The Federal Government has issued a directive mandating all Ministries, Departments, and Agencies (MDAs) to appoint Data Protection Officers (DPOs) within 30 days. The order, announced by the Nigeria Data Protection Commission (NDPC), warns Chief Executive Officers (CEOs) that they will be held personally liable for any data breaches or non-compliance with the Nigeria Data Protection Act.
NDPC Issues Ultimatum to MDAs
In a circular dated July 29, 2026, and signed by the NDPC's Head of Legal, Enforcement and Regulations, Mrs. Olufunke Adegoke, the Commission directed all MDAs to designate a DPO and notify the Commission within one month. The directive is part of the government's efforts to strengthen data privacy and security across public institutions.
According to the NDPC, the appointment of DPOs is a critical requirement under the Nigeria Data Protection Act 2023, which obliges data controllers and processors to ensure compliance. The Commission emphasized that failure to appoint a DPO would be considered a violation of the Act, attracting sanctions.
CEOs Face Personal Liability
The NDPC warned that CEOs of MDAs would be held personally liable for any data protection lapses within their organizations. This includes breaches, unauthorized access, or mishandling of personal data. The Commission cited Section 45 of the Act, which stipulates that "every data controller or processor shall designate a Data Protection Officer" and that "the officer shall be responsible for ensuring compliance with the provisions of this Act."
Mrs. Adegoke stated, "The era of paying lip service to data protection is over. CEOs must take ownership of data governance in their agencies, as they will be accountable for failures." She added that the NDPC would conduct regular audits to verify compliance.
Implications for Public Institutions
The directive affects hundreds of MDAs, including ministries, parastatals, and agencies. Each must appoint a DPO who is a senior staff member with adequate knowledge of data protection laws. The DPO will be responsible for training staff, conducting privacy impact assessments, and serving as the contact point for the NDPC.
Experts say this move will improve transparency and accountability in handling citizens' data. "This is a welcome development," said data protection consultant, Mr. Tunde Adebayo. "It will help build public trust in government services, especially as more services go digital."
Enforcement and Next Steps
The NDPC has threatened to impose fines on non-compliant MDAs. Under the Act, penalties for non-compliance include a fine of up to 2% of annual gross revenue or 10 million Naira, whichever is higher. The Commission also has the power to issue enforcement notices and compel corrective actions.
The NDPC plans to publish a list of MDAs that have complied with the directive by the end of August 2026. MDAs are urged to submit their DPO details through the Commission's online portal.
This directive is part of broader efforts to align Nigeria with global data protection standards, such as the GDPR. It also comes amid growing concerns over data breaches in the public sector.



