The short answer
The Nigeria Data Protection Act 2023 (NDPA), the main data protection law, is enforced by the Nigeria Data Protection Commission (NDPC). When a personal data breach involves data under your control, the main obligations are:
- Notify the NDPC within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of individuals.
- Tell affected individuals without undue delay where the breach is likely to result in a high risk to them.
- Notify other parties who need to know or who may be able to reduce the harm. If you are a data processor, that starts with the controller on whose behalf you hold the data. Others may include law enforcement, a payment processor or your sector regulator.
- Keep a record of every breach, including breaches you decide not to report, with your reasoning.
Operators of critical national information infrastructure have further incident-reporting duties under the Cybercrimes Act (as amended) and to ngCERT, the national computer emergency response team.
The NDPC can take enforcement action, including penalties, for failures to comply with the NDPA. We do not state specific amounts here: check the current Act and the Commission's directives, including the General Application and Implementation Directive (GAID) 2025, for the details.
This article summarises the framework in general terms. It is general information, not legal advice. Sector rules may impose different or additional obligations (see below).
What counts as a breach
In general terms, a personal data breach is a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Common examples:
- A ransomware attack or intrusion that exposes customer or employee records.
- An email sent to the wrong recipient with personal data attached.
- A lost or stolen laptop, phone or USB drive.
- A cloud folder or database left publicly accessible.
- An employee viewing records without a business reason.
The risk test
The NDPA ties notification to risk to the rights and freedoms of individuals. Harm to individuals can include financial loss, fraud and identity theft, damage to reputation or relationships, loss of employment or business opportunities, discrimination, distress and, in some cases, physical harm.
To decide whether a breach is likely to create risk, and whether that risk is high, consider two main factors:
- Sensitivity of the data. Health, financial and identity data are generally sensitive, and the NDPA treats health data as sensitive personal data. Sensitivity also depends on context. A list of names can be sensitive if it reveals, for example, membership in a support group.
- Probability of misuse. Consider who obtained the data, how long it was exposed, whether there is evidence of malicious intent, whether it was encrypted or otherwise unusable, and whether harm has already occurred.
Document your reasoning either way. The record you keep should explain enough for the NDPC or your own legal adviser to verify your assessment.
Two hypothetical lost laptops. In the first case, the laptop had full-disk encryption enabled, the key was not stored with it, and it was reported lost within an hour. The organisation might reasonably conclude that the probability of misuse is low, record the breach and its assessment, and not report. In the second case, the laptop was unencrypted and held a spreadsheet of client names, dates of birth and banking details. The data is sensitive and readily usable, so a risk to individuals, probably a high one, is likely: notify the NDPC within the 72-hour window, tell the clients and consider notifying their banks. Your own assessment will depend on your facts.
Notifying the NDPC
The 72 hours run from when you become aware of the breach. You do not need to wait until the investigation is complete: notify within the window with what you know, and update the NDPC as you learn more. Check the NDPC's website (NDPC) for its current notification channel and any form it requires.
In general terms, the notification should cover:
- A description of the nature of the breach and, if known, its cause.
- The date or period of the breach, or an approximation.
- The categories and approximate number of individuals affected, and the categories and approximate number of records involved.
- The likely consequences of the breach for individuals.
- The measures taken or proposed to address the breach and reduce its effects.
- The name and contact details of your data protection officer or another person who can answer questions.
If you cannot meet the 72-hour window in full, do not delay the notification: report promptly and explain what is still unknown.
Notifying individuals
Where the breach is likely to result in a high risk to individuals, tell them without undue delay. The message must be clear enough for people to understand the significance of the breach and protect themselves. It should include:
- What happened, and when (or approximately when).
- What personal data was involved.
- What your organisation has done to reduce the risk of harm.
- What individuals can do to reduce their own risk, for example changing passwords or watching their accounts.
- Contact information for questions.
Notify people directly (in person, by phone, SMS, email or letter) in most cases. A public notice may be appropriate only in limited situations, for example when direct notification would be impossible or disproportionate, or when you do not have contact details. Ask your legal adviser before relying on it.
Notifying other organisations
If another organisation may be able to reduce the risk of harm, or needs to know under its own rules, tell it. Examples include law enforcement, a bank or payment processor that can monitor or block accounts, a service provider whose system was involved, and your sector regulator. Banks and payment service providers should check the Central Bank of Nigeria's incident-reporting requirements, and operators of critical national information infrastructure should report to ngCERT as well (ngCERT).
Keeping breach records
Keep a record of every personal data breach, whether or not it met the reporting threshold. The record shows the NDPC, an auditor or your insurer how you assessed and handled each incident. The NDPA and the NDPC's directives do not give a retention period that we can state here, so agree one with your legal adviser and keep the register for at least as long as that period.
Breach record template
- Date or estimated date of the breach, and date discovered
- General description of the circumstances and cause
- Nature of the personal data involved
- Number of individuals and records affected (or estimate)
- Risk assessment and reasoning, including whether the risk is high
- Whether reported to the NDPC, and when
- Whether individuals were notified, how and when
- Other organisations notified
- Containment and corrective actions taken
Service providers and accountability
If a breach happens at a service provider that holds personal data on your behalf, such as a cloud host, payroll provider or IT provider, you generally remain accountable for the data as controller. Your contracts should require providers to tell you promptly about breaches and to cooperate with your assessment and notifications, and fast enough for you to meet the 72-hour window. If you are the processor, tell the controller without delay.
Sector-specific rules
The NDPA is not the only framework that may apply. Banks and payment service providers must also follow the Central Bank of Nigeria's cybersecurity framework and guidelines. Insurers, pension operators and capital-market operators answer to NAICOM, PenCom and SEC Nigeria respectively. Health information is sensitive personal data under the NDPA, and the National Health Act 2014 adds confidentiality duties. Public institutions have their own rules, including NITDA guidelines. Check which rules apply to each type of data you hold, and plan for more than one notification if necessary.
A response sequence to prepare in advance
- Contain the breach: revoke access, isolate systems, recover devices or data where possible.
- Preserve evidence and start a timeline, noting when you became aware of the breach, because the 72 hours start there.
- Assess what data was involved, whose, and the risk to individuals.
- Decide and document whether reporting and notification are required under each applicable law or rule.
- Report and notify within the deadline, and notify organisations that can reduce harm.
- Record the breach, even if not reported.
- Review what failed and fix it.
Assign an owner for each step before an incident happens, make sure someone is reachable outside office hours and when the power or internet at the office is down, and rehearse the sequence with a tabletop exercise.
Limitations
This guide summarises the framework in general terms as of its review date. It does not cover every scenario or sector rule, and it is not legal advice. The NDPC's directives and guidance are updated from time to time, so check the current versions. For a specific incident, involve legal counsel early. To prepare policies, a breach register and a response plan before you need them, see our privacy and compliance readiness service.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Nigeria Data Protection Act 2023, GAID 2025 and breach notification guidance, Nigeria Data Protection Commission
- National Computer Emergency Response Team (ngCERT), ngCERT
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.