NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Nigeria NDPA Fines and Penalties Explained
Learn

Nigeria NDPA Fines and Penalties Explained

·Alexander Sverdlov

Under the Nigeria Data Protection Act 2023, the maximum penalty the Nigeria Data Protection Commission can impose is the greater of 10 million naira and 2% of your annual gross revenue in the preceding financial year if you are a data controller or data processor of major importance, and the greater of 2 million naira and 2% of annual gross revenue if you are not. Section 48(4) and 48(5) say so in almost those words.

Read those two ceilings next to each other and the thing most guidance gets wrong becomes obvious. The percentage is identical in both tiers. Only the naira floor changes, from 10 million to 2 million. The 2% against 1% split that circulates everywhere belongs to the 2019 Regulation the Act replaced, not to the Act.

SanctionCeiling or effectSource
Penalty or remedial fee, major importanceThe greater of 10 million naira and 2% of annual gross revenue in the preceding financial year.s. 48(3)(a) and 48(4)
Penalty or remedial fee, everyone elseThe greater of 2 million naira and 2% of annual gross revenue in the preceding financial year.s. 48(3)(b) and 48(5)
Remedy the violationAn order requiring the controller or processor to fix what the investigation found.s. 48(2)(a)
CompensationAn order to pay a data subject who suffered injury, loss or harm.s. 48(2)(b)
Account for profitsAn order to account for the profits realised from the violation.s. 48(2)(c)
Criminal convictionA fine up to the same two ceilings, or imprisonment for not more than one year, or both.s. 49(1)
The two Nigeria NDPA section 48 penalty ceilings, showing the 10 million naira and 2 million naira floors and the 2 percent of annual gross revenue that applies to both

What are the NDPA fines?

Section 48 calls the money a penalty or remedial fee rather than a fine, and the wording is deliberate. It is one of four things an enforcement order can contain, not a standalone instrument.

Section 48(3) sets the cap by reference to who you are. A data controller or data processor of major importance can be ordered to pay up to the higher maximum amount. Everyone else can be ordered to pay up to the standard maximum amount. Section 48(4) defines the higher maximum amount as the greater of 10 million naira and 2% of annual gross revenue in the preceding financial year. Section 48(5) defines the standard maximum amount as the greater of 2 million naira and the same 2%.

Because the test is the greater of the two, the naira figure is only ever a floor. For any organisation with annual gross revenue above 500 million naira, the higher maximum amount is the percentage and the 10 million figure is irrelevant. For a small processor turning over 50 million naira, the 2 million floor is what binds. Quoting either ceiling as a flat number without saying which limb applies to you is meaningless.

What else can the NDPC order besides a fine?

Three things, and two of them can cost more than the penalty.

Section 48(2) says an enforcement order or sanction shall include requiring the controller or processor to remedy the violation, ordering it to pay compensation to a data subject who has suffered injury, loss or harm as a result of the violation, ordering it to account for the profits realised from the violation, or ordering it to pay a penalty or remedial fee. The accounting for profits limb is uncapped in a way the penalty is not: it is measured by what you made, not by a ceiling.

Section 51 sits alongside all of that. A data subject who suffers injury, loss or harm from a violation may recover damages in civil proceedings, independently of anything the Commission does. Section 52 allows a court to make a forfeiture order against a convicted controller, processor or individual under the Proceeds of Crime (Recovery and Management) Act 2022.

Section 53 is the one that reaches individuals. Where an offence is committed by a body corporate or firm, the principal officers are deemed culpable as well, unless they prove both that the offence was committed without their consent or connivance and that they exercised diligence to prevent it. Controllers and processors are also vicariously liable for the acts and omissions of their agents and employees in so far as those relate to the business.

The Nigeria NDPA sanctions that are not fines, including orders to remedy, compensation to data subjects, accounting for profits and imprisonment on conviction

Who counts as a controller of major importance?

This is the question that decides which ceiling applies to you, and the answer sits lower than almost anyone expects.

Section 65 of the Act defines a data controller or data processor of major importance as one that is domiciled, resident in, or operating in Nigeria and processes or intends to process personal data of more than such number of data subjects as the Commission may prescribe, or another class the Commission designates as processing data of particular value or significance to the economy, society or security of Nigeria. The Act itself names no number. The Commission prescribes it.

It did so in the General Application and Implementation Directive, issued on 20 March 2025 under reference NDPC/NDP ACT-GAID/01/2025. Schedule 7 to the GAID says a controller or processor is designated of major importance if it keeps or has access to a filing system, whether analogue or digital, for the processing of personal data, and it processes the personal data of more than 200 data subjects in six months, or carries out commercial information and communications technology services on a digital device belonging to another individual that can store personal data, or processes personal data as an organisation or service provider in any of thirteen listed sectors including aviation, communication, education, financial, health, insurance, oil and gas, e-commerce and public service.

Two hundred data subjects in six months is a threshold that a small Nigerian employer clears on headcount alone. If your reasoning for sitting in the lower tier is that you are small, check it against that number before you rely on it.

Article 8 of the GAID then sorts organisations of major importance into three levels, Ultra High Level, Extra High Level and Ordinary High Level, which drive registration and audit filing obligations rather than the penalty ceiling. The ceiling itself is binary: you are of major importance or you are not.

What makes a Nigerian organisation a data controller of major importance under NDP Act section 65 and GAID Schedule 7, including the 200 data subject test

How does a penalty actually get imposed?

Through a sequence, not in a single step, and the sequence gives you more than one place to stop it.

Section 46 starts it. A data subject lodges a complaint, or the Commission opens an investigation on its own accord where it has reason to believe a violation has occurred or is likely to. During an investigation the Commission can order a person to attend for oral examination, to produce documents, records or articles, or to furnish a written statement on oath.

Section 47 is the compliance order stage. Where the Commission is satisfied that a controller or processor has violated or is likely to violate a requirement, it may issue a warning, a requirement to comply, or a cease and desist order. That order must be in writing and must specify the provisions violated, the specific measures to be taken, the period within which to implement them, and the right to judicial review.

Section 48 is the enforcement order stage, and it is reached after the investigation completes. Section 49 is the criminal stage, and it is triggered by one thing only: failing to comply with an order made under section 47. That is worth restating, because it means the imprisonment exposure attaches to ignoring the regulator rather than to the underlying data protection failure.

Section 50 gives you 30 days from the order to apply to the court for judicial review.

How an NDPC penalty is reached under the Nigeria Data Protection Act, from complaint or own motion investigation through compliance order to enforcement order and prosecution

How does the NDPC decide the amount?

Section 48(6) lists seven factors and gives no weighting: the nature, gravity and duration of the infringement; the purpose of the processing; the number of data subjects involved; the level of damage and the damage mitigation measures implemented; intent or negligence; the degree of cooperation with the Commission; and the types of personal data involved.

Two of those seven are things you control after the fact rather than before it. Damage mitigation and cooperation are both evidence based, which is a practical argument for keeping a written record of what you did once you knew, and when.

Separately, the GAID attaches an administrative penalty to one specific failure. Article 10(9) provides that where a controller or processor fails to file its Compliance Audit Returns when due, it pays the stipulated filing fee plus an administrative penalty of 50% of that fee. Organisations established before 12 June 2023 file by 31 March each year. Organisations established after that date file within fifteen months of establishment and then annually. The filing fee scale itself is in Schedule 10 to the GAID.

What the other results get wrong

The published guidance on NDPA penalties is unusually unreliable, and four errors recur.

The first is quoting the old Regulation. Clause 2.10 of the Nigeria Data Protection Regulation 2019 set 2% of annual gross revenue or 10 million naira for a controller dealing with more than 10,000 data subjects, and 1% or 2 million naira for one dealing with fewer. Those figures are still reproduced as though they were the Act. Section 48 uses 2% in both tiers and keys the tiers to major importance, not to a headcount of data subjects.

The second follows from the first: the 10,000 data subject line. It is not the major importance test. GAID Schedule 7 puts the trigger at more than 200 data subjects in six months, plus the sector and ICT service limbs.

The third is the invented fine schedule. Tables circulate assigning specific amounts to specific breaches, such as a stated figure for failing to report a data breach. No such schedule exists in the Act. Section 40(2) requires a controller to notify the Commission within 72 hours of becoming aware of a breach likely to result in a risk to rights and freedoms, but the consequence of missing it runs through the section 48 ceilings like everything else.

The fourth is the direction of the comparison. Several summaries render the ceiling as 10 million naira or 2%, whichever is lower. Sections 48(4) and 48(5) both say the greater of. For any organisation of real size that inversion understates the exposure by an order of magnitude.

One further caution on enforcement figures. Reported Nigerian data privacy fines circulate widely and are frequently attributed to the wrong regulator, since the Commission is not the only Nigerian authority that has taken action against large technology and media companies. Check the Commission's own announcements before quoting a number.

Working out your own exposure

Fill this in. The aim is not a figure, it is finding out which ceiling and which limb you are actually under.

QuestionYour answerWhat it decides
Do you process the personal data of more than 200 data subjects in any six months?GAID Schedule 7. If yes, you are almost certainly of major importance.
Do you operate in aviation, communication, education, financial, health, insurance, oil and gas, e-commerce or public service?The sector limb of Schedule 7 designates you regardless of volume.
What was your annual gross revenue in the preceding financial year?Above 500 million naira, the 2% limb binds rather than the 10 million floor.
Are you registered with the Commission, and is your registration current?s. 44. Registration is due within six months of becoming of major importance, with changes notified within 60 days.
Have you filed your Compliance Audit Returns for this year?GAID Art. 10. Late filing costs the fee plus 50% of it.
Could you notify the Commission within 72 hours of becoming aware of a breach?s. 40(2). Missing it is assessed under the same s. 48 ceilings.
Can your principal officers evidence diligence to prevent an offence?s. 53. Without it they are deemed culpable personally.

If most rows are blank, the next step is a baseline rather than a legal opinion. Our Nigeria NDPA compliance checklist works through the underlying obligations line by line, and a free compliance check gives you a starting position across the NDPA duties.

The bottom line on Nigeria NDPA penalties: the 2 percent applies in both tiers and only the naira floor changes between them

Frequently asked questions

What is the maximum NDPA fine?

The greater of 10 million naira and 2% of annual gross revenue in the preceding financial year, for a data controller or data processor of major importance, under sections 48(3)(a) and 48(4).

Is the NDPA penalty 2% or 1% of revenue?

2% in both tiers. The 1% figure comes from clause 2.10 of the Nigeria Data Protection Regulation 2019, which the Act superseded. Under the Act the tiers differ only in their naira floor, 10 million against 2 million.

Can anyone go to prison under the NDPA?

Yes. Section 49(1) makes failure to comply with an order made under section 47 an offence, punishable by a fine up to the applicable maximum amount, or imprisonment for not more than one year, or both. Section 53 deems principal officers culpable unless they prove absence of consent or connivance and the exercise of diligence.

Does the NDPA apply to companies outside Nigeria?

It can. Section 65 brings in controllers and processors operating in Nigeria, and Article 1 of the GAID reads that together with section 2 of the Act as covering organisations that are not domiciled in Nigeria but process or target the personal data of data subjects in Nigeria.

How long do we have to notify a breach?

Section 40(2) gives a data controller 72 hours from becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals to notify the Commission. Where the risk is high, section 40(3) requires immediate communication to the data subject in plain and clear language.

Primary sources

Penalty ceilings, the enforcement sequence and the criminal provisions are taken from sections 40, 44, 46 to 53 and 65 of the Nigeria Data Protection Act 2023, published by the Nigeria Data Protection Commission. The major importance test, the Compliance Audit Returns deadlines and the 50% late filing penalty are from Articles 8 and 10 and Schedules 7 and 10 of the General Application and Implementation Directive issued by the Commission on 20 March 2025. The superseded figures are from clause 2.10 of the Nigeria Data Protection Regulation 2019. Confirm the current text before relying on a figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING