Connect with us

Business

FG Holds MDA Heads Personally Liable for Data Protection Compliance

Maritime judges seminar

The Federal Government has directed all Ministries, Departments and Agencies (MDAs) to appoint Data Protection Officers (DPOs), warning that Permanent Secretaries, Accounting Officers and Chief Executive Officers will be held personally responsible for complying with the Nigeria Data Protection Act (NDP Act), 2023.

The directive, contained in a compliance circular signed by the Secretary to the Government of the Federation (SGF), Senator George Akume, requires all MDAs to designate qualified officers as DPOs, register them with the Nigeria Data Protection Commission (NDPC) and fully implement the provisions of the law.

The circular is part of efforts to strengthen responsible data governance and improve public confidence in how citizens’ personal information is collected, stored and processed.

The directive followed an instruction by President Bola Tinubu, who described data as a national asset that must be properly protected.

According to the circular, the President said: “Data is the new oil: its value increases the more it is refined and responsibly shared. I therefore direct all Ministries, Extra Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act, 2023.”

The circular further stated: “MDAs are directed to designate suitably qualified officers as Data Protection Officers (DPOs) to oversee data protection compliance and advise management on all matters relating to the lawful processing of personal data.”

Beyond appointing DPOs, MDAs are required to submit the names and contact details of the officers to the NDPC for registration. Agencies may also engage licensed Data Protection Compliance Organisations where necessary to support compliance efforts and conduct mandatory audits.

The government also directed agencies to make adequate budgetary provisions for staff training, awareness programmes, technical safeguards and periodic compliance audits. They are expected to file all mandatory Data Protection Compliance Audit Returns and other statutory reports within the timelines set by law.

Reacting to the directive, the National Commissioner and Chief Executive Officer of the NDPC, Dr Vincent Olatunji, said the move reflects the Tinubu administration’s commitment to protecting the privacy and fundamental rights of Nigerians.

He added that data accountability is vital to achieving the administration’s eight Presidential Priorities, noting that the commission has established a regulatory clinic to provide technical support to MDAs as they implement the new compliance requirements.