practice
Article
Irish High Court TikTok Ruling 2026: Implications For Nigeria’s NDPA And The NDPC
The Irish High Court's landmark 2026 ruling against TikTok has exposed a critical vulnerability in how multinational tech companies handle cross-border data transfers. By establishing that data access location matters more than storage location, this judgment carries profound implications for Nigeria's digital economy and the enforcement powers of the Nigeria Data Protection Commission under the NDPA 2023.
Nigeria Privacy
OA
Olisa Agbakoba Legal (OAL)
Article
Court Orders GTCO To Cease Unsolicited Marketing To Non-Customers Over Data Privacy Breach
In a landmark Federal High Court ruling, GTCO has been ordered to stop sending unsolicited marketing messages to non-customers, marking a decisive shift in Nigeria's data protection enforcement landscape. The judgment establishes that companies can no longer exploit personal data without demonstrable legal basis, reinforcing that direct marketing requires valid consent under the Nigeria Data Protection Act 2023.
Nigeria Privacy
OA
Olisa Agbakoba Legal (OAL)
Article
Can Lawyers Use ChatGPT? The Rules, The Risks, And The Cases That Ended Careers
As artificial intelligence tools like ChatGPT become increasingly prevalent in legal practice, Nigerian law firms face a critical decision: embrace the technology's productivity gains or risk falling behind competitors. With over 1,490 documented cases of AI-generated fabrications submitted to courts worldwide, the question isn't whether lawyers can use ChatGPT, but how to harness its power without destroying careers through hallucinated case law, confidentiality breaches, or regulatory violations.
Nigeria Commercial
OA
Olisa Agbakoba Legal (OAL)
Article
The Agentic Privacy Gap: Liability And Consent In Autonomous AI Systems
Agentic AI systems operate autonomously, making decisions and processing data in ways users cannot predict or control. This creates a fundamental mismatch between existing data-protection frameworks built on notice-and-choice principles and the reality of how these systems collect, infer, and share personal information. The article examines whether current consent models, controller definitions, and liability frameworks can adequately govern AI agents that independently chain data sources
Nigeria Privacy
BC
Babalakin & Co.Legal Practitioners
Article
One Africa, One Click: What The Afcfta Digital Trade Protocol Means For Africa
The AfCFTA Digital Trade Protocol is evolving from framework to operational instrument, with eight new annexes adopted in February 2025 covering rules of origin, cross-border payments, and data transfers. As Africa's digital economy races toward a projected $712 billion by 2050, businesses and governments face critical decisions about compliance, market access, and regulatory alignment. What practical steps should stakeholders take now to prepare for implementation, and how will ratification timelines affec
Nigeria International
PL
Pavestones Legal
Article
Nigeria's 48-Hour Data Breach Notification Requirement: Regulatory Implications And Comparative Analysis
Nigeria's Internet Code of Practice 2026 introduces a 48-hour breach notification requirement for Internet Access Service Providers, creating a shorter timeline than the Nigeria Data Protection Act 2023 and raising questions about overlapping regulatory obligations. This development reflects a broader global trend toward sector-specific cyber resilience requirements that demand earlier visibility into cyber incidents.
Nigeria Privacy
Syntegral Legal Practice
See more