The Federal Government has issued a fresh compliance directive to all Ministries, Departments and Agencies (MDAs), mandating them to fully comply with Nigeria’s data protection laws as part of efforts to strengthen public trust, improve digital governance and safeguard citizens’ personal information.
The directive was contained in Circular No. 59805/S.I/74, dated July 27, 2026, and signed by the Secretary to the Government of the Federation (SGF), George Akume.
According to a statement by the Head of Legal, Enforcement and Regulations at the Nigeria Data Protection Commission (NDPC), Babatunde Bamigboye, the initiative forms part of the Federal Government’s broader strategy to prepare Nigeria for the opportunities and challenges of the Fourth Industrial Revolution.
The circular reminded all government institutions of President Bola Tinubu’s position that “Data is the new oil,” stressing the need for public institutions to properly collect, manage and protect personal information in line with the Nigeria Data Protection Act (NDP Act), 2023.
Akume directed all Ministries, Extra-Ministerial Departments and Agencies to strictly comply with the provisions of the NDP Act, as well as all regulations, guidelines and directives issued by the Nigeria Data Protection Commission regarding the processing of personal data.
As part of the new requirements, every MDA must appoint a qualified Data Protection Officer (DPO) to oversee compliance with data protection regulations and advise management on matters relating to the lawful handling of personal information.
The circular also instructed government institutions to register their designated Data Protection Officers with the NDPC, engage licensed Data Protection Compliance Organisations (DPCOs) where necessary, and carry out statutory compliance audits as required by law.
In addition, MDAs were directed to make adequate budgetary provisions for data protection activities, including staff training, public awareness programmes, deployment of technical security measures and periodic compliance assessments.
They are also required to submit all mandatory Data Protection Compliance Audit Returns and other statutory reports to the NDPC within the timelines specified under the law.
The circular further placed responsibility for compliance directly on the leadership of each government institution.
“Permanent Secretaries, Accounting Officers and Chief Executive Officers of all MDAs shall be personally responsible for ensuring institutional compliance with the Circular and the provisions of the NDP Act,” the directive stated.
Reacting to the development, the National Commissioner and Chief Executive Officer of the Nigeria Data Protection Commission, Dr. Vincent Olatunji, commended the Tinubu administration for demonstrating strong legal and political commitment to protecting the privacy and fundamental rights of Nigerians.
According to him, data accountability is essential to achieving the administration’s Eight Presidential Priorities, adding that the Commission has established a regulatory clinic to provide technical support and guidance to MDAs in meeting the new compliance requirements.
The latest directive is expected to strengthen data governance across government institutions while improving the protection of citizens’ personal information in Nigeria’s growing digital economy.






