[codicts-css-switcher id=”346″]

Global Law Experts Logo
how to make a data subject access request in nigeria online

How to Make a Data Subject Access Request (DSAR) in Nigeria Online, Step-by-step (2026)

By Global Law Experts
– posted 2 hours ago

Last updated: July 25, 2026

If you want to know how to make a data subject access request in Nigeria online, the process is more straightforward than most people assume, but getting it right the first time depends on understanding the legal framework, choosing the correct submission channel, and attaching the right proof of identity. The Nigeria Data Protection Act (NDPA), signed into law in June 2023, grants every individual in Nigeria a statutory right to request access to any personal data an organisation holds about them.

The Nigeria Data Protection Commission (NDPC), the regulator established under the NDPA, has reinforced this right through its General Application and Implementation Directive (GAID) 2025, which sets out practical expectations for how controllers should handle such requests, including the widely cited 30-day response window. This guide walks you through every step, from scoping your request to escalating a complaint if the organisation ignores you.

TL;DR, Can You Make a DSAR Online in Nigeria?

Yes. Any individual whose personal data is processed by an organisation operating in Nigeria can submit a data subject access request online, by email, through a corporate privacy portal, or via a written online form. Here is what you need to know at a glance:

  • Legal basis. The NDPA (sections 34–38) grants data subjects the right to access, rectify, and in certain cases erase their personal data. The NDPC’s GAID 2025 provides additional procedural guidance for both controllers and data subjects.
  • Response timeline. The NDPC’s GAID 2025 establishes the expectation that data controllers respond to a DSAR within 30 days of receiving a valid, complete request.
  • What to attach. A government-issued photo ID (National Identification Number card, international passport, or driver’s licence) to verify your identity, plus enough detail for the organisation to locate your records.
  • If refused or ignored. You have the right to file a complaint directly with the NDPC if a controller fails to respond, provides an incomplete response, or refuses your request without a lawful basis.

What Is a Data Subject Access Request (DSAR) Under Nigerian Law?

A data subject access request is a formal demand made by an individual (the “data subject”) to an organisation (the “data controller”) requiring the controller to confirm whether it processes the individual’s personal data and, if so, to provide a copy of that data along with specific supplementary information. Under the NDPA, the rights of data subjects are codified in sections 34 through 38, which collectively guarantee the right of access, the right to rectification of inaccurate data, and the right to object to or restrict certain types of processing.

The NDPC’s GAID 2025 supplements the Act by providing interpretive guidance on how these rights should be exercised in practice. Together, these instruments create a clear legal pathway for any person, Nigerian citizen, resident, or anyone whose data is processed within the jurisdiction, to submit a DSAR and receive a meaningful response.

Who Can Make a Data Subject Access Request?

The request can be made by the data subject personally or by an authorised third party acting on the data subject’s behalf. Common examples of authorised representatives include a legal practitioner holding a signed letter of authority, a parent or guardian acting for a minor, or a person granted power of attorney. The representative must provide both their own identification and written proof of authorisation alongside the data subject’s identity document.

Before You Start, Decide Scope and Prepare Documents

A well-scoped request saves time for both you and the controller. Before you submit a data subject access request in Nigeria, consider the following preparatory steps:

  • Define what you want. Are you looking for all personal data the organisation holds, or only specific records (e.g., transaction history, CCTV footage, call recordings, HR file)? A narrower request is typically processed faster.
  • Identify the time period. If you only need records from a particular date range, state it clearly. This reduces the controller’s search burden and speeds up delivery.
  • Gather account identifiers. Collect your customer number, employee ID, policy number, email address on file, or any reference the organisation uses to identify you internally.
  • Prepare your proof of identity. Under NDPC guidance, controllers are entitled to verify the identity of the requester before releasing personal data. Accepted documents typically include a National Identification Number (NIN) card or slip, an international passport, a permanent voter’s card, or a driver’s licence.
  • If acting for someone else. Prepare a signed letter of authority from the data subject, plus copies of both your ID and the data subject’s ID.

Pre-submission checklist:

  1. Government-issued photo ID (scan or clear photograph)
  2. Account or reference number(s) with the organisation
  3. Description of the data you want (broad or specific)
  4. Date range (if applicable)
  5. Contact email address for the response
  6. Signed authorisation letter (if filing on behalf of someone else)

How to Submit a DSAR Online in Nigeria, Step-by-Step

This is the core process for anyone looking to submit a subject request online in Nigeria. Follow these six steps to ensure your request is valid, trackable, and likely to receive a timely response.

Step 1: Identify the Data Controller and Its Data Protection Officer

Start by identifying the organisation that holds your data. This is the “data controller”, the entity that determines why and how your personal data is processed. Under the NDPA, controllers of a certain size or processing scope are required to appoint a Data Protection Officer (DPO). Check the organisation’s website, typically the privacy policy or “data protection” page, for the DPO’s name and contact email. If no DPO is listed, use the organisation’s general contact or compliance email address.

Step 2: Choose Your Submission Channel

Most organisations in Nigeria accept DSARs through one or more of the following online channels:

  • Email. The most common method. Send your request to the DPO’s email or the privacy/compliance address listed on the organisation’s website.
  • Corporate privacy portal. Some larger organisations, particularly banks, insurance companies, and telecoms, offer dedicated DSAR web forms. Look for links labelled “Data Subject Request,” “Privacy Request,” or “Access My Data” on the organisation’s site.
  • NDPC portal. The NDPC website provides guidance materials and forms. While the primary submission should go directly to the data controller, the NDPC portal is relevant if you need to escalate a complaint later.

Step 3: Draft Your Request with the Correct Subject Line and Wording

Clarity is critical. Use a subject line such as: “Data Subject Access Request, [Your Full Name], [Account/Reference Number]”. In the body of your email or form, state explicitly that you are exercising your right of access under the Nigeria Data Protection Act. Specify the data you want, the time period, and the format you prefer (e.g., electronic copy via email, PDF, or CSV).

Step 4: Attach Your ID and Supporting Evidence

Attach a clear scan or photograph of your government-issued photo ID. If you are uncomfortable sending a full ID image, you may redact information that is not needed for verification, for example, masking your NIN number on a driver’s licence if your name, photograph, and date of birth are sufficient for the controller to verify your identity. Never send original documents.

Step 5: Send and Keep Proof of Delivery

If submitting by email, request a read receipt or delivery confirmation. Screenshot the sent email, including the timestamp and recipient address. If using a portal, screenshot the confirmation page or save any reference number provided. This evidence is essential if you later need to prove the date of submission to the NDPC.

Step 6: Respond Promptly if the Controller Asks for More Information

A controller may contact you to verify your identity or to clarify the scope of your request. Respond without delay, the 30-day response clock under NDPC practice guidance does not start running until the controller has enough information to verify you and locate the requested data.

Sample DSAR Email Template

Below is a ready-to-use DSAR form template for Nigeria. Copy, paste, and customise the fields in square brackets:

Subject: Data Subject Access Request, [Full Name], [Account/Reference Number]

Dear Data Protection Officer / Privacy Team,

I am writing to exercise my right of access under the Nigeria Data Protection Act (NDPA). Please treat this email as a formal data subject access request.

I request a copy of all personal data your organisation holds about me, including but not limited to: [describe specific data categories or state “all personal data”]. If possible, please provide the data in [preferred format, e.g., PDF or CSV] to this email address.

For identification purposes, I attach a copy of my [type of ID]. My account/reference number with your organisation is [number]. The relevant period is [date range or “all time”].

I understand that under NDPC guidance (GAID 2025), I should expect a response within 30 days of this request. Please acknowledge receipt of this email.

Yours faithfully,
[Full Name]
[Contact Email]
[Phone Number]

Portal Uploads and File Naming

When uploading documents through a privacy portal, name files clearly, for example, DSAR_ID_JohnDoe_July2026.pdf. This helps the DPO match your documents to your request and avoids processing delays caused by unnamed or ambiguous attachments.

When to Use Postal Delivery Instead of Online Submission

In most cases, an online submission by email or portal is the fastest and most trackable method. However, if your request involves highly sensitive categories of data, such as health records or biometric data, and you have concerns about email security, consider sending a physical letter by registered post with acknowledgment of delivery. Keep the postal receipt as proof of the date of submission.

Timeline and Response Expectations, the 30-Day Question

One of the most frequently asked questions about DSAR response time in Nigeria is how long the controller actually has to reply. The NDPC’s GAID 2025 establishes a 30-day response window as the standard expectation. This means a data controller should provide a substantive response, either the requested data or a lawful reason for refusal, within 30 calendar days of receiving a valid, verified request.

It is important to note that the 30-day clock begins only once the controller has received both the request and sufficient information to verify the requester’s identity. If the controller asks you for additional ID or clarification, the clock pauses until you provide it. Industry observers expect the NDPC to increasingly treat the 30-day standard as an enforceable benchmark as regulatory capacity continues to expand.

Entity Type Typical DSAR Response Practice Notes / Citations
Private companies (banks, insurers, telecoms) Acknowledge within a few business days; full response commonly within 30 days per NDPC practice guidance; may request additional ID verification. Corporate DSAR forms (e.g., Access Bank, Wema Bank) + NDPC GAID 2025.
Public institutions / government agencies May require coordination with the Freedom of Information (FOI) Act process; timelines may vary; FOI Act exemptions could apply to certain categories of data. FOI Act (2011) cross-over, consult both FOI and NDPC guidance.
Employers (employee files) May have separate HR data-access procedures; typically aim for 30-day handling in practice; must balance employee privacy against requester rights. Employer DSAR practices + NDPC GAID 2025.

Proof of Identity, What Counts and How to Submit It Safely

Proof of identity is a mandatory part of any data subject access request in Nigeria. Controllers are entitled, and in fact required by good practice, to verify that the person making the request is who they claim to be before releasing personal data. Failing to verify identity would itself be a data protection breach.

ID Type Accepted for Individual Requests Accepted for Representative Requests
National Identification Number (NIN) card or slip Yes Yes (plus authorisation letter and data subject’s ID)
International passport Yes Yes (plus authorisation letter and data subject’s ID)
Permanent voter’s card (PVC) Yes Yes (plus authorisation letter and data subject’s ID)
Driver’s licence Yes Yes (plus authorisation letter and data subject’s ID)

How to Protect Your Privacy When Submitting ID

  • Redact unnecessary details. If the controller only needs your name, photograph, and date of birth, mask other fields (e.g., NIN digits on a driver’s licence) using a PDF editor or by covering with opaque tape before scanning.
  • Use password-protected files. When emailing sensitive ID documents, compress them into a password-protected ZIP file and share the password in a separate email or SMS.
  • Never send originals. Always submit scanned copies or clear photographs, never the physical document itself.
  • Watermark the scan. Add a text watermark such as “For DSAR verification only, [Organisation Name], [Date]” to discourage misuse of the copy.

Employer DSARs: Employee Data, HR Files, and Disciplinary Records

An employer DSAR in Nigeria raises particular considerations because the employer is typically the data controller of employee personal data. Employees have the same rights under the NDPA as any other data subject, meaning they can request access to their HR files, payroll records, performance reviews, disciplinary proceedings, CCTV footage from the workplace, and email communications that contain their personal data.

Key Considerations for Employees Making a DSAR

  • Scope your request carefully. A broad request for “all data” could encompass thousands of emails. Consider specifying categories, for example, “all disciplinary records and performance appraisals from January 2024 to present.”
  • Third-party personal data. The employer must redact personal data belonging to other identifiable individuals (e.g., colleagues mentioned in investigation notes) before disclosing records to you, unless those individuals consent to disclosure.
  • Legal professional privilege. Documents covered by legal professional privilege, such as legal advice obtained by the employer about a dispute with you, are generally exempt from disclosure under a DSAR.
  • Ongoing investigations. If your request relates to data involved in an active disciplinary or fraud investigation, the employer may seek to delay or partially restrict disclosure where releasing the data would prejudice the investigation. Any such restriction must be communicated to you with a lawful basis.

Guidance for HR Teams and Managers

Employers receiving a DSAR from an employee should route the request immediately to their DPO or compliance function. The same 30-day response expectation under NDPC guidance applies. Managers should not attempt to handle the request informally or delay forwarding it, as the clock starts from the date the organisation, not a specific department, receives the request.

When an Organisation Refuses or Fails to Respond, Grounds and Escalation

Not every DSAR will be granted in full. Under the NDPA, a controller may refuse a request that is manifestly unfounded or excessive, for example, repeated identical requests submitted in quick succession with no reasonable justification. A controller may also restrict access where disclosure would compromise national security, the prevention or detection of crime, or legal proceedings.

However, any refusal must be communicated to you in writing, must state the specific legal ground relied upon, and must inform you of your right to complain to the NDPC. A blanket refusal without explanation does not satisfy the requirements of the NDPA.

How to File an NDPC Complaint

If a controller ignores your request, refuses without adequate justification, or provides an incomplete response, you can escalate by filing a complaint with the Nigeria Data Protection Commission. The steps are:

  1. Prepare a written complaint letter stating: your name, the controller’s name and contact details, the date you submitted your DSAR, what response (if any) you received, and why you believe the response is inadequate or unlawful.
  2. Attach evidence: a copy of your original DSAR, proof of delivery (email receipt, screenshot, postal tracking), the controller’s response (if any), and your ID.
  3. Submit the complaint via the NDPC’s official channels, either through the complaint or contact form on ndpc.gov.ng or by email to the Commission’s published contact address.
  4. Retain copies of everything you submit and note the date of your complaint for follow-up.

Example DSAR Email and Downloadable DSAR Form

The sample email template provided in the step-by-step section above can be used immediately by copying the text into any email client. For a more structured approach, use a DSAR form with the following fields:

  • Full name of data subject
  • Contact email address
  • Contact phone number
  • Name of organisation (controller)
  • Account or reference number
  • Description of data requested
  • Preferred format of response (email, PDF, CSV, hard copy)
  • Date range (if applicable)
  • Type of ID attached
  • Authorisation details (if filing on behalf of another person)
  • Signature and date

If you are acting as an authorised representative, include a signed authorisation letter from the data subject alongside both your identification and theirs.

Practical Tips for Speed and Proof, 7 Quick Wins

  1. Email the DPO directly. Bypass generic customer service addresses where possible, a direct email to the DPO or privacy team triggers the formal DSAR process faster.
  2. Attach ID upfront. Do not wait for the controller to ask. Including verified ID with your initial request prevents the 30-day clock from being paused.
  3. Provide unique identifiers. Customer numbers, policy references, and account IDs help the controller locate your data without delay.
  4. Request a machine-readable copy. Ask for data in CSV, JSON, or PDF format rather than printed pages, this makes the response easier to review and store.
  5. Ask for a processing note. Request that the controller confirm the purposes of processing, the categories of data held, and any recipients to whom your data has been disclosed.
  6. Set a calendar reminder. Mark 30 calendar days from the date the controller confirms receipt. If the deadline passes without a response, follow up immediately in writing.
  7. Use recorded delivery for postal requests. If you must submit by post, use a tracked or registered delivery service and retain the tracking receipt as proof of the submission date.

Conclusion, What to Expect and Next Steps

Making a data subject access request in Nigeria online is a right protected by the NDPA and supported by the NDPC’s GAID 2025 enforcement guidance. Once you have identified the controller, prepared your ID, and submitted your request through the appropriate channel, the organisation should respond within 30 days. If it does not, the NDPC provides a clear complaint pathway to hold controllers accountable. Early indications suggest that as the NDPC continues to expand its enforcement activities and public awareness campaigns, response rates and compliance standards across both the private and public sectors are likely to improve.

Whether you are an individual checking what a bank holds about you or an employee seeking your HR records, the six-step process above gives you a legally grounded, practical path to exercise your rights.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Paul Mgbeoma at Tayo Oyetibo LP, a member of the Global Law Experts network.

Sources

  1. Nigeria Data Protection Commission (NDPC), General Application and Implementation Directive (GAID) 2025
  2. Nigeria Data Protection Commission (NDPC), Official Website and NDPA Resources
  3. National Information Technology Development Agency (NITDA)
  4. American University of Nigeria, A Legal Examination of the Nigeria Data Protection Act, 2023
  5. UK Information Commissioner’s Office (ICO), Subject Access Request Guidance (Comparative)

FAQs

How do I make a data subject access request in Nigeria?
Identify the organisation holding your data, draft a written request citing the Nigeria Data Protection Act, attach a government-issued photo ID, and send it to the organisation’s Data Protection Officer or privacy team by email or online portal. Follow the six-step process outlined above and use the sample email template provided.
The most common online method is email. Send your request to the DPO or privacy compliance email address listed on the organisation’s website. Alternatively, many banks, insurers, and telecoms offer dedicated privacy web forms. Use a clear subject line such as “Data Subject Access Request, [Your Name], [Reference Number].”
Any individual whose personal data is processed by an organisation in Nigeria can make a DSAR. An authorised third party, such as a solicitor, parent or guardian, or power-of-attorney holder, may also submit a request on the data subject’s behalf, provided they present written authorisation and both parties’ identification.
No. The EU’s General Data Protection Regulation (GDPR) does not apply directly in Nigeria. Nigeria has its own standalone legislation, the Nigeria Data Protection Act (NDPA), signed into law in 2023, which governs data protection. However, the NDPA aligns with many GDPR principles, including the right of access, the right to rectification, and obligations on data controllers to respond to subject access requests within a defined timeframe.
Controllers typically accept a scan or clear photograph of a government-issued photo ID: National Identification Number (NIN) card, international passport, permanent voter’s card (PVC), or driver’s licence. If filing on behalf of someone else, provide both your ID and the data subject’s ID, along with a signed authorisation letter.
Yes, but only on specific legal grounds. Under the NDPA, a controller may refuse a request that is manifestly unfounded or excessive, or where an exemption applies (e.g., national security, crime prevention, legal privilege). Any refusal must be in writing, must state the legal ground, and must inform you of your right to complain to the NDPC.
The NDPC’s GAID 2025 establishes a 30-day response expectation from the date the controller receives a valid, verified request. If the controller requests additional information to verify your identity, the 30-day period starts only once you provide it. Complex requests may take longer, but the controller should inform you of the reason for any delay.
Submit a written complaint to the Nigeria Data Protection Commission via its website at ndpc.gov.ng or by email. Include a copy of your original DSAR, proof of delivery, any response received, and your identification. State clearly what remedy you are seeking, such as an order compelling the controller to respond or an investigation into the controller’s data protection practices.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Make a Data Subject Access Request (DSAR) in Nigeria Online, Step-by-step (2026)

Send welcome message

Custom Message