The enforcement of the Nigeria Data Protection Act (NDPA), since its enactment in 2023, has been largely focused on the private sector of the economy. Companies like Meta and Multichoice were victims of the Nigeria Data Protection Commission (NDPC)’s investigations and fines. While all these are happening, government institutions that process larger amounts of data, meanwhile, sit mostly on the other side of the table—unregulated.
That changed on 27 July 2026, when the Secretary to the Government of the Federation, Senator George Akume, signed Circular No. 59805/S.I/74. This new directive instructs every federal ministry, department, and agency to comply fully with the NDPA, appoint a qualified Data Protection Officer (DPO), and register that officer with the NDPC. The NDPC made the directive public a week later, framing it around a line from President Bola Tinubu: that data, like oil, becomes more valuable the more it is refined and responsibly shared.
The directive is timely and the legal question underneath it is more interesting: did this circular actually change anything, or did it just say out loud what the law already required?
Why Now?
According to the NDPC, there are three phases to NDPA enforcement or what it described as its own maturity curve. The first is education and awareness, followed by investigation and sanctions against private data controllers. By early 2026, that second phase had resulted in over 240 investigations, 11 major enforcement actions taken, and roughly ₦7.2 billion collected from registration fees, compliance revenues and fines.
The circular arrives just as the NDPC enters its final phase: full enforcement mode, where critical data controllers and processors, including government agencies, are being told to comply. With this move and its track record, the NDPC is more than a credible messenger still finding its feet.
What Does the Law Already Say?
Section 32(1) of the NDPA already requires any “data controller of major importance” to appoint a DPO. This caveat has been defined as a category defined by the NDPC's own Guidance Notice on Registration as, broadly, any entity processing the personal data of more than 200 people within six months, or one the Commission otherwise considers significant to the economy, society or security of Nigeria. Government MDAs, which hold national identity numbers, tax records, health data and biometric information at a scale most private companies can only imagine, comfortably meet that bar.
In addition to this, the General Application and Implementation Directive (GAID) already extended DPO obligations explicitly to public-sector bodies, with effect from 19 September 2025. So the July 2026 circular is not entirely writing a new law. It is restating, with presidential weight behind it, a duty that technically existed ten months earlier.
So What Actually Changed?
The circular fixes personal responsibility. It named individuals responsible for non-compliance. And for government agencies, the circular identifies certain categories of people, including permanent secretaries, accounting officers, and chief executives of MDAs. These sets of people are now responsible for their institution's compliance.
This is why the immediate audience for the circular is public servants, but the practical effect goes beyond them. Any private organisation that shares personal data with a government MDA should expect its government counterpart to start asking questions about lawful basis, retention, purpose limitation and security, especially now that a named DPO is formally responsible for answering them. Data-sharing arrangements that were informal will have to become formal by necessity.
There's also another signal here for the private sector generally. If the NDPC can credibly tell a federal ministry to fall in line, its patience and leniency with under-compliant private controllers and processors is unlikely to be growing.
We cannot be certain that this circular will be enforced the way it reads. Nigeria's data protection regime has always focused almost exclusively and entirely on private industry. Over the coming months and years, we will need to find out if a permanent secretary can actually answer for a compliance failure the way a fintech founder would, and that exactly is the factor for determining whether the government is ready to allow the NDPA to enter its enforcement stage.
