Professional Data Protection Services  |  Nigeria’s trusted digital governance partner   Book a free Consultation →
Know Your Rights

Your Data Privacy and
Digital Rights in Nigeria

Under the Nigeria Data Protection Act 2023 you hold eight enforceable rights over the personal data organisations keep about you. This is what each one means, how to use it, and what to do when a company says no.

The Short Version

Personal data is yours. The law just says so out loud.

The Nigeria Data Protection Act (NDPA) 2023 is Nigeria’s principal data protection law. It applies to any organisation that decides how and why your personal data is processed — a bank, a hospital, a school, a fintech app, a government agency — whether or not that organisation is based in Nigeria, once it is processing the data of people in Nigeria.

The Act creates a regulator, the Nigeria Data Protection Commission (NDPC), and gives you, the data subject, a set of rights you can exercise directly. You do not need a lawyer, a court, or a fee to use them. You need an email address and a clear request.

Data Subject Rights

Eight rights you already have

You do not apply for these and you do not earn them. They attach to you the moment an organisation starts processing your personal data.

  1. 01

    The right to be informed

    An organisation must tell you, in clear language and before or at the point of collection, what it is collecting, why, on what lawful basis, how long it will keep the data, and who else will see it. This is what a privacy policy is for.

    In practice If you cannot find a privacy notice, or it does not answer those questions, that is itself a compliance failure.

  2. 02

    The right of access

    You can ask any organisation for a copy of the personal data it holds about you, together with an explanation of where it came from, what it is being used for, and who it has been shared with. This is often called a data subject access request, or DSAR.

    In practice The most powerful right you have, because it reveals what everything else applies to.

  3. 03

    The right to rectification

    If the data held about you is wrong, out of date, or incomplete, you can require it to be corrected or completed. Inaccurate data is not a harmless clerical problem — it drives credit refusals, failed identity checks and denied claims.

    In practice Ask in writing, state what is wrong and what the correct value is, and ask them to notify anyone they shared the wrong data with.

  4. 04

    The right to erasure

    Widely known as the right to be forgotten. You can ask for your data to be deleted where there is no longer a lawful reason to keep it — for example when you withdraw consent, when the original purpose is finished, or when the data was processed unlawfully.

    In practice Not absolute. An organisation may keep data it is legally required to retain, such as tax and transaction records.

  5. 05

    The right to restrict processing

    You can require an organisation to pause what it is doing with your data while a dispute is resolved — for instance while it verifies an accuracy challenge, or while it considers an objection you have raised. The data may be stored, but not otherwise used.

    In practice Useful as a holding measure when erasure is contested but you want the processing stopped now.

  6. 06

    The right to data portability

    Where processing is based on your consent or on a contract and is carried out by automated means, you can ask to receive your data in a structured, commonly used, machine-readable format — and to have it transmitted to another provider.

    In practice This is the right that makes switching banks, insurers or platforms possible without starting from zero.

  7. 07

    The right to object

    You can object to processing carried out on the basis of legitimate interest or public interest, and the organisation must stop unless it can show compelling grounds that override your rights. For direct marketing there is no balancing exercise: object, and it must stop.

    In practice “Unsubscribe” is the everyday version of this right. It is not a favour being done for you.

  8. 08

    Rights around automated decisions

    Where a decision with legal or similarly significant effect is made about you by automated means alone — an algorithmic loan refusal, an automated fraud block, an AI screening tool — you have the right not to be subject to it on that basis alone, and to ask for meaningful human review.

    In practice Increasingly the sharpest right in an economy running on scoring models and AI systems.

Alongside these, you may withdraw consent at any time where consent was the lawful basis, and you may lodge a complaint with the NDPC. Withdrawing consent does not make earlier processing unlawful — it stops it going forward.

Making a Request

How to actually use a right

A valid request is a short email. It does not need legal language, and it does not need to explain itself.

  1. Find the right address

    Look for the Data Protection Officer or privacy contact in the organisation’s privacy policy. If there is none, use the general support or legal address and say the request is a data protection matter.

  2. Say which right you are using

    Name it. “I am making a data subject access request” or “I am exercising my right to erasure”. This starts the clock and removes any ambiguity.

  3. Identify yourself, no more than needed

    Give enough to let them find your record — the email or account number they know you by. They may verify your identity, but they may not demand excessive documentation as a delaying tactic.

  4. Keep a dated copy

    Send it by email so there is a timestamp. If you later complain to the NDPC, the date of your request is the first thing you will be asked for.

Copy this

A request that works

Subject: Data Subject Access Request

Dear Data Protection Officer,

I am making a data subject access request under the Nigeria Data Protection Act 2023.

Please provide a copy of all personal data you hold about me, together with the purposes of processing, the lawful basis relied on, the source of the data, the categories of recipients it has been disclosed to, and your retention period.

You can identify my records by the email address from which this message is sent.

Please confirm receipt of this request.

Yours faithfully,
[Your name]
[Date]

Swap the second paragraph for the right you are using — rectification, erasure, restriction, portability or objection — and say plainly what you want done.

If You Are Refused

Silence is also an answer — and it is a complainable one

If an organisation refuses your request, gives you a partial answer, demands an unjustified fee, or simply never replies, you can escalate. You do not need the organisation’s permission and you do not need a lawyer.

  1. Chase once, in writing. Reference your original request and its date.
  2. Ask for their internal review. Larger organisations must have a route for this.
  3. Complain to the NDPC. Take your original request, their response or the absence of one, and the dates.
Nigeria Data Protection Commission
Wider Context

Where privacy rights sit inside digital rights

Data protection is one part of a larger set of freedoms that apply online exactly as they do offline.

Privacy

Freedom from arbitrary interference with your private life, correspondence and communications — the constitutional root that data protection law operationalises.

Data protection

The specific, enforceable rules governing how personal data may be collected and used. The NDPA 2023 is Nigeria’s expression of it.

Access and inclusion

The ability to participate in digital life at all — connectivity, affordability, and services that do not exclude people by design.

Expression and association

Speaking, organising and assembling online, and the limits on surveillance and takedown that make those meaningful.

Non-discrimination

Not being sorted, priced, scored or refused by an automated system on grounds that would be unlawful if a human applied them.

Redress

A real route to challenge a decision and obtain a remedy — a regulator to complain to, and consequences when the law is broken.

Glossary

The vocabulary, defined

The words that appear in every privacy policy, in the order you are likely to meet them.

Personal data
Any information relating to an identified or identifiable living individual — a name, a phone number, an email address, a device identifier, a location trail, or any combination that singles a person out.
Data subject
The living individual the personal data is about. If it is your data, you are the data subject, and the rights on this page are yours.
Data controller
The organisation that decides why and how personal data is processed. The controller carries the legal duties and answers to the regulator.
Data processor
A party that processes personal data on the controller’s instructions — a cloud host, a payroll bureau, an email provider — and may not use it for its own purposes.
Processing
Practically anything done with personal data: collecting, recording, storing, altering, consulting, sharing, combining, restricting, erasing or destroying it.
Lawful basis
The legal ground relied on to process data. Under the NDPA these include consent, performance of a contract, a legal obligation, vital interests, public interest and legitimate interest. No basis, no processing.
A freely given, specific, informed and unambiguous indication of agreement. Pre-ticked boxes, bundled permissions and take-it-or-leave-it terms do not qualify, and consent can always be withdrawn.
NDPA 2023
The Nigeria Data Protection Act 2023, Nigeria’s principal data protection statute. It establishes the NDPC, sets the principles of lawful processing, and creates the data subject rights described on this page.
NDPC
The Nigeria Data Protection Commission — the regulator that supervises compliance, receives complaints from data subjects, and enforces the NDPA.
Data Protection Officer (DPO)
The person responsible for advising an organisation on its data protection obligations, monitoring compliance, and acting as the contact point for data subjects and the regulator.
Data Protection Impact Assessment (DPIA)
A structured assessment carried out before high-risk processing begins, to identify the risks to individuals and the measures that will reduce them.
Records of Processing Activities (ROPA)
The internal register of what personal data an organisation holds, why, where it came from, who it is shared with and how long it is kept. The evidence base for every other obligation.
Right to be forgotten
The common name for the right to erasure — the right to have personal data deleted once there is no longer a lawful reason to retain it.
Privacy by design
Building data protection into a system from the outset — collecting the minimum, defaulting to the most protective setting — rather than bolting a policy on after launch.
Data localisation
A requirement that certain categories of data be stored or processed within a country’s borders, usually on sovereignty, security or supervisory grounds.
Cross-border transfer
Sending personal data outside Nigeria. Permitted where appropriate safeguards apply, such as contractual clauses or an adequacy determination.
Personal data breach
A security failure leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Notifiable to the NDPC, and often to the affected individuals.
Privacy-enhancing technologies (PETs)
Techniques that allow data to be used while limiting exposure — anonymisation, pseudonymisation, differential privacy, federated learning and encryption in use.
Questions

Frequently asked

Under the Nigeria Data Protection Act 2023 you have the right to be informed about processing, to access a copy of your data, to have it corrected, to have it erased, to restrict processing, to receive it in a portable format, to object to processing, and not to be subject to a solely automated decision with significant effect. You may also withdraw consent at any time and complain to the Nigeria Data Protection Commission.

Send a written request — email is sufficient — to the organisation’s Data Protection Officer or privacy contact, stating that you are making a data subject access request under the NDPA 2023. Ask for a copy of your personal data, the purposes of processing, the lawful basis, the source, the recipients and the retention period. Keep a dated copy of what you sent.

Yes, in the form of the right to erasure. You can require deletion where there is no longer a lawful reason to hold the data — for example after you withdraw consent or once the purpose is complete. The right is not absolute: an organisation may retain data it is legally obliged to keep, such as tax and transaction records, or data needed to establish or defend a legal claim.

Normally no. Exercising your rights is generally free. A fee may only be considered where a request is manifestly unfounded or excessive, and an organisation cannot use a fee as a barrier to a genuine request.

Chase once in writing, referencing your original request and its date, and ask for an internal review. If you still receive no adequate response, lodge a complaint with the Nigeria Data Protection Commission at ndpc.gov.ng, enclosing your original request, any reply, and the dates. Failure to respond is itself a compliance failure you can complain about.

Data privacy, and the data protection law that enforces it, governs how personal data about you may be collected and used. Digital rights are broader: they include privacy and data protection, but also access and inclusion, freedom of expression and association online, non-discrimination by automated systems, and the right to an effective remedy. Data protection is the most directly enforceable slice of digital rights.

It can. The NDPA 2023 applies to processing carried out in Nigeria and, importantly, to organisations outside Nigeria that process the personal data of people in Nigeria. A foreign platform with Nigerian users is not automatically outside the Act’s reach.

Not without safeguards. Where a decision produces legal effects or similarly significant consequences for you — a credit refusal, an insurance price, an automated account block — and is based solely on automated processing, you have the right not to be subject to it on that basis alone and to request meaningful human review of the outcome.

Need this handled properly?

If you are an organisation receiving these requests — or an individual who has hit a wall — we do this every day. The first conversation is free.

This page is general information about Nigerian data protection law, not legal advice on your situation, and reading it does not create a solicitor–client relationship. For advice you can rely on, speak to us directly.

Done