Nigeria’s data privacy landscape just got a lot clearer. A Federal High Court ruling has validated the Nigeria Data Protection Commission‘s (NDPC) controversial registration requirements for Data Controllers and Processors of Major Importance (DCPMIs), resolving legal uncertainty that had been building since early 2024.

A POS Agent Challenges the Rules

The Federal High Court in Lagos recently dismissed a lawsuit challenging the NDPC’s mandate, establishing a binding precedent on who must register with the commission.

The case, Emmanuel Haruna v. Nigeria Data Protection Commission, centered on a Point of Sale (POS) agent who argued the registration requirement violated his privacy. He also claimed he wasn’t a DCPMI under the Nigeria Data Protection Act (NDPA) 2023 in the first place.

Where the Registration Mandate Came From

The NDPC issued a Guidance Notice on February 14, 2024, mandating registration for DCPMIs and operationalizing Sections 44 and 65 of the NDPA. The notice sparked widespread anxiety and legal pushback almost immediately.

Critics pointed to ambiguities in the classification criteria and what they saw as burdensome compliance obligations. Many organizations felt they had been unfairly swept into DCPMI status. The NDPC maintained it was acting within its mandate to safeguard fundamental rights and promote secure data processing.

How the Thresholds Actually Work

The Guidance Notice sets numerical thresholds that determine DCPMI status:

  • Ultra High Level (UHL): Entities like banks processing over 5,000 data subjects
  • Extra High Level (EHL): Entities processing 1,000 to 5,000 subjects
  • Ordinary High Level (OHL): Entities processing over 200 data subjects within six months

The court examined whether the NDPC had exceeded its authority in setting these thresholds. Section 65 of the NDPA empowers the commission to designate processing activities significant to Nigeria’s economy, society, or security. The court affirmed this power, noting that even small businesses can pose meaningful data risks depending on what they collect.

Why the “Passive Conduit” Argument Failed

Haruna argued that as a POS agent, he was merely a passive conduit for data rather than a data processor, and that registration interfered with his privacy.

The court disagreed on both counts. It ruled that registration is authorized by the NDPA, serves a legitimate public objective, and is proportionate to that objective. The court also found that the information required for registration was not sensitive. On the classification question, it clarified that POS operators fall under the NDPA’s broad definition of a data processor simply because of their role in collecting and transmitting data.

Where Businesses Stand Now

The Federal High Court delivered its ruling on July 17, 2026, dismissing all claims against the NDPC. The decision gives businesses operating in Nigeria significant clarity going forward and reinforces the commission’s authority to enforce data protection standards.

Businesses should now review their compliance strategies against the clarified NDPC guidance. The judgment’s broader emphasis on accountability suggests that a proactive approach to data protection compliance matters for any entity handling personal data in Nigeria, regardless of how small that entity considers itself.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates