Between February and May 2026, the Nigeria Data Protection Commission opened an investigation into a global e-commerce platform, opened another into a federal government agency, issued a mandatory security advisory to every data controller in the country, and signed agreements that extend its reach into federal procurement and all 36 state governments. Taken separately these are news items. Taken together they are a map of how Nigeria intends to enforce the Nigeria Data Protection Act 2023, and the numbers behind it: ₦400 million generated from a single wave of investigations into 17 companies (Nigeria Data Protection News).
The platform front. On 17 February 2026, National Commissioner Vincent Olatunji ordered an immediate investigation into Temu (Whaleco Technology / PDD Holdings) over its collection, processing and cross-border transfer of Nigerian users' data. The NDPC's preliminary finding: Temu processes personal data of roughly 12.7 million people in Nigeria (Reuters; Techpoint). Temu confirmed receipt and is engaging with the regulator. No outcome had been published as of early July 2026. The probe grew out of a sector-wide investigation into 1,369 organisations launched in August 2025, so it is a signal of method: sweep wide, then single out the largest target.
The government front. On 17 April 2026, reporting confirmed that threat actors had accessed parts of the Corporate Affairs Commission's systems and that the NDPC had opened an investigation, under section 46(3) of the NDPA, covering the CAC's access controls, impact assessments, penetration testing and third-party processors (Premium Times). A regulator investigating the federal companies registry tells every ministry and agency that public bodies get no pass.
The infrastructure front. An advisory issued 16 April 2026 directs all controllers and processors to appoint certified data protection officers, run regular impact assessments, and deploy multi-factor authentication, against a disclosed backdrop of roughly 4,000 cyberattacks on Nigerian systems weekly (Vanguard). Then the institutional deals: MoUs with the Bureau of Public Procurement and the Nigeria Governors' Forum reported 8 May 2026, putting data protection compliance inside federal contracting and state-level governance (Vanguard), and a two-day peer exchange in Abuja (4 and 5 May) with regulators from nine African countries on cross-border enforcement coordination (Ecofin).
Why it matters. The legal baseline for all of this is the GAID 2025, in force since 19 September 2025. The fine ceiling under the NDPA is 2% of annual gross revenue or ₦10 million, whichever is higher. A regulator collecting hundreds of millions of naira in penalties is using its instrument.
Who is affected. International platforms with Nigerian users; every government contractor and procurement vendor (the BPP MoU makes data handling a contract-compliance issue); multi-state operators (the NGF MoU synchronises 36 states plus the FCT); and any controller that has not yet appointed a certified DPO or deployed MFA.
What to do now:
- Close your GAID gap analysis if it is still open. The transition period ended September 2025; the Temu and CAC probes both cite post-GAID obligations.
- Audit cross-border transfers against the GAID's transfer mechanisms. That is the specific issue in the Temu probe, and it applies to routine cloud hosting, not just Chinese e-commerce.
- If you sell to government, add NDPA compliance to your bid checklist now. Procurement-linked audits under the BPP MoU are the cheapest way for the NDPC to scale enforcement.