Our Expert in Nigeria
No results available
Last updated: July 25, 2026
If you want to know how to make a data subject access request in Nigeria online, the process is more straightforward than most people assume, but getting it right the first time depends on understanding the legal framework, choosing the correct submission channel, and attaching the right proof of identity. The Nigeria Data Protection Act (NDPA), signed into law in June 2023, grants every individual in Nigeria a statutory right to request access to any personal data an organisation holds about them.
The Nigeria Data Protection Commission (NDPC), the regulator established under the NDPA, has reinforced this right through its General Application and Implementation Directive (GAID) 2025, which sets out practical expectations for how controllers should handle such requests, including the widely cited 30-day response window. This guide walks you through every step, from scoping your request to escalating a complaint if the organisation ignores you.
Yes. Any individual whose personal data is processed by an organisation operating in Nigeria can submit a data subject access request online, by email, through a corporate privacy portal, or via a written online form. Here is what you need to know at a glance:
A data subject access request is a formal demand made by an individual (the “data subject”) to an organisation (the “data controller”) requiring the controller to confirm whether it processes the individual’s personal data and, if so, to provide a copy of that data along with specific supplementary information. Under the NDPA, the rights of data subjects are codified in sections 34 through 38, which collectively guarantee the right of access, the right to rectification of inaccurate data, and the right to object to or restrict certain types of processing.
The NDPC’s GAID 2025 supplements the Act by providing interpretive guidance on how these rights should be exercised in practice. Together, these instruments create a clear legal pathway for any person, Nigerian citizen, resident, or anyone whose data is processed within the jurisdiction, to submit a DSAR and receive a meaningful response.
The request can be made by the data subject personally or by an authorised third party acting on the data subject’s behalf. Common examples of authorised representatives include a legal practitioner holding a signed letter of authority, a parent or guardian acting for a minor, or a person granted power of attorney. The representative must provide both their own identification and written proof of authorisation alongside the data subject’s identity document.
A well-scoped request saves time for both you and the controller. Before you submit a data subject access request in Nigeria, consider the following preparatory steps:
Pre-submission checklist:
This is the core process for anyone looking to submit a subject request online in Nigeria. Follow these six steps to ensure your request is valid, trackable, and likely to receive a timely response.
Start by identifying the organisation that holds your data. This is the “data controller”, the entity that determines why and how your personal data is processed. Under the NDPA, controllers of a certain size or processing scope are required to appoint a Data Protection Officer (DPO). Check the organisation’s website, typically the privacy policy or “data protection” page, for the DPO’s name and contact email. If no DPO is listed, use the organisation’s general contact or compliance email address.
Most organisations in Nigeria accept DSARs through one or more of the following online channels:
Clarity is critical. Use a subject line such as: “Data Subject Access Request, [Your Full Name], [Account/Reference Number]”. In the body of your email or form, state explicitly that you are exercising your right of access under the Nigeria Data Protection Act. Specify the data you want, the time period, and the format you prefer (e.g., electronic copy via email, PDF, or CSV).
Attach a clear scan or photograph of your government-issued photo ID. If you are uncomfortable sending a full ID image, you may redact information that is not needed for verification, for example, masking your NIN number on a driver’s licence if your name, photograph, and date of birth are sufficient for the controller to verify your identity. Never send original documents.
If submitting by email, request a read receipt or delivery confirmation. Screenshot the sent email, including the timestamp and recipient address. If using a portal, screenshot the confirmation page or save any reference number provided. This evidence is essential if you later need to prove the date of submission to the NDPC.
A controller may contact you to verify your identity or to clarify the scope of your request. Respond without delay, the 30-day response clock under NDPC practice guidance does not start running until the controller has enough information to verify you and locate the requested data.
Below is a ready-to-use DSAR form template for Nigeria. Copy, paste, and customise the fields in square brackets:
Subject: Data Subject Access Request, [Full Name], [Account/Reference Number]
Dear Data Protection Officer / Privacy Team,
I am writing to exercise my right of access under the Nigeria Data Protection Act (NDPA). Please treat this email as a formal data subject access request.
I request a copy of all personal data your organisation holds about me, including but not limited to: [describe specific data categories or state “all personal data”]. If possible, please provide the data in [preferred format, e.g., PDF or CSV] to this email address.
For identification purposes, I attach a copy of my [type of ID]. My account/reference number with your organisation is [number]. The relevant period is [date range or “all time”].
I understand that under NDPC guidance (GAID 2025), I should expect a response within 30 days of this request. Please acknowledge receipt of this email.
Yours faithfully,
[Full Name]
[Contact Email]
[Phone Number]
When uploading documents through a privacy portal, name files clearly, for example, DSAR_ID_JohnDoe_July2026.pdf. This helps the DPO match your documents to your request and avoids processing delays caused by unnamed or ambiguous attachments.
In most cases, an online submission by email or portal is the fastest and most trackable method. However, if your request involves highly sensitive categories of data, such as health records or biometric data, and you have concerns about email security, consider sending a physical letter by registered post with acknowledgment of delivery. Keep the postal receipt as proof of the date of submission.
One of the most frequently asked questions about DSAR response time in Nigeria is how long the controller actually has to reply. The NDPC’s GAID 2025 establishes a 30-day response window as the standard expectation. This means a data controller should provide a substantive response, either the requested data or a lawful reason for refusal, within 30 calendar days of receiving a valid, verified request.
It is important to note that the 30-day clock begins only once the controller has received both the request and sufficient information to verify the requester’s identity. If the controller asks you for additional ID or clarification, the clock pauses until you provide it. Industry observers expect the NDPC to increasingly treat the 30-day standard as an enforceable benchmark as regulatory capacity continues to expand.
| Entity Type | Typical DSAR Response Practice | Notes / Citations |
|---|---|---|
| Private companies (banks, insurers, telecoms) | Acknowledge within a few business days; full response commonly within 30 days per NDPC practice guidance; may request additional ID verification. | Corporate DSAR forms (e.g., Access Bank, Wema Bank) + NDPC GAID 2025. |
| Public institutions / government agencies | May require coordination with the Freedom of Information (FOI) Act process; timelines may vary; FOI Act exemptions could apply to certain categories of data. | FOI Act (2011) cross-over, consult both FOI and NDPC guidance. |
| Employers (employee files) | May have separate HR data-access procedures; typically aim for 30-day handling in practice; must balance employee privacy against requester rights. | Employer DSAR practices + NDPC GAID 2025. |
Proof of identity is a mandatory part of any data subject access request in Nigeria. Controllers are entitled, and in fact required by good practice, to verify that the person making the request is who they claim to be before releasing personal data. Failing to verify identity would itself be a data protection breach.
| ID Type | Accepted for Individual Requests | Accepted for Representative Requests |
|---|---|---|
| National Identification Number (NIN) card or slip | Yes | Yes (plus authorisation letter and data subject’s ID) |
| International passport | Yes | Yes (plus authorisation letter and data subject’s ID) |
| Permanent voter’s card (PVC) | Yes | Yes (plus authorisation letter and data subject’s ID) |
| Driver’s licence | Yes | Yes (plus authorisation letter and data subject’s ID) |
An employer DSAR in Nigeria raises particular considerations because the employer is typically the data controller of employee personal data. Employees have the same rights under the NDPA as any other data subject, meaning they can request access to their HR files, payroll records, performance reviews, disciplinary proceedings, CCTV footage from the workplace, and email communications that contain their personal data.
Employers receiving a DSAR from an employee should route the request immediately to their DPO or compliance function. The same 30-day response expectation under NDPC guidance applies. Managers should not attempt to handle the request informally or delay forwarding it, as the clock starts from the date the organisation, not a specific department, receives the request.
Not every DSAR will be granted in full. Under the NDPA, a controller may refuse a request that is manifestly unfounded or excessive, for example, repeated identical requests submitted in quick succession with no reasonable justification. A controller may also restrict access where disclosure would compromise national security, the prevention or detection of crime, or legal proceedings.
However, any refusal must be communicated to you in writing, must state the specific legal ground relied upon, and must inform you of your right to complain to the NDPC. A blanket refusal without explanation does not satisfy the requirements of the NDPA.
If a controller ignores your request, refuses without adequate justification, or provides an incomplete response, you can escalate by filing a complaint with the Nigeria Data Protection Commission. The steps are:
The sample email template provided in the step-by-step section above can be used immediately by copying the text into any email client. For a more structured approach, use a DSAR form with the following fields:
If you are acting as an authorised representative, include a signed authorisation letter from the data subject alongside both your identification and theirs.
Making a data subject access request in Nigeria online is a right protected by the NDPA and supported by the NDPC’s GAID 2025 enforcement guidance. Once you have identified the controller, prepared your ID, and submitted your request through the appropriate channel, the organisation should respond within 30 days. If it does not, the NDPC provides a clear complaint pathway to hold controllers accountable. Early indications suggest that as the NDPC continues to expand its enforcement activities and public awareness campaigns, response rates and compliance standards across both the private and public sectors are likely to improve.
Whether you are an individual checking what a bank holds about you or an employee seeking your HR records, the six-step process above gives you a legally grounded, practical path to exercise your rights.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Paul Mgbeoma at Tayo Oyetibo LP, a member of the Global Law Experts network.
posted 10 minutes ago
posted 10 minutes ago
posted 33 minutes ago
posted 56 minutes ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message