Since 19 September 2025, the operative rulebook for data protection compliance in Nigeria has been the Nigeria Data Protection Act General Application and Implementation Directive 2025, reference NDPC/NDP ACT-GAID/01/2025, issued by the NDPC on 20 March 2025 with a six-month transition period (full text, NDPC).

The NDPA 2023 is a principles statute. The GAID is where those principles become obligations with procedures attached: who must register with the NDPC and how, which lawful bases carry which documentation duties, how data subject rights requests must be handled, which mechanisms make a cross-border transfer lawful, and how the NDPC's audit and enforcement machinery runs. It replaced the NITDA-era framework in all material respects. A compliance programme still built on the NDPR 2019 is answering questions the regulator no longer asks.

The pieces that bite hardest:

  • Registration and tiering. The GAID operationalises the NDPA's category of "data controllers and processors of major importance." Entities in that tier carry registration, audit-filing and DPO obligations that ordinary controllers do not. Most fintechs, telcos, insurers and large employers qualify.
  • Audit submissions. Entities of major importance must file compliance audit returns, and those returns must now address AI-driven processing. The NDPC signed the February 2026 global joint statement on AI-generated imagery alongside more than 60 authorities (Nairametrics); it treats AI processing as an audit item, not a future topic.
  • Cross-border transfers. The GAID sets out the recognised transfer mechanisms and their evidence requirements. This is the exact ground on which the NDPC opened its Temu investigation in February 2026, five months after the directive took effect.

Why it matters. The GAID converted Nigeria from a jurisdiction with a new statute into a jurisdiction with an enforceable compliance standard, and the NDPC began enforcing on that standard almost immediately: a 1,369-organisation sector sweep in August 2025, the Temu probe in February 2026, the Corporate Affairs Commission breach investigation in April 2026, and ₦400 million collected from a single 17-company investigation wave. The fine ceiling is 2% of annual gross revenue or ₦10 million, whichever is higher. Nigeria is Africa's largest internet market; for most multinationals it is also the African jurisdiction where the enforcement probability is now highest.

Who is affected. Every organisation processing Nigerian personal data, in or outside Nigeria. The practical dividing line is "major importance" status: if you hold that tier, you have filing obligations with deadlines, not just principles to honour.

What to do now:

  1. Confirm your tier. If you are plausibly a controller of major importance, verify your NDPC registration status and your audit-filing calendar before the regulator does it for you.
  2. Re-paper your transfers. List every flow of Nigerian personal data out of the country, match each to a GAID transfer mechanism, and keep the evidence where an investigator can be shown it.
  3. Put AI processing into your audit file. If your products or vendors use AI on personal data (scoring, verification, image processing), your next audit submission must say so and show the compliance analysis.