Nigerian boards are approving AI budgets faster than their compliance functions can keep up. That gap is where regulatory risk lives. The Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive (GAID) issued by the Nigeria Data Protection Commission (NDPC) are not obstacles to AI deployment — but they do impose specific obligations that must be engineered into a system before it touches customer data, not retrofitted after launch.
The NDPA applies to your AI system whether or not it "feels" like data processing
Any AI system that ingests, transforms, scores, or generates outputs from personal data is processing personal data under the NDPA. That includes retrieval-augmented assistants that index customer correspondence, credit models that score loan applicants, and chatbots that log conversations. The Act's definition of processing is deliberately broad, and the NDPC has signalled that automated decision-making sits squarely within its supervisory interest.
Three classifications matter at the design stage. First, whether your organisation is a data controller or processor of major importance (DCPMI) — most banks, insurers, telcos, and large enterprises are, which triggers registration with the NDPC and elevated obligations. Second, whether the AI use case involves sensitive personal data (health, biometric, financial information), which raises the lawful-basis bar. Third, whether the system makes or materially supports decisions with legal or similarly significant effects on individuals — credit, employment, insurance pricing — which engages the data subject's rights around automated decision-making.
Lawful basis: consent is not the default answer
A common mistake is assuming consent is the only lawful basis and burying an AI clause in onboarding terms. Consent under the NDPA must be freely given, specific, informed, and unambiguous — and it can be withdrawn, which means a consent-based AI pipeline needs machinery to honour withdrawal. For many enterprise use cases, legitimate interest or contractual necessity is the sounder basis, provided you document the assessment. The GAID expects that analysis to exist on paper before processing begins.
The DPIA is not optional for most AI deployments
Where processing is likely to result in high risk to data subjects — and the NDPC's guidance treats large-scale automated decision-making, profiling, and processing of sensitive data as presumptively high-risk — a Data Protection Impact Assessment (DPIA) is required before processing starts. A defensible AI DPIA covers: the necessity and proportionality of the model relative to the business purpose; data minimisation (does the model need raw customer records, or would masked or aggregated features suffice?); accuracy and bias risks, with testing evidence; retention and deletion mechanics, including what happens to embeddings and fine-tuned weights when a customer exercises erasure rights; and cross-border transfer analysis if any component — model API, vector store, logging — sits outside Nigeria.
That last point deserves emphasis. If your AI stack calls an offshore model API, customer data is leaving Nigeria. The NDPA permits cross-border transfer where the destination offers adequate protection or appropriate safeguards exist, but the transfer must be mapped and justified. For banks, the CBN's data localisation expectations add a second, stricter layer: payment and core customer data increasingly must remain in-country, which shapes architecture — in-country inference, redaction before API calls, or sovereign-cloud deployment.
Questions your DPO should be asking every AI vendor
Before any pilot goes live, your Data Protection Officer should have written answers to: Where does every byte of customer data travel, including logs and telemetry? Is our data used to train or improve the vendor's models, and can that be disabled contractually? What is the retention period for prompts and outputs? Can the system honour access, rectification, and erasure requests within statutory timelines? Who is the processor, who is the sub-processor, and do our contracts reflect Article-compliant processing terms?
Governance that satisfies the regulator and the board
The organisations that move fastest are, counterintuitively, the ones with the strongest governance. A standing AI governance committee, a maintained model inventory, DPIAs as a gate in the deployment pipeline, and human-in-the-loop review for consequential decisions — these are not bureaucratic drag; they are what allows a bank to say yes to the next use case in weeks rather than quarters. This is precisely the operating model our AI Governance Toolkit NG packages: NDPA-aligned policies, DPIA templates, model-risk registers, and committee charters adapted to Nigerian regulatory reality rather than imported from other jurisdictions.
The NDPA is young, the NDPC is building enforcement capacity, and the first high-profile AI enforcement action in Nigeria will define the market's risk perception for years. The question for executives is simple: when that action comes, do you want to be the cautionary tale or the counterexample?
About Muller Global
Muller Global is an AI Advisory & Engineering firm based in Abuja, taking Nigerian enterprises from AI ambition to working systems through consulting, advisory retainers, training, deployment, and engineering.
The Muller Weekly Briefing
One email a week on AI for Nigerian enterprises — what matters, minus the hype.
