Privacy
Freedom from arbitrary interference with your private life, correspondence and communications — the constitutional root that data protection law operationalises.
Under the Nigeria Data Protection Act 2023 you hold eight enforceable rights over the personal data organisations keep about you. This is what each one means, how to use it, and what to do when a company says no.
The Nigeria Data Protection Act (NDPA) 2023 is Nigeria’s principal data protection law. It applies to any organisation that decides how and why your personal data is processed — a bank, a hospital, a school, a fintech app, a government agency — whether or not that organisation is based in Nigeria, once it is processing the data of people in Nigeria.
The Act creates a regulator, the Nigeria Data Protection Commission (NDPC), and gives you, the data subject, a set of rights you can exercise directly. You do not need a lawyer, a court, or a fee to use them. You need an email address and a clear request.
You do not apply for these and you do not earn them. They attach to you the moment an organisation starts processing your personal data.
An organisation must tell you, in clear language and before or at the point of collection, what it is collecting, why, on what lawful basis, how long it will keep the data, and who else will see it. This is what a privacy policy is for.
In practice If you cannot find a privacy notice, or it does not answer those questions, that is itself a compliance failure.
You can ask any organisation for a copy of the personal data it holds about you, together with an explanation of where it came from, what it is being used for, and who it has been shared with. This is often called a data subject access request, or DSAR.
In practice The most powerful right you have, because it reveals what everything else applies to.
If the data held about you is wrong, out of date, or incomplete, you can require it to be corrected or completed. Inaccurate data is not a harmless clerical problem — it drives credit refusals, failed identity checks and denied claims.
In practice Ask in writing, state what is wrong and what the correct value is, and ask them to notify anyone they shared the wrong data with.
Widely known as the right to be forgotten. You can ask for your data to be deleted where there is no longer a lawful reason to keep it — for example when you withdraw consent, when the original purpose is finished, or when the data was processed unlawfully.
In practice Not absolute. An organisation may keep data it is legally required to retain, such as tax and transaction records.
You can require an organisation to pause what it is doing with your data while a dispute is resolved — for instance while it verifies an accuracy challenge, or while it considers an objection you have raised. The data may be stored, but not otherwise used.
In practice Useful as a holding measure when erasure is contested but you want the processing stopped now.
Where processing is based on your consent or on a contract and is carried out by automated means, you can ask to receive your data in a structured, commonly used, machine-readable format — and to have it transmitted to another provider.
In practice This is the right that makes switching banks, insurers or platforms possible without starting from zero.
You can object to processing carried out on the basis of legitimate interest or public interest, and the organisation must stop unless it can show compelling grounds that override your rights. For direct marketing there is no balancing exercise: object, and it must stop.
In practice “Unsubscribe” is the everyday version of this right. It is not a favour being done for you.
Where a decision with legal or similarly significant effect is made about you by automated means alone — an algorithmic loan refusal, an automated fraud block, an AI screening tool — you have the right not to be subject to it on that basis alone, and to ask for meaningful human review.
In practice Increasingly the sharpest right in an economy running on scoring models and AI systems.
Alongside these, you may withdraw consent at any time where consent was the lawful basis, and you may lodge a complaint with the NDPC. Withdrawing consent does not make earlier processing unlawful — it stops it going forward.
A valid request is a short email. It does not need legal language, and it does not need to explain itself.
Look for the Data Protection Officer or privacy contact in the organisation’s privacy policy. If there is none, use the general support or legal address and say the request is a data protection matter.
Name it. “I am making a data subject access request” or “I am exercising my right to erasure”. This starts the clock and removes any ambiguity.
Give enough to let them find your record — the email or account number they know you by. They may verify your identity, but they may not demand excessive documentation as a delaying tactic.
Send it by email so there is a timestamp. If you later complain to the NDPC, the date of your request is the first thing you will be asked for.
Subject: Data Subject Access Request
Dear Data Protection Officer,
I am making a data subject access request under the Nigeria Data Protection Act 2023.
Please provide a copy of all personal data you hold about me, together with the purposes of processing, the lawful basis relied on, the source of the data, the categories of recipients it has been disclosed to, and your retention period.
You can identify my records by the email address from which this message is sent.
Please confirm receipt of this request.
Yours faithfully,
[Your name]
[Date]
Swap the second paragraph for the right you are using — rectification, erasure, restriction, portability or objection — and say plainly what you want done.
If an organisation refuses your request, gives you a partial answer, demands an unjustified fee, or simply never replies, you can escalate. You do not need the organisation’s permission and you do not need a lawyer.
Data protection is one part of a larger set of freedoms that apply online exactly as they do offline.
Freedom from arbitrary interference with your private life, correspondence and communications — the constitutional root that data protection law operationalises.
The specific, enforceable rules governing how personal data may be collected and used. The NDPA 2023 is Nigeria’s expression of it.
The ability to participate in digital life at all — connectivity, affordability, and services that do not exclude people by design.
Speaking, organising and assembling online, and the limits on surveillance and takedown that make those meaningful.
Not being sorted, priced, scored or refused by an automated system on grounds that would be unlawful if a human applied them.
A real route to challenge a decision and obtain a remedy — a regulator to complain to, and consequences when the law is broken.
The words that appear in every privacy policy, in the order you are likely to meet them.
Under the Nigeria Data Protection Act 2023 you have the right to be informed about processing, to access a copy of your data, to have it corrected, to have it erased, to restrict processing, to receive it in a portable format, to object to processing, and not to be subject to a solely automated decision with significant effect. You may also withdraw consent at any time and complain to the Nigeria Data Protection Commission.
Send a written request — email is sufficient — to the organisation’s Data Protection Officer or privacy contact, stating that you are making a data subject access request under the NDPA 2023. Ask for a copy of your personal data, the purposes of processing, the lawful basis, the source, the recipients and the retention period. Keep a dated copy of what you sent.
Yes, in the form of the right to erasure. You can require deletion where there is no longer a lawful reason to hold the data — for example after you withdraw consent or once the purpose is complete. The right is not absolute: an organisation may retain data it is legally obliged to keep, such as tax and transaction records, or data needed to establish or defend a legal claim.
Normally no. Exercising your rights is generally free. A fee may only be considered where a request is manifestly unfounded or excessive, and an organisation cannot use a fee as a barrier to a genuine request.
Chase once in writing, referencing your original request and its date, and ask for an internal review. If you still receive no adequate response, lodge a complaint with the Nigeria Data Protection Commission at ndpc.gov.ng, enclosing your original request, any reply, and the dates. Failure to respond is itself a compliance failure you can complain about.
Data privacy, and the data protection law that enforces it, governs how personal data about you may be collected and used. Digital rights are broader: they include privacy and data protection, but also access and inclusion, freedom of expression and association online, non-discrimination by automated systems, and the right to an effective remedy. Data protection is the most directly enforceable slice of digital rights.
It can. The NDPA 2023 applies to processing carried out in Nigeria and, importantly, to organisations outside Nigeria that process the personal data of people in Nigeria. A foreign platform with Nigerian users is not automatically outside the Act’s reach.
Not without safeguards. Where a decision produces legal effects or similarly significant consequences for you — a credit refusal, an insurance price, an automated account block — and is based solely on automated processing, you have the right not to be subject to it on that basis alone and to request meaningful human review of the outcome.
If you are an organisation receiving these requests — or an individual who has hit a wall — we do this every day. The first conversation is free.
This page is general information about Nigerian data protection law, not legal advice on your situation, and reading it does not create a solicitor–client relationship. For advice you can rely on, speak to us directly.