Nigeria has the strictest consent regime of any major African market, and one of the strictest anywhere. The governing law is the Nigeria Data Protection Act 2023, in force since 12 June 2023, now supplemented by the NDPC’s General Application and Implementation Directive (GAID) 2025, effective 19 September 2025.
If you are working from guidance about the NDPR 2019, discard it. GAID Article 3(3) means the NDPR no longer applies.
Express opt-in only — there is no soft opt-in
This is the headline, and it catches almost every international sender.
GAID Article 18(1)(a) requires consent for any direct marketing. There is no existing-customer exception, no soft opt-in, and no legitimate-interest route. The carve-outs that make marketing workable in the UK, Australia or South Africa simply do not exist here.
A customer who bought from you last week has not, by that act, consented to marketing. You need a separate, affirmative opt-in.
Two further constraints:
- NDPA s26(7)(a) invalidates pre-ticked boxes. Consent must be an unambiguous affirmative act.
- Legitimate interest is not a workaround. Unlike GDPR, where legitimate interest can sometimes support direct marketing, Nigeria requires consent for it.
The 200-subject threshold that catches small businesses
Nigeria has a concept called a data controller of major importance, and the threshold is remarkably low.
Under GAID Schedule 7, you become one if you process the personal data of more than 200 data subjects in any six-month period — or if you operate in one of thirteen listed sectors, which include e-commerce.
Two hundred subscribers. That is a modest mailing list, not an enterprise database. Most businesses running any real email programme in Nigeria cross it.
Being a controller of major importance brings:
- Mandatory registration with the NDPC
- Annual audit returns, due 31 March, which must be filed by a licensed Data Protection Compliance Organisation — you cannot file them yourself
- The higher penalty tier (see below)
Targeting Nigerians counts as operating in Nigeria
GAID Article 8(2) is explicit: merely targeting data subjects in Nigeria constitutes operating in Nigeria. There is no requirement for an office, an entity or infrastructure in the country.
An overseas company running campaigns to a Nigerian list is in scope, and can be a controller of major importance with registration and audit obligations.
Opt-outs: immediate, with a widely misread deadline
The NDPA sets no grace period. Section 36(4) requires that processing stop on objection; GAID Article 49(2) says requests must be discharged “timeously”. There is no five-day or ten-day window as in Australia or Singapore.
The number people misquote is the 30 days in GAID Schedule 9. That is the ceiling for responding to a complaint — it is not permission to keep mailing someone for a month after they opted out.
Build for immediate suppression.
Penalties — and the 1% error
The NDPA has two tiers, and both use 2%. Many summaries state 1% for the standard tier, which is wrong:
- Controller of major importance (s48(4)): the greater of NGN 10,000,000 or 2% of annual gross revenue in the preceding financial year.
- Standard controller (s48(5)): the greater of NGN 2,000,000 or 2% of annual gross revenue.
Only the naira floor differs between tiers — the percentage is the same.
Section 49 adds criminal liability: failing to comply with a compliance order carries the same sums and/or up to one year’s imprisonment.
SMS and voice sit under a different regulator
Marketing to Nigerian phone numbers is governed by the Nigerian Communications Commission under the Nigerian Communications (Consumer Code of Practice) Regulations 2024, with the Do-Not-Disturb short code 2442.
Worth noting: the NCC’s own consumer portal still references the revoked 2007 Consumer Code in places. The operative instrument is the 2024 Regulations. Email is outside this regime and sits with the NDPC.
A practical compliance checklist
- Collect express, affirmative opt-in. No pre-ticked boxes, no soft opt-in, no legitimate interest
- Check whether you exceed 200 data subjects in six months — most email programmes do
- If so, register with the NDPC and budget for annual audit returns via a licensed DPCO, due 31 March
- Suppress immediately on objection — do not rely on any 30-day figure
- Keep consent records with source, timestamp and method
- Remember that targeting Nigerians brings you in scope regardless of where you are based
- Treat SMS separately — different regulator, different rules
Frequently asked questions
Do I need consent to email customers in Nigeria?
Yes, in every case. Nigeria has no soft opt-in and no existing-customer exception. An affirmative opt-in is required even for people who have bought from you.
What is a data controller of major importance?
A controller processing the data of more than 200 data subjects in six months, or operating in one of thirteen listed sectors including e-commerce. It triggers mandatory NDPC registration and annual audit returns filed by a licensed DPCO.
How quickly must I honour an opt-out in Nigeria?
Immediately. The NDPA provides no grace period. The 30 days often quoted is the deadline for responding to a complaint, not for stopping mail.
Does the NDPA apply to companies outside Nigeria?
Yes. GAID Article 8(2) treats targeting data subjects in Nigeria as operating in Nigeria, with no local entity required.
Is the NDPR 2019 still in force?
No. GAID Article 3(3) means the NDPR is no longer applied. Guidance based on it is out of date.
Related reading
- Bulk email services in Nigeria — platforms and NGN billing
- Email marketing rules by country
- POPIA and email marketing in South Africa
- Double opt-in explained — the safest way to evidence consent here
- GDPR and email marketing
Verified against the Nigeria Data Protection Act 2023 and the NDPC General Application and Implementation Directive 2025, September 2026. General information, not legal advice.
Bluey Email includes consent capture, immediate global suppression and one-click unsubscribe on every plan, and bills in 128 currencies including NGN. Start free.