Nigeria Data Protection Act 2023: Patient Data Rules
Nigeria's Data Protection Act 2023 and the GAID 2025 bring registration, audits and DPO duties to hospitals and clinics. What health providers must do now.
Nigeria's data protection regime has been rebuilt in two steps. The Nigeria Data Protection Act 2023 (NDPA) created the Nigeria Data Protection Commission (NDPC) and set modern principles. The General Application and Implementation Directive (GAID) 2025 then turned those principles into concrete obligations. Hospitals, clinics, laboratories, HMOs and health-tech companies handle large volumes of sensitive health information, so they are among the organisations most exposed.
The framework in 2026
- NDPA 2023: the primary law. It sets lawful bases, data subject rights, security duties and cross-border transfer rules, and it treats health information as sensitive personal data.
- GAID 2025: issued by the NDPC on 20 March 2025 and in force from 19 September 2025. From that date the old NDPR 2019 and its 2020 Implementation Framework stopped applying.
If your clinic's privacy documents still refer to the NDPR, they are out of date.
Are you a "data controller of major importance"?
The NDPA gives the heaviest obligations to data controllers and processors of major importance (DCPMIs). The GAID makes the concept concrete. It names critical sectors, including healthcare, and high-risk processing involving large volumes of sensitive data, and it creates three tiers:
| Tier | Registration | Annual audit (CAR) |
|---|---|---|
| Ultra-High Level (UHL) | Register once | Compliance Audit Return every year, due 31 March |
| Extra-High Level (EHL) | Register once | Compliance Audit Return every year, due 31 March |
| Ordinary-High Level (OHL) | Renew registration annually | Not required every year |
Under Article 9 of the GAID, organisations designated as of major importance must register with the NDPC. Legal analyses list further duties: appointing a qualified data protection officer, annual compliance audits for the higher tiers, and regular reports on data activities.
Many hospitals, diagnostic chains and HMOs are likely to fall in one of these tiers. Smaller clinics should check the NDPC's criteria instead of assuming they are exempt.
Reach beyond Nigeria
Article 8 of the GAID broadens what it means to be "operating in Nigeria". It covers foreign controllers and processors that target Nigerian data subjects, taking into account data volume and sensitivity, cross-border transfers and risk. Telemedicine platforms, foreign laboratories and software vendors serving Nigerian patients may therefore fall within the NDPC's reach.
Enforcement is real
The NDPC has moved from awareness to sanctions:
- In July 2025 it fined MultiChoice Nigeria ₦766,242,500. The investigation concerned the cross-border transfer of subscribers' personal data without proper consent or safeguards.
- A ₦555.8 million penalty against Fidelity Bank was reported in 2024 for processing personal data without informed consent.
- In August 2025 the Commission sent compliance notices to more than 1,300 organisations in banking, insurance, pensions and gaming.
No major sanction against a health provider had been widely reported at the time of writing. But the cross-border transfer case is directly relevant to hospitals that use foreign cloud, AI or transcription services.
What hospitals and clinics should do
1. Determine your status
Assess whether you are a DCPMI and which tier applies. Register with the NDPC and put the Compliance Audit Return deadline in your calendar.
2. Appoint a data protection officer
Pick someone with real authority and training. In a group, one DPO can cover several facilities if they have the resources.
3. Map patient data flows
Cover EMR, lab and imaging systems, HMO claims, messaging apps, cloud storage and AI tools. Identify every point where data leaves Nigeria and check that each transfer has a legal basis and safeguards.
4. Update consent and notices
Patients should get clear, plain-language information on how their data is used, shared with HMOs and stored. Remove NDPR references.
5. Prepare for incidents
Write a breach response procedure that covers notification to the NDPC and to affected patients within the deadlines set by the Act.
Key takeaways
- Since 19 September 2025, the NDPA 2023 and the GAID 2025 govern patient data, and the NDPR 2019 no longer applies.
- Healthcare is named as a critical sector, so many providers will be data controllers of major importance with registration and audit duties.
- Appoint a DPO, register with the NDPC and file Compliance Audit Returns by 31 March if you are in the UHL or EHL tier.
- The NDPC enforces the law: the 2025 MultiChoice fine concerned unlawful cross-border transfers.
- Processing patient data locally reduces cross-border transfer risk.
General information only, not legal advice.
Frequently asked questions
Does the Nigeria Data Protection Act apply to clinics?
Yes. Clinics and hospitals process health information, which the NDPA treats as sensitive personal data. Many will be data controllers of major importance under the GAID 2025.
Is the NDPR 2019 still in force?
No. The NDPR 2019 and its 2020 Implementation Framework ceased to apply when the GAID 2025 took effect on 19 September 2025.
When is the NDPC Compliance Audit Return due?
For Ultra-High and Extra-High Level data controllers of major importance, the Compliance Audit Return is due each year by 31 March.
Sources
- Mondaq — Synoptic analysis of the Nigeria Data Protection Act General Application and Implementation Directive (GAID) 2025
- LawPavilion — NDP Act 2023 & GAID 2025: a comprehensive guide
- Banwo & Ighodalo — GAID publication (2025)
- 21st Century Chronicle — FG fines MultiChoice ₦766 million for data privacy violations
- Techpoint Africa — NDPC targets compliance across sectors
Nabady Whisper transcribes your voice offline in English, French or Arabic, with report templates for every specialty.
General information, checked at the publication date; it is neither medical nor legal advice.