Connect with us

National

FG Mandates Data Protection Officers in MDAs, Escalates CEO Liability Under NDP Act

Published

on

The Federal Government has issued a stringent directive to all Ministries, Departments, and Agencies (MDAs) mandating the appointment of Data Protection Officers (DPOs). This move, aimed at bolstering responsible data governance and public trust, requires MDAs to register these DPOs with the Nigeria Data Protection Commission (NDPC) and ensure full adherence to the Nigeria Data Protection Act (NDP Act), 2023.

The directive, formalised in Circular No. 59805/S.I/74 dated July 27, 2026, and signed by the Secretary to the Government of the Federation (SGF), Senator George Akume, explicitly places personal responsibility on Permanent Secretaries, Accounting Officers, and Chief Executive Officers of MDAs for compliance with Nigeria’s data protection legislation. This initiative stems from President Bola Tinubu’s recognition of data as a critical national asset necessitating enhanced protection. The President underscored the value of data, stating, “Data is the new oil: its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023.”

Consequently, all federal MDAs are now obligated to ensure comprehensive compliance with the NDP Act, its associated regulations, guidelines, and directives from the NDPC concerning the processing of personal data. The circular mandates the designation of suitably qualified officers as DPOs to oversee data protection compliance and provide expert advice on the lawful processing of personal data. Furthermore, MDAs must submit the names and contact details of their appointed DPOs to the NDPC for official registration. Where required, agencies are encouraged to engage licensed Data Protection Compliance Organisations (DPCOs) to support their compliance efforts and conduct mandatory data protection compliance audits.

Adequate budgetary provisions for data protection activities, including staff training, awareness programmes, the implementation of technical safeguards, and periodic compliance audits, are also stipulated. The Federal Government further requires MDAs to submit all mandatory Data Protection Compliance Audit Returns and other statutory returns to the NDPC within the legally prescribed timelines.

The circular explicitly states that Permanent Secretaries, Accounting Officers, and Chief Executive Officers of all MDAs will be held personally accountable for ensuring their institutions comply with this directive and the provisions of the Nigeria Data Protection Act. Dr. Vincent Olatunji, National Commissioner and Chief Executive Officer of the NDPC, lauded the administration’s commitment to protecting citizens’ privacy and fundamental rights, noting that data accountability is pivotal to achieving the administration’s eight Presidential Priorities. The NDPC has established a regulatory clinic to offer technical support to MDAs navigating these new compliance requirements. This directive signifies a strategic shift, with the government now focusing enforcement efforts on public sector entities, mirroring the NDPC’s intensified actions against private organisations, including a recent N766.2 million fine levied against Multichoice Nigeria for NDP Act violations.

… FG Mandates Data Protection Officers in MDAs, Escalates CEO Liability Under NDP Act … Naijaonpoint.

𝕤𝕖𝕖 𝕞𝕠𝕣𝕖/𝕨𝕒𝕥𝕔𝕙 𝕥𝕙𝕖 𝕧𝕚𝕕𝕖𝕠 𝕙𝕖𝕣𝕖

Trending