Organizations with operations in both the United Kingdom and Nigeria face a dual data protection compliance challenge that few governance frameworks are designed to address simultaneously. UK GDPR retained in UK law post-Brexit, and the Nigeria Data Protection Act 2023 (NDPA 2023) share a common philosophical heritage in the EU GDPR but differ in significant ways that make a simple copy and-paste compliance approach unworkable.
The most significant structural difference between UK GDPR and NDPA 2023 is the supervisory authority and enforcement regime. Under UK GDPR, the Information Commissioner's Office (ICO) is the supervisory authority, with powers to issue fines of up to £17.5 million or 4% of global annual turnover. Under NDPA 2023, the Nigeria Data Protection Commission (NDPC) has equivalent enforcement powers, with fines of up to 2% of annual gross revenue for data controllers of major importance.
The legal basis for processing personal data is handled differently in each regime. UK GDPR provides six lawful bases including consent, legitimate interests, and contractual necessity. NDPA 2023 provides eight lawful bases with some differences in how legitimate interests is construed and with additional provisions for processing in the public interest that reflect Nigerian regulatory and constitutional context.
Data subject rights are broadly aligned between the two regimes, both provide rights of access, rectification, erasure, restriction, and data portability. However, the timelines and procedures for responding to data subject requests differ. UK GDPR requires responses within one calendar month. NDPA 2023 requires responses within a reasonable time, with the NDPC providing guidance on what constitutes reasonable.
FortressPoint's approach to dual jurisdiction data governance is to build a single, unified governance framework that satisfies both regimes as a baseline, with jurisdiction specific annexes covering the areas of difference. This avoids duplicating effort while ensuring compliance with both sets of requirements.
The foundation of this unified framework is a comprehensive data inventory mapping all personal data flows across both jurisdictions, identifying the lawful basis for each processing activity, documenting data transfers between the UK and Nigeria, and assessing the risk of each processing activity. Microsoft Purview is the tool we typically deploy to implement this data inventory at enterprise scale, providing automated data discovery, classification, and lineage documentation.
Speak with a FortressPoint consultant — we engage with specific questions, not just general enquiries.