
The Nigeria Data Protection Commission (NDPC) introduced the General Application and Implementation Directive (GAID) on March 20, which will guide the implementation of the Nigeria Data Protection Act 2023 (NDPA) and also offer clarity for individuals and organizations.
GAID and NDPA now become the primary laws governing data privacy matters in Nigeria discarding Nigeria Data Protection Regulation 2019 (NDPR). However, enforcement measures taken under NDPR remain valid for GAID.
Additionally, data subjects can directly seek redress from data controllers in the event of a violation of their data privacy.
This is because GAID comes with a mechanism known as Standard Notice to Address Grievance (SNAG), which empowers data subjects to seek remedial action should their data fall into the wrong hands.
Related: Nigeria Data Protection Commission Investigates TikTok and Truecaller Over Data Privacy Violations
Data controllers and processors are however required, under the GAID to conduct periodic compliance audits of their data processing activities to ensure they have processes and systems in place and implement appropriate technical and organizational data protection measures to mitigate the risks of data breaches.
The GAID provides organizations with additional guidance on the key issues that they need to consider when relying on any of the legal bases recognized under the NDPA for data processing.
The GAID outlines essential requirements to guide data controllers and processors in conducting Data Protection Impact Assessments (DPIAs). It also covers the notification process to the National Data Protection Commission (NDPC) and data subjects in the event of a data breach.
Additionally, it facilitates the exercise of data subject rights and ensures compliance with the NDPA’s regulations regarding cross-border data transfers.
In conclusion, the GAID replaces the NDPR to enhance Nigeria’s data privacy framework by empowering data subjects and requiring organizations to conduct compliance audits. This reinforces accountability and transparency in data processing, ultimately fostering public trust and ensuring that individual rights are prioritized under the Nigeria Data Protection Act 2023.