
NDPA 2023 for Financial Institutions in Nigeria
Key Takeaways
The NDPA 2023 is Nigeria’s primary statutory data protection framework, governing how financial institutions process and protect personal data, including customer identity, BVN, NIN, account, transaction, biometric, and technical information.
Financial institutions must apply NDPA 2023 data protection principles across KYC, fraud monitoring, credit assessment, marketing, customer support, and third-party processing, including lawful processing, purpose limitation, data minimisation, accuracy, retention, security, and accountability.
The NDPA 2023 gives data subjects rights including access, correction, objection, restriction, portability, erasure, withdrawal of consent, and rights relating to automated decision-making, requiring banks and fintechs to maintain processes for handling legitimate data subject requests.
Under Section 40 of the NDPA 2023, financial institutions must assess personal data breaches and notify the NDPC within 72 hours when a breach is likely to create a risk to individuals' rights and freedoms, with additional notification obligations applying where there is high risk.
Financial institutions in Nigeria collect and process some of the most sensitive information about individuals, from names and contact details to BVN, NIN, account information, transaction records and identity documents. The NDPA 2023 provides the main statutory framework governing how this personal data should be processed and protected.
For banks, fintechs, payment service providers and other financial institutions, understanding the Nigeria Data Protection Act 2023 is not simply a privacy exercise. It affects customer onboarding, KYC, fraud monitoring, marketing, third-party technology providers, data retention, security and how organisations respond when something goes wrong.
The data protection act nigeria framework is now built around the Nigeria Data Protection Act 2023 and its implementation framework under the Nigeria Data Protection Commission (NDPC). The older ndpr framework provided the foundation for Nigeria's earlier data protection regime, but the NDPA 2023 now provides the primary statutory framework.
For organisations that previously relied on NDPR policies and procedures, the practical question is whether those controls have been updated to meet the requirements of the Nigeria Data Protection Act 2023.
What Is the NDPA 2023 and Who Does It Apply To?
The NDPA 2023, formally known as the Nigeria Data Protection Act 2023, establishes the legal framework for protecting personal data and regulating its processing in Nigeria.
The Act also established the Nigeria Data Protection Commission (NDPC), which is responsible for regulating data protection and privacy in Nigeria.
The Nigeria Data Protection Act 2023 applies to organisations domiciled, resident or operating in Nigeria, organisations processing personal data in Nigeria, and certain organisations outside Nigeria that process the personal data of people in Nigeria.
This gives the data protection act nigeria a broad reach across the digital economy.
For financial institutions, this includes banks, fintech companies, payment providers and other organisations that collect or process customer information as part of their services.
It can also affect technology companies that process personal data on behalf of these organisations. For example, a bank using a third-party identity verification, cloud, fraud detection or analytics provider still needs to understand how that provider handles personal data.
The NDPC's current framework is centred on the NDPA 2023, with the General Application and Implementation Directive (GAID) 2025 providing additional implementation guidance.
The transition away from the NDPR framework is important for organisations reviewing older privacy policies and compliance programmes. The NDPC's 2025 GAID states that, upon its issuance, the Commission would cease applying the NDPR as a legal instrument for regulating data privacy and protection, subject to the transitional provisions of the Act.
What Personal Data Do Financial Institutions Need to Protect?
Financial institutions process much more than basic customer information.
Depending on the service, a financial institution may process:
Full names
Phone numbers and email addresses
Residential and business addresses
NIN and BVN information
Identity documents
Date of birth
Account information
Transaction records
Financial information
Employment information
Biometric information
Device and technical information
IP addresses and login information
Location information where applicable
Customer communications
Information used for fraud and risk assessment
Under the Nigeria Data Protection Act 2023, organisations need to consider why each category of personal data is being collected, the lawful basis for processing it, how it is protected and how long it should be retained.
This is where the data protection act in Nigeria becomes an operational issue rather than simply a legal document.
For example, a fintech collecting a customer's NIN for identity verification should be able to explain why the information is required, how it will be used, who can access it, whether it will be shared with another processor and how long it will be retained.
The same principle applies to data collected during transaction monitoring, fraud investigations, credit assessments and customer support.
What Does the NDPA Require Financial Institutions to Do?
The NDPA 2023 sets out principles that organisations must follow when processing personal data.
Financial institutions should ensure that personal data is:
Processed fairly, lawfully and transparently
Collected for specific, explicit and legitimate purposes
Adequate, relevant and limited to what is necessary
Accurate and kept up to date where necessary
Retained only for as long as necessary
Protected through appropriate security measures
The Act also places accountability obligations on data controllers and processors.
In practice, this means a financial institution should not simply collect large amounts of customer information because the information might become useful later.
The nigeria data protection act 2023 requires organisations to consider purpose, necessity, security and accountability throughout the data lifecycle.
This is particularly important for fintechs because digital products can collect and connect large amounts of information across onboarding, payments, customer support, fraud detection and analytics.
The principles in the ndpa 2023 should therefore be reflected in product design, internal processes, vendor management and security controls.
READ: NDPR to NDPA and GAID in Nigeria

6 Ways to Protect Your Business From Hackers this December

How Machine Learning is Used In Fraud Prevention For E-commerce
