Skip to main content

Olatokunbo Bamgose

Data Governance as a Board Obligation: What the NDPC’s Enforcement Programme Means for Nigerian Directors in 2026

Data protection compliance in Nigeria is no longer an IT troubleshooting function. It is an active governance obligation that sits squarely at the board level. Directors who continue to treat data privacy as a secondary technical matter are carrying severe personal exposure under the Companies and Allied Matters Act (CAMA)2020-exposure they may not yet fully recognize.

The 2026 Enforcement Context:

Beyond the Warning Phase

The regulatory landscape transformed dramatically when the Nigeria Data Protection Commission (NDPC) issued compliance notices to 1,368 organizations, targeting key economic pillars including banking, insurance, pensions, gaming, and telecommunications.

This operational scale was reinforced by a critical legislative shift: the General Application and Implementation Directive (GAID) 2025 officially superseded the old Nigeria Data Protection Regulation (NDPR) 2019, serving as the definitive operative compliance framework under the Nigeria Data Protection Act (NDPA) 2023.

For Data Controllers and Processors of Major Importance (DCPMI), the statutory deadline for the annual Compliance Audit Return (CAR) was March 15, 2026. Organizations that missed this window are already in regulatory breach, exposing themselves to an aggressive enforcement posture.

Under Section 48 of the NDPA 2023, the financial consequences are material:

• Data Controllers of Major Importance:

Administrative penalties can scale up to

N10,000,000 or 2% of the preceding year’s gross revenue, whichever is greater.

• Data Controllers of Ordinary Importance:

Penalties max out at N2,000,000 or 1% of gross revenue, whichever is greater.

Beyond monetary fines, the NDPC holds the statutory teeth to issue restrictive processing orders, halt business operations, and refer recalcitrant officers for criminal prosecution.

The Shifting Fiduciary Frontier: The Intersection of CAMA and NDPA

The intersection of data protection law and directors’ duties under CAMA 2020 is an emerging battleground in Nigerian corporate governance.

Section 311 of CAMA 2020 imposes a strict statutory duty of care, skill, and diligence on every corporate director. This duty is measured against a dual standard:

1. The Objective Test: The level of care that a reasonably prudent director in comparable circumstances would exercise.

2. The Subjective Test: A standard calibrated to the specific knowledge, professional expertise, and functional role of that individual director.

This fiduciary duty is not passive; it mandates active oversight of every material regulatory risk affecting the corporate entity.

Because the NDPA 2023 governs any entity that processes personal data-encompassing companies with employees, customer databases, consumer-facing websites, or third-party vendor integrations-virtually every enterprise operating at scale in Nigeria falls within its ambition .

A director who delegates data privacy entirely to management without an active, documented assurance mechanism has failed to discharge their governance responsibility. Under Section 311, blind delegation without systemic oversight does not insulate a director from liability.

Legal Reality: The personal liability provisions of CAMA 2020 offer no safe harbor for directors who remain uninformed by choice. The duty of care is an active obligation; willful ignorance is not a defense.

Anatomy of Board-Level Data

Governance Oversight

Effective board engagement does not require directors to morph into cybersecurity or data protection technicians. Instead, it requires the board to subject data governance to the same rigorous internal controls applied to financial auditing and legal risk management.

In practice, an compliant 2026 board protocol must ensure:

• Systemic Reporting: The board must receive periodic, structured updates on the company’s data footprint, including its NDPC registration status, the outcomes of the annual CAR filing, outstanding regulatory notices, and a log of any localized data breaches.

• Empowered Supervision: Boards must satisfy themselves that a qualified Data Protection Officer (DPO) has been formally appointed, properly resourced, and granted the corporate authority to execute compliance strategies.

• Policy Calibration: The board must formally review and ratify the company’s internal and external privacy policies, ensuring they are actively mapped against the current GAID 2025 framework, rather than obsolete NDPR rules.

• Transaction Due Diligence: Corporate data assets must be factored into structural due diligence protocols during mergers, acquisitions, joint ventures, or significant vendor adoptions.

• Tested Incident Response: The board must review and verify a documented, operational data breach response protocol that details immediate containment, mitigation, and statutory reporting channels.

The Defensive Roadmap for Directors

To mitigate personal and corporate exposure in the current enforcement cycle, boards must immediately deploy a clear, four-part defensive playbook:

1.Commission an Independent GAID 2025

Audit: Retain certified, external data protection experts to audit the company’s compliance architecture against the GAID 2025 framework. This must assess lawful bases for processing, data subject right mechanisms, and cross-border data transfer protocols.

2. C-Suite Accountability : Ensure the findings, corporate gaps, and security vulnerabilities identified in the audit are formally presented to, and debated by, the board.

3. Approve a Monitored Remediation Plan:

Where vulnerabilities exist, the board must ratify a time-bound remediation roadmap and receive subsequent progress updates from management.

4. Exhaustive Documentation: Meticulously capture all data governance discussions, expert presentations, and compliance decisions within the official board minutes.

This paper trail serves as the primary shield proving the board exercised its statutory duty of care.

Conclusion

In 2026, data governance is an inescapable board-level obligation under Nigerian law. While the NDPA 2023 dictates the operational rules of the game, CAMA 2020 establishes the personal governance consequences for directors who fail to play  by them. With the NDPC moving aggressively into an era of scaled enforcement, proactive compliance is no longer a luxury—it is a matter of corporate and personal legal survival.

#DataProtectionNigeria #NDPANigeria

#NDPCNigeria #GAID2025

#DirectorsDutiesNigeria #CAMA2020

#CorporateGovernanceNigeria

#BusinessLawNigeria #PrivacyLawNigeria #RegulatoryComplianceNigeria

#LegalTrendsNigeria #OlatokunboBamgboseLP

Share This Article