FG Orders Nigerian Agencies to Comply with Data Protection Act
Translated from English, summarized and contextualized by DistantNews.
At a glance
- All Nigerian Ministries, Departments, and Agencies (MDAs) must comply with the Nigeria Data Protection Act, 2023.
- This directive aims to strengthen data governance and build public trust in government institutions.
- MDAs are required to appoint Data Protection Officers and allocate budgets for compliance activities.
The Nigerian Federal Government has mandated all its Ministries, Departments, and Agencies (MDAs) to strictly adhere to the Nigeria Data Protection Act, 2023. This directive, issued via a circular from the Secretary to the Government of the Federation, Senator George Akume, is part of a broader effort to enhance responsible data governance and bolster public confidence in government operations.
Data is the new oil: its value increases the more it is refined and responsibly shared.
President Bola Tinubu's administration emphasizes the critical importance of data, likening it to "the new oil." The directive instructs government institutions to rigorously capture and safeguard information in accordance with the NDP Act. This includes ensuring full compliance with the Act, its associated regulations, guidelines, and directives issued by the Nigeria Data Protection Commission (NDPC).
I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023 (NDP Act).
To facilitate compliance, MDAs are required to appoint qualified Data Protection Officers (DPOs) responsible for overseeing data processing activities and advising management on lawful practices. The names and contact details of these DPOs must be communicated to the NDPC for registration. Furthermore, MDAs are encouraged to engage licensed Data Protection Compliance Organisations (DPCOs) when necessary to support compliance efforts and conduct statutory audits.
MDAs are to engage licensed Data Protection Compliance Organisations (DPCOs, where required, to facilitate compliance with the NDP Act and support the conduct of statutory compliance audits.
Adequate budgetary allocation for data protection compliance is also mandated, covering areas such as capacity building, awareness programs, technical safeguards, and periodic audits. Permanent Secretaries, Accounting Officers, and Chief Executive Officers of MDAs will be held personally accountable for ensuring their institutions comply with both the circular and the NDP Act. The NDPC's National Commissioner, Dr. Vincent Olatunji, commended the administration's commitment to protecting citizens' privacy and fundamental freedoms, noting that data accountability is crucial for achieving the government's key priorities.
Permanent Secretaries, Accounting Officers and Chief Executive Officers of MDAs would be personally responsible for ensuring institutional compliance with both the circular and the provisions of the NDP Act.
Originally published by The Punch in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.