Personal Data - What the Law Says?

4 June 2026

1.0 Legal Framework for Data Protection

In recent days, controversy has arisen following the publication by Lere Olayinka, an aide to the Minister of the Federal Capital Territory (FCT), of the Permanent Voter Card (PVC) transfer details of Emeka Ike, an aspirant for the House of Representatives. The screenshots shared online reportedly contained details from the administrative portal of the Independent National Electoral Commission's (INEC) Continuous Voter Registration (CVR) system, raising concerns that an individual within INEC may have granted a third party access to a voter's personal information.

This development has sparked important questions about data privacy, the protection of personal information, and the responsibilities of public institutions entrusted with citizens' data.

The legal framework for data protection in Nigeria finds its foundation in the Constitution of the Federal Republic of Nigeria 1999 (as amended). Section 37 of the Constitution guarantees and protects the privacy of citizens, their homes, correspondence, telephone conversations, and telegraphic communications. This constitutional provision establishes privacy as a fundamental right and forms the basis for Nigeria's data protection regime.

Building on this constitutional guarantee, the Nigerian Data Protection Act (NDPA) 2023 provides the principal legal framework for the protection of personal information in Nigeria. The Act establishes the Nigerian Data Protection Commission (NDPC), which is responsible for regulating the processing of personal data and ensuring that individuals' privacy rights are protected.

What Does the Law Say?

The right to privacy is a constitutionally guaranteed right in Nigeria. Section 37 of the Constitution of the Federal Republic of Nigeria 1999 provides that "the privacy of citizens, their homes, correspondence, telephone conversations and telegraphic communications is hereby guaranteed and protected." This provision establishes privacy as a fundamental right. Consequently, any unauthorised intrusion into an individual's private communications, personal information, or private life may constitute a violation of a constitutionally protected right and can be challenged and enforced before a court of law.

Beyond the Constitution, the Nigerian Data Protection Act (NDPA) 2023 provides a comprehensive legal framework for the protection and processing of personal data. Section 24(1) of the Act requires that personal data be processed in a fair, lawful, and transparent manner. This means that organisations, institutions, and individuals handling personal information must do so in accordance with the law and in a way that is clear and understandable to the data subject.

The Act also provides remedies for individuals whose data protection rights have been violated. Under Section 46 of the NDPA, a data subject who is dissatisfied with the decision, action, or inaction of a data controller or data processor may lodge a complaint with the Nigerian Data Protection Commission (NDPC). Furthermore, Section 51 of the Act grants data subjects the right to seek compensation where they suffer injury, loss, or harm as a result of a violation of the law. Such individuals may recover damages from the responsible data controller or data processor through civil proceedings.

In addition, the NDPA requires that personal data be collected only for specified, explicit, and legitimate purposes. Section 24(1) prohibits the further processing of personal data in a manner that is incompatible with the purpose for which it was originally collected. This principle seeks to prevent the misuse or unauthorised repurposing of personal information. The Act also emphasises the importance of data accuracy. Personal data must be accurate, complete, not misleading, and kept up to date where necessary, taking into account the purpose for which the information is being processed. This obligation helps to ensure that decisions affecting individuals are based on correct and reliable information. Another key requirement under Section 24(1) is the protection of personal data against unauthorised access, unlawful processing, loss, destruction, damage, or any other form of data breach. Data controllers and processors are therefore expected to implement measures that safeguard the confidentiality and security of the information under their control.

To reinforce these obligations, Section 24(2) of the NDPA mandates data controllers and data processors to adopt appropriate technical and organisational measures to ensure the confidentiality, integrity, and availability of personal data. This includes putting in place adequate security systems, policies, and procedures to prevent data breaches and protect the rights of data subjects. Taken together, the Constitution and the Nigerian Data Protection Act 2023 establish a robust legal framework for the protection of privacy and personal data in Nigeria. They not only impose obligations on those who process personal information but also provide individuals with avenues for redress where their rights have been violated.

INEC's LIABILITY?

INEC has issued a statement indicating that the data breach occurred through the credentials of one of its personnel. The Commission stated that it has commenced an internal investigation into the incident and that the Department of State Services (DSS) is also conducting an investigation. According to INEC, there have been no additional breaches beyond the release of the personal data of the individual concerned.

Under the Nigerian Data Protection Act (NDPA) 2023, organisations such as INEC that process personal data are required to notify the Nigerian Data Protection Commission (NDPC) within 72 hours of becoming aware of a personal data breach where the breach is likely to pose a risk to the rights and freedoms of individuals. Such notification should, where feasible, include details of the nature of the breach, the categories and approximate number of affected data subjects, and the categories and approximate number of personal data records involved. This is one of the key obligations imposed on INEC under the Act.

The NDPA further provides that where a personal data breach is likely to result in a high risk to the rights and freedoms of a data subject, the data controller must communicate the breach directly to the affected individual in clear and plain language. Such communication should explain the nature of the breach and provide advice on measures the affected person can take to mitigate any potential adverse effects. However, where direct communication with the affected data subject would involve disproportionate effort or expense, or is otherwise not feasible, the Act permits the data controller to make a public announcement through one or more widely used media platforms to ensure that affected individuals are adequately informed of the breach and any steps they may need to take to protect themselves.

In determining the impact of a personal data breach, consideration should be given to:

  1. How effective the security and administrative measures were in reducing the harm caused by the breach, including whether the data was encrypted or anonymised
  2. Any additional steps taken by the data controller after the breach to reduce the risks and protect affected individuals; and
  3. The type of personal data involved, the amount of data affected, and how sensitive the information is.

Conclusion

The reported breach once again raises important concerns about the protection of personal data and the security of sensitive information held by public institutions. While INEC has acknowledged the incident and commenced investigations, compliance with the requirements of the Nigerian Data Protection Act 2023 extends beyond investigating the source of the breach. The Commission is also expected to fulfil its statutory obligations regarding breach notification, risk assessment, and communication with the affected individual where necessary. INEC must also ensure that the individuals responsible for these breaches face disciplinary actions under its organisational rules.

Ultimately, the manner in which INEC responds to this incident will not only determine its compliance with the law but will also influence public confidence in its ability to safeguard the personal voter information entrusted to it by citizens.

AllAfrica publishes around 600 reports a day from more than 90 news organizations and over 500 other institutions and individuals, representing a diversity of positions on every topic. We publish news and views ranging from vigorous opponents of governments to government publications and spokespersons. Publishers named above each report are responsible for their own content, which AllAfrica does not have the legal right to edit or correct.

Articles and commentaries that identify allAfrica.com as the publisher are produced or commissioned by AllAfrica. To address comments or complaints, please Contact us.