Federal Government has directed all Ministries, Departments and Agencies (MDAs) to fully comply with the provisions of the Nigeria Data Protection Act (NDP Act) 2023, as part of efforts to strengthen responsible data governance and build public trust in data-driven public administration.
The directive is contained in Circular No. 59805/S.I/74, dated July 27, 2026, and signed by the Secretary to the Government of the Federation (SGF), Senator George Akume.
According to the circular, the directive follows President Bola Tinubu’s instruction that all government institutions must ensure the rigorous collection and secure management of personal data in accordance with the Nigeria Data Protection Act.
The President was quoted as saying: “Data is the new oil: its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023.”
The circular mandates MDAs to ensure full compliance with the NDP Act, its regulations, guidelines and directives issued by the Nigeria Data Protection Commission (NDPC) regarding the processing of personal data.
To achieve this, every MDA is required to appoint a suitably qualified Data Protection Officer (DPO) responsible for overseeing compliance and advising management on lawful data processing practices.
The agencies are also required to register the names and contact details of their designated DPOs with the NDPC and engage licensed Data Protection Compliance Organisations (DPCOs), where necessary, to support compliance and conduct statutory data protection audits.
In addition, the Federal Government directed MDAs to make adequate budgetary provisions for data protection compliance activities, including staff capacity building, awareness programmes, deployment of technical safeguards and periodic compliance audits.
The circular further requires all MDAs to submit mandatory Data Protection Compliance Audit Returns and other statutory reports to the NDPC within the timelines stipulated by law.
It also places responsibility for compliance squarely on the leadership of government institutions.
According to the circular, Permanent Secretaries, Accounting Officers and Chief Executive Officers of all MDAs will be held personally accountable for ensuring full compliance with the directive and the provisions of the Nigeria Data Protection Act.
Reacting to the development, the National Commissioner and Chief Executive Officer of the Nigeria Data Protection Commission, Dr. Vincent Olatunji, commended the administration of President Tinubu for demonstrating strong legal and political commitment to protecting the privacy and fundamental rights of data subjects in Nigeria.
Olatunji said the Commission remained committed to supporting government institutions in implementing effective data governance frameworks, noting that data accountability is critical to achieving the administration’s eight Presidential Priorities.
He disclosed that the NDPC had established a regulatory clinic to provide technical guidance and support to MDAs in meeting their compliance obligations.
According to him, the initiative is part of ongoing regulatory measures aimed at strengthening Nigeria’s data governance ecosystem as the country positions itself to harness opportunities presented by the Fourth Industrial Revolution.
![]()





















































