The directive was communicated through Circular No. 59805/S.I/74, dated 27 July 2026 and issued by the Secretary to the Government of the Federation, Senator George Akume. The Nigeria Data Protection Commission (NDPC) publicly confirmed the order in a statement released in Abuja by its Head of Legal, Enforcement and Regulations, Babatunde Bamigboye.
Presidential Emphasis on Rigorous Data Capture and Safeguards
According to the NDPC, the circular aligns with President Bola Tinubu’s instruction that government institutions must rigorously capture information and safeguard it in accordance with the Nigeria Data Protection Act. In the statement, Bamigboye quoted the underlying principle driving the policy: “Data is the new oil: its value increases the more it is refined and responsibly shared.”
The Federal Government has therefore directed every MDA to ensure full compliance with the NDP Act, as well as with the regulations, guidelines, and directives issued by the NDPC that govern the processing of personal data.
Compliance Obligations for MDAs
The circular sets out several concrete requirements that public institutions must now meet:
- Appointment of Data Protection Officers. Each MDA must appoint a qualified Data Protection Officer responsible for overseeing compliance and advising management on lawful data processing. The names and contact details of these officers must be communicated to the NDPC for registration.
- Engagement of licensed compliance support where needed. MDAs are expected to engage licensed Data Protection Compliance Organisations (DPCOs) when required to facilitate compliance with the Act and to support the conduct of statutory compliance audits.
- Budgetary allocation for data protection. Institutions must provide adequate budgetary resources for compliance activities. This includes capacity building, awareness programmes, deployment of appropriate technical safeguards, and periodic compliance audits.
- Timely submission of statutory returns. MDAs must submit all mandatory Data Protection Compliance Audit Returns and other required filings to the NDPC within the timelines prescribed by law.
Permanent Secretaries, Accounting Officers, and Chief Executive Officers of MDAs have been made personally responsible for ensuring that their institutions meet both the circular’s requirements and the substantive obligations of the NDP Act.
NDPC Response and Support Mechanisms
National Commissioner of the NDPC, Dr. Vincent Olatunji, welcomed the administration’s stance. He described the directive as evidence of the government’s commitment to protecting the privacy and fundamental freedoms of Nigerians. Olatunji linked data accountability directly to the successful delivery of the administration’s Eight Presidential Priorities, noting that responsible data practices are foundational to effective governance in the digital age.
To help public institutions meet their obligations, the Commission has established a regulatory clinic that will provide technical support to MDAs. The clinic forms part of a wider set of measures the NDPC is implementing to strengthen Nigeria’s data governance framework as the country advances toward greater participation in the Fourth Industrial Revolution.
Why the Directive Matters
The Nigeria Data Protection Act, 2023 established a comprehensive legal framework for the processing of personal data in both the public and private sectors. While the law has been in force, consistent implementation across the large and diverse landscape of federal MDAs has remained uneven. By placing explicit responsibility on institutional leaders and requiring the appointment of dedicated Data Protection Officers, the new circular seeks to close that implementation gap.
Public-sector compliance carries particular weight. Government agencies collect and process some of the most sensitive categories of personal data—identity records, health information, tax data, biometric identifiers, and records related to social services. Failures in this environment can erode public trust more quickly and more severely than equivalent shortcomings in the private sector.
The directive also signals that data protection is no longer viewed as a purely legal or technical side issue. By tying compliance to presidential priorities and by requiring budgetary provision for technical safeguards and capacity building, the Federal Government is treating data governance as an operational necessity rather than an optional add-on.
MDAs that have not already done so will need to move quickly on several fronts. Identifying and formally appointing a qualified Data Protection Officer is the most immediate structural requirement. Institutions should also assess whether they need external support from a licensed DPCO to conduct gap analyses, design compliance programmes, or prepare for statutory audits.
Budget planning will need to reflect the new expectations. Capacity-building programmes, awareness campaigns for staff who handle personal data, investment in technical controls, and the cost of periodic audits all require dedicated funding lines if compliance is to be sustained rather than treated as a one-time exercise.
Finally, MDAs should review their existing data inventories, processing activities, and information-security measures against the requirements of the NDP Act and the NDPC’s published guidance. Early identification of high-risk processing activities will allow institutions to prioritise remediation before formal audit cycles begin in earnest.
Nigeria’s Data Governance Agenda
The circular arrives as Nigeria continues to position itself as a serious participant in the global digital economy. Effective data protection is increasingly viewed as a prerequisite for cross-border data flows, digital trade, and public confidence in e-government services. By tightening expectations on its own institutions, the Federal Government is attempting to lead by example and to create a more coherent national compliance culture.
For private-sector organisations that interact with government systems or process data on behalf of public bodies, the directive may also have indirect effects. As MDAs strengthen their internal controls and contractual requirements, vendors and service providers are likely to face heightened due-diligence and data-protection expectations in their dealings with the public sector.
The NDPC’s regulatory clinic and the personal accountability placed on senior officials suggest that the Commission intends to move from awareness-raising into more systematic oversight. Institutions that treat the circular as a routine administrative notice rather than a substantive compliance mandate may find themselves exposed as enforcement and audit activity increases.
Overall, the Federal Government’s directive marks a clear elevation of data protection within Nigeria’s public administration. Full compliance with the Nigeria Data Protection Act is now an explicit, measurable expectation for every MDA, backed by leadership accountability, mandatory officer appointments, and dedicated resourcing requirements. How quickly and thoroughly institutions respond will help determine whether the country’s data governance framework delivers the public trust and operational discipline its architects intend.