The Nigeria Data Protection Commission (NDPC) has published a circular to promote public trust and strengthen data governance across public institutions. The circular, issued on August 4, 2026, mandates Ministries, Departments, and Agencies (MDAs) to ensure full compliance with the Nigeria Data Protection Act 2023 (NDP Act). The circular elevates data protection from a simple compliance issue to a priority at the highest levels of government. The NDPC has confirmed that it has established a regulatory clinic to provide technical support to MDAs to achieve compliance.
The circular imposes several obligations on MDAs, including the appointment of Data Protection Officers (DPOs) to oversee data protection compliance and advise management on all matters relating to the lawful processing of personal data. MDAs are also required to register their DPOs with the NDPC for official records. Additionally, MDAs may engage the services of licensed Data Protection Compliance Organisations (DPCOs) to facilitate compliance with the NDP Act and support statutory compliance audits.
The circular also requires MDAs to allocate adequate budget for data protection compliance activities, including capacity building, awareness programmes, deployment of appropriate technical safeguards, and compliance audits. MDAs must submit all mandatory Data Protection Compliance Audit Returns (CAR) not later than March 31st of each year. The circular states that Permanent Secretaries, Accounting Officers, and Chief Executive Officers of all MDAs shall be personally responsible for ensuring institutional compliance with the circular and the provisions of the NDP Act.
The implications of the circular extend beyond the public sector, as MDAs must require private contractors, technology vendors, and cloud service providers engaged by them to comply with data protection obligations under the NDP Act. MDAs should incorporate appropriate data protection safeguards into their engagements with such third parties, including entering into data processing agreements and conducting Data Protection Impact Assessments (DPIAs) where required.
The circular requires MDAs to establish internal data-protection policies and operational procedures, and budget for staff training and awareness programmes. MDAs will need to undertake a range of activities to ensure compliance with the circular, including identifying data-processing activities across departments and appointing qualified, experienced DPOs. Where internal capacity is limited, MDAs will need to engage licensed DPCOs and prepare and submit data-compliance audit returns.
Private-sector entities dealing with MDAs can anticipate heightened due diligence requirements in their procurement processes. Data processing agreements would need to reflect the requirements of the NDP Act, and there would be audit requirements and rights of inspection by MDAs or their licensed DPCOs. Businesses with demonstrable data-protection compliance may be better positioned to participate in government procurement processes and secure contracts involving the processing of personal data.
However, MDAs may face practical challenges in implementing the circular, including making adequate budgetary provision for data protection and integrating data protection due diligence into procurement processes. Many MDAs process personal data on systems not designed with data protection principles in mind and may lack support for modern access controls, encryption, or audit trails. The government procurement processes are often lengthy and procedurally rigid, which may strain MDAs' efforts to ensure compliance.
Key points
- The circular mandates MDAs to ensure full compliance with the NDP Act and imposes personal accountability on leadership.
- The implications of the circular extend beyond the public sector, affecting private entities that process personal data on behalf of government institutions.
- MDAs may face practical challenges in implementing the circular, including budgetary constraints and integrating data protection due diligence into procurement processes.