A Federal High Court in Lagos has ruled that Point-of-Sale (PoS) operators must register with the Nigeria Data Protection Commission (NDPC), affirming that these businesses process personal data subject to the Nigeria Data Protection Act (NDPA) 2023. The judgement, delivered by Justice F.N. Ogazi, dismissed a lawsuit challenging the NDPC's authority to require registration and strengthens data privacy oversight in Nigeria's rapidly growing digital payments sector.
Court Ruling and Legal Background
The case, Emmanuel Harunna v. Nigeria Data Protection Commission (Suit No. FHC/L/CS/1116/2024), arose when the claimant sought to block the NDPC's directive requiring PoS operators to register as Data Controllers and Processors of Major Importance (DCPMI). Justice Ogazi upheld the Commission's powers under Sections 5(d), 6(c), 44, 45, and 65 of the NDPA, noting that Section 65 grants the Act overriding effect over conflicting laws. The court classified PoS operators under the Major Data Processing – Ordinary High Level (OHL) category of the DCPMI framework.
Why PoS Agents Are Considered Data Processors
Every PoS transaction involves handling sensitive personal data, including full names, phone numbers, bank account details, BVN-linked transaction records, transaction history, and debit card information. Although agents process data on behalf of financial institutions and payment service providers, the court agreed that they fall under the NDPC's regulatory oversight because they routinely collect, store, and transmit customers' personal information.
Who Is Affected by the Ruling?
The court affirmed the NDPC's authority to mandate registration, but the exact scope—whether individual standalone agents must register or can be covered through aggregator platforms—depends on the Commission's upcoming implementation guidelines. Many PoS agents operate under licensed fintech companies or super-agent networks. The NDPC's DCPMI framework classifies organisations based on data volume, sensitivity, number of data subjects, and strategic importance. Further guidance is expected to clarify registration obligations for each tier.
What PoS Operators Should Do Now
- Contact your aggregator: Check with your fintech provider or bank (e.g., Moniepoint, OPay, Flutterwave) to confirm if their compliance covers your location.
- Practice data privacy: Avoid recording customer card details, PINs, or BVNs on paper or unencrypted logs.
- Monitor NDPC announcements: Watch for official guidelines on registration deadlines and whether standalone agents need independent filings.
Penalties for Non-Compliance
Following the ruling, NDPC National Commissioner Dr. Vincent Olatunji directed all unregistered major data controllers and processors to register without delay. Under the NDPA 2023, organisations classified as DCPMI face administrative fines of up to ₦10 million or 2% of annual gross revenue, whichever is higher. Other data controllers and processors may be fined up to ₦2 million or 1% of annual revenue. Additional enforcement measures include compliance orders, investigations, operational restrictions, and criminal prosecution.
Why This Matters for Nigeria's Digital Economy
The judgement reinforces data protection safeguards for millions of Nigerians who rely on PoS terminals for cash withdrawals, transfers, and bill payments, especially in underserved communities. Regulators argue that stronger oversight is essential to prevent identity theft, fraud, and unauthorized use of personal information as the digital payments ecosystem expands.
Operators should follow any compliance timelines issued by the NDPC, as the court ruling itself did not set a new deadline but upheld existing registration requirements.



