{
 "jurisdiction_id": "ID",
 "jurisdiction": "Indonesia",
 "url": "https://dataprotection.gi/jurisdictions/indonesia/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 37,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core statute and regulator are in force and enforcing, but subsidiary rulemaking (e.g., finalized DPIA methodology, full sectoral codes) and registration mechanics have continued to evolve since 2023, warranting an amber rather than green rating pending fuller primary-source verification.",
   "claims": [
    {
     "statement": "The Nigeria Data Protection Act 2023 establishes the Nigeria Data Protection Commission (NDPC) as an independent commission for the regulation of the processing of personal information, with the Commission being independent in the performance of its functions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance (reproducing Nigerian statute)",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_act_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Nigeria's Data Protection Act was enacted on 12 June 2023, and Section 65 of the Act introduced the concept of data controllers and data processors 'of major importance' without providing a concrete statutory definition, leaving that task to the NDPC.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nigerias-dpa-moves-towards-improved-regulatory-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In March 2025, the NDPC published the General Application and Implementation Directive (GAID) of the NDPA 2023, which took effect on 19 September 2025 and expressly replaced the Nigeria Data Protection Regulation (NDPR) 2019.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/from-principles-to-practice-operationalizing-nigerias-data-protection-act-through-the-gaid",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 2(c) of the NDPA provides that the Act applies to the processing of personal data of data subjects in Nigeria even where the data controller or data processor is not domiciled in Nigeria.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/from-principles-to-practice-operationalizing-nigerias-data-protection-act-through-the-gaid",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 1(3-4) of the GAID clarifies the residency rules governing the territorial scope of data subject rights under the NDPA, applying regardless of nationality and migration status.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/from-principles-to-practice-operationalizing-nigerias-data-protection-act-through-the-gaid",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data controllers and data processors of major importance were required to register with the NDPC between 30 January and 30 June 2024, with late registration or failure to register incurring statutory penalties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nigerias-dpa-moves-towards-improved-regulatory-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A data controller or processor is designated as being 'of major importance' if it processes personal data of more than 200 individuals within six months, provides commercial ICT storage services, or operates in sectors such as finance, communications, health, education, insurance, aviation or oil and gas, with a higher top tier applying to entities such as commercial banks, telecoms operators, insurers and payment gateway providers that process data of over 5,000 individuals in six months.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nigerias-dpa-moves-towards-improved-regulatory-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 48(1)(a) of the NDPA, the penalty for noncompliance by a data controller or processor of major importance may be a sanction or remedial fee greater than NGN10 million and 2% of the entity's annual gross revenue in the preceding financial year.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nigerias-dpa-moves-towards-improved-regulatory-enforcement",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Structural provisions (Part V sections) are confirmed, but granular content (full lawful-basis list, pseudonymisation/anonymisation definitions under the current Act) could not be fully verified from primary text in this pass.",
   "claims": [
    {
     "statement": "Part V of the NDPA (Sections 24-30) sets out the principles and lawful bases governing the processing of personal data, including a dedicated provision on the lawful basis of personal data processing (Section 25) and consent (Section 26).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPA permits a data controller to rely on consent given by a child aged 13 years or older for the purposes of Sections 26(1)(a) and 31(1)(a), in relation to the provision of information and services by electronic means at the child's specific request, without prejudice to the Child's Rights Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 35 of the NDPA, a data subject has the right to withdraw consent to processing at any time, and the data controller must ensure it is as easy for the data subject to withdraw consent as it was to give it.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance (reproducing Nigerian statute)",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_act_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 30 of the NDPA specifically addresses the processing of sensitive personal data, establishing a distinct category subject to heightened obligations under Part V of the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The predecessor Nigeria Data Protection Regulation (NDPR) 2019 did not provide statutory definitions for 'pseudonymised' or 'anonymised' personal data; whether the NDPA 2023 introduced such definitions has not been independently confirmed in the sources reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._nigeria.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Erasure/restriction/withdrawal rights are confirmed from primary text; access, portability and statutory deadlines require further primary-source verification.",
   "claims": [
    {
     "statement": "Section 34 of the NDPA requires a data controller to erase personal data without undue delay where the personal data is no longer necessary for the purposes for which it was collected or processed, or where the controller has no other lawful basis to retain it.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance (reproducing Nigerian statute)",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_act_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 34 of the NDPA provides for restriction of data processing pending the resolution of a request, an objection by the data subject, or the establishment, exercise, or defense of legal claims.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance (reproducing Nigerian statute)",
     "source_url": "https://www.dataguidance.com/sites/default/files/data_protection_act_2023.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "DPIA, DPO and security provisions are confirmed by section references; breach-notification timelines and ROPA specifics under the current Act require further primary verification, as retrieved evidence largely concerned the superseded NDPR/Draft NITDA Framework.",
   "claims": [
    {
     "statement": "Section 28 of the NDPA establishes a data privacy impact assessment obligation as part of Part V of the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data controllers of major importance under the NDPA must designate a Data Protection Officer with expert knowledge of data protection law and practices and the ability to carry out tasks prescribed under the Act and subsidiary legislation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPC has issued continuing professional development (CPD) guidance applicable to verified Data Protection Officers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/nigeria-ndpc-issues-cpd-guidance-verified-dpos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The predecessor NDPR did not explicitly require the record-keeping (records of processing) obligations equivalent to those required by the GDPR; whether the NDPA 2023 introduced an explicit ROPA requirement has not been independently confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._nigeria.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 39(1) of the NDPA requires a data controller and data processor to implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data in its possession or under its control, including protection against accidental or unlawful destruction, loss, misuse, alteration or unauthorised disclosure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the pre-NDPA Draft NITDA Framework, data handlers were required to report data breaches to NITDA within 72 hours of becoming aware of the breach; this framework was not approved and was not in effect, and its successor status under the NDPA/GAID has not been independently confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._nigeria.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "The core adequacy standard (Section 42) is confirmed from primary text; the operative adequacy list, SCC/BCR forms, TIA requirement and localisation posture under the current NDPC regime require further primary-source verification.",
   "claims": [
    {
     "statement": "Section 42(1) of the NDPA provides that a level of protection is adequate for cross-border transfer purposes if it upholds principles substantially similar to the conditions governing the processing of personal data under the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the predecessor NDPR framework, a 'White List' of jurisdictions considered to have adequate data protection law was compiled by NITDA (set out in Annexure C to the NDPR Implementation Framework); whether the NDPC has published an equivalent list under the NDPA has not been independently confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NITDA",
     "source_url": "https://www.dataguidance.com/sites/default/files/ndpr_implementation_framework_november_2020.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the predecessor NDPR Implementation Framework, a data controller could rely on documented consent or BCR/SCC-style documentation, includable in the data audit report, to justify transfers to jurisdictions outside the adequacy White List.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NITDA",
     "source_url": "https://www.dataguidance.com/sites/default/files/ndpr_implementation_framework_november_2020.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and telecoms sector overlay is evidenced by NDPC enforcement action and major-importance criteria; other sector overlays (education, insurance, credit/scoring, employment) lack independently confirmed primary-source detail.",
   "claims": [
    {
     "statement": "Commercial banks operating at national or regional levels and payment gateway service providers are designated data controllers/processors of major importance under NDPC guidance, subjecting them to heightened NDPA obligations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nigerias-dpa-moves-towards-improved-regulatory-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPC fined Fidelity Bank NGN 555.8 million for a data protection violation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/nigeria-ndpc-fines-fidelity-bank-ngn-5558m-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPC and the Nigerian Communications Commission (NCC) have reportedly launched a joint data protection working group covering the telecoms sector, though the working group's substantive outputs were not independently retrievable in this research pass.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/node/641365",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only one concrete enforcement data point (MultiChoice) was confirmed; the sub-modules covering cookies, dark patterns, opt-out signals, clean rooms and direct marketing lack NDPA-specific primary-source confirmation.",
   "claims": [
    {
     "statement": "Under the predecessor NDPR Implementation Framework, continued surfing of a website upon clear notice was treated as indicating consent to cookie deployment, subject to disclosure requirements on website owners.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NITDA",
     "source_url": "https://www.dataguidance.com/sites/default/files/ndpr_implementation_framework_november_2020.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPC fined Multichoice Nigeria NGN 766 million for unlawful data transfers and privacy rights violations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/nigeria-ndpc-fines-multichoice-nigeria-ngn-766m",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No claims could be substantiated from the sources reviewed in this run.",
   "claims": []
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "The Section 26/31 child-consent age threshold is confirmed from primary text; parental-consent mechanics, minor-profiling bans, and dependent-adult protections lack independent confirmation.",
   "claims": [
    {
     "statement": "The NDPA permits a data controller to rely on consent given directly by a child aged 13 years or older for purposes of Sections 26(1)(a) and 31(1)(a), specifically in relation to the provision of information and services by electronic means at the child's specific request, without prejudice to the Child's Rights Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The predecessor NDPR did not grant special protection to children's personal data and did not require data controllers to make reasonable efforts to verify that consent for processing a child's data was given by a parent or guardian; whether the NDPA changed this has not been independently confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._nigeria.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/indonesia/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator powers and recent enforcement activity are well evidenced; collective redress, private right of action, and funding/capacity metrics beyond the statutory Fund mechanism lack independent confirmation.",
   "claims": [
    {
     "statement": "Under Section 46 of the NDPA, a data subject aggrieved by the decision, action, or inaction of a data controller or data processor in violation of the Act may lodge a complaint with the Commission, and the Commission may also initiate an investigation of its own accord where it has reason to believe a violation has occurred or is likely to occur.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 48(1)(a) of the NDPA, the penalty for noncompliance by a data controller or processor of major importance may be a sanction or remedial fee greater than NGN10 million and 2% of the entity's annual gross revenue in the preceding financial year.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nigerias-dpa-moves-towards-improved-regulatory-enforcement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPC fined Fidelity Bank NGN 555.8 million for a data protection violation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/nigeria-ndpc-fines-fidelity-bank-ngn-5558m-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPC fined Multichoice Nigeria NGN 766 million for unlawful data transfers and privacy rights violations, and separately began a sector-by-sector investigation of NDPA compliance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/nigeria-ndpc-fines-multichoice-nigeria-ngn-766m",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPA empowers the Commission to borrow sums of money as may be required to perform its functions, and requires the Commission to keep and maintain proper accounts and records subject to audit by the Auditor-General for the Federation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Assembly Press, Abuja",
     "source_url": "https://www.dataguidance.com/sites/default/files/nigeria_data_protection_establishment_etc._bill_2023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NDPC has issued continuing professional development (CPD) guidance for verified Data Protection Officers, though the precise publication date was not independently confirmed and may or may not fall within the last 180 days.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/nigeria-ndpc-issues-cpd-guidance-verified-dpos",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}