NDPC Urges Senate to Align Social Media Office Bill with Existing Data Protection Act

The Nigeria Data Protection Commission (NDPC) has urged the Senate to align the proposed bill seeking to compel global social media platforms to establish physical offices in Nigeria with the provisions of the Nigeria Data Protection Act, 2023, warned that the amendment, in its current form, could undermine the country’s existing data protection framework and weaken its global digital competitiveness.

The position of the Commission was presented at the public hearing organised by the Senate Committee on ICT and Cyber Security by the Head of Legal and Regulatory Compliance, Nigeria Data Protection Commission, on behalf of the National Commissioner and Chief Executive Officer, Dr. Vincent Olatunji, who was unavoidably absent due to a national assignment.

The public hearing, chaired by Senator Shuaibu Afolabi Salisu, considered a bill sponsored by Senator Ned Munir Nwoko (Delta North) seeking to amend the Nigeria Data Protection Act, 2023, by requiring social media platforms, data controllers and data processors operating in Nigeria to establish physical offices within the country.

While reaffirming the Commission’s commitment to supporting the National Assembly in strengthening Nigeria’s digital ecosystem, the NDPC expressed reservations over aspects of the proposed legislation, maintaining that the accountability objectives of the bill are already adequately addressed under the existing Nigeria Data Protection Act.

According to the Commission, the Act already provided for extraterritorial application, enabling Nigeria to regulate organisations that process the personal data of Nigerians regardless of where such organisations are physically located.

The NDPC explained that because the digital ecosystem is globally interconnected, laws governing data protection must also be interoperable with international standards rather than creating isolated regulatory regimes.

It noted that the definitions of data controllers and data processors contained in the Nigeria Data Protection Act are consistent with globally recognised instruments, including the African Union Convention on Cyber Security and Personal Data Protection, the ECOWAS Supplementary Act on Personal Data Protection, Convention 108+, and the European Union General Data Protection Regulation (EU GDPR).

The Commission further stated that Nigeria currently chairs the Harmonisation Regulatory Committee of the Network of African Data Protection Authorities, stressing that introducing provisions inconsistent with globally accepted frameworks could isolate Nigeria from the international digital economy.

The NDPC also informed lawmakers that the statutory mechanisms for accountability are already clearly established under the Nigeria Data Protection Act.

It explained that data controllers of major importance are required to register in Nigeria and appoint local representatives who can be reached by regulators, courts and data subjects whenever necessary.

According to the Commission, major global platforms, including TikTok, Facebook and WhatsApp, already maintain representatives in Nigeria out of operational necessity, while the Commission has established effective channels through which they are engaged and held accountable for regulatory compliance.

“We have held Meta accountable, we have held TikTok accountable and we are engaging other organisations as well. We have no difficulty whatsoever in holding them accountable under the existing legal framework,” the Commission stated.

The NDPC cautioned that introducing a mandatory physical office requirement could also trigger reciprocal measures from other jurisdictions, compelling Nigerian digital businesses and startups to establish offices abroad before offering services in those countries.

Such a development, it warned, could negatively affect Nigeria’s growing digital economy and reduce the competitiveness of indigenous technology companies in the global marketplace.

Rather than requiring physical offices, the Commission urged the Senate to strengthen the existing legal provisions that require companies to maintain accessible local representatives capable of receiving legal processes and responding to regulators.

It argued that this approach reflects international best practices, pointing out that Article 27 of the European Union General Data Protection Regulation (EU GDPR) similarly requires designated representatives rather than mandatory physical offices.

Addressing concerns over data sovereignty, the Commission stressed that sovereignty in the digital age is determined not by the physical location of company offices but by a country’s legal and technological capacity to regulate and protect data wherever it is processed.

According to the NDPC, effective data sovereignty depend on strong institutions, robust regulatory frameworks and the technical capability to enforce compliance across jurisdictions.

The Commission explained that the Nigeria Data Protection Act already empowers it to protect national data sovereignty through adequacy decisions, standard contractual clauses, binding corporate rules and certification mechanisms governing international data transfers.

It added that countries seeking to receive personal data from Nigeria must demonstrate comparable legal protections, enforceable rights for data subjects, independent data protection authorities and adherence to the rule of law before they can be recognised as providing adequate protection.

The NDPC warned that departing from internationally accepted regulatory standards could have unintended consequences for Nigeria’s digital economy, urging lawmakers to carefully consider the broader implications of the proposed amendment.

It therefore recommended that the draft legislation be harmonised with the existing provisions of the Nigeria Data Protection Act while strengthening the Commission’s capacity to enforce compliance by both local and international organisations.

The Commission also urged lawmakers to focus on improving compliance among domestic organisations, noting that ensuring Nigerian entities fully implement existing legal obligations would further strengthen accountability across the digital ecosystem.

Responding after the presentation, Chairman of the Senate Committee on ICT and Cyber Security, Senator Shuaibu Afolabi Salisu, commended the Commission’s submission, describing it as insightful and assured stakeholders that all memoranda presented at the public hearing would be carefully reviewed before the committee submits its recommendations to the Senate.

The NDPC reaffirmed its readiness to continue working with the National Assembly, government institutions, industry stakeholders and civil society organisations to develop a regulatory framework that protects Nigerians’ data rights, strengthens digital accountability and supports the continued growth of the country’s digital economy.

Related posts