NITDA and NDPC Pledge Closer Ties, but Put Nothing in Writing

NITDA X NDPC
NITDA X NDPC

Nigeria’s two main digital regulators promised closer integration this week. The pledge matters because the data protection regulator only recently became independent of the agency that built it. For companies that handle Nigerians’ personal data, the real question is not whether the two bodies get along, but who is responsible for what, and who has the final word when they disagree.

What the Two Agencies Agreed

Kashifu Inuwa Abdullahi, director-general of the National Information Technology Development Agency (NITDA), visited Nigeria Data Protection Commission (NDPC) chief Vincent Olatunji at the commission’s new Abuja headquarters, according to Voice of Nigeria and TechAfrica News. Abdullahi pledged continued strategic support and urged the NDPC to keep Nigeria’s standards in line with global best practice.

Olatunji thanked NITDA for backing the NDPC as it moved from an internal NITDA unit to an independent regulator. He also traced the framework’s path from the Nigeria Data Protection Regulation to the Nigeria Data Protection Act of 2023. That history is worth remembering. The NDPC did not start as a separate body. It grew inside NITDA, which is why the relationship between the two is closer, and more delicate, than a typical link between agencies.

Both institutions closed the meeting by reaffirming closer integration and cooperation. On the surface, that is a warm and unremarkable courtesy call. The substance is thinner.

The published accounts mention no memorandum, joint work plan or deadline. Vague pledges between regulators cost nothing, and they leave companies guessing which agency answers which question. A business that suffers a breach, launches a new data-driven product or handles cross-border transfers needs to know where to go for guidance and who will enforce the rules. A statement of goodwill does not tell them.

A Busy Year for NDPC Partnerships

The NDPC has collected partners quickly. In February, the Nigerian Communications Commission and the NDPC finalised an MoU on data protection in telecoms, according to the News Agency of Nigeria. That agreement matters because telecoms firms hold some of the largest pools of personal data in the country, and both regulators have a stake in how it is handled.

In January, officials from NITDA and the NDPC joined a week-long UK study mission organised by NITDA with Britain’s Foreign, Commonwealth & Development Office. The agenda covered data protection, cybersecurity, procurement and IT project clearance.

Set side by side, the pattern is clear. The NDPC’s arrangement with the NCC is a written, sector-specific agreement. Its relationship with NITDA, so far, is a spoken commitment. If the telecoms MoU is the model, the NITDA relationship still needs its own document.

Why the Timing Matters

The visit came days after the African Union opened a two-day consultation on AI governance and regulation. According to TechAfrica News, the consultation named data governance, cross-border data flows, cybersecurity and sandbox testing as the areas where alignment matters most. Those are the domains where NITDA and the NDPC already operate.

The timing looks coincidental, but the logic is not. Any continental approach to AI will lean heavily on data protection, and Nigeria’s data regulators are among those that will have to make it work in practice. That raises the stakes for how clearly the two Nigerian agencies divide their roles. Regulators that cannot explain their own division of labour will struggle to shape, or enforce, a wider framework.

Enforcement Is the Real Test

TechMoonshot reported in February that the NDPC had collected ₦7.2 billion in penalties, registered 38,677 companies and completed 246 breach investigations. Those figures point to an active regulator.

Yet our May analysis of AI regulation across Africa found more than 1,300 organisations listed as under investigation and relatively few settled with binding penalties. The gap between investigations opened and cases closed suggests that capacity, not intent, is the constraint. It also flagged a proposed AI commission bill that could change registration requirements within a year, which adds another moving part for companies already trying to keep up.

Closer ties with NITDA raise a harder question. An independent regulator must be able to investigate and fine public bodies as readily as private firms. NITDA is itself a government agency, and the NDPC only recently left its structure. Neither agency has said how integration will protect the NDPC’s independence, or who decides when their priorities collide.

What Companies Should Watch

For businesses operating in Nigeria, the practical takeaways are straightforward:

Treat the pledge as a signal, not a rule. Nothing published so far changes a company’s compliance obligations under the Nigeria Data Protection Act of 2023.

Expect the NDPC to remain the main point of contact for data protection matters, while NITDA continues to shape wider digital policy. The boundary between the two is where confusion is most likely.

Keep an eye on enforcement. With more than 1,300 organisations reportedly under investigation, and penalties already collected, the risk of being pursued is real even if settlements are slow.

Watch for a signed agreement with a timeline and a clear split of responsibilities. Until then, the NITDA-NDPC relationship is a statement of intent, not a framework.

Nigeria’s two main digital regulators promised closer integration this week. The pledge matters because the data protection regulator only recently became independent of the agency that built it. For companies that handle Nigerians’ personal data, the real question is not whether the two bodies get along, but who is responsible for what, and who has the final word when they disagree.

What the Two Agencies Agreed

Kashifu Inuwa Abdullahi, director-general of the National Information Technology Development Agency (NITDA), visited Nigeria Data Protection Commission (NDPC) chief Vincent Olatunji at the commission’s new Abuja headquarters, according to Voice of Nigeria and TechAfrica News. Abdullahi pledged continued strategic support and urged the NDPC to keep Nigeria’s standards in line with global best practice.

Olatunji thanked NITDA for backing the NDPC as it moved from an internal NITDA unit to an independent regulator. He also traced the framework’s path from the Nigeria Data Protection Regulation to the Nigeria Data Protection Act of 2023. That history is worth remembering. The NDPC did not start as a separate body. It grew inside NITDA, which is why the relationship between the two is closer, and more delicate, than a typical link between agencies.

Both institutions closed the meeting by reaffirming closer integration and cooperation. On the surface, that is a warm and unremarkable courtesy call. The substance is thinner.

The published accounts mention no memorandum, joint work plan or deadline. Vague pledges between regulators cost nothing, and they leave companies guessing which agency answers which question. A business that suffers a breach, launches a new data-driven product or handles cross-border transfers needs to know where to go for guidance and who will enforce the rules. A statement of goodwill does not tell them.

A Busy Year for NDPC Partnerships

The NDPC has collected partners quickly. In February, the Nigerian Communications Commission and the NDPC finalised an MoU on data protection in telecoms, according to the News Agency of Nigeria. That agreement matters because telecoms firms hold some of the largest pools of personal data in the country, and both regulators have a stake in how it is handled.

In January, officials from NITDA and the NDPC joined a week-long UK study mission organised by NITDA with Britain’s Foreign, Commonwealth & Development Office. The agenda covered data protection, cybersecurity, procurement and IT project clearance.

Set side by side, the pattern is clear. The NDPC’s arrangement with the NCC is a written, sector-specific agreement. Its relationship with NITDA, so far, is a spoken commitment. If the telecoms MoU is the model, the NITDA relationship still needs its own document.

Why the Timing Matters

The visit came days after the African Union opened a two-day consultation on AI governance and regulation. According to TechAfrica News, the consultation named data governance, cross-border data flows, cybersecurity and sandbox testing as the areas where alignment matters most. Those are the domains where NITDA and the NDPC already operate.

The timing looks coincidental, but the logic is not. Any continental approach to AI will lean heavily on data protection, and Nigeria’s data regulators are among those that will have to make it work in practice. That raises the stakes for how clearly the two Nigerian agencies divide their roles. Regulators that cannot explain their own division of labour will struggle to shape, or enforce, a wider framework.

Enforcement Is the Real Test

TechMoonshot reported in February that the NDPC had collected ₦7.2 billion in penalties, registered 38,677 companies and completed 246 breach investigations. Those figures point to an active regulator.

Yet our May analysis of AI regulation across Africa found more than 1,300 organisations listed as under investigation and relatively few settled with binding penalties. The gap between investigations opened and cases closed suggests that capacity, not intent, is the constraint. It also flagged a proposed AI commission bill that could change registration requirements within a year, which adds another moving part for companies already trying to keep up.

Closer ties with NITDA raise a harder question. An independent regulator must be able to investigate and fine public bodies as readily as private firms. NITDA is itself a government agency, and the NDPC only recently left its structure. Neither agency has said how integration will protect the NDPC’s independence, or who decides when their priorities collide.

What Companies Should Watch

For businesses operating in Nigeria, the practical takeaways are straightforward:

Treat the pledge as a signal, not a rule. Nothing published so far changes a company’s compliance obligations under the Nigeria Data Protection Act of 2023.

Expect the NDPC to remain the main point of contact for data protection matters, while NITDA continues to shape wider digital policy. The boundary between the two is where confusion is most likely.

Keep an eye on enforcement. With more than 1,300 organisations reportedly under investigation, and penalties already collected, the risk of being pursued is real even if settlements are slow.

Watch for a signed agreement with a timeline and a clear split of responsibilities. Until then, the NITDA-NDPC relationship is a statement of intent, not a framework.

Leave a Reply

Your email address will not be published. Required fields are marked *

Prev
How to Get a Police Character Certificate in Nigeria via POSSAP
How to Get a Police Character Certificate via POSSAP

How to Get a Police Character Certificate in Nigeria via POSSAP

Nigeria's police now process Police Character Certificates entirely through the

You May Also Like