Compliance · Regulation

NDPA 2023: a plain-English checklist for AI-driven businesses.

10 min read·Patrick Enwerem Limited

The Nigeria Data Protection Act 2023 is the most significant data regulation in Nigerian history. For enterprises deploying AI systems, it creates obligations that go well beyond standard data privacy compliance. This checklist translates the Act's requirements into the decisions your technical, legal, and operational teams need to make before deploying any AI system that processes personal data.

Note: This checklist reflects our reading of NDPA 2023 as it applies to AI and automated decision-making systems. It is not legal advice. Engage qualified data protection counsel for your specific deployment. The NDPC's published guidance should be reviewed alongside this checklist, as regulatory interpretation evolves.

01

Lawful Basis for Processing

Every AI system that processes personal data must have a documented lawful basis before it goes live. NDPA 2023 Section 25 sets out six lawful bases. For most AI deployments, the relevant ones are consent, contract, and legitimate interest.

Consent

If you are relying on consent, it must be freely given, specific, informed, and unambiguous. Pre-ticked boxes, bundled consent, and consent buried in terms of service do not meet the standard. AI systems that personalise content, analyse behaviour, or make inferences about data subjects based on their activity require fresh, granular consent; not the consent the data subject gave when they opened their account in 2019.

Contract

Processing is lawful where necessary for the performance of a contract. An AI system that automates loan origination decisions as part of a credit agreement has a stronger case than one that uses loan applicant data to train a marketing model. The processing must be necessary, not merely convenient.

Legitimate interest

This requires a documented legitimate interest assessment (LIA): what is the interest, is the processing necessary for it, and do the data subject's rights override it? For AI systems making consequential decisions, the LIA bar is high. Document it before you deploy, not after the NDPC audit begins.

Documented and retrievable

The lawful basis for each category of processing must be documented in your data register and retrievable by your DPO within 24 hours of a regulatory request. 'We are working on it' is not a compliant answer.

02

Data Protection Impact Assessment (DPIA)

Section 66 of NDPA 2023 requires a DPIA before any processing that is likely to result in high risk to data subjects. Automated decision-making; which is the output of most AI systems; is explicitly listed as high-risk processing. A DPIA is not optional for AI deployments in Nigeria. It is a mandatory pre-condition.

Scope the DPIA correctly

The DPIA must cover the full processing lifecycle: data collection, storage, model training, inference, decision output, human review, and data deletion. Most DPIAs I have reviewed for Nigerian AI deployments are scoped to the application layer and miss the model training and third-party API components entirely.

Assess the risks honestly

The DPIA must identify the risks, assess their likelihood and severity, and document the mitigations. A DPIA that concludes with no residual risks for a customer credit scoring model is not a credible document. The NDPC knows what the risks of credit scoring models are. Your DPIA should too.

DPO sign-off is required

Your Data Protection Officer must review and sign off on the DPIA before deployment. If you have not appointed a DPO; which is mandatory for large-scale processing under NDPA 2023; you are non-compliant before the AI conversation begins.

Review on material change

A DPIA is not a one-time document. Any material change to the AI system; new training data, expanded use cases, new data inputs, change of model architecture; requires a DPIA review. Build this into your AI development lifecycle, not as a retrospective exercise.

03

Automated Decision-Making and Profiling

Section 32 of NDPA 2023 creates specific rights for data subjects subject to solely automated decisions that produce legal or similarly significant effects. Credit decisions, employment screening, insurance underwriting, and fraud detection are all within scope. This is the section most Nigerian AI deployments are not ready for.

Right to human review

Data subjects have the right to request human review of any automated decision that significantly affects them. Your AI system must have a documented, operational escalation path to a human reviewer. The reviewer must have the authority and the information to actually override the model; not just confirm it.

Right to explanation

Data subjects can request a meaningful explanation of the logic underlying any automated decision. 'The algorithm determined this' is not an explanation. You must be able to articulate the top factors that influenced the decision and how they were weighted. Explainable AI is not an academic luxury. It is a legal requirement under Nigerian law.

Right to object

Data subjects can object to profiling. You must have a documented process for receiving, logging, and acting on objections; including suspending automated processing while the objection is assessed.

Prohibited bases

Automated decisions cannot be based solely on special categories of data; health, ethnicity, religion, political opinion, biometric data; without explicit consent and a compelling justification. Review your model's feature set for indirect proxies of special category data. Postcode, for instance, can be a proxy for ethnicity or religion in the Nigerian context.

04

Data Residency and Cross-Border Transfer

Nigeria has data localisation requirements that affect where AI processing can occur. This is not a minor operational consideration. It is a hard constraint that should determine your cloud architecture before you write a line of production code.

Personal data localisation

Personal data of Nigerian data subjects must be processed and stored within Nigeria unless specific conditions are met. The NDPC maintains a list of adequate jurisdictions and approved standard contractual clauses. Processing customer PII through a US-hosted AI API without a cross-border transfer mechanism in place is a violation.

Third-party API usage

Every external API call that transmits personal data; including AI inference APIs that receive customer data as input; is a cross-border transfer if the API endpoint is outside Nigeria. Your vendor audit must include the location of every inference endpoint and the legal instrument that permits transfer to that jurisdiction.

Sector-specific requirements

Financial services, healthcare, and telecoms have additional localisation requirements beyond the NDPA baseline. CBN's cloud computing framework, NHIA guidelines, and NCC directives each add obligations. If your AI system operates in one of these sectors, the compliance framework is layered, not singular.

Transfer impact assessments

For any cross-border transfer, you must assess whether the destination country's legal environment provides equivalent protection to Nigerian law. For transfers to the US and UK, the analysis is non-trivial given national security surveillance powers. Document the assessment. Do not assume adequacy.

05

Data Minimisation and Retention

AI systems have an appetite for data that frequently conflicts with the minimisation principles in NDPA 2023. Section 27(1)(c) requires that personal data be adequate, relevant, and limited to what is necessary for the stated purpose. Model training corpora, feature engineering pipelines, and data warehouses built for AI often violate this principle by design.

Training data audit

Every dataset used to train a production AI model should be audited against the original collection purpose. Data collected for loan origination cannot be repurposed for marketing model training without a new lawful basis. This is a common violation in Nigerian fintech AI deployments.

Retention schedules

Define and enforce retention schedules for all AI-related data: training sets, inference logs, model outputs, and DPIA documentation. The NDPA does not specify universal retention periods, but CBN Circular BSD/DNI/DIR/GEN/LAB/06/010 requires financial institutions to retain records for at least seven years. Your AI audit trail must meet this standard.

Deletion on request

Data subjects have the right to erasure under Section 34 of the NDPA. For AI systems, this requires not just deleting the raw data record but understanding whether that data was used in model training and, if so, whether model unlearning or retraining is required. Most organisations have not thought through the operational implications of this requirement.

Anonymisation standards

Data that has been genuinely anonymised falls outside the NDPA. But anonymisation is technically harder than most data teams appreciate. Pseudonymisation, aggregation, and k-anonymity are not sufficient in contexts where re-identification risk is non-trivial. Test your anonymisation process against re-identification attacks before relying on it for compliance.

06

Vendor and Processor Management

Your AI vendor is a data processor under NDPA 2023. You are the data controller. The obligations under the Act attach to you; and your vendors' failures become your violations.

Data Processing Agreements (DPAs)

Every AI vendor that touches personal data on your behalf must have a signed DPA in place before processing begins. The DPA must include the mandatory clauses from NDPA 2023 Section 43: purpose limitation, security obligations, sub-processor management, assistance with data subject rights, and deletion obligations at contract end.

Sub-processor audit

Your AI vendor will use sub-processors; cloud providers, data labelling services, model infrastructure providers. Each sub-processor must be identified, their location disclosed, and appropriate transfer mechanisms established. 'We use best-in-class cloud infrastructure' is not a DPA clause.

Security standards

Require written evidence of your vendor's security controls: penetration testing reports, ISO 27001 certification or equivalent, incident response capability, and encryption standards for data in transit and at rest. For AI model endpoints, additionally require evidence of prompt-injection defence and output filtering.

Breach notification obligations

NDPA 2023 requires notification of the NDPC within 72 hours of becoming aware of a personal data breach. Your vendor contracts must require notification to you within 24 hours of any breach; giving you operational time to assess, contain, and notify the regulator within the statutory window.

The audit-readiness test

The NDPC has signalled that enforcement activity will increase through 2026. The organisations that will be best positioned are not those who have perfect compliance; perfect compliance for a live AI system is a moving target; but those who can demonstrate a credible, documented, and improving compliance programme.

Before any NDPC audit, you should be able to produce, within 24 hours: your data register, all active DPAs, all DPIAs for high-risk processing, your lawful basis documentation for each data processing activity, your DPIA for any automated decision-making system, and your breach notification log.

If producing any of these documents would require more than 24 hours of effort, you are not audit-ready. The gap between where you are and where you need to be is measurable, and it is closable; but only if you start before the notice of audit arrives.