The Federal Government has directed all Ministries, Departments and Agencies (MDAs) to appoint Data Protection Officers (DPOs) and fully comply with the Nigeria Data Protection Act (NDP Act) 2023, in a move aimed at strengthening data privacy, accountability and public trust across government institutions.
The directive is contained in Circular No. 59805/S.I/74, dated July 27, 2026, and signed by Senator George Akume, Secretary to the Government of the Federation (SGF). The circular was announced by the Nigeria Data Protection Commission (NDPC) in a statement issued by its Head of Legal, Enforcement and Regulations, Babatunde Bamigboye.
According to the circular, President Bola Tinubu stressed the strategic importance of data in national development, saying: “Data is the new oil: its value increases the more it is refined and responsibly shared.” He directed all Ministries, Extra-Ministerial Departments and Agencies to collect information responsibly and safeguard personal data in line with the NDP Act 2023.
The circular mandates all MDAs to comply fully with the NDP Act, its regulations, guidelines and directives issued by the NDPC.
To achieve this, every MDA is required to:
- Appoint a suitably qualified Data Protection Officer (DPO) to oversee compliance and advise management on lawful data processing.
- Register designated DPOs with the NDPC and, where necessary, engage licensed Data Protection Compliance Organisations (DPCOs) to support statutory compliance audits.
- Make adequate budgetary provisions for data protection activities, including staff training, public awareness campaigns, technical safeguards and periodic compliance audits.
- Submit mandatory Data Protection Compliance Audit Returns and other statutory reports to the NDPC within prescribed timelines.
The circular also places direct responsibility for compliance on Permanent Secretaries, Accounting Officers and Chief Executive Officers of MDAs, making them personally accountable for ensuring their institutions comply with the law.
Welcoming the directive, Dr. Vincent Olatunji,, National Commissioner and Chief Executive Officer of the NDPC, described the circular as a significant step towards strengthening data governance in the public sector.
He reaffirmed the Commission’s commitment to supporting government institutions, noting that a “regulatory clinic” has been established to provide technical guidance to MDAs as they implement the requirements of the law.
According to Olatunji, stronger data accountability is essential to achieving the Tinubu administration’s eight priority areas and positioning Nigeria to compete effectively in the Fourth Industrial Revolution.
He added that the Commission would continue to pursue robust regulatory measures to safeguard the privacy and fundamental rights of Nigerians while promoting responsible, data-driven governance.
The directive signals a tougher enforcement regime for public institutions that collect, process or store personal data. With the Nigeria Data Protection Act now fully operational, MDAs are expected to demonstrate greater transparency, accountability and security in handling citizens’ information.
The mandatory appointment of Data Protection Officers, engagement of licensed compliance organisations, dedicated budget allocations and regular compliance audits are expected to institutionalise data protection across the public sector.
The Federal Government has directed all MDAs to begin immediate implementation of the circular and align their data processing activities with NDPC regulations and guidelines.

