The Federal Government has directed all Ministries, Departments and Agencies (MDAs) to comply fully with the provisions of the Nigeria Data Protection Act (NDPA) 2023, in a move aimed at strengthening data governance, enhancing accountability and protecting the personal data of Nigerians across the public sector.
The directive, according to a statement seen by Technology Times, issued by Senator George Akume, Secretary to the Government of the Federation (SGF), mandates all federal MDAs to comply with the Nigeria Data Protection Act, its regulations, implementation guidelines and all directives issued by the Nigeria Data Protection Commission (NDPC) governing the lawful processing of personal data.
The development is expected to accelerate the integration of data protection practices across federal institutions as government services continue to migrate to digital platforms, making privacy, security and responsible data governance central to public service delivery.

“To this end, MDAs are directed to designate suitably qualified officers as Data Protection Officers (DPOs) to oversee data protection compliance and advise management on all matters relating to the lawful processing of personal data,” the circular states.
MDAs to appoint Data Protection Officers, register with NDPC
Under the directive, all MDAs are required to designate suitably qualified Data Protection Officers (DPOs) to oversee institutional compliance with the NDPA and advise management on all matters relating to the lawful processing of personal data.
“To this end, MDAs are directed to designate suitably qualified officers as Data Protection Officers (DPOs) to oversee data protection compliance and advise management on all matters relating to the lawful processing of personal data,” the circular states.
The agencies must also submit the names and contact details of their designated DPOs to the NDPC for registration and official records.
Where necessary, MDAs are required to engage licensed Data Protection Compliance Organisations (DPCOs) to support implementation of the law.
The circular further directs government institutions to provide adequate budgetary allocations for data protection compliance, including capacity building, awareness programmes, deployment of technical safeguards and the conduct of periodic compliance audits.
In addition, all MDAs are required to submit mandatory Data Protection Compliance Audit Returns within the timelines prescribed by law.

“Data is the new oil: its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023,” President Tinubu said.
Nigeria Data Protection Act: Permanent Secretaries, CEOs held personally accountable
To strengthen institutional accountability, the Federal Government has placed responsibility for compliance directly on the leadership of public institutions.
According to the directive, Permanent Secretaries, Accounting Officers and Chief Executive Officers of all MDAs shall be personally responsible for ensuring that their organisations comply fully with the provisions of the circular and the Nigeria Data Protection Act.
The directive gives practical effect to President Bola Ahmed Tinubu’s policy on responsible data governance as the Federal Government accelerates digital transformation and data-driven governance across the public sector.
“Data is the new oil: its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023,” President Tinubu said.
NDPC welcomes directive, expands support for MDAs
The Nigeria Data Protection Commission (NDPC) welcomed the directive, describing it as a strong demonstration of the Federal Government’s commitment to protecting the privacy and fundamental freedoms of Nigerians while advancing responsible data governance.
Dr Vincent Olatunji, National Commissioner and Chief Executive Officer of the NDPC, said accountability remains critical to achieving the Federal Government’s Eight Presidential Priorities.
According to him, the commission has established a Regulatory Clinic to provide technical support and guidance to MDAs in implementing the provisions of the Act.
The NDPC said the initiative is expected to strengthen institutional compliance with Nigeria’s data protection requirements as the country advances its digital transformation agenda.
Nigeria strengthens public sector data governance
The latest directive reinforces the Federal Government’s drive to embed data protection into public sector governance following the enactment of the Act.
The NDPA established the NDPC as Nigeria’s independent data protection regulator with powers to enforce compliance, investigate violations and safeguard the privacy rights of data subjects.
The legislation replaced the Nigeria Data Protection Regulation (NDPR), which had served as Nigeria’s principal data protection framework since 2019.
In recent years, the Commission has expanded Nigeria’s data governance ecosystem through the licensing of Data Protection Compliance Organisations (DPCOs), the issuance of implementation directives and regulatory guidance, as well as increased enforcement actions against organisations found to have breached the country’s data protection law.
The Federal Government’s latest directive is expected to deepen institutional compliance with the NDPA and strengthen public confidence in the protection of personal data as Nigeria continues to expand digital public services and accelerate its digital economy agenda.


























Home