A loan application in Lagos can be processed in under two seconds. This is possible because an algorithm evaluates the applicant’s financial and repayment history, her phone metadata, and the creditworthiness of the people in her contacts list, all in a twinkle of an eye without human reviews. In most cases for low-income earners, it returns a rejection, and for high-income applicants, it reads “loan approved”.

This is not an inequality that future regulation needs to address. It is already covered by an existing law. Section 37 of the Nigeria Data Protection Act 2023 (NDPA), gives every Nigerian the right not to be subjected to a decision “based solely on automated processing” where that decision produces legal effects or similarly significant effects, unless the processing is necessary for a contract, authorised by law, or based on explicit consent. This provision predates the current wave of AI adoption in Nigeria.

Unfortunately, most companies building or deploying AI systems in the country do not appear to know such law exists, or perhaps do not agree it applies to AI systems.

THE AI LAW DEBATE

The public conversation about AI regulation in Nigeria tends to follow one of two scripts. There are arguments that clear rules must be established before responsible development is possible. The Nigerian government has also declared that a dedicated AI law is being developed and will address these questions in time. These positions ignore the possibility that a functioning legal framework already exists, applies to the systems in question, and the Nigeria Data Protection Commission (NDPC) has already invoked it.

Consider what the NDPC has done since the Act came into force. In August 2024, it fined Fidelity Bank ₦555.8 million after finding that the bank processed personal data without informed consent, used non-transparent cookies in its mobile banking app, and relied on third-party data processors that were themselves non-compliant with the Act. Though Fidelity disputed the finding, the case shows the Commission is prepared to fine a listed financial institution over consent and vendor-management failures, not just data breaches in the conventional sense.

They in July 2025, the NDPC fined MultiChoice Nigeria ₦766.2 million for processing subscriber data without valid consent and transferring personal data outside Nigeria without the safeguards or approval the Act requires. And in February 2025, the Commission fined Meta $32.8 million for carrying out behavioural advertising on Facebook and Instagram without obtaining Nigerian users’ explicit consent, and for transferring their data abroad without prior authorisation. As part of that action, the NDPC ordered Meta to revise its privacy policies, obtain proper consent before behavioural advertising, conduct a data privacy impact assessment, and stop transferring user data outside the country without approval.

All the three cases turned on ordinary provisions of the NDPA, namely lawful basis for processing (section 25), consent (section 26), cross-border transfer safeguards (Part VIII), and the duty to ensure third-party processors also comply (section 29). While none involved an “AI law”, behavioural advertising, the practice at the centre of the Meta fine, is itself a form of algorithmic profiling. The Commission treated it as a straightforward data protection violation under the data protection law, without needing a separate AI-specific legislation.

THE AI (DATA) RULES

While exercising its power under the NDPA, the NDPC issued a directive in 2025 called the General Application and Implementation Directive (GAID). This directive goes further than the Act itself in naming artificial intelligence directly.

Article 28 of the GAID makes a data privacy impact assessment (DPIA) mandatory, and requires it to be filed with the Commission, wherever processing involves profiling, automated decision-making with legal or similarly significant effects, systematic monitoring, or the deployment of new technological solutions that could pose a significant risk to privacy. The same article lists financial services conducted through digital devices, healthcare services and educational services among the sectors where a DPIA is required. A DPIA under this article must be reviewed and signed by a Data Protection Officer accredited by the Commission before the system goes live.

Article 18(1)(f) of the GAID requires consent specifically before a controller makes a decision “based solely on automated processing which produces legal effects” or significantly affects the data subject. This sits alongside, and tightens, section 37 of the Act that it is not enough to identify some other lawful basis for a solely automated decision with serious consequences, consent is required in that specific circumstance.

Article 43 of the GAID is the most direct AI provision in Nigerian law. It applies to any controller or processor that “deploys or intends to deploy Emerging Technologies (ETs) such as Artificial Intelligence, Internet of Things and Blockchain” to process personal data. It requires such a party to document technical and organisational parameters for the processing, assess “disparate outcomes” of the system, test the technology in low-risk environments, and repeat the test-and-retool cycle until the outcomes are satisfactory — or discard the tool altogether if the privacy risk cannot be reduced. Article 44 goes further, instructing controllers and processors to refrain from, or cease, using AI systems that are “impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights.”

Article 41 imposes a separate data-ethics duty, emphasizing that discrimination on the basis of gender, ethnicity, religion, physical ability, or any other characteristic is prohibited in data processing, and safeguards must be in place to prevent the creation of profiles or algorithms that lead to prejudiced outcomes.

These are not proposals, strategies, or policies, they are current regulatory text, and the Commission’s record on Fidelity Bank, MultiChoice and Meta shows it is prepared to impose penalties for the underlying failures that AI systems might reproduce at scale.

THE DATA MINIMISATION

A common justification for disregarding these rules is that data protection law and AI development are fundamentally incompatible. Some argue that AI systems require large volumes of data, the significance of which is incomprehensible to data protection law. This framing is inaccurate. Section 24 of the NDPA lists data minimisation as one principle among several others, namely lawfulness, fairness, transparency, purpose limitation, storage limitation, accuracy, and accountability, and none of them restricts the volume of data a system may use. What section 24 requires is that an organisation must be able to justify why each category of data collected is necessary for a specific, stated purpose.

A credit-scoring model trained on years of repayment records across a large customer base does not violate this principle, provided that data is relevant to assessing creditworthiness. Meanwhile, a model that collected data from a user’s phone contacts because it was accessible, not because it was necessary, does violate this principle. This was true before AI systems made such collection technically easier, and it remains true now.

The more difficult problem, which receives less attention in public discussion, concerns data subject rights after a model has been trained. Once personal data has been used to train a machine learning model, it is technically difficult to fully remove that data’s influence from the model in response to an erasure request. Article 43(2)(b) of the GAID refers to this problem by pointing developers toward synthetic data and tokenisation as ways to reduce reliance on personal data in the first place, and Article 49(3) of the GAID sets a default storage limit for six months, in the absence of a specific legal basis for longer retention and after the original purpose has been accomplished.

CONSENT NOT ‘UNLIMITED’

Many companies rely on consent obtained through terms-of-service agreements to justify data processing for AI systems. Section 26 of the NDPA requires that consent be freely given, specific, informed, and unambiguous, and specifies that silence or inactivity does not constitute consent. Article 17 of the GAID adds that a data controller must keep proper records of how consent was obtained, must make withdrawal of consent as easy as giving it, and must ensure that refusal of consent is not detrimental to the data subject.

This approach has a structural weakness in AI contexts. A user cannot meaningfully consent to a use of their data that the company itself has not yet determined, which describes a substantial portion of how machine learning systems generate new inferences from existing data. Nigerian law reflects an awareness of this limitation in a different way. Article 17(2) of the GAID states that where reliance on consent would “effectively defeat the rule of law,” another lawful basis may be considered instead; but Article 17(5) then subjects any non-consent basis that is not supported by a defined set of “Special Rule of Law Indexes” to strict scrutiny during compliance audits and in any proceeding. In other words, the law does not let a company simply substitute a vague “legitimate interest” claim for consent, it treats that substitution as something that must be justified and that will be tested closely if challenged. Article 18(1) then lists the specific situations where consent is not optional at all as follows: direct marketing, sensitive personal data, further processing incompatible with the original purpose, children’s data, cross-border transfers to countries without an adequacy decision, and, again, solely automated decisions with legal or significant effects.

A general consent clause obtained at account signup does not satisfy this requirement for every subsequent use of a person’s data, and the Meta case is a direct illustration. The NDPC’s finding was not that Meta collected data without any consent mechanism at all, but that the consent obtained did not cover behavioural advertising and cross-border transfer specifically. The same applies to any company deploying AI systems wherein could get consent for processing their customers data, but not consent to be used to process automated decisions.

The practical stakes are clearest in sectors like consumer lending, recruitment, insurance, and healthcare. Article 28(3) of the GAID identifies sectors such as financial services through digital devices, health care, and education, as requiring a documented risk assessment before an automated system can be deployed. In practice, “human review” of an automated decision in these sectors often consists of an employee approving an output they have neither the time nor the authority to meaningfully question.

There is relevant precedent from outside Nigeria that is likely to inform how Nigerian regulators and courts read section 37. The Court of Justice of the European Union ruled, in Case C-634/21 (OQ v Land Hessen, the SCHUFA case), that the generation of a credit score can itself constitute an automated decision if a third party relies on that score heavily enough when making a subsequent decision. The court further ruled that an automated credit score generated by a credit reference agency counts as prohibited "automated individual decision-making" under Article 22 of the GDPR. No Nigerian court has yet ruled on this specific question. However, the underlying principle that a person should not be denied access to credit, employment, or insurance by a process they cannot question or appeal is already established in Nigerian statute, independent of how future case law develops.

WHAT NOW?

To regulate AI, the most immediate need is not new legislation but clear guidance on the legislation that already exists. The NDPC could issue a single guidance document that translates the requirements of Article 43 into a process a compliance team could actually implement and references the Fidelity Bank, MultiChoice and Meta decisions as worked examples of what non-compliance looks like in practice.

To avoid establishing a separate and potentially conflicting regulatory structure, NDPA could be amended to incorporate more AI-specific provisions. Section 63 of the Act already states that it takes precedence over inconsistent legislation on this subject. Creating two regulators with overlapping authority over the same activity would increase compliance costs without increasing the level of protection for individuals.

A lower-cost measure would be the development of free, standardised compliance templates, for example, a data privacy impact assessment template tailored to common AI use cases, aimed at smaller companies that cannot afford dedicated compliance staff. Larger financial institutions and telecommunications companies already have the resources to interpret and apply these rules, and the enforcement record shows they are not necessarily getting it right either. Smaller AI developers, who represent a significant share of the sector’s activity, generally have fewer resources still.

Industry experts and lawmakers need to look at the issue of AI governance again and understand that the underlying issue is not an absence of applicable law, it is the absence of clear, accessible guidance connecting existing law and existing enforcement decisions to current AI development practices. Every AI company processing personal data in Nigeria today is already operating within a defined regulatory framework, regardless of whether that framework has been clearly communicated to them, and the NDPC has already shown, three times over, that it is willing to act on it.