This article is general information to help you ask the right questions. It isn’t legal advice. For advice on your own situation, speak to a lawyer or a data protection professional.

The Nigeria Data Protection Act 2023 (the NDPA) sets the rules for how organisations collect and use personal data about people. It also set up the Nigeria Data Protection Commission, which oversees those rules.

Many small businesses assume it only matters for banks and big tech companies. But if your website has a contact form, a newsletter sign-up or analytics, it almost certainly collects personal data. Here’s what that means in plain terms.

What counts as personal data

Personal data is anything that identifies a person, directly or indirectly. On a typical business website that includes:

  • names, email addresses and phone numbers from a contact form;
  • messages people send you;
  • IP addresses and device details collected by analytics or security tools;
  • anything stored in cookies that can be tied back to a person.

The principles, in plain language

The NDPA is built on principles you’ll recognise from data protection laws elsewhere:

  • Have a lawful reason. Consent is one, but not the only one. Replying to someone who asked you a question, for example, can rest on taking steps they asked for.
  • Collect only what you need. If you only reply by email, don’t ask for a home address.
  • Use it only for what you said. Don’t add contact form enquiries to a marketing list without a proper basis.
  • Keep it accurate, and not for longer than needed.
  • Keep it secure. Use HTTPS, keep software updated, and limit who can see the inbox.
  • Be accountable. Know what you collect, where it’s stored and who can see it.

Your privacy notice

A privacy notice tells people what you do with their data. It should be easy to find (usually linked in your footer and next to your forms) and written in plain language. As a starting point, it should cover:

  • who you are and how to contact you;
  • what personal data you collect, and why;
  • your lawful basis for each use;
  • who you share it with (for example, your email or hosting provider);
  • how long you keep it;
  • people’s rights, including to see, correct or delete their data, and to complain to the Commission.

Cookies and analytics

Some cookies are needed for a site to work, such as one that remembers what’s in a basket. Others, like many analytics and advertising cookies, are not.

A cautious approach, and common good practice, is:

  • use as few cookies as you can;
  • don’t set non-essential cookies until the visitor agrees;
  • make “no” as easy as “yes”;
  • explain your cookies in a short cookie notice.

Privacy-friendly analytics that don’t use cookies or track people across sites can remove much of the problem altogether.

Contact forms

Contact forms are where most small business websites collect personal data. A few habits go a long way:

  • ask only for what you need to reply;
  • say, next to the form, how you’ll use the details, and link to your privacy notice;
  • make sure form submissions are sent and stored securely;
  • don’t leave old enquiries sitting in inboxes for years;
  • protect the form from spam without tracking every visitor.

If something goes wrong

If personal data is lost, stolen or exposed, the NDPA expects organisations to act quickly, which can include telling the Commission and, where the risk is high, the people affected. Decide now who would handle that, so you’re not working it out in a hurry.

How we build websites

When we build a website, privacy is part of the build, not an afterthought: few cookies, forms that ask only for what’s needed, and clear notices. We’re building our Websites with an Admin Panel the same way, and we can look over an existing site with you. You should still have your notices checked by a professional.