A POS Agent Challenges the Rules
The Federal High Court in Lagos recently dismissed a lawsuit challenging the NDPC’s mandate, establishing a binding precedent on who must register with the commission.
The case, Emmanuel Haruna v. Nigeria Data Protection Commission, centered on a Point of Sale (POS) agent who argued the registration requirement violated his privacy. He also claimed he wasn’t a DCPMI under the Nigeria Data Protection Act (NDPA) 2023 in the first place.
Where the Registration Mandate Came From
The NDPC issued a Guidance Notice on February 14, 2024, mandating registration for DCPMIs and operationalizing Sections 44 and 65 of the NDPA. The notice sparked widespread anxiety and legal pushback almost immediately.
Critics pointed to ambiguities in the classification criteria and what they saw as burdensome compliance obligations. Many organizations felt they had been unfairly swept into DCPMI status. The NDPC maintained it was acting within its mandate to safeguard fundamental rights and promote secure data processing.
How the Thresholds Actually Work
The Guidance Notice sets numerical thresholds that determine DCPMI status:
- Ultra High Level (UHL): Entities like banks processing over 5,000 data subjects
- Extra High Level (EHL): Entities processing 1,000 to 5,000 subjects
- Ordinary High Level (OHL): Entities processing over 200 data subjects within six months
The court examined whether the NDPC had exceeded its authority in setting these thresholds. Section 65 of the NDPA empowers the commission to designate processing activities significant to Nigeria’s economy, society, or security. The court affirmed this power, noting that even small businesses can pose meaningful data risks depending on what they collect.
Why the “Passive Conduit” Argument Failed
Haruna argued that as a POS agent, he was merely a passive conduit for data rather than a data processor, and that registration interfered with his privacy.
The court disagreed on both counts. It ruled that registration is authorized by the NDPA, serves a legitimate public objective, and is proportionate to that objective. The court also found that the information required for registration was not sensitive. On the classification question, it clarified that POS operators fall under the NDPA’s broad definition of a data processor simply because of their role in collecting and transmitting data.
Where Businesses Stand Now
The Federal High Court delivered its ruling on July 17, 2026, dismissing all claims against the NDPC. The decision gives businesses operating in Nigeria significant clarity going forward and reinforces the commission’s authority to enforce data protection standards.
Businesses should now review their compliance strategies against the clarified NDPC guidance. The judgment’s broader emphasis on accountability suggests that a proactive approach to data protection compliance matters for any entity handling personal data in Nigeria, regardless of how small that entity considers itself.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates


