Nigeria’s 72-Hour Data Breach Notification Rule: What the CAC, Remita and MultiChoice Cases Teach Businesses

For years, Nigeria's 72-hour data breach notification requirement existed largely as a compliance obligation on paper. Many businesses treated it as another provision in a lengthy data protection policy, important in theory, but unlikely to be seriously tested in practice.
That has changed.
In April 2026, the Corporate Affairs Commission (CAC) confirmed that threat actors had gained unauthorised access to parts of its systems, prompting the Nigeria Data Protection Commission (NDPC) to open an investigation. Around the same period, the NDPC also began investigating a separate incident involving Remita Payment Services and Sterling Bank over the possible exposure of sensitive personal and financial information.
These incidents are part of a much larger cybersecurity problem. Reporting reviewed by Medium indicates that Nigeria recorded well over 100,000 data breaches in the first quarter of 2025 alone.
For businesses that collect, store, process, or otherwise handle personal data—and that now includes virtually every organisation—the implication is significant.
The question is no longer whether a data breach can happen.
It is whether your organisation is prepared to recognise, assess, contain and report one within the required timeframe.
What Does Nigeria’s 72-Hour Breach Notification Rule Actually Require?

Section 40 of the Nigeria Data Protection Act (NDPA) requires data controllers and processors of major importance to notify the NDPC within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals.
The obligation was further reinforced through the General Application and Implementation Directive (GAID), which took effect on 19 September 2025.
According to NDPC, the GAID requires organisations to provide specific information about the incident when making a notification rather than simply reporting that a breach has occurred. It also provides for immediate notification where an incident presents a systemic or public risk.
In other words, breach notification is not simply a matter of sending an email within 72 hours.
An organisation needs to be capable of quickly establishing what happened, what information may have been affected, who may be at risk, what containment measures have been taken, and what further action is required.
The 72-hour window isn't the only deadline
Businesses should also be careful about assuming that the NDPA's 72-hour period is always the only notification requirement that applies.
Where a breach presents a high risk to individuals, affected data subjects may also need to be informed without undue delay, according to a compliance checklist published by Dimeri.
There are also sector-specific obligations.
For example, Internet Access Service Providers are subject to a separate 48-hour breach reporting requirement under a Nigerian Communications Commission code, according to legal analysis published by Mondaq.
Where multiple regulatory frameworks apply to the same organisation, the shortest applicable deadline may become the practical constraint.
This is why organisations operating in regulated industries should not build their incident-response process around the NDPA alone. They should map every potentially applicable notification obligation before an incident occurs.

Why Data Protection Enforcement Feels Different in 2026
The regulatory environment surrounding data protection in Nigeria has evolved considerably.
According to reporting from the Rio Times, the NDPC's approach has progressed through several stages: an education and warning phase from 2019 to 2023, more systematic investigations and sanctions between 2024 and 2025, and what the Commission describes as a period of full enforcement beginning in 2026.
The numbers illustrate the increasing level of regulatory activity.
By early 2026, the NDPC had reportedly collected an estimated ₦7.2 billion through registrations, compliance revenues and fines, concluded more than 240 breach investigations, and issued 11 major enforcement actions.
Under the NDPA, administrative penalties can reach ₦10 million or 2% of an organisation's gross annual revenue from the preceding financial year, whichever is greater, depending on the circumstances and applicable provisions.
The important point for businesses is not simply the size of the potential fine.
It is the increasing likelihood that regulators will actually examine whether organisations have put appropriate processes in place.

Enforcement is no longer limited to a few industries
The scope of regulatory attention is also becoming broader.
In February 2026, the NDPC issued compliance notices to 649 higher education institutions across Nigeria, including federal and state universities, private universities, polytechnics and colleges of education.
The institutions were directed to provide evidence relating to Data Protection Officer appointments and previous audit returns within 21 days, according to Aluko & Oyebode.
The message for businesses is straightforward:
Data protection compliance is not something reserved for banks, fintech companies and large technology platforms.
If your organisation processes personal data, you have a compliance responsibility.
And if something goes wrong, the quality of your response can become just as important as the original security failure.
A Data Breach Response Plan Must Be Built Before the Breach
A 72-hour deadline can sound relatively generous until you experience an actual security incident.
The clock does not start when your organisation has finished investigating the breach.
It starts when the organisation becomes aware of the relevant breach.
That distinction is critical.
A serious incident can involve multiple systems, incomplete logs, conflicting information, unavailable personnel, third-party vendors and uncertainty about exactly what information has been accessed.
By the time the organisation establishes that a reportable breach has occurred, a significant portion of the 72-hour window may already have passed.
Your incident response plan should already define:
Detection and containment
Your technical team should know how to isolate affected systems, preserve evidence and prevent further unauthorised access.
Internal escalation
The person who first discovers the problem, whether an IT employee, security analyst, customer service representative or external vendor, needs to know exactly who to contact and how quickly.
Risk assessment
Your Data Protection Officer and relevant legal/compliance personnel need a defined framework for determining whether an incident creates a risk to individuals and whether notification obligations are triggered.
Regulatory notification
The organisation should already understand who is responsible for preparing and submitting notifications and what information needs to be included.
Breach documentation
Every incident should be documented, including incidents that are ultimately determined not to require notification.
Guidance from Osuntuyi & Tokan-Lawal Law highlights the importance of maintaining appropriate breach records as part of demonstrating accountability.
This documentation can become particularly important when a regulator later asks a simple question:
Don't Wait for a Perfect Investigation Before Acting
One of the biggest practical challenges during a serious breach is that the investigation may take considerably longer than 72 hours.
Forensic teams may need weeks to establish the full extent of an intrusion.
That does not necessarily mean an organisation can simply wait until the investigation is complete before considering its notification obligations.
A more practical approach is to use a tiered incident-response process.
The organisation makes an initial notification based on the information reasonably available within the required timeframe and provides additional information or updates as the investigation progresses, where appropriate.
The mistake is assuming that you need to know everything before you can report anything.
In a serious incident, waiting for perfect certainty can create a bigger compliance problem than reporting an evolving picture and updating it as new facts emerge.
The objective should be to provide regulators with meaningful information within the applicable timeframe while continuing the investigation and remediation process.

What Businesses Should Be Doing Now
The direction of travel is increasingly clear.
Nigeria's data protection regime is moving from a period where compliance was often treated primarily as an administrative requirement toward one where organisations can expect greater regulatory scrutiny.
The NDPC's increasing investigations, compliance notices and enforcement actions suggest that businesses should no longer assume that their industry, size or profile places them outside the regulator's attention.
The right response is not simply to add another paragraph to your privacy policy.
It is to make sure your organisation can actually respond when something goes wrong.
Start with a practical breach-response exercise
If your organisation has never tested its incident-response process, conduct a tabletop exercise.
Create a realistic scenario:
Then ask:
- Who is notified first?
- Who takes control of the incident?
- Who determines whether personal data was affected?
- Who contacts the Data Protection Officer?
- Who assesses the risk to affected individuals?
- Who determines whether the NDPC must be notified?
- What information needs to be included in the notification?
- Who communicates with affected customers?
- What other regulators or contractual parties need to be notified?
- How will the organisation document its decisions?
- What happens if the investigation is still incomplete after 48 hours?
If nobody can answer those questions confidently, your organisation does not yet have a tested incident-response capability.
It has a policy.
And those are not the same thing.
The Real Lesson from Nigeria's Recent Breach Cases
The CAC, Remita, Sterling Bank and MultiChoice cases demonstrate something that businesses should take seriously: data protection enforcement is becoming a practical operational issue, not merely a legal or administrative one.
A company can have security policies, privacy notices, a Data Protection Officer and compliance documentation and still discover, during a real incident, that its response process is too slow or poorly coordinated.
That is where the 72-hour rule becomes particularly important.
Compliance is not measured only by what is written in your policy documents.
It is also demonstrated by what your organisation does when the policy is put under pressure.
For businesses that have not tested their breach-response procedures, 2026 is a good time to do so.
Run the simulation. Identify the gaps. Clarify responsibilities. Establish escalation procedures. Review your notification requirements. Test your communication channels.
Because when a breach happens, the 72-hour clock doesn't care whether your organisation was ready.
Your response process needs to be.
Ready to transform your business?
Let's discuss how our expert GRC solutions can drive measurable growth for your organization.
Schedule a Consultation
