🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
ID · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

Indonesia

ID schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 37 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute and regulator are in force and enforcing, but subsidiary rulemaking (e.g., finalized DPIA methodology, full sectoral codes) and registration mechanics have continued to evolve since 2023, warranting an amber rather than green rating pending fuller primary-source verification.

Primary frameworkNigeria Data Protection Act 2023 (NDPA), operationalised by the NDPC General Application and Implementation Directive (GAID) 2025
Traffic-light rationale — AmberCore statute and regulator are in force and enforcing, but subsidiary rulemaking (e.g., finalized DPIA methodology, full sectoral codes) and registration mechanics have continued to evolve since 2023, warranting an amber rather than green rating pending fuller primary-source verification.

Sub-modules (5)

Regulator And AuthorityGreen

The NDPA establishes the NDPC as an independent commission responsible for regulating personal data processing in Nigeria, headed by a National Commissioner.

Claims: CLM-NG-a1b2c3d4

Act And InstrumentsGreen

Primary instrument is the NDPA 2023; operationalised via the GAID 2025, which replaced the NDPR 2019.

Claims: CLM-NG-b2c3d4e5, CLM-NG-c3d4e5f6

Material ScopeGreen

The Act applies to processing of personal data of data subjects in Nigeria, with an extraterritorial reach captured in Section 2(c).

Claims: CLM-NG-d4e5f6a7

Territorial ScopeGreen

GAID Article 1(3-4) confirms data-subject-rights protections apply based on the data subject's presence/connection to Nigeria irrespective of nationality or migration status.

Claims: CLM-NG-e5f6a7b8

Regulator Registration And FilingAmber

Controllers/processors of 'major importance' must register with the NDPC; the registration window, criteria, and penalties for non-registration have been clarified via NDPC guidance notices issued in tranches since early 2024.

Claims: CLM-NG-f6a7b8c9, CLM-NG-a7b8c9d0, CLM-NG-b8c9d0e1

Category narrative127 words

Nigeria's data protection regime is anchored in the Nigeria Data Protection Act 2023 (NDPA), enacted 12 June 2023, which established the Nigeria Data Protection Commission (NDPC) as an independent regulator superseding the prior NITDA-administered Nigeria Data Protection Regulation (NDPR) 2019. The NDPC published a General Application and Implementation Directive (GAID) in March 2025, effective 19 September 2025, which operationalises the NDPA and formally replaced the NDPR 2019. The Act applies extraterritorially to processing of Nigerian data subjects' personal data regardless of controller/processor domicile. A registration regime for 'data controllers and data processors of major importance' has been rolled out but implementation has been iterative (guidance revised, deadlines extended), which is why elements of the regime are still treated as transitional even though the NDPC is actively enforcing.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidance (reproducing Nigerian statute)The Nigeria Data Protection Act 2023 establishes the Nigeria Data Protection Commission (NDPC) as an independent commission for the regulation of the processing of personal information, with the Commission being independent in the performance of its functions.
  2. ConfirmedIAPPNigeria's Data Protection Act was enacted on 12 June 2023, and Section 65 of the Act introduced the concept of data controllers and data processors 'of major importance' without providing a concrete statutory definition, leaving that task to the NDPC.
  3. ConfirmedIAPPIn March 2025, the NDPC published the General Application and Implementation Directive (GAID) of the NDPA 2023, which took effect on 19 September 2025 and expressly replaced the Nigeria Data Protection Regulation (NDPR) 2019.
  4. ConfirmedIAPPSection 2(c) of the NDPA provides that the Act applies to the processing of personal data of data subjects in Nigeria even where the data controller or data processor is not domiciled in Nigeria.
  5. ConfirmedIAPPArticle 1(3-4) of the GAID clarifies the residency rules governing the territorial scope of data subject rights under the NDPA, applying regardless of nationality and migration status.
  6. ConfirmedIAPPData controllers and data processors of major importance were required to register with the NDPC between 30 January and 30 June 2024, with late registration or failure to register incurring statutory penalties.
  7. ConfirmedIAPPA data controller or processor is designated as being 'of major importance' if it processes personal data of more than 200 individuals within six months, provides commercial ICT storage services, or operates in sectors such as finance, communications, health, education, insurance, aviation or oil and gas, with a higher top tier applying to entities such as commercial banks, telecoms operators, insurers and payment gateway providers that process data of over 5,000 individuals in six months.
  8. ConfirmedIAPPUnder Section 48(1)(a) of the NDPA, the penalty for noncompliance by a data controller or processor of major importance may be a sanction or remedial fee greater than NGN10 million and 2% of the entity's annual gross revenue in the preceding financial year.

#

Structural provisions (Part V sections) are confirmed, but granular content (full lawful-basis list, pseudonymisation/anonymisation definitions under the current Act) could not be fully verified from primary text in this pass.

Primary frameworkNigeria Data Protection Act 2023, Part V (Sections 24-30)
Traffic-light rationale — AmberStructural provisions (Part V sections) are confirmed, but granular content (full lawful-basis list, pseudonymisation/anonymisation definitions under the current Act) could not be fully verified from primary text in this pass.

Sub-modules (4)

Lawful BasesAmber

Section 25 of the NDPA sets out the lawful basis of personal data processing; the full statutory enumeration was not independently confirmed in this pass beyond confirming the section's existence and title.

Claims: CLM-NG-c9d0e1f2

Special CategoriesAmber

Section 30 of the NDPA specifically addresses sensitive personal data as a distinct category subject to heightened obligations.

Claims: CLM-NG-f2a3b4c5

Pseudonymisation And AnonymisationRed

No confirmed NDPA-specific statutory definitions of pseudonymisation or anonymisation were located; the predecessor NDPR is documented as lacking such definitions, but whether the NDPA 2023 changed this has not been confirmed.

Claims: CLM-NG-a3b4c5d6

Category narrative85 words

Part V of the NDPA (Sections 24-30) sets out the principles and lawful bases for processing personal data, including dedicated provisions on lawful basis (Section 25), consent (Section 26), DPIA (Section 28), and sensitive personal data (Section 30). Consent thresholds include a minimum age of 13 for a child to consent to information-society services. Full statutory text on the complete enumeration of lawful bases and definitions of pseudonymisation/anonymisation under the NDPA (as distinct from the predecessor NDPR) was not independently retrievable in this research pass.

Sources and claims (5)
  1. ConfirmedNational Assembly Press, AbujaPart V of the NDPA (Sections 24-30) sets out the principles and lawful bases governing the processing of personal data, including a dedicated provision on the lawful basis of personal data processing (Section 25) and consent (Section 26).
  2. ConfirmedNational Assembly Press, AbujaThe NDPA permits a data controller to rely on consent given by a child aged 13 years or older for the purposes of Sections 26(1)(a) and 31(1)(a), in relation to the provision of information and services by electronic means at the child's specific request, without prejudice to the Child's Rights Act.
  3. ConfirmedOneTrust DataGuidance (reproducing Nigerian statute)Under Section 35 of the NDPA, a data subject has the right to withdraw consent to processing at any time, and the data controller must ensure it is as easy for the data subject to withdraw consent as it was to give it.
  4. ConfirmedNational Assembly Press, AbujaSection 30 of the NDPA specifically addresses the processing of sensitive personal data, establishing a distinct category subject to heightened obligations under Part V of the Act.
  5. UncertainOneTrust DataGuidanceThe predecessor Nigeria Data Protection Regulation (NDPR) 2019 did not provide statutory definitions for 'pseudonymised' or 'anonymised' personal data; whether the NDPA 2023 introduced such definitions has not been independently confirmed in the sources reviewed.

#

Erasure/restriction/withdrawal rights are confirmed from primary text; access, portability and statutory deadlines require further primary-source verification.

Primary frameworkNigeria Data Protection Act 2023, Sections 34-36
Traffic-light rationale — AmberErasure/restriction/withdrawal rights are confirmed from primary text; access, portability and statutory deadlines require further primary-source verification.

Sub-modules (5)

Access RightRed

No section-level primary-source confirmation of the specific access-right mechanics was retrieved in this pass; the NDPA is understood to include an access right consistent with GDPR-style regimes, but this was not independently verified here.

Rectification And ErasureGreen

Section 34 of the NDPA provides for erasure of personal data without undue delay where data is no longer necessary or the controller lacks a lawful basis to retain it.

Claims: CLM-NG-b4c5d6e7

Restriction And ObjectionGreen

Section 34(1)(e) of the NDPA provides for restriction of data processing pending resolution of a request, an objection by the data subject, or the establishment, exercise or defense of legal claims.

Claims: CLM-NG-c5d6e7f8

Data PortabilityRed

No section-level primary-source confirmation of a data portability right was retrieved in this research pass.

Deadlines And Response WindowsRed

Statutory response-time windows for controller compliance with data subject requests under the NDPA were not independently confirmed with primary-source citations in this pass.

Category narrative48 words

The NDPA sets out a suite of data subject rights including erasure, restriction, and consent withdrawal, evidenced directly by statutory text (Sections 34-35). Rights of access and portability, and the precise statutory response-time windows for controller compliance, were not independently confirmed with section-level citations in this research pass.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidance (reproducing Nigerian statute)Section 34 of the NDPA requires a data controller to erase personal data without undue delay where the personal data is no longer necessary for the purposes for which it was collected or processed, or where the controller has no other lawful basis to retain it.
  2. ConfirmedOneTrust DataGuidance (reproducing Nigerian statute)Section 34 of the NDPA provides for restriction of data processing pending the resolution of a request, an objection by the data subject, or the establishment, exercise, or defense of legal claims.

#

DPIA, DPO and security provisions are confirmed by section references; breach-notification timelines and ROPA specifics under the current Act require further primary verification, as retrieved evidence largely concerned the superseded NDPR/Draft NITDA Framework.

Primary frameworkNigeria Data Protection Act 2023, Sections 27-30, 39
Traffic-light rationale — AmberDPIA, DPO and security provisions are confirmed by section references; breach-notification timelines and ROPA specifics under the current Act require further primary verification, as retrieved evidence largely concerned the superseded NDPR/Draft NITDA Framework.

Sub-modules (7)

Accountability And DpiaAmber

Section 28 of the NDPA establishes a data privacy impact assessment obligation; detailed triggers/methodology were not independently confirmed in this pass.

Claims: CLM-NG-d6e7f8a9

Dpo RequirementsGreen

Data controllers of major importance must designate a Data Protection Officer with expert knowledge of data protection law and practice; the NDPC has also issued continuing professional development (CPD) guidance for verified DPOs.

Claims: CLM-NG-e7f8a9b0, CLM-NG-f8a9b0c1

Ropa RequirementsRed

No NDPA-specific primary-source confirmation of records-of-processing (ROPA) mechanics was retrieved; the predecessor NDPR was noted as not explicitly requiring GDPR-equivalent record-keeping obligations.

Claims: CLM-NG-a9b0c1d2

Joint Controller ArrangementsRed

No NDPA-specific primary-source confirmation of joint-controller apportionment mechanics was retrieved in this research pass.

Security MeasuresGreen

Section 39(1) of the NDPA requires data controllers and processors to implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data.

Claims: CLM-NG-b0c1d2e3

Breach NotificationRed

The predecessor Draft NITDA framework (pre-NDPA) required breach notification to NITDA within 72 hours of knowledge of the breach; whether an equivalent timeline is codified under the NDPA/GAID has not been independently confirmed.

Claims: CLM-NG-c1d2e3f4

Retention And DisposalAmber

Retention limits are implicit in the erasure obligation (Section 34) requiring erasure once data is no longer necessary, but a dedicated NDPA retention-schedule provision was not independently confirmed.

Category narrative63 words

The NDPA imposes accountability obligations including a data privacy impact assessment provision (Section 28), DPO designation for controllers of major importance, and security-of-processing duties (Section 39) requiring appropriate technical and organisational measures. Breach notification specifics under the current Act (as distinct from the predecessor NITDA 72-hour draft framework) and full ROPA/joint-controller mechanics were not independently confirmed with NDPA-specific primary text in this pass.

Sources and claims (6)
  1. ConfirmedNational Assembly Press, AbujaSection 28 of the NDPA establishes a data privacy impact assessment obligation as part of Part V of the Act.
  2. ConfirmedNational Assembly Press, AbujaData controllers of major importance under the NDPA must designate a Data Protection Officer with expert knowledge of data protection law and practices and the ability to carry out tasks prescribed under the Act and subsidiary legislation.
  3. UncertainOneTrust DataGuidanceThe NDPC has issued continuing professional development (CPD) guidance applicable to verified Data Protection Officers.
  4. UncertainOneTrust DataGuidanceThe predecessor NDPR did not explicitly require the record-keeping (records of processing) obligations equivalent to those required by the GDPR; whether the NDPA 2023 introduced an explicit ROPA requirement has not been independently confirmed.
  5. ConfirmedNational Assembly Press, AbujaSection 39(1) of the NDPA requires a data controller and data processor to implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data in its possession or under its control, including protection against accidental or unlawful destruction, loss, misuse, alteration or unauthorised disclosure.
  6. UncertainOneTrust DataGuidanceUnder the pre-NDPA Draft NITDA Framework, data handlers were required to report data breaches to NITDA within 72 hours of becoming aware of the breach; this framework was not approved and was not in effect, and its successor status under the NDPA/GAID has not been independently confirmed.

#

The core adequacy standard (Section 42) is confirmed from primary text; the operative adequacy list, SCC/BCR forms, TIA requirement and localisation posture under the current NDPC regime require further primary-source verification.

Primary frameworkNigeria Data Protection Act 2023, Section 42
Traffic-light rationale — AmberThe core adequacy standard (Section 42) is confirmed from primary text; the operative adequacy list, SCC/BCR forms, TIA requirement and localisation posture under the current NDPC regime require further primary-source verification.

Sub-modules (6)

Transfer MechanismsAmber

Section 42 of the NDPA conditions cross-border transfer on the receiving jurisdiction upholding principles substantially similar to the NDPA's own processing conditions.

Claims: CLM-NG-d2e3f4a5

Adequacy ReceivedRed

No evidence was found of any foreign regulator/EU-style body having granted Nigeria an inbound adequacy determination.

Adequacy GrantedAmber

Under the predecessor NDPR, NITDA compiled a 'White List' of jurisdictions considered to have adequate data protection law; whether the NDPC has published or carried forward an equivalent adequacy list under the NDPA has not been independently confirmed.

Claims: CLM-NG-e3f4a5b6

Sccs And BcrsAmber

The predecessor NDPR framework referenced BCRs/SCCs as documentation that could accompany data audit reports for transfers outside the White List; NDPA-specific SCC/BCR forms were not independently confirmed.

Claims: CLM-NG-f4a5b6c7

Transfer Impact AssessmentRed

No NDPA/GAID-specific transfer impact assessment requirement was independently confirmed in this research pass.

Data LocalisationRed

No general data-localisation mandate under the NDPA was independently confirmed in this research pass.

Category narrative87 words

Section 42 of the NDPA establishes an adequacy standard requiring that a third country/organisation uphold principles substantially similar to the NDPA's own conditions for processing personal data before cross-border transfer is permitted on that basis. The predecessor NDPR regime operated a NITDA-compiled 'White List' of jurisdictions deemed adequate and permitted SCC/BCR-style safeguards and consent-based derogations for non-White-List transfers; whether the NDPC has published an equivalent adequacy list or transfer-impact-assessment requirement under the NDPA/GAID was not independently confirmed. No NDPA-specific data-localisation mandate was identified in this research pass.

Sources and claims (3)
  1. ConfirmedNational Assembly Press, AbujaSection 42(1) of the NDPA provides that a level of protection is adequate for cross-border transfer purposes if it upholds principles substantially similar to the conditions governing the processing of personal data under the Act.
  2. UncertainNITDAUnder the predecessor NDPR framework, a 'White List' of jurisdictions considered to have adequate data protection law was compiled by NITDA (set out in Annexure C to the NDPR Implementation Framework); whether the NDPC has published an equivalent list under the NDPA has not been independently confirmed.
  3. UncertainNITDAUnder the predecessor NDPR Implementation Framework, a data controller could rely on documented consent or BCR/SCC-style documentation, includable in the data audit report, to justify transfers to jurisdictions outside the adequacy White List.

#

Financial and telecoms sector overlay is evidenced by NDPC enforcement action and major-importance criteria; other sector overlays (education, insurance, credit/scoring, employment) lack independently confirmed primary-source detail.

Primary frameworkNigeria Data Protection Act 2023 (sectoral application via 'major importance' criteria)
Traffic-light rationale — AmberFinancial and telecoms sector overlay is evidenced by NDPC enforcement action and major-importance criteria; other sector overlays (education, insurance, credit/scoring, employment) lack independently confirmed primary-source detail.

Sub-modules (7)

Financial Sector OverlayGreen

Commercial banks and payment gateway providers are explicitly captured in the top tier of 'major importance' entities, and the NDPC has fined banks (e.g., Fidelity Bank) for data protection violations.

Claims: CLM-NG-a5b6c7d8, CLM-NG-b6c7d8e9

Health Sector OverlayAmber

Health-sector organisations are captured within the 'major importance' criteria; no dedicated health-sector data code was independently confirmed.

Telecoms And EprivacyAmber

Telecommunications companies are explicitly named in the top tier of 'major importance' entities, and the NDPC and NCC have reportedly launched a joint data protection working group, though its substantive output was not independently retrievable.

Claims: CLM-NG-c7d8e9f0

Employment DataRed

No NDPA-specific employment-data code was independently confirmed in this research pass.

Credit And ScoringRed

No NDPA-specific credit-scoring rules were independently confirmed in this research pass.

EducationAmber

Education-sector entities are captured within the 'major importance' criteria; no dedicated education-sector code was independently confirmed.

InsuranceAmber

Insurance-sector entities are explicitly captured within the top tier of 'major importance' entities; no dedicated insurance-sector code was independently confirmed.

Category narrative73 words

The NDPC's 'major importance' criteria explicitly sweep in finance, communications/telecoms, health, education, insurance, aviation, oil and gas and electric power sector entities, and the NDPC has begun a sector-by-sector compliance investigation. A joint working arrangement between the NDPC and the Nigerian Communications Commission (NCC) on data protection was referenced in secondary sources but its substantive content was not independently retrievable. No confirmed sector-specific credit-scoring or dedicated employment-data code was identified in this pass.

Sources and claims (3)
  1. ConfirmedIAPPCommercial banks operating at national or regional levels and payment gateway service providers are designated data controllers/processors of major importance under NDPC guidance, subjecting them to heightened NDPA obligations.
  2. ProbableOneTrust DataGuidanceThe NDPC fined Fidelity Bank NGN 555.8 million for a data protection violation.
  3. UncertainOneTrust DataGuidanceThe NDPC and the Nigerian Communications Commission (NCC) have reportedly launched a joint data protection working group covering the telecoms sector, though the working group's substantive outputs were not independently retrievable in this research pass.

#

Only one concrete enforcement data point (MultiChoice) was confirmed; the sub-modules covering cookies, dark patterns, opt-out signals, clean rooms and direct marketing lack NDPA-specific primary-source confirmation.

Traffic-light rationale — RedOnly one concrete enforcement data point (MultiChoice) was confirmed; the sub-modules covering cookies, dark patterns, opt-out signals, clean rooms and direct marketing lack NDPA-specific primary-source confirmation.

Sub-modules (6)

Cookies And TrackersAmber

The predecessor NDPR Implementation Framework treated surfing a website after clear cookie notice as indicating consent; whether this standard persists under the NDPA/GAID was not independently confirmed.

Claims: CLM-NG-d8e9f0a1

Dark PatternsRed

No NDPA-specific dark-pattern prohibition was independently confirmed in this research pass.

Opt Out SignalsRed

No NDPA-specific recognition of technical opt-out signals (e.g., Global Privacy Control) was independently confirmed in this research pass.

Clean Rooms And DcrRed

No NDPA-specific clean-room or data-collaboration-room framework was independently confirmed in this research pass.

Cross Context AdvertisingRed

No NDPA-specific 'sale'/'share' cross-context advertising framework analogous to CPRA was independently confirmed in this research pass.

Direct MarketingAmber

The NDPC's fine against MultiChoice Nigeria concerned unlawful data transfers and privacy-rights violations, which touches on commercial data-sharing practices, but no dedicated direct-marketing consent/suppression rule was independently confirmed.

Claims: CLM-NG-e9f0a1b2

Category narrative70 words

The NDPC's July 2025 fine against MultiChoice Nigeria for unlawful data transfers and privacy-rights violations is the clearest evidence of commercial-privacy enforcement touching cross-border/vendor data flows. No NDPA-specific cookie-consent regime, dark-pattern prohibition, opt-out-signal recognition (e.g., Global Privacy Control), clean-room framework, or direct-marketing suppression rule was independently confirmed with primary-source detail in this research pass; the predecessor NDPR did address cookie consent via implied-consent-on-clear-notice language but this predates the current Act.

Sources and claims (2)
  1. UncertainNITDAUnder the predecessor NDPR Implementation Framework, continued surfing of a website upon clear notice was treated as indicating consent to cookie deployment, subject to disclosure requirements on website owners.
  2. ProbableOneTrust DataGuidanceThe NDPC fined Multichoice Nigeria NGN 766 million for unlawful data transfers and privacy rights violations.

#

No claims could be substantiated from the sources reviewed in this run.

Traffic-light rationale — RedNo claims could be substantiated from the sources reviewed in this run.

Sub-modules (6)

Profiling RestrictionsRed

No NDPA-specific profiling-restriction provision was independently confirmed in this research pass.

Automated Decision Making TransparencyRed

No NDPA-specific ADM transparency/explanation right analogous to GDPR Art 22 was independently confirmed in this research pass.

Ai Risk AssessmentsRed

No NDPA-specific AI risk-assessment regime was independently confirmed in this research pass.

Biometric RegimeRed

No NDPA-specific biometric-data regime was independently confirmed in this research pass.

Genetic DataRed

No NDPA-specific genetic-data regime was independently confirmed in this research pass.

State Surveillance CarveoutsRed

No NDPA-specific state-surveillance carve-out provision was independently confirmed in this research pass.

Category narrative40 words

No NDPA-specific profiling-restriction, automated-decision-making transparency right, AI-risk-assessment regime, biometric-data regime, genetic-data regime, or state-surveillance carve-out provision was independently confirmed with primary-source detail in this research pass. This module is emitted with an explicit absence finding rather than a fabricated obligation.

#

The Section 26/31 child-consent age threshold is confirmed from primary text; parental-consent mechanics, minor-profiling bans, and dependent-adult protections lack independent confirmation.

Primary frameworkNigeria Data Protection Act 2023, Sections 26, 31
Traffic-light rationale — AmberThe Section 26/31 child-consent age threshold is confirmed from primary text; parental-consent mechanics, minor-profiling bans, and dependent-adult protections lack independent confirmation.

Sub-modules (5)

Age VerificationGreen

The NDPA sets 13 as the age at which a child may give their own consent to information-society services under Sections 26(1)(a)/31(1)(a).

Claims: CLM-NG-f0a1b2c3

Minor Profiling BansRed

No NDPA-specific profiling ban on minors was independently confirmed in this research pass.

Education SettingsRed

No NDPA-specific education-settings data rule was independently confirmed in this research pass.

Dependent AdultsRed

No NDPA-specific dependent-adult protection was independently confirmed in this research pass.

Category narrative75 words

The NDPA sets a minimum age of 13 for a child's own consent to information-society services (Sections 26(1)(a)/31(1)(a)), operating without prejudice to the Child's Rights Act. No NDPA-specific parental-consent mechanism (as distinct from the child's own consent above age 13), profiling ban on minors, education-setting-specific rule, or dependent-adult protection was independently confirmed in this research pass; the predecessor NDPR was documented as not granting special protection to children's data or specifying parental consent verification requirements.

Sources and claims (2)
  1. ConfirmedNational Assembly Press, AbujaThe NDPA permits a data controller to rely on consent given directly by a child aged 13 years or older for purposes of Sections 26(1)(a) and 31(1)(a), specifically in relation to the provision of information and services by electronic means at the child's specific request, without prejudice to the Child's Rights Act.
  2. UncertainOneTrust DataGuidanceThe predecessor NDPR did not grant special protection to children's personal data and did not require data controllers to make reasonable efforts to verify that consent for processing a child's data was given by a parent or guardian; whether the NDPA changed this has not been independently confirmed.

#

Regulator powers and recent enforcement activity are well evidenced; collective redress, private right of action, and funding/capacity metrics beyond the statutory Fund mechanism lack independent confirmation.

Primary frameworkNigeria Data Protection Act 2023, Sections 19-22, 46-48
Traffic-light rationale — AmberRegulator powers and recent enforcement activity are well evidenced; collective redress, private right of action, and funding/capacity metrics beyond the statutory Fund mechanism lack independent confirmation.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Section 46 allows a data subject to lodge a complaint with the Commission; the Commission may investigate complaints or initiate investigations of its own accord (Section 46(3)); Section 47 allows compliance orders; Section 48(1)(a) sets penalties for major-importance entities greater than NGN10 million and 2% of annual gross revenue.

Claims: CLM-NG-b2c3d5e6, CLM-NG-c3d5e6f7

Enforcement Activity IndexGreen

Confirmed recent enforcement actions include fines against Fidelity Bank and MultiChoice Nigeria, and a sector-by-sector compliance investigation launched by the NDPC.

Claims: CLM-NG-d5e6f7a8, CLM-NG-e6f7a8b9

Regulator Funding And CapacityGreen

The NDPA provides the Commission with its own Fund, borrowing powers, and requires proper accounts subject to audit oversight by the Auditor-General for the Federation.

Claims: CLM-NG-f7a8b9c0

Collective Redress And Class ActionsRed

No NDPA-specific collective-redress or class-action mechanism was independently confirmed in this research pass.

Private Right Of ActionAmber

Section 46 establishes an administrative complaint route to the Commission; whether data subjects additionally have a standalone private right of direct court action distinct from the Commission complaint process was not independently confirmed.

Recent Developments 180DAmber

The clearest recent developments identified (GAID effective 19 September 2025; MultiChoice fine, July 2025) fall outside a strict 180-day window from the current date; the NDPC's CPD guidance for verified DPOs may be more recent but its precise publication date could not be confirmed in this research pass.

Claims: CLM-NG-a8b9c0d1

Category narrative88 words

The NDPC has active investigative and sanctioning powers under Sections 46-48 of the NDPA (complaint handling, compliance orders, and penalties), and has demonstrated enforcement activity including fines against Fidelity Bank (NGN 555.8M) and MultiChoice Nigeria (NGN 766M, July 2025) and the commencement of a sector-by-sector compliance investigation. The Commission is funded through its own Fund with borrowing power and Auditor-General oversight (Sections 19-22). Dedicated collective-redress/class-action mechanisms and a standalone private right of action distinct from the Section 46 complaint-to-Commission route were not independently confirmed in this research pass.

Sources and claims (6)
  1. ConfirmedNational Assembly Press, AbujaUnder Section 46 of the NDPA, a data subject aggrieved by the decision, action, or inaction of a data controller or data processor in violation of the Act may lodge a complaint with the Commission, and the Commission may also initiate an investigation of its own accord where it has reason to believe a violation has occurred or is likely to occur.
  2. ConfirmedIAPPUnder Section 48(1)(a) of the NDPA, the penalty for noncompliance by a data controller or processor of major importance may be a sanction or remedial fee greater than NGN10 million and 2% of the entity's annual gross revenue in the preceding financial year.
  3. ProbableOneTrust DataGuidanceThe NDPC fined Fidelity Bank NGN 555.8 million for a data protection violation.
  4. ProbableOneTrust DataGuidanceThe NDPC fined Multichoice Nigeria NGN 766 million for unlawful data transfers and privacy rights violations, and separately began a sector-by-sector investigation of NDPA compliance.
  5. ConfirmedNational Assembly Press, AbujaThe NDPA empowers the Commission to borrow sums of money as may be required to perform its functions, and requires the Commission to keep and maintain proper accounts and records subject to audit by the Auditor-General for the Federation.
  6. UncertainOneTrust DataGuidanceThe NDPC has issued continuing professional development (CPD) guidance for verified Data Protection Officers, though the precise publication date was not independently confirmed and may or may not fall within the last 180 days.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Indonesia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s), 13 source(s) in the cumulative register.