Data Protection in the Age of AI: A Comparative Legal Snapshot of Nigeria,European Union and India
Comparing the Nigerian framework with the European Union's General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act 2023 (DPDPA).
Introduction
Data protection is no longer only about keeping files private. Today, personal information can move between countries in seconds. A company may collect data in Nigeria, store it on a cloud server in another country, and use it in an Artificial Intelligence (AI) system somewhere else. That makes a simple question much harder: which law should protect the person whose data is being used? AI has made the issue even more serious. AI systems often need large amounts of data for training and testing. They may also use personal information to make predictions or support decisions. The more data a system uses, the greater the need for clear rules about collection, storage, sharing, and deletion.
Nigeria responded to the growing need for stronger privacy rules by enacting the Nigeria Data Protection Act (NDPA) in 2023. The Act gives individuals rights over their personal data and places duties on organisations that collect or use it. This report uses the NDPA as the main law for study. It compares the Nigerian framework with the European Union's General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act 2023 (DPDPA). The GDPR is useful because it has been in force for several years and has a large body of regulatory practice behind it. India offers a different example. Its law is newer and uses a simpler structure. The aim is not to decide which law is perfect. No system is. Instead, the report looks at what the three laws have in common, where they differ, what each does well, and where each still faces problems. It then considers what Nigeria might reasonably learn from the two other frameworks.
Overview of the Primary Legislation: Nigeria Data Protection Act (NDPA)
Country: Nigeria
Name of the Legislation: Nigeria Data Protection Act, 2023 (NDPA)
Year Enacted: The NDPA was signed into law in June 2023.
Regulatory Authority: The Nigeria Data Protection Commission (NDPC) is the main regulator. It oversees data protection in Nigeria, investigates complaints and possible breaches, and can take enforcement action.2
Objective of the Law: The Act is meant to protect the privacy rights of individuals and make organisations handle personal data in a responsible way. It also supports a safer digital economy.
Scope of the Law: The NDPA applies to relevant processing carried out in Nigeria. In some cases, it also reaches organisations outside Nigeria when they process the personal data of people in Nigeria. This matters because many online services used in Nigeria are run by companies based in other countries.
Major Provisions: Core Data Protection Principles: Section 24 requires lawful, fair, and transparent processing. The Act also limits organisations to stated purposes and discourages the collection of more data than they need.
Rights of Data Subjects: The Act gives data subjects rights such as access, correction, objection, portability, and erasure. A data subject is simply the person whose personal data is being processed. The Act also contains rules for some forms of automated decision-making. Data Controllers and Processors of Major Importance: Some organisations handle much larger amounts of data or carry greater risks. The NDPA places extra duties on these Data Controllers and Processors of Major Importance, including registration with the NDPC.
Financial Penalties: The Act provides financial penalties for serious breaches. For a Data Controller or Processor of Major Importance, the maximum can reach the greater of ₦10 million or 2% of annual gross revenue, subject to the Act. Other controllers and processors may face lower statutory limits.
Comparative Legislation Overviews
A. General Data Protection Regulation (GDPR) — European Union
Country/Region: European Union (EU) and European Economic Area (EEA)
Legislation: General Data Protection Regulation, Regulation (EU) 2016/679
Year: The GDPR was adopted in 2016 and became applicable on 25 May 2018.
Regulatory Authority: The GDPR is enforced by national Data Protection Authorities (DPAs) in the EU Member States. These authorities work together through the European Data Protection Board (EDPB), which helps keep enforcement consistent across the EU.3
Objective: The GDPR protects people when their personal data is processed. It also aims to make the rules for handling data more consistent across the EU.
Scope: The GDPR covers automated processing and some organised paper records. It can also apply to companies outside the EU when they offer goods or services to people in the EU or monitor their behaviour.
Major Features: The GDPR sets out rules on fairness, transparency, purpose limitation, data minimisation, accuracy, storage, security, and accountability. It also gives people rights such as access, correction, erasure, restriction, portability, and objection. For serious breaches, fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher.
B. Digital Personal Data Protection Act (DPDPA) — India
Country: India
Legislation: Digital Personal Data Protection Act, 2023 (DPDPA)
Year: The Act was enacted in August 2023. Its implementation has been phased.
Regulatory Authority: The Data Protection Board of India (DPBI) is the statutory body responsible for enforcement under the Act.
Objective: The DPDPA seeks to protect digital personal data while allowing organisations to use data for lawful business and other purposes.
Scope: The Act mainly deals with digital personal data. It can also apply to some processing outside India where the processing is connected with offering goods or services to people in India.
Major Features: Consent has a central place in the DPDPA. The Act also recognises specified legitimate uses. Organisations that are classified as Significant Data Fiduciaries face extra duties, including requirements relating to Data Protection Officers (DPOs) and audits.
Understanding 'Data Principal' and 'Data Fiduciary': A 'Data Principal' is the person to whom the personal data relates. A 'Data Fiduciary' is the organisation that decides why and how personal data will be used. The role is broadly similar to a 'Data Controller' under the GDPR and NDPA. The DPDPA does not create the same broad separate category of sensitive personal data found in the GDPR and NDPA. It instead uses one main framework for digital personal data. Certain breaches can attract fixed penalties of up to ₹250 crore.
Comparative Analysis
Research Method:The report uses a qualitative comparative approach. The main materials are the three laws, regulatory information, and academic writing. Each framework is examined using the same basic questions: What does the law protect? Who enforces it? What rights do people have? How can organisations be punished for breaking the rules? This method makes the comparison clearer. It also avoids treating one country's system as the standard for all others.
A. Similarities
Protection of Individuals: All three laws are built around the idea that people should have some control over information about them. Organisations cannot simply treat personal data as a resource with no legal limits.
Rules for Processing: Each framework places limits on how organisations collect and use data. Purpose limitation and careful collection appear across the three systems, although the wording and details are not identical.
Individual Rights: People can ask organisations for information about their data and, in different ways, seek correction or other forms of control. The exact rights vary, but the basic idea is shared.
Key Terms Across the Three Laws
Although Nigeria, the European Union and India use different terms in their data protection laws, the roles behind those terms are quite similar. For example, the NDPA and GDPR use the term “Data Subject” for the person whose personal information is being collected or used, while the DPDPA refers to that person as a “Data Principal.” Despite the difference in wording, they essentially refer to the same person. This could be a customer, student, employee or any other individual whose personal data is being processed. There is also a similar idea when it comes to the organisation that decides why and how personal data should be used. Under the NDPA and GDPR, this organisation is called a “Data Controller,” while the Indian DPDPA uses the term “Data Fiduciary.” The terminology is different, but the basic responsibility is similar because both refer to the organisation that determines the purpose and manner of processing personal data. For instance, if a bank decides what customer information it needs and how it will use that information, the bank would generally be acting in this role.
The term “Data Processor” is used in all three frameworks. A Data Processor is an organisation or person that processes personal data on behalf of another organisation. This distinction is important because the organisation deciding why the data is being used is not necessarily the same organisation that carries out the actual processing. For example, a company may collect customers’ information but use another company to store or manage that information.
There are also differences in the way the regulatory systems are organised. Nigeria has the Nigeria Data Protection Commission (NDPC) as its main data protection regulator, while India has the Data Protection Board of India (DPBI). The European Union operates differently because enforcement is carried out by national Data Protection Authorities in the different Member States, with the European Data Protection Board (EDPB) helping to coordinate their work. Therefore, even though the names and structures are not exactly the same, the three systems are trying to perform similar functions: protecting individuals' personal data and ensuring that organisations comply with data protection rules.
Overall, the differences in terminology should not make the three laws appear more different than they actually are. Once the roles are understood, it becomes easier to compare the systems. The names may change from one jurisdiction to another, but the basic legal relationships between the individual, the organisation controlling the data, and the organisation processing it remain broadly similar.
Regulatory Oversight
Each system has a body or group of bodies responsible for enforcement. Nigeria has the NDPC. India has the DPBI. In the EU, national DPAs enforce the GDPR while the EDPB helps coordinate their work.
Cross-Border Reach
None of these laws is limited only to activity inside national borders. Under stated conditions, an organisation based abroad can still fall within the law. That matters in a world of cloud storage, social media, online shopping, and AI services.6
Financial Enforcement
All three frameworks use financial penalties. The figures and calculation methods differ, but the message is similar: serious violations can have a real financial cost.
B. Differences
Penalties
The biggest difference is how the laws calculate fines. The NDPA uses statutory amounts and revenue-based limits. The GDPR can impose up to €20 million or 4% of worldwide annual turnover for certain serious breaches. India uses fixed statutory penalties, with some breaches carrying a maximum of ₹250 crore.
Data Categories
The GDPR and NDPA provide extra protection for certain kinds of personal data. The DPDPA takes a simpler route and does not use the same broad separate category of sensitive personal data.
Consent and Other Legal Bases
Consent is especially important under the DPDPA. The GDPR and NDPA also recognise other lawful grounds for processing. That can matter where asking for consent is not the right legal route, such as some contractual or legal situations.
Regulatory Structure
Nigeria has one main national regulator. India has one main statutory board. The EU has several national DPAs working within a shared European system. That model can bring more regulatory experience, but it can also make cross-border cases harder to manage.
Implementation
The GDPR had a two-year period between adoption and full application. Nigeria's framework is newer. India's rollout is more gradual, with different parts of the DPDPA coming into force at different stages.
Enforcement Experience
The GDPR has a clear advantage here. It has been in use since 2018, so regulators and courts have had time to interpret its rules. The NDPA and DPDPA are much newer. Their long-term impact is therefore harder to judge.
C. Strengths of Each Law
Nigeria — NDPA: The NDPA gives Nigeria a clear national data protection framework and a dedicated regulator. Its reach can also extend to foreign organisations in cases covered by the Act. That is useful when Nigerian data is processed outside the country.
European Union — GDPR: The GDPR's strongest point is its track record. There are years of decisions, guidance, and legal interpretation behind it. Organisations can therefore look to real cases when trying to understand what compliance means in practice.
India — DPDPA: India's approach is easier to describe because it uses a simpler data model. That may help smaller organisations understand their basic duties. The extra rules for Significant Data Fiduciaries also allow greater attention to higher-risk organisations.
D. Challenges or Limitations
Nigeria — NDPA: Nigeria still has to build deeper enforcement experience and professional capacity. A law can be well written and still fall short if organisations do not understand it or the regulator lacks enough resources to enforce it.
European Union — GDPR: The GDPR can be demanding. Smaller organisations may find the paperwork, risk checks, security duties, and other compliance costs difficult to manage. The involvement of many national regulators can also make some cross-border cases complicated.
India — DPDPA: India's system has less enforcement history because it is new and is being introduced in stages. It is also not yet clear how well the simpler model will cope with more complex AI systems and new forms of data use.
International Perspective
The comparison suggests that Nigeria should borrow useful ideas rather than copy another country's law word for word. The GDPR offers one clear lesson: practical guidance matters. A detailed law can still leave businesses unsure about what to do on Monday morning. The NDPC could therefore publish simple guidance for sectors such as banking, telecommunications, health care, education, and AI services. India offers a different lesson. Its simpler structure may be easier for smaller businesses to follow. That could be useful in Nigeria, where not every organisation can afford a large privacy team.
Simplicity, however, should not mean weaker protection. Nigeria also needs more people who can put the law into practice. More training for Data Protection Officers, clearer public information, and better regulatory tools would help. These steps may matter as much as adding new words to the Act.
AI raises the stakes. An AI system can use large datasets, create profiles, or help make decisions about people. A person may not even know that their data was used in the first place. Nigeria's privacy rules will likely need to keep developing as these systems become more common. The wider lesson is simple: good data protection needs both good law and good enforcement. One without the other is unlikely to work well.
Conclusion
The NDPA gives Nigeria a solid starting point for protecting personal data. Its basic structure is close to ideas already used in other major privacy laws, especially the GDPR. The main concern appears to be less about having no legal framework and more about how well the framework can be applied. The comparison found several common features. All three systems protect individuals, place limits on data processing, create regulatory oversight, and allow financial penalties. Yet the details matter.
The laws differ in their treatment of sensitive data, the role of consent, the way fines are calculated, and the speed of implementation. The GDPR currently has the strongest practical track record. India offers an interesting example of a newer and simpler system. Nigeria sits somewhere between the two. Its law is developed enough to provide meaningful rights, but its success will likely depend on enforcement, professional skills, and clear guidance.
For Nigeria, the best path may not be to copy either framework. A better approach would be to keep the parts of the NDPA that fit the country while learning from proven practices elsewhere. As AI becomes part of everyday business and public services, that approach could become even more important.
References
Primary Legal Sources
Nigeria Data Protection Act 2023, particularly ss. 2(2), 24, 25, 27, 29–30, 34–38, 48–49.
Constitution of the Federal Republic of Nigeria 1999 (as amended), s. 37.
Regulation (EU) 2016/679 (General Data Protection Regulation), particularly Arts. 1, 2, 3, 5, 6,12–22 and 83.
Digital Personal Data Protection Act 2023 (India), particularly ss. 3, 6, 10 and 33 and the Schedule.
Institutional and Regulatory Sources
Nigeria Data Protection Commission, Nigeria Data Protection Act 2023.
Nigeria Data Protection Commission, Frequently Asked Questions on the Nigeria Data Protection Act.
Nigeria Data Protection Commission, Annual Report 2023.
European Union, Regulation (EU) 2016/679 of the European Parliament and of the Council.
European Data Protection Board, Annual Report 2024.
Ministry of Electronics and Information Technology, Government of India, Digital Personal Data Protection Rules 2025.
Government of India, Digital Personal Data Protection Act 2023: Commencement Notification, Gazette of India, 13 November 2025.
Academic Source
Ekpo, O., Okokon, A. and Akpakpan, M., 'Data Protection in the Digital Age: A Comparative Analysis of Nigeria's NDPA and the EU's GDPR', Proceedings of the 13th International Conference on Information & Communication Technologies and Development (ICTD '24), pp. 48–56.
Enforcement Materials
Nigeria Data Protection Commission, public enforcement materials concerning data protection investigations and sanctions, including the MultiChoice Nigeria enforcement action.
Dutch Data Protection Authority, enforcement materials concerning the 2024 Uber GDPR fine.