Logo
Logo
Logo
Back to Archive
Technology Law

Highlights of the General Application and Implementation Directive (GAID) 2025

September 25, 2025 10 min read
Highlights of the General Application and Implementation Directive (GAID) 2025
Chidinma Egwu

By Chidinma Egwu

Principal Counsel

HIGHLIGHTS OF THE GENERAL APPLICATION AND IMPLEMENTATION DIRECTIVE (GAID) 2025

On 19 September 2025, the Nigeria Data Protection Commission (NDPC) issued the General Application and Implementation Directive ("GAID" or the "Directive") 2025. The Directive gives operational effect to the Nigeria Data Protection Act 2023 (the "Act"), repeals the Nigerian Data Protection Regulation ("NDPR 2019"), and establishes binding obligations for organisations, public authorities, and individuals.

Importantly, GAID recognises that data protection does not operate in a static environment. It provides guidance in an era of disruptive technologies and evolving modes of engagement, where the processing of personal information now extends across citizens, businesses, governments, and international borders. The aim is legal certainty, protection of fundamental rights, and a coherent framework for Nigeria's participation in the global digital economy.

Expanded Scope of Protection

Section (2c) of the Act applies to data controllers or processors that are not domiciled in Nigeria but process the personal data of a data subject in Nigeria or targets the personal data of data subjects in Nigeria. The Act also covers data subjects in Nigeria regardless of nationality, personal data transferred to Nigeria, Nigerians abroad, and even data merely transiting through Nigeria (See Article 1 of the Directive). This provision reflects the universality of privacy rights and Nigeria's intention to extend protection beyond its physical borders.

Supremacy of the NDP Act

Where other laws conflict with the Act in relation to data processing, the Act prevails (See Article 3 of the Directive).

Compliance Obligations

Organisations designated as data controllers or processors of major importance must register with the NDPC and are also required to conduct compliance audits (see Article 7 of the Directive). They are required to file annual returns (see Article 10 of the Directive). They must also designate a Data Protection Officer (Article 11), who is subject to credential assessments (Article 14) and responsible for submitting semi-annual internal compliance reports (Article 13).

Principles and Lawful Bases of Processing

The Directive restates the principles of personal data protection, including fairness, lawfulness, transparency, purpose limitation, data minimisation, and accountability (Article 15). Lawful bases of processing are consent, contract, legal obligation, vital interest, public interest, and legitimate interest (Article 16). The Directive sets out detailed conditions for reliance on consent (Article 17) and specifies circumstances where consent is mandatory, such as direct marketing, processing of children's data, and cross-border transfers without an adequacy decision (Article 18).

Rights of Data Subjects

The Directive reaffirms the right to correct inaccurate data (Article 36), the right to move data from one service to another (Article 37), and the right to have personal data erased when retention is no longer lawful (Article 38). It also strengthens grievance mechanisms by introducing a standard notice procedure for complaints before the Commission (Article 40).

In addition, the Directive requires organisations to provide information in a form that data subjects can easily understand (Article 27). This includes adapting privacy notices for vulnerable groups such as children or persons with disabilities. Together, these provisions shift the balance towards greater transparency and accountability in how personal data is handled.

Mandatory Privacy Impact Assessments

Data controllers must conduct a Data Privacy Impact Assessment (DPIA) where processing is likely to pose high risks to data subjects, such as profiling, automated decision-making, healthcare, financial services, e-commerce, education, surveillance, or cross-border transfers (Article 28). DPIAs must be vetted by certified Data Protection Officers and submitted to the Commission.

Cross-Border Data Transfers

Transfers of personal data outside Nigeria are permitted only under conditions that guarantee adequacy and respect for human rights (Article 45; Schedule 5). This is consistent with Nigeria's objective of aligning with global best practices.

Emerging Technologies

The Directive acknowledges the challenges posed by artificial intelligence, the Internet of Things, and other emerging technologies (Articles 43–44). Controllers and processors are required to integrate data ethics into their operations and avoid technologies that undermine human dignity or fundamental rights.

Enforcement and Remedies

Data subjects may enforce their rights before the Federal or State High Court under the Fundamental Rights Enforcement Procedure Rules (Article 47). Non-compliance with obligations such as registration, audits, or DPIAs may attract sanctions, including restrictions on operations (Article 28(6)).

Conclusion

GAID 2025 moves Nigeria's data protection framework from principle to practice. It widens the scope of protection, clarifies lawful bases for processing, strengthens compliance obligations, and places human dignity at the centre of technological innovation. For organisations, it signals the need to align governance structures with the NDP Act. For individuals, it affirms that privacy is not a privilege but a fundamental right.

Organisations handling personal data in or from Nigeria should not delay in reviewing their compliance frameworks against GAID 2025. Registration, audits, DPO designation, and transparent communication with data subjects are no longer optional. Now is the time to strengthen governance structures, update policies, and embed privacy into business operations. The cost of inaction will be regulatory exposure; the benefit of compliance is both legal certainty and public trust.

For further enquiries on this, please reach us at C. Egwu Law Firm at c.egwu@cegwulawfirm.com or call at +234 707 167 4471.

Share this article