ICT
NITDA begins review of guideline on data protection, to release new rules
The National Information Technology Development Agency (NITDA) has said it is currently working on the review of the 2013 guideline on data protection.
In a statement signed by the Director General, Dr. Isa Pantami in Abuja and made available to Business Hilights, NITDA said the existing guideline, which was issued in 2013, was being revised to meet up new trends in the data protection sub sector.
Panatmi said “Organisations are required to note the provisions of the NITDA Guidelines on Data Protection issued in 2013 and currently being revised.
“In an effort to make the agency’s rule-making process transparent and industry-focused, the revised guideline will soon be presented for stakeholder consultation as stipulated in the Rule-making Process Regulation of the NITDA.”
NITDA also raised issues on the implications of the new European Union General Data Protection Regulation on Nigerian businesses, especially those that collect, store and process personal data of EU citizens.
The new regulation applies whether the data controller, an organisation that collects data from EU residents or processor, an organisation that processes data on behalf of data controller such as data centres or the data subject, the person whose personal data has been collected is based within or outside any EU member state, if they collect or process personal data of EU citizens and residents.
NITDA added further that “The agency has realised that this regulation might have huge impact on Nigerian businesses and/or individuals that use information technologies to collect, store, process and transact on EU citizens personal data in EU territory or elsewhere.
“It is in the utmost interest of the agency to protect Nigerian businesses from unnecessary exposure to the risks of this regulation and/or any regulations that might have negative impact on their businesses as well as the rights of Nigerians that have dual citizenship of any EU member state.
“The regulation requires that data controllers and processors must seek consent from data subjects in an intelligible and easily accessible form, clearly specifying the purpose for the collection. It also stipulates that consent must be clear and distinguishable from other matters and presented in a clear and plain language.”
“A breach of the regulation can attract a fine of up to four per cent of a company’s annual global turnover or an equivalent of €20m. Furthermore, companies can be fined up to two per cent for not having their records in order, not notifying the supervising authority and data subject about a breach or not conducting impact assessment.”
“The regulation also gives data subjects the right to obtain from the data controller confirmation as to whether or not personal data concerning them were being processed, where and for what purpose. They also have the right to transmit data they had previously provided to another controller.”
In line with the planned revision, Dr. Pantami therefore calls on Nigerian businesses, especially those carrying out online transactions, to meet the GDPR compliance criteria by putting in place appropriate measures to observe the provisions of the regulation to avoid sanctions.
-
Trending Stories1 week agoDavido, Wizkid, Burna Boy or Asake: Who is having the biggest 2026 so far?
-
Football1 week agoPremier League releases 2026/27 festive fixtures, 7 matches set for Boxing Day
-
Crime6 days agoAnambra Police arrest mother over alleged child sexual exploitation
-
Business5 days agoJetour Nigeria, dealers take dashing, other models to Abuja Experience
-
Business6 days agoDangote Refinery IPO shifts spotlight to corporate governance, investor protection
-
Business3 days agoDangote IPO rush crashes Bamboo login as investors flood platform
-
Business2 days agoAbuja gears up for Jetour T2’s rugged-luxury experience
-
Business4 days agoNigeria Business Outlook: Dangote IPO, markets, inflation and naira in focus this week


