By Ogbu, Blessing Ekpere, Esq.

  • INTRODUCTION

The birth of Nigeria’s Fourth Republic in 1999 coincided with the rise of information and communication technology, leading to the digital collection and storage of data. This shift prompted concerns over the state’s potential misuse of citizens’ data, conflicting with the civil liberties guaranteed in the Nigerian Constitution, particularly the right to privacy under Section 37. To address these concerns and attract foreign investment, the Nigeria Data Protection Bureau, in collaboration with the World Bank’s IDA, facilitated the passage of the Nigerian Data Protection Act, 2023. This Act, which supersedes the NITDA’s 2019 regulation, governs data collection and processing by entities in Nigeria.

  • OBJECTIVES OF THE ACT

Section 1(1)(a)-(h) contains the cardinal objectives of the Act. According to the subsection, the Act declares its overarching objective to be the protection and preservation of the fundamental rights, freedoms, and interests of data subjects, as enshrined in the Constitution of the Federal Republic of Nigeria, 1999, through the regulation of the fair, lawful, and accountable processing of personal data. It further mandates data controllers and processors to uphold the security and confidentiality of personal data, guarantee the privacy rights of data subjects, and provide adequate means of redress in the event of any breach. In furtherance of these aims, the Act establishes an independent and impartial regulatory Commission[1] to oversee compliance, ensure adherence to data protection obligations, and strengthen Nigeria’s position within the national, regional, and global digital economies.

  • EXTENT OF THE APPLICATION OF THE ACT

The Nigeria Data Protection Act, 2023 is not designed to operate at large. The provisions of the Act itself circumscribe its operation. Section 2 (1) and (2) (a), (b), and (c) of the Act delineate the limitations of the Act’s application. By virtue of section 2 of the Act, the Act is applicable to the processing of personal data, whether such processing is carried out by automated means or otherwise. It is further provided that the Act shall extend to instances where the data controller or data processor is domiciled, resident, or carries on business within the territory of Nigeria; or where the processing of personal data takes place within Nigeria. Furthermore, the provisions of this Act applies to data controllers or processors who, though not domiciled, resident, or operating in Nigeria, engage in the processing of personal data belonging to data subjects resident in Nigeria.

Though the extent of the application of the Act appears to be unlimited by virtue of the provisions of section 2 of the Act, section 3, however, establishes some spheres that are not covered by the circumference of section 2 of the Act. By this corollary, therefore, the provisions of this Act shall not extend to the processing of personal data undertaken by an individual or individuals solely for personal or domestic purposes, provided always that such processing does not infringe upon the fundamental right to privacy of any data subject.

Furthermore, and subject to the constitutional rights and freedoms guaranteed under the law, as well as the limitations therein, the obligations imposed under Part V of this Act—save for the provisions of sections 24, 25, 32, and 40—shall not apply to a data controller or processor where the processing of personal data is undertaken in any of the following circumstances: (a) by a competent authority for the purposes of preventing, investigating, detecting, prosecuting, or adjudicating a criminal offence, or for the execution of criminal penalties, pursuant to applicable law; (b) by a competent authority in the interest of preventing or controlling a national public health emergency; (c) by a competent authority, as may be necessary, in furtherance of national security; (d) for purposes of publication in the public interest, including journalism, education, art, or literature, to the extent that compliance with such obligations would be incompatible with these purposes; or (e) where necessary for the establishment, exercise, or defence of legal claims, whether in judicial, administrative, or alternative dispute resolution proceedings.

In addition, the Commission may, by regulation, prescribe categories of personal data or specific forms of processing that may be exempted from the application of this Act. Notwithstanding any exemption so prescribed, the Commission may issue guidance notices setting out legal safeguards and best practices to data controllers or processors where, in its opinion, such processing constitutes or is likely to constitute a violation of sections 24 and 25 of this Act.

  • PRACTICAL INSTANCES WHEN THE ACT WILL NOT APPLY

The applicability of the Nigerian Data Protection Act is not absolute; its scope is circumscribed by specific exceptions grounded in practical realities. The Act does not extend to data collected for domestic use — typically defined by personal, non-commercial purposes within familiar social settings, such as a family compiling medical histories for dietary planning. Equally, data processed for crime detection, prevention, prosecution, and adjudication — including CCTV surveillance — is excluded, as is data processed in the interests of national security or during public health emergencies. Medical data collection, particularly during treatment or registration at healthcare facilities, is also exempt where consent is implied through voluntary submission and acceptance of services. The Act further exempts data gathered for educational, research, artistic, journalistic, or literary purposes, mirroring principles akin to fair use under the Nigerian Copyright Act, 2022. Lastly, data processed in connection with asserting or defending legal rights in ongoing adjudication also falls outside the Act’s protective scope. These exclusions underscore the contextual nature of data protection, reflecting the balance between privacy rights and societal, legal, and operational imperatives.

  • THE INTERSECTION OF THE ACT AND THE CONSTITUTION OF THE FEDERAL REPUBLIC OF NIGERIA, 1999

The Nigeria Data Protection Act, 2023 (“the Act”) establishes a comprehensive legal framework for the protection of personal data and, significantly, grounds its provisions within the broader context of constitutional rights and liberties as guaranteed under the 1999 Constitution of the Federal Republic of Nigeria (as amended). The Act’s frequent and express references to the Constitution emphasize its objective of reinforcing the primacy of constitutional safeguards in the processing and regulation of personal data.

Section 1(1)(a) of the Act articulates as a fundamental objective the protection of the rights, freedoms, and interests of data subjects, expressly referencing the Constitution. This constitutional underpinning reappears across other provisions, including sections 3(2), 25(2)(a), 28(1), (2), and (4)(c), 30(1)(f), (h), (i), 36(2), 37(2)(b) and (3), and 40(2), (3), and (7). Collectively, these provisions reaffirm that data processing activities in Nigeria must conform to constitutional principles, particularly the safeguarding of fundamental rights.

Section 3 of the Act defines its scope and outlines several exceptions to its application. Notably, section 3(2) grants competent authorities wide discretion in processing personal data for purposes such as national security, public safety, or the prevention, investigation, detection, prosecution, or adjudication of criminal offences. However, the provision is expressly conditioned on the overarching requirement that data processing must remain within the boundaries established by the Constitution.

Crucially, the exceptions under section 3(2) are subject to certain provisions found in Chapter V of the Act, including sections 24, 25, 32, and 40. These provisions impose substantive obligations on data controllers and processors to ensure that personal data is handled lawfully, fairly, and transparently, for specified and legitimate purposes, and with adequate security safeguards to prevent unauthorized access or breaches. Section 25(2)(a) further clarifies that no legitimate interest can justify data processing where it would override constitutionally guaranteed fundamental rights.

Particular procedural protections also attend the processing of sensitive personal data. Sections 28(1), (2), and (4)(c) mandate that data controllers conduct Data Privacy Impact Assessments (DPIAs) before processing data likely to pose high risks to individual rights. Where such risks persist, controllers must consult the Commission. Section 30(1)(f), (h), and (i) establishes that the processing of sensitive personal data is permissible only under stringent conditions, including the demonstration of substantial public interest and the application of lawful and proportionate safeguards designed to preserve fundamental rights.

The rights of data subjects are further bolstered by the provisions in sections 36 and 37, which confer upon them the right to object to the processing or further processing of their data, particularly in cases involving automated decision-making. Section 37(2)(b) stipulates that this right may be curtailed only where such processing is authorized by a written law containing adequate measures to safeguard the rights and interests of the data subject. Subsection (3) of the same section mandates human oversight in automated decision-making to ensure due respect for data subjects’ dignity and autonomy.

The connection between data protection and the right to private and family life, as enshrined in section 37 of the Constitution, is both direct and significant. Section 37 guarantees the privacy of citizens, their homes, correspondence, telephone conversations, and telegraphic communications. Nigerian courts have clarified the scope of this right in decisions such as Hon. Peter Nwali v. Ebonyi State Independent Electoral Commission (EBSIEC) & Ors (2014) LPELR-23682(CA) at 27-29, paras E-E per Agim, JCA (as he then was, now, JSC), where the Court of Appeal elaborated on the various dimensions of privacy protected under section 37, affirming that any intrusion inconsistent with the protected spheres of privacy constitutes a breach.

Beyond privacy, the improper collection and processing of personal data may also infringe upon the right to dignity of the human person under section 34 of the Constitution. In Nduka Eziegbo & Anor v. ASCO Investment Ltd & Anor (2022) LPELR-56864(SC) per Mohammed Lawal Garba, JSC at Pp. 6-7, paras. B-A, the Supreme Court reiterated that the constitutional guarantee of dignity encompasses not only protection against physical harm but also psychological and emotional abuse. Against this backdrop, sections 36(2), 37(2)(b), 37(3), and 40 of the Act are properly understood as mechanisms for safeguarding not just privacy but also the mental and emotional well-being of data subjects, especially in the event of data breaches.

Furthermore, the constitutional right to property, as articulated in section 44, has relevance to data protection. If personal data is regarded as the property of the data subject, then its acquisition, processing, and use must comply with the legal framework for property rights. Section 44(2)(k) of the Constitution, which allows the temporary possession of property for purposes of examination, investigation, or inquiry, mirrors the lawful exceptions provided in section 3(2) of the Act, which permit data processing by competent authorities under certain conditions. Nonetheless, both the Constitution and the Act insist on adherence to due process and the preservation of fundamental rights.

Notably, the right to fair hearing under section 36 of the Constitution intersects meaningfully with data protection. Whether in the context of administrative decisions, criminal investigations, or public health emergencies, the procedural safeguards associated with the collection and use of personal data must comply with the requirements of fair hearing. It is particularly telling that while section 45 of the Constitution permits derogations from several rights (including the right to privacy) in the interest of national security, public order, or public health, it does not authorize derogation from the right to fair hearing under section 36. This underscores the centrality of procedural justice in the realm of data protection.

In conclusion, the Nigeria Data Protection Act, 2023, while substantively establishing the contours of Nigeria’s data protection regime, draws heavily on the constitutional architecture of fundamental rights. The Act’s provisions are not designed to displace or diminish constitutional rights but to complement and operationalize them in the evolving digital landscape. The interpretive synergy between the Act and the Constitution is essential to ensuring that the protection of personal data is not only a statutory obligation but a constitutional imperative.

  • JUDICIAL AMPLIFICATION OF THE NIGERIA DATA PROTECTION ACT, 2023

The Nigeria Data Protection Act, 2023 is a new Act, having come into effect on the 12th day of June, 2023 – barely two years ago. Owing to this fact, its provisions have not been tested in the courts, especially the Court of Appeal and the Supreme Court. It is expected that these two courts will have the opportunity to pronounce on the provisions of the Act in order to provide guidance to the lower courts, especially the High Courts of the States and that of the Federal Capital Territory, Abuja and the Federal High Court.

This inadequacy notwithstanding, there are at least two judgments of the High Court on certain provisions of the Act. The Federal High Court (Kaduna Division) delivered the first judgment of a court on data protection on the 22nd November, 2024. This judgment arose out of a suit the claimant filed challenging certain provisions of the Nigeria Data Protection Commission Guidance Notice for Registration of Data Controllers and Data Processors of Major Importance published on 12 February 2024. In the case of Frank Ijege (trading under the name and style of Springfield Law Practice) v. Nigeria Data Protection Commission (Suit No: FHC/KD/CS/34/2024), the claimant, the data protection officer of a Nigerian law firm, challenged the Guidance Notice the Commission made pursuant to the exercise of its powers donated to it by the combined provisions of sections 5(d), 6(c), 44, 45 and 65 of the Act.

The claimant alleged that certain aspects of the Guidance Notice interfered with his constitutional right to privacy protected by section 37 of the Constitution. He raised several points, including the requirement for registration of data controllers or data processors who were under a fiduciary relationship with data subjects. The Guidance Notice imposed ultra high-level compliance factors on controllers or processors under the Major Data Processing-Ultra High Level (MDP-UHL) category, including the legal competence to generate revenue on a commercial scale and the need for accountability.

He also argued that the Guidance Notice required third-party agents, contractors, or vendors engaging with data subjects on behalf of MDP-UHL or MDP-EHL data controllers or data processors to register with the National Data Protection Commission (NDPC). Furthermore, it was argued that the Guidance Notice failed to specify exemptions, as required by the Nigerian Data Protection Act (NDPA).

The Court, in its judgment, held that the requirements for registration under a fiduciary relationship, ultra high-level compliance factors, and registration of third-party agents did not align with the factors outlined in Section 65 of the NDPA. The Court declared the relevant paragraphs of the Guidance Notice null and void.

The Court also held that the NDPC was required to specify exemptions in the Guidance Notice, as an exemption requires explicit clarification and cannot be conflated with exclusion. The Court ordered the NDPC to clarify the exemptions in the Guidance Notice.

The second judgment on the Act emanated from the High Court of the Federal Capital Territory, Abuja.  In the case of Incorporated Trustees of Personal Data Protection Awareness Initiative v. Nizamiya Hospital Limited (Suit Number FCT/HC/GAR/CV/187/2024)[2], the High Court of the Federal Capital Territory, Abuja coram Abubakar Hussaini Musa, J. dismissed the claims of the claimant and held that the suit was speculative on the ground that no breach of any provision of the Act had been occasioned to justify the presentation of the suit. The suit which was commenced by way of an Originating Summons sought the construction of the provisions of sections 27 and 28 of the Act which obligate a data collector to deploy privacy and to conduct data protection impact assessment.

The court, in its judgment further held inter alia that a data subject who walked into a hospital and paid the registration fee as a prelude to their data being collected and processed has consented to the collection and processing of his data and, in the absence of any evidence that the data was used for purposes other than that for which they were collected, the data collector and the data processor cannot be held liable merely because it failed to deploy privacy notices on its facility. The court also held that the installation of closed-circuit television (CCTV) was consistent with the exceptions created in section 3(2) (a), (b) and (c) of the Act.

It will be interesting to see how these two cases will fare on appeal should the dissatisfied parties proceed to challenge these decisions on appeal. This, it is hoped, will provide some clarity and binding precedents on the extent of the application of the Act.

  • CONCLUSION

The Nigeria Data Protection Act, 2023 is an expansive and ambitious piece of legislation. It makes commendably copious provisions on the protection of private data and the processing thereof. Impressively, the draftsmen of the Act consciously and strenuously seek to subject the operation of the Act to the constitutional provisions that provide for and protect fundamental rights of the citizens. Notably, the exceptions that are provided for under section 3 of the Act obligate the competent authority to act scrupulously whenever it is collecting and processing data. Significantly, too, sections 35 and 36(2) empower a data subject to withhold their consent or to object to further collection or processing of their data if they have reason to believe that the data so collected is used for purposes other than those for which they are collected.

In conclusion, it is expected that this Act will engender responsibility and due care on the part of data collectors and data processors regarding the manner they handle the personal data of data subjects. Further, it is projected that the data collectors and data processors, especially those data collectors and data processors who have been designated as competent authorities by the Act will have to be subject to the provisions of the Constitution regarding sanctity of fundamental rights in the processing of data in order to guarantee the integrity of the process.

  • RECOMMENDATIONS

We have noted earlier that the Nigeria Data Protection Act, 2023 is a comprehensive and data subject-friendly piece of legislation. This notwithstanding, there is room for improvements. Primarily, the provisions relating to a competent authority as a data collector and a data processor should be subject to the obligations contained in Chapter V of the Act in addition to the obligations stipulated in sections 24, 25, 32 and 40 of the Act. This will necessitate the amendment of section 3(2) of the Act.

The powers of the Commission as provided for under sections 3(3), 6 and 44 of the Act should be subject to oversight by the National Assembly. That way, checks adequate and reasonable in a democratic society will be assured. This, it must be pointed out, does not detract from the independence of the Commission as guaranteed under section 7 of the Act.

The entities designated as competent authorities enjoy wide berths in respect to exceptions by reason of the operation of section 3 of the Act. These sweeping exceptions are susceptible to abuse. We submit that the Act can be amended to trim down the powers in a manner that will reflect the status of Nigeria as a democratic nation and not a police state where the competent authority acts like Big Brother in George Orwell’s dystopian novel “1984”.

We further submit that the courts should demonstrate courage where need be by adopting the contra proferentem rule of statutory interpretation in constructing the provisions of the Act against the competent authority and in favour of the citizens. The contra proferentem rule of statutory interpretation simply means that if the language used by a party lends itself to some obscuration or obfuscation by imprecision, then it is the proponent that would suffer from the use of inelegant terms. See Asogwa v. Chukwu (2003) 4 NWLR (Pt. 811) 540 CA at 581, paras D-E. A variant of the rule is expressed in the Latin maxim “fortissime contra proferetes”. This doctrine posits that a statute which takes away the citizen’s right of access to the court, or encroaches on their personal or proprietory rights must be construed narrowly and strictly as against the authority seeking to rely on the statute. See N.D.I.C. v. Akahall & Sons Co. Ltd. (2004) 6 NWLR (Pt. 869) 245 CA at 272, paras D-E; Din v. Fed. A.G. (1988) 4 NWLR (Pt. 87) 147 SC; Oguejiofor v. F.R.N. (2002) 16 NWLR (Pt. 793) 262 CA, Nangibo v. Okafor (2003) 14 NWLR (Pt. 839) 78 SC.  We contend that the principle inherent in this maxim can be applied mutatis mutandis to the rights of data subjects under the Act.

We believe that these recommendations will further engender confidence and trust of the data subject in particular and Nigeria residents and citizens in general in the Act, seeing that the application of the Act is in consonance with the rule of law and the basic tenets of constitutionalism.

[1] The Nigerian Data Protection Commission is established by virtue of section 4 of the Act. Its functions are delineated in section 5 of the Act while its powers are enumerated in section 6 of the Act.

[2] Judgment in this case was delivered on the 10th of April, 2025.

______________________________________________________________________ “Enhance Legal Practice With Authoritative Reports” — Alexander Payne Offers Comprehensive Law Reports, Spanning Over A Century Of Nigerian Jurisprudence

Interested buyers are encouraged to place their orders and enquiries via: 0704 444 4777, 0704 444 4999, 0818 199 9888 Website: www.alexandernigeria.com

_______________________________________________________________________ [A MUST HAVE] Evidence Act Demystified With Recent And Contemporary Cases And Materials
“Evidence Act: Complete Annotation” by renowned legal experts Sanni & Etti.
Available now for NGN 40,000 at ASC Publications, 10, Boyle Street, Onikan, Lagos. Beside High Court, TBS. Email publications@ayindesanni.com or WhatsApp +2347056667384. Purchase Link: https://paystack.com/buy/evidence-act-complete-annotation _______________________________________________________________________ Groundbreaking Guide For Lawyers: Adigwe Publishes ‘Artificial Intelligence For Lawyers’ With Free Research eBook The book also examines Nigeria's legal ecosystem, focusing on the LPELR and NBA AI Guidelines. As a bonus, every purchase comes with a FREE eBook titled: How to Use the AI Features in LegalPedia and LawPavilion. Ohio Books Ltd praises the publication, stating: "....this is the only Nigerian book I know of on the topic." How to Order: 📞 Call, Text, or WhatsApp: 08034917063 | 07055285878 📧 Email: benadigwe1@gmail.com 🌎 Website: www.benadigwe.com Ebook Version: Access it directly online at https://selar.com/prv626 Authored by Ben Ijeoma Adigwe Esq., ACIarb (UK), LL.M, Dip. in Artificial Intelligence, Director at the Delta State Ministry of Justice, Asaba, Nigeria. _______________________________________________________________________