The Federal Government has directed all ministries, departments and agencies to comply fully with the Nigeria Data Protection Act 2023 and related privacy regulations.
The directive is intended to improve the handling of citizens’ personal information, strengthen data accountability and increase public confidence in government institutions.
It was communicated through Circular No. 59805/S.I/74, dated July 27, 2026, and issued by Secretary to the Government of the Federation George Akume.
MDAs Must Follow NDPC Regulations
Babatunde Bamigboye, Head of Legal, Enforcement and Regulations at the Nigeria Data Protection Commission, announced the directive in Abuja on Tuesday, August 4.
Under the circular, federal institutions must comply with the Data Protection Act as well as regulations, guidelines and directives issued by the NDPC on the collection and processing of personal data.
The policy follows an earlier instruction by President Bola Tinubu that government institutions should gather reliable information while protecting it according to established privacy standards.
Tinubu issued the instruction during the International Civil Service Conference in Abuja in June 2025, where he described accurate and secure data as essential to evidence-based governance.
Agencies Directed to Appoint Data Protection Officers
The circular requires every MDA to designate a suitably qualified Data Protection Officer.
The appointed officer will oversee compliance, advise institutional management and promote the lawful handling of personal information.
Each agency must also submit the name and contact details of its Data Protection Officer to the NDPC for registration and official documentation.
The requirement is intended to establish a clearly identified official responsible for privacy and data protection matters within every federal institution.
Licensed Compliance Organisations May Be Engaged
MDAs may be required to engage licensed Data Protection Compliance Organisations to assist with their obligations under the law.
These organisations can provide professional support and facilitate the statutory compliance audits required by the NDPC.
The agencies must ensure that any external compliance organisation they engage is properly licensed by the commission.
MDAs Told to Budget for Data Protection
Federal institutions have also been instructed to make adequate budgetary provisions for data protection activities.
The funding should cover staff training, privacy-awareness programmes, technical security measures and periodic compliance audits.
The directive means data protection must be incorporated into institutional planning rather than treated as an occasional administrative exercise.
Mandatory Audit Returns Required
MDAs must submit mandatory Data Protection Compliance Audit Returns and other statutory reports to the NDPC within the timelines prescribed by law.
The returns are expected to show how each institution collects, uses, stores, shares and protects personal information.
Regular reporting will also enable the commission to monitor compliance and identify weaknesses in government data-management systems.
Permanent Secretaries and CEOs Held Responsible
The circular places responsibility for implementation on the leadership of each federal institution.
Permanent secretaries, accounting officers and chief executive officers are expected to ensure that their organisations comply with both the circular and the Nigeria Data Protection Act.
The directive therefore makes data protection a management and governance responsibility rather than an issue limited to information technology departments.
NDPC Establishes Regulatory Clinic
NDPC National Commissioner and Chief Executive Officer Vincent Olatunji welcomed the government’s decision, describing data accountability as important to the administration’s policy objectives.
Olatunji said the commission had established a regulatory clinic to offer technical assistance to ministries, departments and agencies as they work towards compliance.
The support programme is expected to help federal institutions understand their legal obligations and implement appropriate data-protection systems.
Directive Targets Responsible Data Governance
The Federal Government said responsible use of data was essential as public services increasingly relied on digital platforms and information-sharing systems.
Government agencies process a wide range of personal information, including identity records, employment data, financial details, healthcare information and citizens’ applications for public services.
Compliance with the Nigeria Data Protection Act is intended to reduce misuse, unauthorised disclosure and weak handling of such information.
The NDPC is the federal regulator established under the 2023 Act to oversee privacy compliance and promote responsible processing of personal data in Nigeria.
The commission said the latest directive formed part of wider efforts to strengthen Nigeria’s data-governance framework as the country expands its digital economy.



















