FG Orders MDAs to Appoint Data Protection Officers, Warns CEOs of Personal Liability

Published on 4 August 2026 at 16:30

Reported by: Oahimire Omone Precious | Edited by: Oravbiere Osayomore Promise.

The Federal Government has issued a sweeping directive to all Ministries, Departments and Agencies (MDAs), mandating the appointment of qualified Data Protection Officers (DPOs) and warning that Chief Executive Officers, Permanent Secretaries, and Accounting Officers will be held personally liable for non-compliance with the Nigeria Data Protection Act (NDP Act), 2023. The directive, contained in Circular No. 59805/S.I/74 dated July 27, 2026, and signed by the Secretary to the Government of the Federation, Senator George Akume, represents the government's strongest move yet to enforce data protection rules across the public sector as digital government services expand.

The circular, which was made public on Tuesday, August 4, 2026, through a statement by the Head of Legal, Enforcement and Regulations of the Nigeria Data Protection Commission (NDPC), Babatunde Bamigboye, draws attention to President Bola Tinubu's directive that "data is the new oil" and that its value increases the more it is refined and responsibly shared. The President had earlier directed all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023. The latest circular builds on that directive by establishing specific compliance requirements that all federal MDAs must now meet.

Under the new directive, all MDAs are required to designate suitably qualified officers as Data Protection Officers to oversee institutional compliance and advise management on all matters relating to the lawful processing of personal data. The names and contact details of the designated DPOs must be forwarded to the NDPC for registration and official records. Agencies are also required to engage licensed Data Protection Compliance Organisations (DPCOs), where necessary, to facilitate compliance with the NDP Act and support the conduct of statutory compliance audits. In addition, the circular mandates MDAs to make adequate budgetary provisions for data protection activities, including capacity building, awareness programmes, deployment of appropriate technical safeguards, and periodic compliance audits. All mandatory Data Protection Compliance Audit Returns and other statutory returns must be submitted to the NDPC within the timelines prescribed by law.

Perhaps the most significant provision of the circular is the assignment of personal responsibility to top public officials. The directive explicitly states that Permanent Secretaries, Accounting Officers, and Chief Executive Officers of all MDAs shall be personally responsible for ensuring institutional compliance with the circular and the provisions of the NDP Act. This accountability clause raises the stakes for agency leadership, signalling that data protection is no longer viewed as merely an information technology function but as a core governance responsibility. The move comes as government agencies increasingly rely on digital platforms to deliver services ranging from identity management and healthcare to taxation, education, immigration, and social welfare, placing vast amounts of Nigerians' personal data under public institutions.

Reacting to the directive, the National Commissioner and Chief Executive Officer of the NDPC, Dr Vincent Olatunji, commended the Tinubu administration for demonstrating what he described as strong legal and political commitment to protecting the privacy rights and fundamental freedoms of Nigerians. Olatunji said effective data governance and accountability remain essential to achieving the eight priority areas of the Federal Government. He disclosed that the commission had established a regulatory clinic to provide technical support to MDAs and assist them in complying with the requirements of the Nigeria Data Protection Act. According to him, the initiative forms part of broader regulatory measures being pursued by the commission to strengthen Nigeria's digital governance framework as the country positions itself to take advantage of opportunities presented by the Fourth Industrial Revolution.

The directive is expected to significantly improve public confidence in digital government if fully implemented. Nigeria has accelerated digital transformation in recent years through wider adoption of online public services, digital identity systems, electronic tax administration, and integrated government databases. While these initiatives promise greater efficiency, they have also increased concerns over privacy, cybersecurity, and the management of personal information. The latest directive is expected to standardise data governance practices across the federal public service and reduce differences in compliance among agencies. For businesses operating in the data protection ecosystem, including licensed compliance firms, cybersecurity providers, and privacy consultants, the directive is expected to create fresh demand for compliance services as federal institutions move to meet the new requirements.

The NDPC said the latest directive indicates the Federal Government's determination to institutionalise responsible data management across the public sector while ensuring that personal information entrusted to government institutions is processed in line with global best practices. The circular places the onus on agency heads to act swiftly, with the NDPC offering technical support through its newly established regulatory clinic. As Nigeria advances its digital transformation agenda, the directive marks a critical step towards building a data governance framework that protects citizens' privacy while enabling the efficient delivery of public services.

📩 Stone Reporters News | 🌍 stonereportersnews.com
✉️ info@stonereportersnews.com | 📘 Facebook: Stone Reporters News | 🐦 X (Twitter): @StoneReportNew | 📸 Instagram: @stonereportersnews

Add comment

Comments

There are no comments yet.