In a landmark decision that underscores Nigeria’s commitment to data privacy and regulatory compliance, the Federal High Court sitting in Lagos has affirmed the statutory powers of the Nigeria Data Protection Commission (NDPC) to mandate the registration of Data Controllers and Processors of Major Importance (DCPMIs).
The judgment delivered by Honourable Justice F.N. Ogazi in the suit Emmanuel Harunna Vs NDPC (FHC/L/CS/1116/2024) dismisses prayers seeking to restrain the Commission from registering Point of Sale (POS) agents and similar entities categorized under Major Data Processing – Ordinary High Level (OHL).
The Applicant had approached the court seeking declarations to exempt POS agents from being designated as DCPMIs under the Nigeria Data Protection Act (NDPA) 2023, along with a perpetual injunction against the NDPC.
However, after a thorough judicial analysis of Sections 5(d), 6(c), 44, 45, and 65 of the NDPA 2023 alongside the Commission’s Guidance Notice on Registration, Justice Ogazi held that the NDPC acted squarely within its statutory mandate.
“The Nigeria Data Protection Act was enacted to promote accountability, transparency, and responsible data governance… Registration enables the Respondent to identify entities engaged in significant data processing activities and monitor compliance. Far from undermining the constitutional right to privacy, the registration framework is one of the statutory mechanisms designed to safeguard that very right by subjecting data controllers and data processors to effective regulatory oversight.”
The court further emphasized that Section 65 of the NDPA provides that its provisions prevail over any inconsistent law regarding personal data processing, firmly embedding the registration obligation under the protective shield of Section 45 of the 1999 Constitution of Nigeria.
Following the court ruling, NDPC’s National Commissioner and CEO, Dr. Vincent Olatunji, directed all unregistered DCPMIs across Nigeria to complete their registration immediately.
Organizations handling significant volumes of personal data, such as fintechs, POS networks, financial institutions, telecommunications providers, and major commercial enterprises, face heavy consequences for non-compliance. Non-compliance creates immediate statutory liability under the NDPA 2023, exposing violators to criminal prosecution, operational suspension orders, and administrative fines up to 2% of annual gross revenue or ₦10 million, whichever is higher. Without formal registration, organizations operate outside regulatory legitimacy, making them highly vulnerable to court injunctions and liability claims from data subjects if a breach occurs. Furthermore, failing to register signals a lack of data stewardship, which erodes public trust and risks customer fallout as well as the loss of institutional partnerships in Nigeria’s expanding digital economy. Ultimately, compliance ensures organizations are benchmarked against national security and privacy protocols, directly mitigating the risks of identity theft, fraud, and data leaks.
Reiterating the significance of the judgment, Babatunde Bamigboye, Head of Legal, Enforcement & Regulations at the NDPC, noted that the ruling marks a crucial milestone for Nigerian data jurisprudence.
By validating the NDPC’s supervisory boundaries, the judgment reinforces a clear standard for Nigeria’s digital ecosystem: any organization processing major volumes of personal data must be accountable, transparent, and registered. Compliance is no longer just a legal recommendation, it is a mandatory pillar for conducting business safely in Nigeria.

