INTA Data Committee

Jurisdictions / Nigeria

Nigeria

Africa · Law stated as at Aug 2026

Overview — from the Part II reportFixed reference content

Nigeria's legal framework offers only partial and indirect protection for data as an IP asset. The Copyright Act 2022, the country's modernized copyright statute, protects compilations of data — including data stored in a computer or any medium — as literary works where they show creativity or originality in selection or arrangement. However, Section 2(5) makes clear that copyright in a compilation confers no rights over the raw data it contains, and Section 3(a) expressly excludes 'mere data,' ideas, procedures, and processes from protection.

Nigeria has no dedicated trade secrets law and has not fully domesticated TRIPS Article 39, so confidential business data is protected mainly through common law principles and private arrangements such as NDAs and non-compete agreements — with no formal statutory penalties for trade secret theft beyond contractual remedies. There is likewise no sui generis database right; calls for such protection in sectors like fintech and healthtech have not produced concrete legislative proposals. Privity of contract further limits recourse against third-party misuse of data.

The Nigeria Data Protection Act 2023 governs personal data processing but does not extend to non-personal data or datasets as proprietary assets, leaving a recognized gap for data as a commodified resource. Supplementary protection comes from Section 37 of the 1999 Constitution, which guarantees privacy, and the Cybercrimes Act 2015, which criminalizes unauthorized access to computer systems and unauthorized access, interception and data interference, reaching intangible assets such as data. Data itself remains difficult to patent under the Patents and Designs Act 2004.

Key takeaways

  • Copyright over compilations is the most prominent protection for databases in Nigeria, but it never reaches the underlying raw data.
  • Without a trade secrets statute, NDAs and confidentiality agreements are the main safeguards, and remedies are limited to contract claims.
  • The NDPA 2023 protects personal data only, leaving non-personal datasets without a proprietary protection regime.
  • The Cybercrimes Act 2015 provides criminal backstops against unauthorized access and theft of intangible assets, including data.
  • Privity of contract limits enforcement against third parties, so layered technical and contractual controls are advisable.

Primary legal instruments

Copyright Act 2022 (ss. 2(5), 3(a))Nigeria Data Protection Act 2023Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (ss. 6, 12)Constitution of Nigeria 1999, s. 37Patents and Designs Act 2004

AI-assisted summary of the report, editorially reviewed before publication · AI transparency

Protection mechanisms

Report-derived analysis per mechanism. The report text is fixed; committee members with contributor access can revise the rating (with an audit trail) and add notes below each block.

Recent Developments

Live updates contributed by committee members and the AI research bot — separate from the fixed report content above.

NITDA DG Calls for Evolved Regulatory Frameworks for Digital Banking and Data Systems

21 Aug 2026GuidanceFinalNITDAAI-generated

The Director General of the National Information Technology Development Agency (NITDA) highlighted the inadequacy of traditional regulatory tools for modern banking. He advocated for a shift towards real-time supervision and a broader ecosystem approach, emphasizing that financial stability now depends on digital stability. This includes adapting regulations to encompass evolving data systems and emerging technologies within the financial sector.

NITDA news & draft instruments

Multi-Agency Technical Committee Inaugurated to Advance National Sovereign Cloud Implementation

20 Aug 2026Rule changeApprovedNITDAAI-generated

The National Information Technology Development Agency (NITDA) and the Budget Office of the Federation have established a Joint Technical Committee for the National Sovereign Cloud Initiative. This committee will address fiscal, procurement, and investment aspects, with a focus on cybersecurity and data governance. The initiative aims to enhance efficiency, resilience, and optimize public sector digital infrastructure and data management.

NITDA news & draft instruments

NDPC and Governors' Forum Lead Sensitisation on Data Protection Act Implementation for State Governments

19 Aug 2026GuidanceFinalNDPCAI-generated

The Nigeria Data Protection Commission (NDPC), in collaboration with the Nigeria Governors’ Forum, conducted an implementation workshop for state government officials. This initiative aimed to sensitize Commissioners, Heads of Service, and Attorneys-General on the provisions of the Nigeria Data Protection Act, 2023, and its General Application and Implementation Directive. The workshop emphasized the critical role of state governments in fostering trust and compliance with national data protection policies.

NDPC news

Regulators Partner to Enhance Data Protection Compliance in Financial Sector

13 Aug 2026GuidanceNDPC#Trade Secrets#ContractsAI-generated

The Nigeria Data Protection Commission (NDPC) has partnered with the Securities and Exchange Commission (SEC) to ensure sector-wide compliance with the Nigeria Data Protection Act, 2023. This collaboration aims to strengthen the protection of investor data and promote adherence to data privacy principles within the financial sector. The NDPC urged the SEC to sensitize its staff and stakeholders on data protection, with both bodies exploring further cooperation to bolster data security.

NDPC news

NDPC extends first GAID-era Compliance Audit Return deadline to 30 May 2026 amid tightened audit enforcement

2 Apr 2026AI-generated

The Nigeria Data Protection Commission moved the filing deadline for 2025 Compliance Audit Returns from 31 March to 30 May 2026, in what is the first full audit cycle conducted under the General Application and Implementation Directive (GAID) 2025 that replaced the NDPR. Data controllers and processors of major importance must file through licensed Data Protection Compliance Organisations, and late filing attracts a 50% surcharge on the filing fee plus exposure to enforcement action. The Commission has signalled a stricter 2026 audit season, with sanctions of up to N10 million or 2% of annual gross revenue for non-compliant organisations.

Udo Udoma & Belo-Osagie (UUBO)