The Nigeria Data Protection Act 2023 is built on the same frame as the EU General Data Protection Regulation: the same six lawful bases, near identical principles, a 72 hour breach notice to the regulator, impact assessments for high risk processing and a familiar list of data subject rights. A GDPR programme therefore carries most of the way. It does not carry all of it. The NDPA adds a registration duty with the Nigeria Data Protection Commission for controllers and processors of major importance, a line the Commission draws at more than 200 data subjects in six months; annual Compliance Audit Returns for the two higher tiers; a 72 hour breach notice to the regulator with no "where feasible" softening of the deadline and a notice to data subjects that must be immediate; penalties set as the greater of a naira floor and 2% of annual gross revenue; and its own test for moving data out of Nigeria. If you operate in Nigeria and also serve people in the EU, or the reverse, you are under both, and the gaps are where the work is.
This guide sets the two side by side from the text of each law and the Commission's 2025 General Application and Implementation Directive, the GAID. For the NDPA duties section by section, start with Nigeria NDPA requirements explained.
| GDPR | NDPA | |
|---|---|---|
| Instrument | Regulation (EU) 2016/679, applying from 25 May 2018, Article 99(2) | Nigeria Data Protection Act 2023, Act No. 37, commencing 12 June 2023 |
| Regulator | Independent supervisory authorities in each Member State | The Nigeria Data Protection Commission, established by section 4 |
| Reach | Establishment in the Union, or offering goods or services to, or monitoring, people in the Union, Article 3 | Operating in Nigeria, processing in Nigeria, or processing the data of a data subject in Nigeria, section 2(2) |
| Lawful bases | Six, Article 6(1) | The same six, section 25(1) |
| Registration | None | Controllers and processors of major importance register with the Commission, section 44 |
| Breach notice to regulator | Without undue delay and, where feasible, within 72 hours, Article 33(1) | Within 72 hours of becoming aware, section 40(2); the deadline has no where feasible |
| Maximum penalty | EUR 20 million or 4% of total worldwide annual turnover, whichever is higher, Article 83(5) | The greater of 10 million naira and 2% of annual gross revenue, section 48(4) |
What is the difference between GDPR and the NDPA?
Less in the principles than in the machinery around them. Section 24(1) of the NDPA requires personal data to be "processed in a fair, lawful and transparent manner", "collected for specified, explicit, and legitimate purposes", "adequate, relevant, and limited to the minimum necessary", retained no longer than necessary, accurate, and processed with appropriate security. Section 25(1) lists consent, contract, legal obligation, vital interest, public interest or official authority, and legitimate interests: the six bases of GDPR Article 6(1). Section 26(3) adds that "Silence or inactivity of the data subject shall not constitute consent", which a GDPR consent flow already respects.
The machinery is where they part. The GDPR has no register of controllers; the NDPA does. The GDPR sets fines in euros and turnover; the NDPA in naira and gross revenue. The GDPR is enforced by supervisory authorities in each Member State, cooperating on cross-border cases; the NDPA by a single Commission that issues directives under the Act, the most important of which is the GAID, signed on 20 March 2025. Article 3(2) of the GAID says that where it conflicts with the Act, "the NDP Act shall prevail".
Who has to comply with both?
More organisations than expect to. GDPR Article 3(2) reaches a controller or processor outside the Union when its processing relates to "the offering of goods or services" to people in the Union or "the monitoring of their behaviour" there. NDPA section 2(2)(c) reaches a controller or processor that "is not domiciled in, resident in, or operating in Nigeria, but is processing personal data of a data subject in Nigeria", and Article 8(2) of the GAID reads "operating in Nigeria" as including one "who targets a data subject in Nigeria". A Lagos fintech with customers in Ireland, or a Berlin software company with users in Abuja, carries both laws for those data subjects.
Does GDPR compliance make you NDPA compliant?
No, although it gets you most of the way. Five things a GDPR programme will not produce on its own.
Registration. Section 44(1) requires a data controller or processor of major importance to register with the Commission. The Act leaves the threshold to the Commission, and Schedule 7 to the GAID sets it: anyone with a filing system that "Processes the personal data of more than Two-Hundred (200) data subjects in six (6) months", plus thirteen named sectors. The GAID sorts those organisations into Ultra-High, Extra-High and Ordinary-High levels, with registration fees of 250,000, 100,000 and 10,000 naira. A Nigerian employer can cross the line on staff records alone. The tiers and fees are in our guide to NDPA compliance cost.
Annual returns. GAID Article 9(2) says the Ultra-High and Extra-High levels "shall register once and shall only be required to file CAR annually", the Compliance Audit Return. Under Article 10(7) and (8), an organisation established before 12 June 2023 files by 31 March each year, and one established later files within fifteen months of its establishment and annually after that; Article 10(9) adds a penalty of 50% of the filing fee for filing late. The Ordinary-High level renews its registration every year instead. The GDPR has no annual filing.
The DPO trigger. GDPR Article 37(1) requires a data protection officer for public authorities and for core activities involving large scale, regular and systematic monitoring or large scale special category data. NDPA section 32(1) attaches the duty to status: "A data controller of major importance shall designate a Data Protection Officer". A GDPR analysis that concluded you need no DPO says nothing about Nigeria.
Sensitive data. The NDPA's definition in section 65 lists genetic and biometric data, race or ethnic origin, religious or similar beliefs, health status, sex life, political opinions or affiliations, trade union memberships, and "other information prescribed by the Commission". GDPR Article 9(1) also names sexual orientation, and the NDPA leaves the Commission free to add categories. Map each list separately.
Transfers. Covered below, because it runs in both directions.

How do the breach notification rules differ?
The clock to the regulator is the same length and stricter in Nigeria. GDPR Article 33(1) requires notice "without undue delay and, where feasible, not later than 72 hours after having become aware of it", and a late notice comes with reasons. NDPA section 40(2) requires a controller, "within 72 hours of becoming aware of a breach which is likely to result in a risk to the rights and freedoms of individuals", to notify the Commission. The words "where feasible" appear in section 40(2) too, but they qualify how much of the breach must be described, not the deadline. Section 40(9) does allow the information to be given "in phases without undue delay", so the 72 hours is for the notice, not the full investigation.
The notice to people differs too. GDPR Article 34(1) requires a high risk breach to be communicated to the data subject "without undue delay". NDPA section 40(3) says the controller "shall immediately communicate the personal data breach to the data subject in plain and clear language". Run one incident process with two regulators and the stricter of each step. Our guide to incident reporting deadlines by regulation sets the GDPR clock beside the others.
Do data subject rights work the same way?
The list is close; the deadlines are not. NDPA sections 34 to 38 give access and a copy "in a commonly used electronic format", rectification, erasure "without undue delay", restriction, withdrawal of consent, objection, which is absolute for direct marketing, protection from decisions based solely on automated processing, and portability, for which section 38 lets the Commission make regulations. GDPR Article 12(3) sets a response deadline: "within one month of receipt of the request", extendable "by two further months where necessary". The NDPA sets no day count; section 34(1) says only "without constraint or unreasonable delay". The safe operating rule is to answer Nigerian requests on the GDPR clock.
Children differ as well. GDPR Article 8(1) sets 16 as the age for a child's own consent to online services, which Member States may lower "not below 13 years". The NDPA states no age: section 65 adopts the meaning of child in the Child's Right Act 2003, and section 31(1) requires the consent of a parent or legal guardian.
How do transfers between the EU and Nigeria work?
Each law needs its own basis, and neither has declared the other adequate. Nigeria is not on the European Commission's list of adequacy decisions, so personal data leaving the EU for Nigeria needs another GDPR transfer mechanism, typically appropriate safeguards under Article 46 such as standard contractual clauses. In the other direction, NDPA section 41(1) bars a transfer out of Nigeria unless the recipient "is subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism that affords an adequate level of protection", or a section 43 condition such as informed consent or contract applies. Section 41(2) requires the basis for each transfer to be recorded. Section 42(7) lets the Commission rely on an adequacy decision of another jurisdiction, but we found no published Commission decision naming the EU, so record your basis rather than assume one.
How do the fines compare?
Both are the higher of a fixed sum and a percentage, and the bases differ. GDPR Article 83(5) allows up to EUR 20 million or "4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher", and Article 83(4) up to EUR 10 million or 2% for the controller and processor obligations. NDPA section 48(4) sets the "higher maximum amount" for a controller or processor of major importance as "the greater of" 10 million naira and "2% of its annual gross revenue in the preceding financial year"; section 48(5) sets the "standard maximum amount" for everyone else as the greater of 2 million naira and the same 2%. The percentage is the same in both NDPA tiers, and there is no 4% tier. Section 49 makes ignoring a Commission compliance order a criminal offence, with imprisonment of up to one year. The detail is in GDPR fines and penalties and NDPA fines and penalties.
What the other results get wrong
Page one for this query mixes academic comparisons, vendor checklists and consultancies, and the same errors recur. One comparison on page one sets the GDPR against the Nigeria Data Protection Regulation 2019, which is no longer the instrument to compare: GAID Article 3(3) says the Commission "shall cease to apply" the NDPR "as a legal instrument" from the GAID's issue. One checklist says high risk breaches go to data subjects "without undue delay", which is the GDPR wording; section 40(3) says immediately. The same checklist puts the DPO duty in section 31, which is the children's section; it is section 32. Another comparison says a DPO is required above 2,000 Nigerian data subjects; section 32 ties the duty to major importance, and GAID Schedule 7 draws that line at more than 200 data subjects in six months.
How do you run GDPR and NDPA compliance together?
On one programme with Nigerian additions, not two programmes. Settle scope first: which data subjects are in the Union, which are in Nigeria, and whether you are of major importance. Then build one record of processing that tags each activity with the laws that reach it, one lawful basis per purpose, and one incident process with the stricter step from each law. Add the NDPA-only items: registration, the DPO, Compliance Audit Returns at the higher levels, and a recorded section 41 basis for each transfer out of Nigeria. The GDPR compliance checklist and NDPA compliance checklist cover each side.

Check your own programme
Fill in the middle column. Every blank is a question either regulator can ask.
| Question | Your answer | Why it matters |
|---|---|---|
| How many data subjects in Nigeria do you process in six months, and are you in a named sector? | More than 200, or a listed sector, makes you of major importance, GAID Schedule 7. | |
| Are you registered with the NDPC, and at which level? | Section 44; the level sets fees and filings. | |
| When is your next Compliance Audit Return due? | GAID Articles 9(2) and 10: 31 March if established before 12 June 2023; late filing adds 50%. | |
| Who is your DPO for Nigeria? | Section 32 attaches the duty to major importance, not GDPR Article 37. | |
| Can your incident process notify the NDPC within 72 hours, with no exceptions? | Section 40(2) has no where feasible. | |
| Is the basis for every transfer out of Nigeria recorded? | Section 41(2). | |
| What mechanism covers data you send from the EU to Nigeria? | Nigeria has no EU adequacy decision. |
If most rows are blank, the free compliance check gives you a baseline. Venvera's GDPR module and NDPA module share one control set, one record of processing and one incident register, so a DPIA, a transfer record or a breach notice is kept once and counted for each law it answers.
Frequently asked questions
Is the NDPA the same as the GDPR?
No. It shares the principles and the six lawful bases, but adds registration, annual returns at the higher levels, a DPO duty tied to major importance, stricter breach timing and its own penalties and transfer rules.
Do I need to register with the NDPC if I comply with GDPR?
Yes, if you are a data controller or processor of major importance. GDPR compliance does not change that test, which turns on more than 200 data subjects in six months or a named sector under GAID Schedule 7.
Is the NDPA breach deadline 72 hours?
Yes, to the Commission, under section 40(2), and without the GDPR's where feasible. High risk breaches must also be communicated to data subjects immediately under section 40(3).
Can we send personal data from the EU to Nigeria?
Yes, with a GDPR transfer mechanism such as standard contractual clauses, because the European Commission has not adopted an adequacy decision for Nigeria.
Did the NDPA repeal the NDPR 2019?
Not directly. Section 64(2)(f) kept existing regulations in effect until replaced, and GAID Article 3(3) says the Commission ceased to apply the NDPR as a legal instrument once the GAID was issued on 20 March 2025.
Primary sources
GDPR articles are quoted from Regulation (EU) 2016/679; the adequacy position from the European Commission's adequacy decisions page. NDPA sections are quoted from the Nigeria Data Protection Act 2023 as published in the Official Gazette, available from the NDPC resources page; registration tiers, fees, returns and the status of the NDPR from the General Application and Implementation Directive 2025, Articles 3, 8, 9 and 10 and Schedule 7. Where the Commission issues later guidance, it takes precedence over any general comparison.





