Tuesday, August 4, 2026
HomeBUSINESSFG orders MDAs to fully comply with data protection law

FG orders MDAs to fully comply with data protection law

The Federal Government has directed all Ministries, Departments and Agencies, MDAs, to fully comply with the provisions of the Nigeria Data Protection Act, NDP Act, 2023, in a renewed push to strengthen responsible data governance, safeguard citizens’ personal information and deepen public confidence in government institutions.

Under the new directive, all MDAs are required to appoint suitably qualified Data Protection Officers, DPOs, who will oversee compliance with the Act and provide management with guidance on lawful data processing.

According to a statement issued on Tuesday by the Head of Legal, Enforcement and Regulations at the Nigeria Data Protection Commission, NDPC, Babatunde Bamigboye, the directive is contained in Circular No. 59805/S.1/74, dated July 27, 2026, and signed by the Secretary to the Government of the Federation, SGF, Senator George Akume.

Bamigboye said circular draws attention to President Bola Tinubu’s directive that government institutions must rigorously collect, responsibly manage and protect data in line with the country’s data protection framework, describing data as “the new oil” whose value grows when properly refined and securely shared.

The circular mandates every Federal MDA to ensure full compliance with the Nigeria Data Protection Act, relevant regulations, guidelines and directives issued by the Nigeria Data Protection Commission, NDPC.

It also places responsibility on Permanent Secretaries, Accounting Officers and Chief Executive Officers of government agencies to ensure their institutions strictly adhere to the provisions of the law, warning that they will be held personally accountable for compliance.

The statement said the compliance framework is aimed at promoting public trust through data-driven governance while ensuring that personal information handled by government institutions is processed lawfully, securely and transparently.

The agencies must also forward the names and contact details of their designated DPOs to the NDPC for registration and official documentation.

In addition, government institutions have been instructed to engage licensed Data Protection Compliance Organisations, DPCOs, where necessary, to facilitate compliance with the law and support the conduct of mandatory data protection compliance audits.

The circular also requires MDAs to make adequate budgetary provisions for data protection activities, including staff training, public awareness campaigns, deployment of technical safeguards and periodic compliance assessments.

The government further directed all affected agencies to submit statutory Data Protection Compliance Audit Returns and other mandatory reports to the NDPC within timelines prescribed by law, stressing that timely reporting is a critical component of institutional accountability.

Reacting to the development, the National Commissioner and Chief Executive Officer of the NDPC, Dr. Vincent Olatunji, commended the Tinubu administration for demonstrating strong legal and political commitment to protecting the privacy and fundamental freedoms of Nigerians.

Olatunji said effective data accountability remains essential to achieving the administration’s eight Presidential Priorities and pledged the Commission’s continued support to all MDAs in meeting their obligations under the law. He disclosed that the NDPC has established a regulatory clinic to provide technical guidance and compliance support to government institutions.

The Commission added that the latest compliance circular forms part of a broader series of regulatory initiatives designed to strengthen Nigeria’s digital governance architecture as the country positions itself to harness opportunities presented by the Fourth Industrial Revolution while ensuring the protection of citizens’ personal data.

RELATED ARTICLES
- Advertisment -

LATEST NEWS