Skip to main content

Aluko & Oyebode

Search by keywords

Issuance of the Nigeria Data Protection Act – General Application and Implementation Directive 2025 (GAID)

NITDA Imposes Fines for Data Breach

On Thursday, 20 March 2025, the Nigeria Data Protection Commission (the “Commission”) issued the Nigeria Data Protection Act – General Application and Implementation Directive  (“GAID”) pursuant to its powers under the Nigeria Data Protection Act 2023 (“NDPA”). The GAID seeks to enhance the understanding, implementation and effectiveness of the NDPA and is divided into 52 Articles and 10 Schedules.

By virtue of Article 3(3) of the GAID, the Nigeria Data Protection Regulation (NDPR) 2019 (and consequently the NDPR Implementation Framework 2020 ) will cease to be operational as data protection regulation. All acts carried out during their subsistence, however, will remain valid. The GAID will become effective on 19 September 2025.

Some of the highlights of the GAID include:

  • Compliance Measures by Data Controllers and Processors (DCs/DPs): The GAID lists out twenty-three (23) key measures to be undertaken by DCs/DPs in order to comply with the provisions of the NDPA such as the registration as a DC/DP of major importance (“DCPMIs”); conduct of annual compliance audit by DCPMIs of Ultra-High Level and Extra-High Level before the 31st of March each year; maintenance of semi-annual data protection reports which are to contain an analysis of data processing within six (6) months and so on.
  • Compliance Audit Returns: Issuance of a new template for the conduct of annual compliance audits and increase in the filing fees up to NGN1,000,000.00 (One Million Naira) for DCPMIs of Ultra High-Level processing the Personal Data of more than 50,000 Data Subjects.
  • Assessment on the Reliance on Each Basis of Legal Processing: The GAID contains provisions on circumstances that each lawful basis of processing- consent, contract, vital interest, public interest and legitimate interest can be relied on and any attending obligations such as the requirement to conduct a Legitimate Interest Assessment for the reliance on legitimate interest for processing.
  • Introduction of the Data Subjects’ Notice to Address Grievance (“SNAG”): Introduction of the SNAG, a tool through which Data Subjects can access the instrumentality of the Commission to demand remedial action and address grievance from Data Controllers and Processors without first writing to the Commission.

Follow us on the “GAID Compliance Series” as we explore and analyse key provisions of the GAID over the coming weeks.

For any enquiries or clarification, please reach out to us at ao@aluko-oyebode.com.ng for further details.

 

AUTHORS

No data was found

See More

Related Insights

check

Registration Successful

Please check the confirmation email sent to your email address

image 995

Google Calendar

icons8-outlook-calendar 1

Outlook.com

image 996

Apple Calender

Registration Successful

You’re all set. Your registration for the event has been received and confirmed. We’re excited to have you join us.

Issuance of the Nigeria Data Protection Act – General Application and Implementation Directive 2025 (GAID)