Introduction

Artificial Intelligence (AI) is rapidly reshaping economies, governance, and social systems worldwide. In Nigeria, the convergence of AI and data governance has emerged as a critical policy frontier. As the country accelerates its digital transformation, the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025 (GAID) provide a foundational legal framework for the responsible development and deployment of AI systems. This policy brief explores the legal architecture, identifies key tensions between AI and data protection, and proposes actionable recommendations for harmonising innovation with rights-based governance.

Conceptual Framework

The responsible development of Artificial Intelligence (AI) in Nigeria is anchored on a triad of regulatory, strategic, and ethical instruments. These include the Nigeria Data Protection Act 2023 (NDPA), the General Application and Implementation Directive 2025 (GAID), and the National Artificial Intelligence Strategy 2025 (NAIS). Together, they form the conceptual backbone for AI governance in Nigeria.

The NDPA 2023 replaces the Nigeria Data Protection Regulation 2019 and introduces a rights-based approach to data governance. It establishes principles such as lawfulness, fairness, transparency, data minimisation, purpose limitation, and accountability. The Act applies to any entity domiciled in, resident in, or processing personal data of individuals in Nigeria, regardless of the location of the data infrastructure or processing activities. It also introduces obligations for Data Controllers and Processors of Major Importance (DCMIs/DPMIs), including mandatory registration, Data Protection Impact Assessments (DPIAs), and the designation of Data Protection Officers (DPOs).

GAID 2025 operationalises the NDPA by detailing compliance expectations and enforcement mechanisms. It clarifies the thresholds for classification as a DCMI/DPMI and outlines sector-specific responsibilities, particularly for entities deploying AI systems that process personal or sensitive data.

The NAIS 2025 complements this regulatory framework by articulating Nigeria’s strategic vision for AI. It promotes ethical, inclusive, and sustainable AI development, with a focus on sectoral transformation, capacity building, and global competitiveness. The strategy proposes the establishment of an AI Ethics Expert Group (AIEEG), the adoption of national AI principles, and the development of standardised tools for algorithmic impact assessment.

The Core Conflict: Data Volume Versus Data Minimisation

AI systems, particularly those based on machine learning and large language models (LLMs), require vast datasets to function effectively. These systems often ingest and process large volumes of structured and unstructured data, including personal and sensitive information. However, the NDPA mandates data minimisation, requiring that only data necessary for a specific, lawful purpose be collected and processed.

This creates a regulatory paradox: while AI innovation thrives on data abundance, data protection law demands restraint. For instance, LLMs trained on publicly available internet data may inadvertently process personal data without consent or clear purpose, potentially violating the NDPA’s principles of purpose limitation and minimisation.

The Legal Basis: Consent is Insufficient on Its Own

Under the NDPA, consent must be freely given, specific, informed, and unambiguous. Silence, inactivity, or pre-selected options do not constitute valid consent, and withdrawal must be as easy as giving it. However, in AI contexts, relying solely on consent is problematic. Users may not fully understand how their data will be used, especially in opaque algorithmic systems. Moreover, AI systems often process data indirectly or inferentially, beyond what users explicitly provide.

Therefore, data controllers must consider alternative legal bases such as legitimate interest, public interest, or contractual necessity. These must be supported by robust DPIAs and documented risk assessments to ensure compliance and accountability.

The AI-Specific Right: Automated Decision-Making

Section 37 of the NDPA introduces a critical safeguard: individuals must not be subject to decisions based solely on automated processing, including profiling, unless such processing is necessary for a contract, authorised by law, or based on explicit consent. Even in such cases, data subjects have the right to obtain human intervention, express their point of view, and contest the decision.

This provision directly impacts AI systems used in high-stakes domains such as credit scoring, recruitment, and healthcare triage. Developers and deployers of AI must ensure explainability, fairness audits, and human oversight mechanisms. The NAIS reinforces this by promoting ethical AI development and requiring standardised tools to evaluate algorithmic impact.

Actionable Recommendations

Mandate DPIAs for High-Risk AI Systems: All AI deployments involving personal data or automated decision-making should undergo DPIAs, assessing risks and mitigation strategies in line with NDPA sections 54–57.

Establish Sector-Specific AI Guidelines: Regulatory bodies such as the Nigerian Communications Commission (NCC) and the Securities and Exchange Commission (SEC) should issue tailored rules for AI use in telecoms, finance, healthcare, and education, aligned with NDPA and NAIS.

Promote Algorithmic Transparency: Require AI providers to disclose model logic, training data provenance, and bias mitigation efforts, especially for public-facing systems.

Strengthen Consent Mechanisms: Develop user-friendly interfaces for consent collection and withdrawal, with layered explanations of data use in AI systems.

Support Local AI Innovation with Ethical Oversight: Invest in AI Centres of Excellence and fund startups that embed NDPA-compliant data governance and ethical design from inception.

Operationalise the AI Ethics Expert Group (AIEEG): Empower the AIEEG to audit AI systems, advise regulators, and engage civil society on ethical concerns.

Conclusion

Nigeria stands at a pivotal moment in its digital transformation journey. The convergence of AI and data governance demands a forward-looking approach. While the NDPA and GAID 2025 provide a solid legal foundation, their effective implementation requires sectoral coordination, ethical foresight, and inclusive innovation. By aligning AI development with rights-respecting data practices, Nigeria can harness AI’s transformative potential while safeguarding its citizens’ dignity and autonomy.

Reference

Nigeria Data Protection Act 2023, ss 2–3, 44–47.

Nigeria Data Protection Commission, General Application and Implementation Directive 2025 (NDPC, 2025).

National Information Technology Development Agency, National Artificial Intelligence Strategy 2025 (NITDA, 2025) https://ncair.nitda.gov.ng/wp-content/uploads/2025/09/National-Artificial-Intelligence-Strategy-19092025.pdf accessed 12 October 2025.

Nigeria Data Protection Act 2023, s 44(1)(c).

White & Case LLP, ‘AI Watch: Global Regulatory Tracker – Nigeria’ (White & Case, 2025) https://www.whitecase.com/insight-our-thinking/ai-watch-global-regulatory-tracker-nigeria accessed 12 October 2025.

Nigeria Data Protection Act 2023, ss 49–51.

Balogun Harold, ‘Artificial Intelligence in Nigeria: Key Regulatory Considerations’ (Mondaq, 2025) https://www.mondaq.com/nigeria/new-technology/1656714/artificial-intelligence-in-nigeria-key-regulatory-considerations accessed 12 October 2025.

Nigeria Data Protection Act 2023, s 37.

Paradigm Initiative, Towards a Rights-Respecting Artificial Intelligence Policy for Nigeria (2021) https://paradigmhq.org/wp-content/uploads/2021/11/Towards-A-Rights-Respecting-Artificial-Intelligence-Policy-for-Nigeria.pdf accessed 12 October 2025.