Must a Data Protection Officer Be Nigerian? Examining the NDPC’s NIN Requirement for DPCO Licence Applications

Introduction

The Nigeria Data Protection Act 2023 requires certain organisations to designate a Data Protection Officer. It also empowers the Nigeria Data Protection Commission to license suitably qualified persons to provide data-protection compliance services.

A practical question has nevertheless arisen from the licensing process for Data Protection Compliance Organisations: where an organisation applying for a DPCO licence is required to provide the National Identification Number of its proposed Data Protection Officer, does this mean that only a Nigerian citizen—or a person legally resident in Nigeria—can perform that role?

The short answer is that the Nigeria Data Protection Act does not expressly require a DPO to be a Nigerian citizen, resident in Nigeria or holder of a NIN.

However, where the NDPC’s DPCO application system makes submission of a NIN mandatory, the person presented by the applicant may, as a practical matter, need to be a Nigerian citizen or lawful resident who is eligible to obtain a NIN. This creates an important distinction between the legal eligibility requirements established by the Act and the administrative requirements applied during the DPCO licensing process.

Speak With a Data Privacy Consultant

The DPO Requirements Under the Nigeria Data Protection Act

Section 32 of the Nigeria Data Protection Act provides that a data controller of major importance must designate a Data Protection Officer who possesses:

  • Expert knowledge of data-protection law and practices; and
  • The ability to perform the responsibilities prescribed by the Act and applicable subsidiary legislation.

The Act permits the DPO to be either an employee of the data controller or a person engaged under a service contract.

The DPO’s statutory responsibilities include:

  • Advising the data controller or data processor and relevant employees;
  • Monitoring compliance with the Act and the organisation’s related policies; and
  • Acting as the organisation’s contact point for the Nigeria Data Protection Commission.

Section 32 does not state that the DPO must:

  • Be a Nigerian citizen;
  • Be resident in Nigeria;
  • Be physically located in Nigeria;
  • Hold a National Identification Number; or
  • Be employed directly by the appointing organisation.

The express statutory criteria focus on expertise, competence and the ability to perform the required responsibilities.

The fact that a DPO may be engaged under a service contract also supports the availability of an outsourced DPO model. It does not, by itself, restrict the location, nationality or residence of the service provider.

An organisation must nevertheless consider whether its chosen DPO can perform the role effectively. A DPO located outside Nigeria would still need to understand the Nigerian regulatory framework, remain accessible to the organisation, respond to the NDPC and adequately monitor the organisation’s processing activities. These are practical effectiveness considerations rather than express citizenship or residence requirements.

DPO Appointment and DPCO Licensing Are Different Questions

It is important not to confuse the appointment of a DPO by a data controller or processor with the licensing of a Data Protection Compliance Organisation.

Section 32 governs the designation and responsibilities of a DPO.

Section 33 separately empowers the NDPC to license a person with the required level of expertise to monitor, audit and report on compliance with the Act and related regulations, directives, guidelines and codes of conduct.

A DPCO is therefore a licensed compliance-service provider. An organisation applying for a DPCO licence may be asked to provide information about its directors, personnel, proposed DPO or technical team as part of the NDPC’s assessment of its capacity and suitability.

An identity requirement imposed during that licensing process does not automatically become a general legal qualification applicable to every DPO appointed under the NDPA.

In other words:

  • A requirement imposed on a DPCO licence applicant is not necessarily a requirement imposed on all DPOs under Section 32.
  • The DPO presented by a prospective DPCO may be subject to additional licensing and identity-verification requirements.
  • Those additional requirements should not be interpreted as amending the general DPO eligibility criteria in the Act unless they are supported by an applicable regulation, directive or formal licensing condition.

What Does a Mandatory NIN Field Mean?

A NIN is an identity credential issued through Nigeria’s national identity system. It is not limited exclusively to Nigerian citizens. Lawful residents may also be eligible to register for a NIN.

The National Identity Management Commission has referred to the national identity system as covering both registered Nigerian citizens and legal residents.

Consequently, requiring a NIN does not necessarily mean that the proposed DPO must be a Nigerian citizen. A non-Nigerian who is lawfully resident in Nigeria and has completed the relevant identity-registration process may also possess a NIN.

The practical categories are therefore likely to be:

  • Nigerian citizens with a NIN: able to satisfy the identification requirement.
  • Non-Nigerian lawful residents with a NIN: potentially able to satisfy the same requirement.
  • Qualified foreign professionals living outside Nigeria without a NIN: potentially prevented from completing the relevant part of the application, even though the NDPA does not expressly disqualify them from acting as a DPO.

If the application portal provides no alternative identification route, the NIN field may create a de facto restriction to non-NIN holders. That is not the same as an express statutory rule that only Nigerian citizens or residents may act as DPOs.

Can an Application Form Create a New DPO Qualification?

An application form is ordinarily used to collect the information required to assess an application and verify the identity and suitability of the persons involved.

It should not, without an appropriate legal or regulatory basis, be treated as introducing a substantive qualification that does not appear in the governing legislation.

The NDPC has statutory authority to issue regulations, directives, codes and guidance and to prescribe application processes. It may therefore impose proportionate licensing requirements when assessing organisations seeking to provide regulated compliance services.

However, where a licensing requirement appears capable of excluding an otherwise qualified category of professional, the regulatory basis and intended scope of the requirement should be clear.

A mandatory NIN field could serve several legitimate purposes, including:

  • Confirming the identity of the person presented by the applicant;
  • Preventing the unauthorised use of another person’s qualifications;
  • Establishing accountability for licensed compliance services;
  • Supporting background or qualification verification;
  • Maintaining accurate regulatory records; or
  • Ensuring that the NDPC can identify and contact responsible personnel.

None of these purposes necessarily establishes that Nigerian citizenship is required.

The critical question is whether the NIN is being requested solely as an identity-verification mechanism or whether the NDPC intends it to operate as an eligibility condition requiring the DPCO’s nominated DPO to be a Nigerian citizen or lawful resident.

That distinction should be expressly clarified.

Does a Foreign DPO Contradict the NDPA?

The NDPA has a broad territorial scope. It can apply to organisations outside Nigeria where they process the personal data of individuals in Nigeria.

The Act therefore operates within an international data-processing environment. It recognises cross-border processing, international transfers and service arrangements extending beyond Nigeria.

Against that background, an interpretation that categorically excludes every non-resident foreign professional from serving as a DPO would require a clear legal or regulatory basis.

There may be legitimate reasons for a DPCO to maintain qualified and accountable personnel within Nigeria. A locally available professional may be better positioned to:

  • Communicate promptly with the NDPC;
  • Understand local regulatory expectations;
  • Participate in inspections and regulatory meetings;
  • Support Nigerian clients;
  • Respond to incidents within applicable timelines; and
  • Maintain operational accountability within the licensed organisation.

These considerations may justify a local-presence requirement for a DPCO or for specified members of its compliance team. They do not establish that the NDPA itself imposes such a requirement on every person serving as a DPO.

The Practical Position for DPCO Applicants

Until the NDPC publishes a clear statement confirming whether non-resident DPOs without a NIN may be presented, a cautious DPCO applicant should nominate a person who:

  • Is a Nigerian citizen or lawful resident;
  • Has an active and verifiable NIN;
  • Possesses demonstrable data-protection knowledge and experience;
  • Understands the Nigeria Data Protection Act and applicable NDPC directives;
  • Is genuinely engaged by the applicant;
  • Is available to perform the stated responsibilities; and
  • Can communicate effectively with the NDPC.

The appointment should be substantive rather than nominal. An applicant should not present a person merely because that individual has a NIN while assigning the actual responsibilities to someone else.

The proposed DPO’s qualifications, contract, responsibilities, reporting arrangements and availability should be documented. The applicant should also be prepared to demonstrate how the DPO will exercise appropriate independence and obtain access to management and organisational information.

Where an applicant wishes to present a qualified foreign professional who does not possess a NIN, it should seek written clarification from the NDPC before submitting the application. The applicant should ask whether the NDPC will accept:

  • An international passport;
  • A foreign national identity document;
  • Proof of professional qualifications;
  • Proof of the contractual relationship;
  • Details of a Nigerian representative or contact person; or
  • Another approved identification and verification process.

Written clarification is preferable to relying on an informal interpretation of the portal.

Implications for Organisations Appointing Their Own DPOs

Organisations appointing a DPO under Section 32 should not automatically conclude that the DPO must have a NIN merely because a NIN may be requested during a DPCO licence application.

The organisation should primarily assess whether the proposed DPO:

  • Has suitable expertise;
  • Understands the organisation’s processing activities;
  • Can monitor compliance effectively;
  • Has sufficient independence and access to management;
  • Has adequate resources;
  • Can act as an accessible contact point for the NDPC; and
  • Can perform the role without an inappropriate conflict of interest.

Location and availability may be relevant to these considerations, particularly where the DPO is outsourced or based outside Nigeria. They should be assessed as part of the effectiveness of the appointment rather than treated as an automatic nationality restriction.

Why Regulatory Clarification Is Needed

The NDPC should clarify the status of the NIN requirement by confirming:

  • Whether a NIN is required for all DPOs or only for persons presented in connection with a DPCO licence application;
  • Whether the requirement applies to the DPO, directors, beneficial owners, principal consultant or another responsible officer;
  • Whether a non-Nigerian lawful resident with a NIN is eligible;
  • Whether a qualified non-resident professional may use an international passport or another identity document;
  • Whether a DPCO must maintain a locally resident DPO or merely an accessible Nigerian contact person;
  • The statutory or regulatory basis for any residence requirement; and
  • Whether existing DPCOs and DPO appointments are affected.

Clear guidance would protect applicants from inconsistent interpretations and prevent the administrative design of a portal from being mistaken for a statutory citizenship requirement.

It would also support transparency, regulatory certainty and equal treatment of applicants while preserving the NDPC’s legitimate interest in identity verification and accountability.

Conclusion

The Nigeria Data Protection Act does not expressly require a Data Protection Officer to be a Nigerian citizen, resident in Nigeria or holder of a National Identification Number. Its stated requirements focus on expert knowledge, competence and the ability to perform the statutory responsibilities of the role.

A mandatory NIN field in a DPCO licence application does not, by itself, establish that only Nigerian citizens may act as DPOs. Non-Nigerian lawful residents may also be eligible to obtain a NIN.

Nevertheless, where the NDPC’s application process does not provide an alternative to the NIN, a DPCO applicant may, as a practical matter, need to present a suitably qualified Nigerian citizen or lawful resident who holds a NIN.

The appropriate conclusion is therefore not that foreign or non-resident professionals are prohibited from acting as DPOs under the NDPA. Rather, the current licensing process may create an administrative limitation for DPCO applicants until the NDPC clarifies the purpose, scope and alternatives to the NIN requirement.

Pending that clarification, DPCO applicants should adopt a cautious approach: present a qualified and genuinely appointed NIN-holding professional for the licence application, while obtaining written confirmation before relying on a non-resident DPO who does not possess a NIN.

Appoint a Certified Outsourced DPO

Whether your organisation requires independent DPO oversight, statutory regulatory filing, or clarification on cross-border compliance, Amstel Consulting provides accredited DPCO advisory services.

Speak With a Data Privacy Consultant

Important Notice

This article is provided for general information and does not constitute legal advice. Organisations should obtain advice based on their particular circumstances and confirm current licensing requirements directly with the Nigeria Data Protection Commission.