The rules changed
Last updated 13 September 2026. Nigeria’s data-protection and banking-security requirements increasingly ask organisations to show what happened, not simply describe a policy. This page summarises what changed, when it changed, and what each change asks of an organisation that provides services, handles customer requests, sends documents, or collects consent. Every date links to its source.
June 2023: the NDPA becomes law
The Nigeria Data Protection Act 2023 creates the NDPC and provides for registration of data controllers and processors of major importance. For those organisations, enforcement orders can include a fine of up to the higher of ₦10m or 2% of annual gross revenue in the preceding financial year.
What it asks of you: register, appoint accountability, and be able to show a lawful basis for every category of processing.
How Keepable answers: every consent request and processing notice delivered through Keepable carries its lawful basis in the record itself, sealed on delivery. The evidence exists because the delivery happened, not because someone remembered to file it.
March 2025: GAID is issued
The NDPC’s General Application and Implementation Directive (effective 19 September 2025) operationalises the Act. Consent must be freely given, specific, informed and unambiguous. Ultra-High and Extra-High Level organisations file annual Compliance Audit Returns through a licensed Data Protection Compliance Organisation. Filing fees reach ₦1m, with a 50% administrative penalty for late filing.
What it asks of you: a checkbox screenshot may not be enough for a DPCO review. You need a record of what the person saw, what they decided, and when.
How Keepable answers: a Keepable consent decision records the stated purpose, the exact wording the person saw, their grant or decline, and when they decided. Both sides retain the same sealed record. The Compliance Audit Return export assembles those records for review.
July 2025: enforcement action
The NDPC fined MultiChoice Nigeria ₦766,242,500 after findings that included unfair, unnecessary and disproportionate data processing and unlawful cross-border transfers. The Commission records the action in its 2026 enforcement journal.
What it asks of you: the requirements did not change, but the enforcement action made the financial risk concrete.
August 2025: wider investigations
The NDPC named 1,369 organisations over statutory audit-filing obligations, giving them 21 days to provide evidence of compliance. The action is summarised in the Commission’s 2026 enforcement journal.
What it asks of you: be ready to produce the requested reports and compliance evidence within the stated deadline.
How Keepable answers: when consent and delivery evidence is already on the record, an organisation can respond with an export instead of rebuilding the history from separate systems.
Every 31 March: annual returns
Under the GAID, Ultra-High and Extra-High Level data controllers and processors file annual Compliance Audit Returns by 31 March through a licensed Data Protection Compliance Organisation, unless the Commission determines otherwise.
What it asks of you: a repeatable filing supported by evidence each year.
March 2026: stronger mobile-banking identity checks
The CBN’s 12 March 2026 guidance on instant payments requires stronger identity verification for online account opening and reactivation. It also requires mobile banking apps to be bound to one device at a time and uses multi-factor authentication for important controls. The standards took effect on 1 July 2026. The CBN summarises them in its reforms and initiatives record.
What it asks of you: do not treat a phone number alone as proof of identity. The NCC’s Telecom Identity Risk Management System distinguishes numbers that are churned, reassigned, swapped or blacklisted so approved service providers can check their status.
How Keepable answers: Keepable does not use a phone number as a person’s identity. Each delivery resolves to an identity verified with the NIN, and each person signs in with a passkey on their device.
What to do with this
If your organisation provides services, handles requests, or sends notices, statements, policies, offers, and consent requests to Nigerians, the common thread is evidence: what was sent, what the person saw, what they decided, and what happened next. See how Keepable helps, or email sales@keepable.co and we will walk your compliance team through it.