NDPC Issues Urgent Advisory on Rising Data Security Threats in Nigeria

The Nigeria Data Protection Commission (NDPC) has issued a critical advisory warning of escalating threats to Nigeria’s data security infrastructure, urging organisations across both public and private sectors to strengthen their data protection measures.
In the advisory dated April 16, 2026, the Commission revealed that its technical assessment had identified coordinated activities by “shadowy threat actors” targeting financial systems and key digital infrastructure within the country. This development underscores growing concerns about cyber vulnerabilities in Nigeria’s rapidly expanding digital ecosystem.
The NDPC called on all data controllers and processors—including Ministries, Departments, and Agencies (MDAs)—to urgently enhance their technical and organisational safeguards in line with the provisions of the Nigeria Data Protection Act 2023.
Reinforcing this directive, the Commission referenced the position of Bola Ahmed Tinubu, who described data as “the new oil,” emphasizing that its value increases when properly managed, refined, and responsibly shared. The President has also directed government institutions to rigorously capture and secure data in compliance with national regulations.
Key Security Measures Recommended
To mitigate risks and strengthen resilience, the NDPC outlined several critical measures organisations must adopt:
- Appointment of trained and certified Data Protection Officers
- Implementation of comprehensive privacy policies and security standards
- Conduct of Data Privacy Impact Assessments
- Deployment of strong identity and access controls, including Multi-Factor Authentication (MFA)
- Adoption of zero-trust security architecture and network segmentation
- Continuous vulnerability management and patch updates
- Protection of cloud systems, APIs, and databases
- Real-time monitoring, logging, and threat detection
- Encryption and secure credential management
- Regular Vulnerability Assessment and Penetration Testing (VAPT)
- Routine data backup and resilience testing
Compliance and Legal Implications
The Commission warned that organisations that fail to comply with the requirements of the Data Protection Act may face legal consequences. It reaffirmed its commitment to supporting organisations in achieving compliance while ensuring the privacy and security of personal data.
According to the NDPC, strengthening data protection frameworks is essential not only for safeguarding sensitive information but also for building trust in Nigeria’s digital economy and enhancing institutional resilience.
A Call to Action
As cyber threats continue to evolve, the NDPC’s advisory serves as a timely reminder of the need for proactive measures in protecting digital assets. Organisations are encouraged to act swiftly, not only to avoid regulatory penalties but also to ensure the safety and integrity of the data they manage.




