Nigeria’s federal government has directed all Ministries, Departments and Agencies (MDAs) to fully comply with the Nigeria Data Protection Act 2023, in a push to strengthen data governance across the public sector. The order is contained in Circular No. 59805/S.I/74 dated 27 July 2026 and signed by Secretary to the Government of the Federation George Akume.
The circular cites a directive from President Bola Tinubu stating: “Data is the new oil: its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023.”
Under the new requirements, every federal MDA must appoint a qualified Data Protection Officer (DPO) to oversee compliance and advise management on lawful processing of personal data. The names and contact details of these officers must be submitted to the Nigeria Data Protection Commission (NDPC) for registration. Agencies are also required to engage licensed Data Protection Compliance Organisations where necessary, allocate specific budgets for data-protection activities including training, technical safeguards and audits and submit mandatory compliance audit returns within statutory timelines.
In a notable enforcement shift, Permanent Secretaries, Accounting Officers and Chief Executive Officers of MDAs will be held personally responsible for ensuring their institutions comply with both the circular and the NDP Act.
The move comes as government digital services expand and public institutions handle growing volumes of citizen data. The NDP Act, passed in 2023, established the NDPC as the primary regulator and set out obligations for controllers and processors of personal data. The latest circular aims to close the gap between the law on paper and day-to-day practice inside government agencies.
NDPC National Commissioner Vincent Olatunji welcomed the political will behind the directive and said the commission remains committed to supporting data-driven governance while protecting citizens’ privacy. How consistently MDAs appoint DPOs, fund compliance work and file timely audits will determine whether the circular translates into stronger practical safeguards or remains largely administrative.


