The Data Law Most Nigerian Businesses Have Never Actually Read

Back to Blog
The Data Law Most Nigerian Businesses Have Never Actually Read

In Part 2, we looked at how Nigerian businesses can structure recurring client relationships using documents such as Master Service Agreements (MSA) and Statements of Work (SOW). But the moment a business starts delivering those services, another relationship often exists in the background: the relationship between the business and the people whose personal data it collects and processes.

Ask a founder in Lagos or Port Harcourt whether their startup needs a Data Processing Agreement, and a common answer is some version of "that's a GDPR thing, we're not in Europe." Ask about a Business Associate Agreement and you'll often get a blank look, or "that's American, for hospitals." Both responses are understandable — DPAs and BAAs are documents most founders encountered, if at all, in US-drafted templates pulled off the internet while building their product. But both responses are also wrong in a way that matters, because Nigeria has had its own binding data protection law since June 2023, and it doesn't care whether your legal instincts came from a Silicon Valley blog post.

The Nigeria Data Protection Act 2023 is Nigeria's comprehensive data protection legislation, aimed at safeguarding the rights of individuals and setting requirements for businesses that process personal data of Nigerian citizens. It's enforced by the Nigeria Data Protection Commission, and it applies to more businesses than most founders assume. It covers any data controller or processor domiciled, resident, or operating in Nigeria, and even applies to entities outside Nigeria if they're processing the personal data of someone inside Nigeria. A Nigerian fintech using a foreign cloud provider doesn't escape the law by virtue of where the servers sit. Neither does a US company with Nigerian users escape it by virtue of being American.

Here's the layer nobody talks about: this law isn't a "someday" compliance concern for businesses that get big enough to attract regulatory attention. It has real, current teeth. The maximum penalty is 2% of annual gross revenue or ₦10,000,000, whichever is greater, with criminal penalties possible for willful violations. For a growing business, 2% of revenue is not a rounding error. And enforcement isn't hypothetical — Nigerian regulators have already investigated banks, telecom firms, consulting firms, and a number of digital lending platforms over alleged data breaches and privacy abuses, some of which became public news stories rather than quiet settlements.

So where does the DPA actually come in? Most Nigerian businesses today don't handle their customers' data entirely in-house. You're using a payment processor, a cloud hosting provider, an email marketing tool, maybe a customer support platform, maybe an outsourced developer with access to your production database. Every one of those relationships is, under Nigerian law, a data controller (you) working with a data processor (them) — and data controllers are required to ensure their processors comply with the NDPA through binding data processing agreements, with regular reviews of the processor's security measures. If you've never signed one with your hosting provider or your payment gateway, that's a gap regulators can point to, not just a theoretical best practice you skipped.

This is the part that surprises founders most: a DPA isn't primarily about protecting your company from your vendor. It's about the fact that you remain legally responsible for what your vendor does with your customers' data, even though you're not the one touching it day to day. If your email marketing tool has a breach and leaks your customer list, the NDPC's first question isn't "whose fault was the breach" — it's "did you have an agreement in place governing how that vendor was required to handle the data." No agreement, weak answer.

Now, the BAA side of this — the US healthcare-specific document — genuinely doesn't have a direct Nigerian equivalent, and it would be a mistake for a Nigerian health-tech business to just translate a HIPAA template and assume it fits. HIPAA is a US statute governing a specific category of American healthcare entities; it has no jurisdiction here. But the underlying problem a BAA solves — a vendor handling especially sensitive personal information on your behalf, requiring an extra layer of contractual protection — is not uniquely American. Under the NDPA, health data sits inside a more sensitive category of personal data than, say, someone's email address, and businesses processing it are expected to apply more stringent safeguards accordingly. The NDPA and its supporting directives treat health-related data as requiring heightened protection, consistent with global data protection norms, though the specific compliance mechanics for Nigerian health-tech businesses are still maturing as the NDPC issues sector guidance — this is not a substitute for a lawyer's read on a specific product. Practically, if you're running a Nigerian telehealth platform, a fertility app, or anything that touches patient records, you need a data processing agreement with your vendors that's written with that sensitivity in mind — closer in spirit to a BAA than a generic DPA, even if Nigerian law doesn't call it that.

The founders who get caught out here aren't usually the ones ignoring data protection entirely. They're the ones who did the responsible thing — added a privacy policy to their website, got consent checkboxes on their signup form — and stopped there, assuming that covers it. Consent has to be informed, specific, freely given, and unambiguous — that's the front-facing part users see. But the back-end part, the agreements with the processors actually handling that data once it's collected, is where most Nigerian businesses have a real, unaddressed gap. It's less visible than a privacy policy, so it gets skipped, right up until it's the thing an investor's legal team flags during due diligence, or the thing that turns a minor vendor breach into a regulatory investigation.

If there's one action worth taking after reading this: pull up the list of every third-party tool your business hands customer data to, and check whether you have a written agreement with any of them addressing how that data is protected. For most Nigerian businesses, that list is longer than the agreements are.

In Part 4, we move to the point where the stakes become even higher: when investors start putting money into the company or ownership begins to change. We'll look at the paperwork behind fundraising, including term sheets, SAFEs, board approvals and share purchase agreements.

Keep reading

Related Posts

Newsletter

Want more insights like this?

Subscribe for the latest tech news, tips, and updates from Easy World Techs.