New directive mandates the appointment of Data Protection Officers, compliance audits, and dedicated funding as Nigeria intensifies efforts to safeguard personal data and accelerate digital governance…….
The Federal Government has directed all Ministries, Departments and Agencies (MDAs) to fully comply with Nigeria’s data protection laws, introducing a series of mandatory measures aimed at strengthening the handling of personal information across the public sector.
The directive was conveyed through Circular No. 59805/S.I/74, dated July 27, 2026, and signed by the Secretary to the Government of the Federation (SGF), George Akume. According to a statement issued by Babatunde Bamigboye, Head of Legal, Enforcement and Regulations at the Nigeria Data Protection Commission (NDPC), the move forms part of the government’s broader strategy to deepen trust in digital governance and prepare Nigeria for the opportunities of the Fourth Industrial Revolution.
The circular reminds government institutions of President Bola Tinubu’s position that “data is the new oil,” underscoring the growing importance of data as a strategic national asset. It instructs MDAs to collect, manage and protect personal information in line with the provisions of the Nigeria Data Protection Act (NDP Act), 2023.
Under the new directive, every MDA is expected to appoint a suitably qualified Data Protection Officer (DPO) responsible for overseeing compliance with data protection obligations and advising management on the lawful processing of personal data. The names and contact details of designated officers must also be submitted to the NDPC for registration and official documentation.
The Federal Government further instructed agencies to engage licensed Data Protection Compliance Organisations (DPCOs), where necessary, to support compliance efforts and conduct mandatory data protection audits.
In addition, MDAs have been asked to make adequate budgetary provisions for data protection initiatives, including staff training, public awareness programmes, deployment of appropriate technological safeguards and periodic compliance assessments.
The circular also requires government institutions to submit all statutory Data Protection Compliance Audit Returns and other mandatory reports to the NDPC within timelines prescribed by law.
To reinforce accountability, the government stated that Permanent Secretaries, Accounting Officers and Chief Executive Officers of all MDAs will be personally responsible for ensuring their organisations comply with both the circular and the provisions of the Nigeria Data Protection Act.
Reacting to the directive, the National Commissioner and Chief Executive Officer of the NDPC, Dr. Vincent Olatunji, described the circular as a strong demonstration of the Federal Government’s commitment to protecting the privacy rights and fundamental freedoms of Nigerians.
He added that strengthening data accountability remains essential to achieving the administration’s key development priorities and disclosed that the Commission has established a regulatory clinic to provide technical support to MDAs as they work towards full compliance.
The latest directive signals a renewed push by the Federal Government to institutionalise responsible data governance across the public sector, as Nigeria continues to expand its digital economy while placing greater emphasis on privacy, accountability and public confidence in government data systems.