The Federal Government has directed all Ministries, Departments and Agencies (MDAs) to appoint Data Protection Officers (DPOs), register them with the Nigeria Data Protection Commission (NDPC), and fully comply with the provisions of the Nigeria Data Protection Act (NDPA), 2023.
The directive was conveyed in a compliance circular signed by the Secretary to the Government of the Federation (SGF), Senator George Akume, which places personal responsibility on Permanent Secretaries, Accounting Officers and Chief Executive Officers of MDAs for ensuring compliance with Nigeria’s data protection laws.
Dated July 27, 2026, Circular No. 59805/S.I/74 forms part of the Federal Government’s efforts to strengthen data governance and improve public confidence in the management of citizens’ personal information.
According to the circular, the directive follows an instruction from President Bola Tinubu, who described data as a strategic national asset requiring stronger protection.
“Data is the new oil: its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023,” the President was quoted as saying.
The circular requires all federal MDAs to comply fully with the Nigeria Data Protection Act, related regulations, guidelines and directives issued by the NDPC governing the processing of personal data.
It also directs every MDA to appoint suitably qualified officers as Data Protection Officers responsible for overseeing compliance and advising management on lawful data processing practices.
In addition, agencies are required to submit the names and contact details of their designated DPOs to the NDPC for registration.
Where necessary, MDAs are expected to engage licensed Data Protection Compliance Organisations (DPCOs) to conduct mandatory compliance audits and support implementation efforts.
The government further instructed agencies to make adequate budgetary provisions for data protection activities, including staff training, public awareness programmes, technical safeguards and periodic compliance audits.
MDAs are also required to submit all mandatory Data Protection Compliance Audit Returns and other statutory filings to the NDPC within the timelines prescribed by law.
The circular states that Permanent Secretaries, Accounting Officers and Chief Executive Officers will be held personally accountable for ensuring compliance with the directive.
Reacting to the development, National Commissioner and Chief Executive Officer of the NDPC, Dr. Vincent Olatunji, commended the Tinubu administration for demonstrating strong political commitment to protecting the privacy and fundamental rights of Nigerians.
He said the Commission had established a regulatory clinic to provide technical support to MDAs implementing the new requirements.
According to the NDPC, the directive forms part of broader efforts to strengthen Nigeria’s data governance framework as the country advances its digital transformation agenda and prepares for the opportunities presented by the Fourth Industrial Revolution.















