News
Nigeria’s Data Regulator Collects ₦7.2 Billion: What It Means
The NDPC has completed 246 investigations and plans to strengthen enforcement throughout 2026. For businesses in Nigeria, registration is now an important compliance requirement, not just a formality.
Prem Kumar Dvivedi · 12 tháng 9, 2026
The Nigeria Data Protection Commission (NDPC) is taking a stronger approach to enforcing data protection. The Commission has concluded 246 investigations into data protection and privacy breaches and has taken 11 major enforcement actions. Its enforcement activity has also generated billions of naira in compliance-related revenue. More than 38,000 organisations are now registered as data controllers or processors of major importance.
One notable case involved MultiChoice Nigeria. In July 2025, the NDPC imposed a ₦766.2 million penalty after finding issues with the company's data processing practices. The case raised concerns about how the company processed and transferred subscribers' personal information.
Source: BusinessDay — NDPC concludes 246 investigations, generates ₦5.2bn revenue
These actions show that data protection is becoming a more important compliance issue for organisations operating in Nigeria.
NDPC Tightens Data Protection Oversight
The NDPC has continued to increase its focus on organisations that process personal information. In 2025, the Commission issued compliance notices to more than 1,300 organisations across sectors such as banking, insurance, pensions and gaming.
The notices required organisations to provide evidence of compliance with the Nigeria Data Protection Act (NDPA). This included proof of registration, appointments of data protection officers, and compliance audit returns. Organisations were also asked to show that they had appropriate technical and organisational measures to protect personal information.
The Commission has indicated that enforcement will remain an important part of its work. This means organisations cannot treat data protection registration and compliance as simple paperwork.
Why Data Protection Compliance Matters?
For many businesses, personal data is part of everyday operations. Organisations collect information from customers, employees, suppliers and other stakeholders. They may use this information for payments, marketing, customer support, recruitment and other business activities.
The NDPC's recent actions show that organisations need to understand what personal information they hold and how they use it.
A business should know why it collects each type of personal data. It should also understand who can access the information, how long it is kept, and what happens if it is exposed.
Organisations also need clear procedures for handling data breaches and responding to privacy risks. These processes should not exist only on paper. Employees should understand their responsibilities, and organisations should keep evidence that they review the controls.
NDPC Enforcement Could Bring Heavy Financial Penalties
The Nigeria Data Protection Act allows the NDPC to impose administrative penalties for data protection violations. For major data controllers and processors, penalties can reach ₦10 million or 2% of annual gross revenue, whichever is higher, depending on the applicable circumstances and category.
Source: AllAfrica — Nigeria targets 1,368 firms in landmark data protection crackdown
The MultiChoice case shows that enforcement can result in penalties much higher than the basic statutory figure when the applicable calculation links to an organisation's revenue.
The NDPC has also taken action against other large organisations. In 2024, the NDPC fined Fidelity Bank ₦555.8 million over findings that included processing personal data without informed consent and issues involving cookies and third-party processors.
These cases show why organisations should address privacy risks before they become regulatory problems.
How ISO/IEC 27701 Can Support Data Protection
Organisations can use recognised management system frameworks to bring greater structure to their privacy and information security practices.
ISO/IEC 27701 provides a framework for establishing and improving a Privacy Information Management System (PIMS). It helps organisations manage privacy responsibilities, identify personal information processing activities, and establish controls around handling personal data.
ISO/IEC 27001 can complement this approach by helping organisations manage information security risks through an Information Security Management System (ISMS).
Together, these standards can help organisations create a more organised approach to privacy and information security. However, ISO certification does not automatically mean that an organisation complies with every requirement of Nigerian data protection law. Organisations must still assess and address their specific obligations under the NDPA and applicable regulatory requirements.
NDPC Pushes Organisations Beyond Data Protection Paperwork
Nigeria's recent enforcement activity sends a clear message to organisations that process personal information. Registration, audit returns and policies are only part of the compliance process. Organisations also need to show that their privacy and security controls work in practice.
The growing number of investigations and enforcement actions means that businesses should review their existing systems rather than wait for a compliance notice.
MSCi provides ISO consultancy services to help organisations assess their management systems, identify gaps and prepare for ISO certification. MSCi does not issue ISO certificates or operate as a certification body. Its role is to support organisations in building and improving systems that are aligned with relevant ISO requirements.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13 tháng 9, 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13 tháng 9, 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 tháng 9, 2026
