FG orders MDA’s to comply with data protection act

The Federal Government has directed all Ministries, Departments and Agencies to fully comply with the Nigeria Data Protection Act 2023 to strengthen data governance and safeguard citizens’ personal information.

The directive, contained in a compliance circular issued by the Office of the Secretary to the Government of the Federation, requires all federal MDAs to implement the provisions of the Act, as well as regulations, guidelines and directives issued by the Nigeria Data Protection Commission in the processing of personal data.

The circular, dated July 27, 2026, and signed by the Secretary to the Government of the Federation, George Akume, conveyed President Bola Tinubu’s directive that all Ministries, Extra-Ministerial Departments and Agencies must rigorously collect, protect and responsibly manage personal data in line with the Nigeria Data Protection Act 2023.

In a statement issued on Tuesday, the Head of Legal, Enforcement and Regulation at the Nigeria Data Protection Commission, Babatunde Bamigboye, said the circular reinforces the President’s commitment to responsible data governance and institutional accountability across the public sector.

According to the statement, the circular drew the attention of MDAs to President Tinubu’s directive, which described data as a strategic national asset requiring careful management and protection.

The President was quoted as saying, “Data is the new oil; its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act 2023.”

To ensure compliance, the circular mandates all MDAs to designate suitably qualified officers as Data Protection Officers to oversee data protection compliance, advise management on lawful data processing, and serve as focal persons on privacy-related matters within their respective institutions.

The directive also requires MDAs to submit the names and contact details of their designated Data Protection Officers to the Nigeria Data Protection Commission for registration and official records. Where necessary, agencies are to engage licensed Data Protection Compliance Organisations to support compliance with the Act and facilitate statutory data protection audits.

In addition, the Federal Government instructed all MDAs to make adequate budgetary provisions for data protection compliance activities, including staff capacity building, public awareness programmes, deployment of appropriate technical safeguards and the conduct of periodic compliance audits.

The circular further mandates federal institutions to submit all mandatory Data Protection Compliance Audit Returns and other statutory reports to the Nigeria Data Protection Commission within the timelines prescribed by law.

It also places responsibility for compliance squarely on the leadership of government institutions, stating that Permanent Secretaries, Accounting Officers and Chief Executive Officers of all MDAs will be held personally accountable for ensuring their organisations comply with the circular and the provisions of the Nigeria Data Protection Act 2023.