Compliance in Nigeria: Data Protection Directives for Businesses

BY SEUN TIMI-KOLEOLU AND EBIKENIYE BEST

Introduction

As businesses in Nigeria increasingly leverage technology including social media platforms such as LinkedIn, Instagram, and Medium; and Emerging Technologies including Artificial Intelligence to expand their customer reach both locally and internationally, such businesses must adhere to Data Protection provisions in Nigeria.

In view of the foregoing, it is important to note recent updates to the protection of Personal Data in Nigeria. The most recent update is the Nigeria Data Protection Act – General Application and Implementation Directive (the “GAID”) issued on March 20, 2025, by the Nigeria Data Protection Commission (the “Commission”).

In this newsletter, we have set out useful information on the GAID to guide businesses.

1.     What is the effect of the GAID on the Nigeria Data Protection Regulation (NDPR), 2019?

With the adoption of the GAID, the NDPR shall no longer regulate data in Nigeria. Data Protection in Nigeria is now regulated by the existing Nigeria Data Protection Act and the GAID.

Please note, however, n that any act done under the NDPR prior to the issuance of the GAID remains valid.

2.    What are the obligations under the GAID for data controllers and processors?

Under the GAID, data controllers and processors of major importance are required to adhere to certain obligations including:

a.    engaging a licensed Data Protection Compliance Organisation (DPCO) to carry out an audit of their business within 15 (fifteen) months of commencing business and subsequently annually before March 31 of each year;

b.    filing a compliance audit report not later than March 31 of each year through a DPCO;

c.     appointing associate/assistant Data Protection Officers (DPOs) and privacy champions to support the DPO where the data controller or processor interfaces with data subjects on multiple platforms;

d.    storing personal data for not more than 6 (six) months after the purpose of processing the data has been achieved. Please note that this would only apply where no existing law has specified a retention period.

3.   In what circumstances is explicit consent required under the GAID?

The GAID acknowledges that consent as a lawful basis for processing personal data could be constructive or implied. It, however, states that explicit consent is required for certain activities like – direct marketing, processing children’s data and sensitive personal data, automated decision making and cross-border data transfer.

4.    Are there provisions for Emerging Technologies?

Yes, the GAID now provides explicit provisions on Emerging Technologies such as Artificial Intelligence, Blockchain, and the Internet of Things. It requires that any data controller or processor deploying or planning to deploy Emerging Technologies for personal data processing must adhere to the provisions of the NDPA, public policies, the GAID, and any other regulations issued by the Commission.

In addition, a data controller or processor must do the following:

a.    develop and implement technical and organizational frameworks for the design of Emerging Technologies tools, ensuring that these frameworks are properly documented and submitted to the Commission; and

b.    conduct a Data Privacy Impact Assessment, considering factors such as how data processing might unfairly affect different groups and the level of risk faced by vulnerable individuals, to access and reduce privacy risks effectively.

5.    Are there provisions on Data Ethics under the GAID?

Yes. In auditing data controllers and processors, DPCOs are required to confirm if data controllers and processors apply global best practices on Data Ethics when handling personal data. The DPCO must ensure that data controllers and processors possess: (i) organizational policy on ownership of data; (ii) demonstrable transparency and accountability; (iii) fairness of intention; and (iv) respect for data subjects’ rights to control the use of their personal data.

6.    What are the requirements for Cross-Border Data Transfer?

Under the GAID, a data controller or processor must obtain approval from the Commission before transferring personal data outside Nigeria. The Commission will grant approval based on an adequacy decision, which considers whether the receiving country has enforceable data subject rights; a robust data protection law; and a competent supervisory authority with sufficient enforcement powers.

In the absence of an adequacy decision, the data controller or processor will be required to prepare and submit a Cross-Border Data Transfer Instrument (the “Instrument”) for approval by the Commission. This Instrument may be in the form of (i) code of conduct; (ii) certification, (iii) binding corporate rules; or (iv) standard contractual clauses.

7.    Are data subject’s rights provided for under the GAID?

The GAID reinforces data subjects’ rights, including the right to access, right to rectification, right to data portability, right to be forgotten, right to lodge a complaint, and right to objection. Businesses are required to create transparent and easy to use processes to respond to these rights promptly.

8.    What is the procedure for lodging complaints under the GAID?

The GAID now allows data subjects who believe that their right to privacy has been violated to seek redress directly from data controllers by sending a document titled “Standard Notice to Address Grievance” to the relevant data controller or processor. A format of this document has been provided in the GAID. This action is to be taken without prior notification to the Commission.

9.    When will the GAID come into effect?

The Commission noted that for ease of doing business, the GAID shall take effect 6 (six) months from the date of publication, that is, September 2025.

Conclusion

To ensure compliance with Nigeria’s evolving data protection landscape, organizations should carefully review the key updates introduced by the GAID. To align with applicable data protection laws, organisations should engage the services of licensed DPCOs.

 

For more information on data protection compliance, please see our previous newsletter.

INFLUENCER AND DIGITAL MARKETING REGULATION IN NIGERIA

BY ADERONKE ALEX-ADEDIPE AND PROMISE ITAH

INFLUENCER AND DIGITAL MARKETING REGULATION IN NIGERIA

Introduction
As businesses continue to explore innovative ways to engage their target audience, influencer marketing and digital advertising (ads) have become increasingly popular. This marketing strategy presents significant opportunities for businesses and influencers alike. It is however essential for all parties involved to understand the legal implication of their activities to avoid potential legal pitfalls.

In this newsletter we highlight key legal aspects of influencer marketing and digital advertising which businesses, influencers, and digital marketers need to consider.

What is Influencer Marketing?

This occurs when businesses collaborate with individuals (influencers) who have a substantial following or influence on social media platforms, blogs, or other digital channels to promote products, services, or brands to their audience, leveraging their credibility and trust.

What is Digital Advertising?

This involves using online platforms, websites, and digital channels to promote products, services, or brands. This includes various strategies such as display ads, search engine marketing (e.g., Google ads), social media ads, email marketing, and video ads, all targeted toward specific demographics or user behavior.

What You Need to Know

1.Advertising and Marketing Content
As the primary regulatory body for advertising in Nigeria, the Advertising Regulatory Council of Nigeria (ARCON) sets the rules governing advertising activities, including those in the digital space, such as influencer marketing campaigns and online ads. The Advertising Regulatory Council of Nigeria Act (ARCON Act), the Code of Advertising Practice, and the Vetting Guidelines establish specific principles and requirements for advertising and marketing content and materials. Some key considerations  include:

  • Advertising and Marketing Principles: Marketing and advertising materials must be truthful, decent, and non-deceptive, ensuring they are appropriate for minors if the target audience includes them. Content should never exploit sexual behavior, promote superstition, or discriminate based on sex. It should also avoid misleading or exaggerating claims. Influencers who endorse brands and products must ensure that endorsements  they give are accurate and transparent, providing genuine recommendations. It is essential that brands and influencers constantly review their materials to ensure they comply.
  • Vetting of Advertisements and Marketing Materials: All marketing and advertising materials, including flyers and jingles intended for digital platforms, must undergo vetting by ARCON before publication. The only exceptions are vacancies, notices, financial statements, goodwill messages, obituaries, and immemorial ads. The Vetting Guidelines issued by ARCON provide the procedure to follow to obtain vetting approval for advertising and marketing materials before exposure to the public.
  • Failure to obtain vetting approval prior to exposure of the advertising or marketing materials attracts a fine of up to N1,000,000.00 (One Million Naira) per infraction from ARCON. The ARCON Act also makes failure to obtain vetting approval prior to exposure a crime punishable by both fine and imprisonment upon conviction.
  • Disclosure of Paid Partnerships: Influencers must clearly disclose any paid partnerships to maintain transparency and prevent misleading their audience by presenting paid promotions as organic content.

2.Consumer Protection
The Federal Competition and Consumer Protection Commission Act (FCCPCA) empowers the Federal Competition and Consumer Protection Commission (FCCPC) to maintain and protect consumer rights in Nigeria. Brands and influencers must avoid engaging in unfair or deceptive marketing practices that could harm consumers. Key things to look out for here include:

  • False Advertising & Consumer Rights: Both influencers and advertisers must avoid practices that mislead or deceive consumers. False or exaggerated claims about products or services can lead to consumer complaints and regulatory sanctions from the Federal Competition and Consumer Protection Commission (FCCPC).
  • Transparency in Pricing and Products: The FCCPC mandates clear and honest communication about product pricing and quality. Influencers must avoid making misleading claims, such as promising unrealistic results or misrepresenting product effectiveness.
  • Brands and influencers who engage in activities that violate these provisions and other consumer rights may be required to pay damages to consumers or face fines imposed by the FCCPC. Additionally, engaging in unfair and deceptive practices that infringe upon consumer rights is considered a criminal offense under the FCCPCA, which may result in fines and potential imprisonment for the brands and influencers involved.

3.Data Privacy and Protection
Personal data is sometimes often processed during the creation and publication of digital ads. Brands and influencers must therefore comply with the Nigeria Data Protection Act (NDPA) and other data protection laws and regulations when collecting, processing, and using consumer data. Key points include:

  • Data Collection and Consent: Businesses and influencers must obtain explicit consent before collecting or processing personal data of individuals, including using cookies or tracking data to target ads. Non-compliance with the NDPA may result in severe penalties.
  • Data Sharing and Security: Influencers and brands must ensure consumer data is securely stored and not shared without consent. If data is shared, there must be adequate protection provided for such data.

4.Intellectual Property
Influencers and businesses must be cautious about intellectual property laws when creating or sharing content. The Copyright Act in Nigeria governs the protection of original works, including photographs, videos, written content, and logos.

  • Use of Copyrighted Content: Influencers often share content provided by brands. Both brands and influencers must ensure that the content shared does not violate copyright laws. Proper licenses or permissions should be obtained for any third-party content used in marketing campaigns.
  • Trademarks and Branding: Brands must protect their logos, trademarks, and other intellectual property from unauthorized use through contractual arrangements. Influencers should avoid infringing on trademarks when promoting products.

5.Contractual Agreements and Legal Liabilities
Contracts between brands and influencers are essential for defining the scope of work, compensation, content requirements, timelines, and other terms. Clear written contracts help avoid misunderstandings and protect all parties involved. These contracts should include the following key provisions:

  • Terms and Conditions: Contracts should specify deliverables, payment schedules, content rights, and usage restrictions.
  • Breach of Contract: Both influencers and brands should be aware of their contractual obligations. Breaches may lead to legal disputes and claims for damages. Brands should include clauses that protect them against potential non-performance by influencers.

6.Social Media Platforms and Terms of Service
Influencers and advertisers must adhere to the terms of service of platforms like Instagram, Facebook, X (formerly Twitter), and TikTok. These platforms have specific rules regarding advertising, promotions, and sponsored content.

  • Platform Rules on Sponsored Content: Most platforms require influencers to disclose when content is sponsored or when they are paid to promote a product. Influencers must comply with these rules to avoid sanctions such as account suspension or banning.
  • Platform Liability: Brands and influencers must understand the platform’s role in digital advertising. While platforms provide the medium, they may not always enforce advertising laws. However, they can remove content that violates policies or legal standards.

Conclusion
As influencer marketing and digital advertising continue to grow in Nigeria, understanding the legal landscape is crucial for businesses, influencers, and marketers. Adhering to advertising, consumer protection, data privacy, and intellectual property laws can mitigate legal risks and ensure that marketing campaigns are conducted ethically and transparently. The foregoing is, however, not exhaustive, and we advise seeking legal counsel to effectively navigate legal aspects of influencer marketing and digital advertising.

Intellectual Property Protection in Nigeria’s Agricultural Sector

BY SEUN TIMI-KOLEOLU AND HILLAY OKOROTIE

INTRODUCTION

The agricultural sector is an important sector in Nigeria, with great potential to drive significant growth to the economy. There are various opportunities in the sector to create value which are largely untapped. One of these opportunities is with respect to the value that can be derived from the protection of Intellectual Property( “IP”) arising from innovative works- such as improved plant varieties, and new food processing technology amongst other novel works- developed by players in the agricultural sector.

In view of the foregoing, we have set out in this newsletter some IP protections available for innovative works in the agricultural sector to enable players in this space explore protecting their creative works and derive investment value amongst other values from such protection.

Plant Variety Protection (PVP)

One of the most significant developments in Nigeria’s agricultural IP landscape is the Plant Variety Protection Act (the “Act”) 2021. This legislation grants breeders the right to protect their IP in new plant varieties they develop. With protection under this Act, a breeder has the exclusive and sole  right to reproduce, export, or license their  proprietary right in the protected varieties. The Act also grants the breeder exclusive proprietary rights to the plant variety developed for a duration of 20 years. With this protection, the breeder will for a period of 20years from the date of registration, have the sole right to grant licenses to third parties to use the plant variety and obtain payment for granting such right. The breeder may also attract investments for his or her unique IP in the plant variety.

Patenting of Novel Agricultural Technology

Another form of protection available to stakeholders in the agricultural sector is a Patent. The sector can benefit from protecting novel technologies, such as novel food processing machines, mechanized farming tools and techniques by obtaining a Patent for such technologies.

An inventor who obtains a Patent for his or her agricultural technology invention will have exclusive proprietary right to the invention for up to 20 years. This means that where third parties wish to use the technology, they will have to obtain a license or similar rights from the inventor to use or reproduce that technology and make payments to the inventor for the grant of such rights.

It should be noted that a duly registered Patent has the potential to increase the investment value of the inventors business and drive investment to the business.

Protecting Trade Secrets and Trademarks

Another IP which can drive value to players in the agricultural sector is the Trade secret of the business such as formulas, business process, techniques and other confidential information that have played a key role in the success of the business. Such Trade secrets are valuable and can increase the investment value of businesses. Accordingly, Trade secrets should be guarded carefully to ensure they are not freely available in the public domain. To safeguard Trade secrets, businesses must implement confidentiality measures, this may include  non-disclosure and confidentiality clauses in agreements with potential investors, employees or consultants.

The Trademark of the agriculture business and products is also valuable IP which should be carefully guarded by registering the trademark at the Trademark registry. Please see our newsletter for more information with respect to trademarks.

Geographical Indication (GI)

Although Nigeria is yet to enact legislation protecting Geographical Indications (GIs), it is useful to note its potential to drive value to Nigeria.

GI are products originating from specific locations which can be registered by representatives of a country in relevant registries as IP of that country. For instance, “Champagne” is registered as a GI for France, “Argan” Oil for Morocco and “Darjeeling” tea for India.

Certain Nigerian products, like “Ijebu Garri” or “Amala,” could benefit from GI registration as they have gained international recognition and should be protected as IP belonging to Nigeria.

It is important that our policymakers establish a framework for the registration of Nigeria GIs at international trademark offices and within Nigeria.

GI registration would also help distinguish Nigerian agricultural products in the global food supply chain and create economic opportunities for the country’s agricultural sector. It would also prevent foreign competitors from marketing products as Nigerian-origin, thereby securing an exclusive market for Nigeria’s agricultural sector.

Conclusion

By effectively protecting IP, the Nigeria’s agricultural sector can drive innovative research, increase productivity, and create opportunities for employment. There is also the need for policy makers to provide the framework that would encourage registration of GI in various international trademark offices thereby providing distinction and marketability for Nigerian specific product in the global food supply chain.

For more information on Trademarks and Patents, please see our newsletters at

  1. https://pavestoneslegal.com/requirements-and-procedure-for-registration-of-trademarks-in-nigeria/
  2. https://pavestoneslegal.com/registering-patents-in-nigeria/

 

 

Compliance with Nigerian Data Protection Laws – The Role of Data Protection Compliance Organizations

BY ADERONKE ALEX-ADEDIPE AND OLAWALE ATANDA


Introduction

In an era where data breaches and privacy concerns are on the rise, organizations processing Personal Data must prioritize compliance. In Nigeria, data protection laws have evolved to ensure businesses and public institutions uphold data privacy standards.

The Nigeria Data Protection Act, 2023 (NDPA) and the Nigeria Data Protection Regulation, 2019 (NDPR) set out the legal obligations for entities that collect, process, and store personal data. To assist organizations in meeting these obligations, the Nigeria Data Protection Commission (NDPC) issues licenses to qualified Data Protection Compliance Organisations (DPCOs). These specialized firms provide guidance, conduct statutory data audits, and help businesses implement robust compliance frameworks.

This newsletter addresses the key responsibilities of DPCOs vis-à-vis the regulatory framework governing data protection in Nigeria.

Regulatory Framework for Data Protection Compliance Organizations

Section 33 of the NDPA empowers the NDPC to license DPCOs to monitor, audit, and report on data protection compliance. According to the NDPC, DPCOs may be Law Firms, Professional Service Consultants, IT Service Providers, or Audit Firms.

Only licensed DPCOs are authorized to conduct data protection audits.. Furthermore, Part 4.1(4) of the NDPR mandates DPCOs to provide training and compliance consulting to Data Controllers (and Processors).*

The NDPR mandates all organizations that process Personal Data to conduct audits of their privacy and data protection practices. These audits must detail the nature of Personal Data collected, purpose of collection, notice provided to Data Subjects*, policies and procedures for data protection, security measures, and other key compliance factors.

In addition, organizations that process up to 2,000 Data Subjects’ data within 12 months or up to 1,000 within 6 months must submit a Compliance Audit Report (CAR) to the NDPC by March 15 each year. Failure to meet this deadline will attract a penalty of 50% of the filing fee.

Core Functions of DPCOs

DPCOs provide a swathe of services in relation to data privacy and protection. For the purpose of this newsletter, we shall put these services into three main buckets – Data Audit Services, Data Compliance Implementation Services, and Data Protection Officer (DPO) Services.

1.Data Audit Services

A core function of a DPCO is conducting data audits to assess an organization’s compliance with the NDPA and NDPR. This process involves reviewing an organization’s data protection policies, assessing how personal data is collected, processed, stored, and shared, and identifying potential risks. The audit typically begins with an evaluation of the organization’s data protection framework, including privacy policies, data retention practices, security measures, and contracts with third-party processors. A DPCO will also interview key personnel who process data as part of their functions—such as compliance officers, IT teams, and HR representatives—to gauge awareness and ascertain if policies are effectively implemented in daily operations.

Beyond policy review, a data mapping exercise is done to trace the flow of personal data within the organization. Security measures, including encryption, access controls, and breach response plans, are also examined to identify vulnerabilities.

At the end of the audit, the DPCO issues a detailed report, highlighting compliance gaps, risks, and recommended corrective actions.

2. Data Compliance Implementation Services

Beyond audits, DPCOs also support organizations in implementing corrective actions to address compliance gaps. These include:

  • Developing internal policies that align with data protection laws, including privacy policies, terms of use, cookie policies, data protection policies, subject access request procedures, amongst others.
  • Providing data protection and privacy advisory services to help organizations understand and comply with their legal obligations to Data Subjects* and other third parties.
  • Conducting training and awareness programs to ensure employees are aware of data privacy risks and best practices.
  • Drafting and reviewing data protection contracts, including Data Processing Agreements (DPAs), Data Sharing Agreements (DSAs), and Binding Corporate Rules (BCRs) to establish legally compliant relationships with related and third parties.
  • Assisting in breach remediation by helping organizations develop response strategies for handling data breaches effectively.
  • Conducting due diligence investigations in cases of mergers, acquisitions, or partnerships to assess the data privacy risks associated with third-party engagements.
  • Representing organisations as a liaison with the NDPC for regulatory filings and compliance matters.

3. Outsourced Data Protection Officer Services

Part 4.1. (3) of the NDPR requires every Data Controller and Processor to have a Data Protection Officer (DPO). However, some organizations may not have the resources to appoint an internal DPO. DPCOs fill this gap by offering outsourced DPO services to ensure that organizations meet this requirement without needing to hire a full-time in-house expert.

An outsourced DPO performs various functions, including:

  • Overseeing data protection impact assessments (DPIAs) for high-risk processing activities.
  • Ensuring that the organization maintains records of data processing activities as required by law.
  • Providing ongoing advisory support to senior management on data protection risks and obligations.
  • Conducting data protection awareness training to equip staff with the necessary knowledge to handle personal data responsibly.
  • Acting as the primary liaison between the organization and the DPCO as it delivers data protection services to the organization.

Outsourced DPO services are especially valuable to startups, SMEs, and multinational companies operating in Nigeria, as they provide expert compliance oversight without the burden of a full-time hire.

Conclusion

DPCOs play a vital role in helping businesses navigate regulatory requirements through data audits, compliance implementation, and outsourced DPO services. Engaging a DPCO strengthens data governance, mitigates risks, and fosters trust. This ensures organizations stay compliant while maintaining a secure posture in an evolving data landscape.

 

Endnotes

  • Data Controller – An organization that decides why and how personal data is collected and used. For example: A bank collecting customer details for account creation.
  • Data Processor – A third party that processes personal data on behalf of the Data Controller based on their instructions. For example: A cloud storage provider storing customer data for a bank.
  • Data Subject – The individual whose personal data is being collected or processed. For example: A customer whose name, email, and phone number are stored by the bank.

For more reading on data protection in Nigeria, we invite you to explore our collection of articles here – https://pavestoneslegal.com/newsletters/