
Overview
IntroductionThe Nigerian data protection sector has continued its path of resilient and encouraging growth nationwide. The first half of 2025 recorded important developments, emphasizing Nigeria’s sustained commitment towards protecting digital rights and, in the broader context, building a more inclusive and secure digital ecosystem. Now in its sophomore year, the Nigerian Data Protection Commission (NDPC) has intensified its efforts to give full effect to the provisions of the Nigerian Data Protection Act (NDPA), primarily through policies and frameworks, including the introduction of the General Application and Implementation Directive (GAID). The GAID, as an implementation framework, contextualizes the provisions of the NDPA with the aim of improving both understanding and compliance in practice.
These efforts have had a ripple effect on the economy, particularly in expanding the scope and quality of data compliance services currently available. It is not surprising that the sector is projected to generate around N13 billion in revenue for the year. Interestingly, however, the most noteworthy policy shifts in the year have come from judicial pronouncements. Landmark judicial decisions, like the cases of Araka v E-Cart Internet Services Limited & Anor. and The Incorporated Trustees of Personal Data Protection Awareness Initiative v Nizamiye Hospital Limited, have not only set important precedents for the future but have also accentuated the enforceability of the NDPA. These cases reflect an increasing awareness among data subjects of their rights and the willingness to enforce these rights through the necessary legal channels.
They also contribute to the growing body of data protection jurisprudence in Nigeria, complementing the existing regulatory policies. Additionally, countries around the globe are not left out; several regulatory trends have defined the global data protection narrative. For example, the Digital Operational Resilience Act (DORA), applicable to European Union states, became effective on January 17, 2025. Like, several US states implemented new privacy laws in 2025, expanding data protection requirements. Notwithstanding regulatory efforts, data breaches continue to occur on a significant scale. In one instance, cybersecurity firm Surfshark released a report detailing that more than 119,000 data breaches had been recorded in Nigeria in the first quarter of 2025.
Clearly, while progress has been made, much work remains to be done to ensure adequate protection. In this newsletter, we delve into some of the recent developments in the data protection landscape, we feature key regulatory and enforcement updates from Nigeria and across the globe, and we shall also highlight notable court decisions which are gradually shaping the Nigerian data protection jurisprudence.











