Nigeria Has a Data Protection Law, So Why Are Nigerians Still Losing Money and Privacy Every Day?

Able Cookey
By
Able Cookey
Staff Writer
I’m Able Cookey, a Building Technology graduate and digital content writer with a strong focus on technology-related insights. I create clear, engaging, and practical tech content...
- Staff Writer

Nigeria passed the Nigeria Data Protection Act (NDPA) in 2023, one of the most important digital laws in the country’s history. Three years later, Nigerians are still losing money to ATM fraud, still having their personal data sold online for as little as N70, and still watching loan apps destroy their reputations without consequences. The law exists. The enforcement is the problem.

In January 2025, a Lagos man lost N1.4 million after his ATM card got stuck in a machine. While he went inside the bank to report it, a fraudster posing as a fellow customer retrieved the card, already having noted the PIN. The money disappeared through a distant point-of-sale terminal. The shock triggered a stroke in his wife. She never recovered.

In a separate case, a 27-year-old cloud engineer in Lagos applied for a vehicle loan from a commercial bank. The bank rejected him, citing a severe non-performing loan on his record. He had never defaulted on anything. The culprit was a quick-lending fintech app he had downloaded out of curiosity. After he repaid a N15,000 loan, the app disbursed another N25,000 without his consent, charged a 90 per cent interest rate, then reported him as a defaulter when he refused to pay. The app then sent messages to his colleagues and managers calling him a corporate fraudster. His career was nearly destroyed.

Data Protection 1024x683 2
Nigeria Has a Data Protection Law, So Why Are Nigerians Still Losing Money and Privacy Every Day? 3

The Nigeria Inter-Bank Settlement System (NIBSS) reported that in 2024, N400 million in fraud proceeds was channelled through accounts opened with stolen identities. A global identity fraud report by Sumsub ranked Nigeria highest in Africa, with a fraud rate of 5.91 per cent.

Cybersecurity firm Surfshark found that more than 566,300 Nigerian accounts were breached in 2025 alone, placing Nigeria among the most affected countries in sub-Saharan Africa. In March 2024, NIMC data including NINs, BVNs, demographic profiles and biometric photographs was openly sold online for as little as N70, after private partners illegally sub-leased their credentials to black-market entities through unsecured APIs.

Fraud does not always look like hacking. Sometimes it is a phone call.

A fraudster logs into a victim’s internet banking portal using stolen credentials, triggering a one-time password (OTP) to be sent to the victim’s phone. Then the fraudster calls the victim, pretending to be a bank customer care representative. They confirm the victim’s name using data pulled from Truecaller or leaked databases and ask the victim to read out the OTP to “complete an unblocking process.” If the victim complies, the account is wiped.

ATMs are also targeted through card skimming and PIN theft. USSD and mobile apps are hit through SIM swaps and fake apps. Internet banking faces malware and credential theft.

The NDPA 2023 is a solid piece of legislation on paper. It requires companies that collect personal data to register with the Nigeria Data Protection Commission (NDPC), appoint data protection officers, obtain clear consent before processing data, and conduct yearly audits. It also gives Nigerians the right to know how their data is used, correct inaccurate records, request deletion, and object to automated decision-making.

The NDPC has shown it is willing to act. Multichoice Nigeria was fined N766.2 million for intrusive practices and illegal cross-border data transfers. Fidelity Bank was fined N555.8 million for processing data without consent. In August 2025, the commission issued a 21-day compliance notice to over 1,360 organisations across banking, insurance, pensions and gaming sectors.

But the Meta case showed the limits of enforcement. The NDPC accused Meta of collecting data from over 60 million Nigerian users without consent and initially imposed a $32.8 million fine in 2025. The fine was dropped in 2026 after a confidential settlement, raising questions about what enforcement really means when it is applied to the world’s largest social media companies.

DPI expert and Data Processing Officer Bola Adegba said the core problem is that Nigeria’s digital systems do not work together the way they should. Payment platforms, identity databases, and regulatory oversight each operate in their own lanes. Unlike India’s Aadhaar system, which links identity to payments to governance in one connected framework, Nigeria’s systems remain largely siloed.

She said this fragmentation leaves citizens exposed to fraud, phishing and unauthorised data sharing. She added that the NDPC cannot succeed without a stronger, integrated digital public infrastructure that prioritises security, interoperability and real inclusion. Rural Nigerians without internet access or digital literacy are particularly at risk.

NIBSS Corporate Communications Manager Lilian Phido said interoperability must go hand in hand with consent-based access, audit trails, and role-based controls. She said every integration point must be logged and governed within clearly defined regulatory boundaries.

Cybersecurity expert Lana Adegoke advises Nigerians to enable two-factor authentication on all banking apps, avoid using public Wi-Fi for any financial transaction, and report suspicious activity immediately to both their bank and the NDPC. She also says Nigerians should demand transparency from any app or service that asks for personal data, asking specifically how that data will be stored and used.

Under the NDPA 2023, Nigerians have the legal right to ask any company what data it holds on them, request corrections, and ask for deletion. If a company refuses or misuses data, a complaint can be filed directly with the NDPC.

Nigeria’s digital economy is growing fast. Cashless transactions, mobile wallets and fintech apps are now part of daily life for millions. But speed without safety is a trap. The NDPA exists. The NDPC is growing. The fines are coming. What is still needed is consistent, visible enforcement that makes every company, big or small, local or foreign, understand that Nigerian data is not free to harvest, sell or lose carelessly.

Share This Article
Staff Writer
I’m Able Cookey, a Building Technology graduate and digital content writer with a strong focus on technology-related insights. I create clear, engaging, and practical tech content for TechSocial, where I write about digital trends, and real-world tech problems people face every day. My goal is to simplify complex tech topics and help everyday users understand how technology works and how to make the most of it in their daily lives.