AI Data Protection for Nigerian Businesses: How the NDPA Applies to AI

The NDPA does not mention chatbots, large language models or AI agents. It does not need to. It regulates the processing of personal data, and almost every business use of AI processes personal data: a WhatsApp assistant reading customer messages, a document tool extracting details from KYC forms, a CRM feature scoring leads, a staff member pasting a client list into an AI assistant. Each of those is processing, and each falls under the Act.
This article maps the Act's main obligations to AI activities in a Nigerian business. It is a compliance orientation, not legal advice; the Act and the NDPC's implementing directives and guidance evolve, and specific obligations depend on your sector and scale. Linestech's companion articles approach the same subject from different directions: AI privacy for Nigerian businesses covers principles and expectations, AI security for Nigerian businesses covers threats and controls, and how Nigerian businesses should protect data when using AI gives the operational playbook. This one is about what the law requires.
What does the NDPA regulate, and why does AI fall under it?
The Nigeria Data Protection Act 2023 regulates the processing of personal data by data controllers and data processors in Nigeria, and in certain circumstances outside Nigeria where Nigerian data subjects are involved. It established the Nigeria Data Protection Commission (NDPC) as the regulator, replacing the earlier NDPR framework administered by NITDA, and it sets out principles, obligations, data subject rights, enforcement powers and penalties.
"Processing" is defined broadly: collecting, recording, storing, adapting, retrieving, disclosing, combining, erasing. AI systems do all of these. When a model receives a customer's message, that is processing. When a transcript is stored, that is processing. When an AI infers a customer segment, that is processing. There is no AI exemption and no size exemption from the principles, although certain formal duties attach to "data controllers and data processors of major importance", a category the NDPC defines by thresholds and sector. Check your status with the Commission.
Who is responsible: controllers, processors and AI vendors
The Act distinguishes the data controller (who decides the purpose and means of processing) from the data processor (who processes on the controller's behalf). For AI:
| Party | Typical role | What it means |
|---|---|---|
| Your business | Controller | You decide to use AI, for what, on whose data; you carry primary responsibility |
| AI model provider (API) | Processor, usually | Processes your data to provide the service; needs written terms covering security, retention, sub-processors and training use |
| AI SaaS tool vendor | Processor, sometimes joint controller | Depends on whether the vendor uses your data for its own purposes such as model improvement |
| Development agency building your AI | Processor during build and support | Should be bound by contract on confidentiality, security and data handling |
| Automation platform | Processor | Same as tool vendor; check data flows through the platform |
The practical consequence: you cannot outsource responsibility. If a vendor mishandles your customers' data, the NDPC and your customers look to you first. Written processing terms with every AI vendor are not optional paperwork; they are how you evidence that you chose processors with adequate guarantees, which the Act expects of controllers.
NDPA obligations mapped to AI activities
| NDPA area | What the Act expects | How it applies to AI use |
|---|---|---|
| Principles (lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity) | Every processing activity respects them | Only send AI the data the task needs; do not reuse for training or profiling without basis; keep AI logs no longer than needed; correct inaccurate AI outputs |
| Lawful basis | One of the recognised bases applies | Identify it per AI use case, before deployment |
| Transparency and notice | Data subjects are informed | Privacy notice covers AI processing, vendors, transfers; chatbot disclosure |
| Data protection impact assessment | Required where processing is likely to result in high risk | Most AI on sensitive data, profiling or significant decisions qualifies |
| Processor contracts | Written terms with processors | Every AI vendor and development partner |
| Cross-border transfer | Adequacy or appropriate safeguards | Overseas AI providers, cloud hosting outside Nigeria |
| Data subject rights | Access, rectification, erasure, restriction, portability, objection, automated-decision safeguards | AI logs and outputs must be searchable, correctable and deletable; human review for significant decisions |
| Security | Appropriate technical and organisational measures | Access control, scoping, encryption, key management, logging for AI systems |
| Breach notification | Notify NDPC within the Act's timeframe; inform affected individuals where required | AI leaks, prompt-injection exposures and key compromises may be breaches |
| Records and accountability | Demonstrate compliance | AI inventory, DPIAs, vendor terms, decisions and reviews on file |
| Registration and DPO | For controllers and processors of major importance | Check thresholds; AI at scale may push a business into this category |
Verify each item against the current Act, NDPC directives and any sector rules.
Lawful basis for AI processing
The Act recognises several lawful bases, including consent, performance of a contract, compliance with a legal obligation, protection of vital interests, public interest, and legitimate interests balanced against the data subject's rights. Which applies depends on the AI use:
- Answering a customer's order query by AI assistant: usually contract (you are fulfilling the relationship) or legitimate interests.
- Using customer data to build a recommendation or churn model: legitimate interests, with a documented balancing test and an opt-out, or consent where profiling goes beyond reasonable expectations.
- AI screening of job applicants: legitimate interests or pre-contractual steps, with safeguards on automated decisions.
- Processing health or financial data through AI: sensitive categories require stronger justification and safeguards; consent is often needed, and sector rules (for example from the CBN for financial institutions) may add requirements.
- Using customer conversations to train or fine-tune a model: a new purpose that usually needs consent or a clearly documented legitimate-interest basis and notice.
Write the basis down per use case. "We had the data anyway" is not a basis.
Data protection impact assessments for AI
The Act provides for a data protection impact assessment (DPIA) where processing is likely to result in high risk to data subjects. AI uses that commonly meet that threshold include:
- Profiling or scoring individuals (credit, risk, churn, lead quality tied to personal characteristics).
- Automated decisions with significant effects (approvals, rejections, pricing).
- Processing sensitive data (health, biometric, financial, children's data) through AI.
- Large-scale monitoring, including of employees.
- Combining datasets from several sources for AI analysis.
- New technologies applied to personal data, which describes most AI deployments.
A DPIA for an AI project should describe the processing, the data and its sources, the AI vendor and data flows including transfers, the necessity and proportionality of the AI approach, the risks to individuals (leakage, inaccurate outputs, unfair decisions, over-collection), and the measures taken. It is a working document, not a formality: done properly, it produces the data-scoping, hand-off and retention rules your AI will run on. Consult the NDPC's guidance for the expected form.
Cross-border transfers to overseas AI providers
Most AI models and many AI tools process data on infrastructure outside Nigeria. The Act restricts transferring personal data outside Nigeria unless conditions are met, such as an adequacy decision for the destination, appropriate safeguards (for example contractual clauses or binding corporate rules), or specific exceptions including consent. The NDPC issues the relevant directives and adequacy determinations.
For AI, this means:
- Know where each AI vendor processes and stores your data. Ask; do not assume.
- Put appropriate contractual safeguards in place with overseas providers, and keep them on file.
- Reflect transfers in your privacy notice.
- Where data is especially sensitive or a client contract restricts location, consider architectures that keep raw personal data in Nigeria and send only redacted or pseudonymised content to the model. The article on how to build a private AI assistant for your business discusses these designs.
- Verify current transfer requirements with the NDPC; this is an area where directives change.
Data subject rights and automated decisions
The Act grants data subjects rights of access, rectification, erasure, restriction, portability and objection, and provides safeguards against decisions based solely on automated processing, including profiling, that have legal or similarly significant effects, subject to exceptions and conditions.
For an AI-using business this creates concrete requirements:
- Searchable AI records. If a customer asks what you hold, your AI conversation logs and generated records are part of the answer. You need to be able to find them by individual.
- Correction and deletion. Inaccurate AI outputs stored against a person must be correctable; deletion requests must reach AI logs and vendor-held data.
- Objection to profiling. Customers can object to AI-driven profiling for marketing; you need an opt-out route that actually stops it.
- Human review of significant automated decisions. Credit, hiring, admissions, insurance and fraud-blocking decisions should have human involvement, an explanation and a way to contest. Design AI as "recommend" rather than "decide" for these.
- Timelines. Respond to requests within the periods the Act and NDPC set. Verify current timelines.
Security, breach notification and records
Security. The Act requires appropriate technical and organisational measures. For AI systems that means scoping data per user, least-privilege access for agents, protected API keys, encryption in transit and at rest, logging, and vendor security due diligence. Linestech's article on AI security for Nigerian businesses details the controls.
Breach notification. The Act requires controllers to notify the NDPC of personal data breaches within a short statutory timeframe after becoming aware, and to inform affected data subjects where the breach is likely to result in high risk to them. Processors must notify controllers. AI-specific incidents that may qualify include: a chatbot disclosing other customers' data, a leaked model API key that exposed conversation data, a vendor breach, or staff uploading customer records to an unapproved tool. Prepare a notification procedure and verify the current timeframe with the NDPC.
Records. Controllers must be able to demonstrate compliance. For AI, keep: an inventory of AI systems and vendors; the lawful basis per use; DPIAs; processor terms and transfer safeguards; privacy notices; retention decisions; access logs; training records; incident records.
Registration and DPO. Data controllers and processors of major importance must register with the NDPC and appoint a data protection officer, among other duties. Thresholds are set by the Commission and may relate to volume of data subjects and sector. AI deployments that scale customer data processing may change your status. Check.
What changes for Nigerian businesses
- The regulator is active and the framework is new. The NDPA is recent, and the NDPC continues to issue directives, guidance and enforcement actions. Assume requirements will develop and build a habit of checking, rather than a one-time compliance exercise.
- Sector overlays. Financial institutions answer to the CBN as well; health providers, telecoms and others have their own regulators with data expectations. AI in those sectors must satisfy both.
- Almost every AI vendor is overseas. Cross-border transfer is the norm, not the exception, so safeguards and notices need to be in place from the first deployment.
- WhatsApp is where the personal data is. Customer conversations on the WhatsApp Business Platform contain names, numbers, addresses and often more. AI on that channel is high-volume personal data processing and deserves a DPIA.
- Sensitive data is routine in ordinary businesses. Pharmacies, clinics, schools, microfinance, insurance, HR and recruitment firms handle sensitive categories daily. AI in these businesses needs stronger bases and safeguards.
- Small businesses still have obligations. Formal duties such as registration scale with importance, but principles, lawful basis, security and data subject rights apply to everyone processing personal data.
- Penalties can be significant. The Act provides for fines that can be calculated as a proportion of revenue for major-importance entities, alongside other remedies. Verify current figures. Reputational damage from a public incident is often the larger cost.
Example (hypothetical): an Abuja HR outsourcing firm
Example (hypothetical): an HR outsourcing company in Abuja manages recruitment and payroll for 30 client companies. It wants to use AI to screen CVs, draft interview summaries from recorded calls, and answer employee payroll queries on WhatsApp.
Roles. The firm is a processor for its clients' employee data and a controller for its own candidate database. Each AI vendor becomes a sub-processor for client data, which the firm's client contracts may require it to disclose and get approval for.
Lawful basis. CV screening: legitimate interests and pre-contractual steps, documented, with human review of every rejection. Interview recording and AI summarisation: notice to candidates and consent to recording. Payroll queries by AI: contract, with strict per-employee data scoping since payroll data is sensitive.
DPIA. The firm carries out a DPIA covering all three uses: profiling of candidates, sensitive payroll data, cross-border processing by the AI vendor, and the risk of a WhatsApp assistant disclosing one employee's salary to another. The DPIA produces design rules: no fully automated rejections; per-employee authentication before any payroll answer; redaction of identifiers before transcripts reach the model; 90-day retention of AI logs.
Transfers and vendors. The firm confirms in writing where each vendor processes data, signs processing terms with training-use exclusions, and updates its privacy notice and client contracts.
Rights and breach readiness. The firm builds a procedure to search and delete AI logs by individual, adds a "request human review" option for candidates, and writes a breach notification runbook naming who contacts the NDPC and clients.
None of this stops the firm using AI. It determines how the AI is built, and it makes the firm's client contracts easier to win, because clients ask exactly these questions.
Implementation: an AI compliance sequence
The first step is an inventory, because you cannot assess what you have not listed. Then:
- Inventory AI processing. Every AI tool, feature, chatbot, assistant and agent; the personal data each touches; the vendor; where data goes.
- Assign roles. Controller or processor for each activity; note client contracts that impose obligations on you.
- Fix a lawful basis per use. Write it down. Flag uses that need consent or a documented legitimate-interest assessment.
- Screen for high risk and run DPIAs. Sensitive data, profiling, significant decisions, large scale, employee monitoring. Complete DPIAs before deployment, and let them drive design.
- Contract with vendors. Processing terms covering security, retention, sub-processors, training-use exclusion, breach notification and transfer safeguards. Keep copies.
- Update notices. Privacy notice and chatbot disclosure covering AI use, vendors and transfers, in plain language.
- Build rights handling into the system. Searchable, correctable, deletable AI records; opt-out from profiling; human review route for significant decisions.
- Implement security controls and retention. Per the AI security article; set retention periods and enforce them.
- Write the breach procedure. Who assesses, who notifies the NDPC and individuals, within what time.
- Train staff and record it. What may be entered into AI tools, how to recognise a data subject request, how to escalate an incident. See how to train employees to use AI.
- Check registration status. Determine whether you are a controller or processor of major importance and act accordingly.
- Review annually and on change. New AI use, new vendor, new data type or new NDPC directive triggers a review.
Mistakes to avoid
- Assuming AI vendors carry the responsibility. You are the controller. Vendor terms allocate tasks, not accountability.
- No lawful basis on file. Deploying first and justifying later is how businesses end up with processing they cannot defend.
- Skipping the DPIA because the project is "just a chatbot". A WhatsApp assistant on customer data at scale is high-volume processing and often sensitive. The DPIA is where the safe design comes from.
- Ignoring cross-border transfer. Nearly every AI provider is overseas. Safeguards and notices must reflect that.
- Storing AI logs indefinitely with no way to search them. Data subject requests then become impossible to satisfy.
- Fully automated significant decisions. Rejections, approvals and pricing without human involvement create legal exposure under the automated-decision provisions.
- Consumer AI accounts for customer data. Terms rarely meet processor requirements. Use business tiers with written terms.
- Treating compliance as a document. Notices and policies that are not reflected in how the AI system actually behaves protect no one.
Conclusion
The NDPA applies to AI the way it applies to any processing of personal data, which means a Nigerian business using AI needs a lawful basis for each use, impact assessments for high-risk processing, written terms with every AI vendor, safeguards for cross-border transfers, systems that can honour data subject rights (including human review of significant automated decisions), appropriate security, and a breach procedure. Done in sequence, starting with an inventory, this is manageable for an SME and expected of a larger company. The compliance work also produces better AI systems, because the DPIA and the rights requirements force the data scoping, hand-off and retention decisions that make AI safe to run.
If you are planning an AI deployment that touches customer, employee or client data and want it designed around NDPA-aligned data flows, retention and rights handling from the start, Linestech can help you scope and build it that way.
Frequently asked questions
Does the NDPA apply if our AI vendor is outside Nigeria?
Yes. Your business, as the controller in Nigeria, remains responsible for processing carried out on its behalf, wherever the processor is. Using an overseas AI provider also engages the Act's cross-border transfer rules, so you need appropriate safeguards in place and disclosed. Verify current transfer requirements with the NDPC.
Do we need consent to use AI on customer data?
Not always. Consent is one lawful basis among several; contract and legitimate interests often apply to ordinary customer service and operations. Consent becomes more likely where processing goes beyond reasonable expectations, involves sensitive data, or reuses data for a new purpose such as training a model or profiling. Document the basis for each use.
Is a DPIA legally required for an AI chatbot?
The Act requires a DPIA where processing is likely to result in high risk. A chatbot handling customer personal data at scale, especially on WhatsApp or with sensitive categories, commonly meets that threshold, and a DPIA is good practice regardless. Consult the NDPC's guidance and a qualified adviser for your specific case.
What if a staff member pastes customer data into ChatGPT?
That is processing by your business through a processor you may not have terms with. It may breach purpose limitation, security and transfer requirements, and if the data is exposed it may be a notifiable breach. Prevent it with approved business-tier tools, written rules and training; if it happens, assess the exposure and follow your breach procedure.
Can we use AI to make credit or hiring decisions in Nigeria?
AI can assist, but the Act provides safeguards against decisions based solely on automated processing with legal or similarly significant effects. The safe pattern is AI recommends, a human decides, with reasoning available and a route for the individual to contest. Financial institutions should also check CBN requirements.
Are we a "data controller of major importance" because we use AI?
Possibly. The NDPC sets the criteria, which relate to factors such as the number of data subjects processed and sector. An AI deployment that scales customer data processing can move a business across a threshold, triggering registration, DPO appointment and other duties. Check the current criteria with the Commission.
How long do we have to report an AI-related data breach?
The Act sets a short statutory timeframe for notifying the NDPC after becoming aware of a breach, with affected individuals to be informed where the breach is likely to result in high risk. Prepare the procedure in advance so the timeframe is achievable, and verify the current requirement with the NDPC.
Sources and further reading
Figures, platform rules and regulations change. These are the primary references behind this article and the places to check before you act on it.


