Wise Hustlers — Digital Product & App Development Studio Logo
Get Consultation
By Wise Hustler Admin•9/20/2026•10 min read

How Long Should You Keep CCTV Footage in Nigeria? Setting a Retention Period You Can Defend

How Long Should You Keep CCTV Footage in Nigeria? Setting a Retention Period You Can Defend

# How Long Should You Keep CCTV Footage in Nigeria? Setting a Retention Period You Can Defend

TL;DR: Nigerian law does not name a fixed number of days for CCTV retention — the Nigeria Data Protection Act, 2023 (NDPA) instead requires you to keep footage no longer than is necessary for its purpose (Section 24(1)(d)), and the NDPC's 2025 implementation directive (GAID) adds an outer limit: where no law sets a time limit, storage must end no later than six calendar months after the original purpose has been accomplished (Article 49(3)). Within that, you choose the number, write down why, and must be able to justify it to the Nigeria Data Protection Commission (NDPC) or a court. Footage tied to an active incident, dispute or investigation is held separately, for as long as that matter needs it.

This article is general information, not legal advice.

If you run a retail outlet in Lekki, a bank branch in Kano, a factory floor in Aba, or a serviced office in Abuja, you probably have a DVR or NVR quietly filling up with footage right now, retaining everything until the disk is full and then overwriting the oldest files — with nobody able to say why that number was chosen, or whether it's still the right one. That's the exact gap the NDPA was written to close, and it's now a live compliance risk, not a theoretical one.

CCTV footage that captures identifiable people — faces, number plates, gait, badge-linked movement — is personal data under the Nigeria Data Protection Act, 2023. Section 24 of the Act sets out the core processing principles that apply to that footage, including two that matter most for retention:

  • Purpose limitation — you must collect and process the footage for a specific, explicit, lawful purpose (e.g., "loss prevention on the sales floor" or "perimeter security"), not a vague "just in case."
  • Storage limitation: under Section 24(1)(d), personal data, including video, must be "retained for not longer than is necessary to achieve the lawful bases for which the personal data was collected or further processed".

On 20 March 2025 the NDPC issued the General Application and Implementation Directive (GAID) 2025, which took effect on 19 September 2025; under its Article 3(3) the Commission no longer applies the old Nigeria Data Protection Regulation (NDPR) as a legal instrument. The GAID matters for retention in three ways:

  • A written retention policy is required. Schedule 1 of the GAID says a controller must have a clear data retention policy, consistent with relevant laws, and must communicate it to data subjects.
  • A default outer limit. Article 49(3) says that where no law sets a time limit, storage must lapse no later than six calendar months after the original purpose of the processing has been accomplished. Article 49(4) allows data to be kept, with appropriate safeguards, for the defence of a legal claim.
  • A mandatory DPIA for public-facing cameras. Article 28(3)(k) makes a Data Privacy Impact Assessment mandatory, and fileable with the Commission, for the deployment of surveillance cameras in places that may be accessed by members of the public, and Article 28(3)(c) does the same for systematic monitoring. So a shop entrance or banking hall camera is in scope, not only biometric access control or employee monitoring. The retention period you land on should be one of the DPIA's documented outputs, not an afterthought.

Data minimisation (Section 24(1)(c): data must be "adequate, relevant, and limited to the minimum necessary") points the same way for coverage: cameras should be aimed at what actually needs protecting, not blanket-covering an office because it's easier to configure that way.

Why "keep everything forever" is now a liability, not a safety net

The instinct to over-retain is understandable — storage is cheap, and footage feels like free insurance. But under the NDPA, holding identifiable footage past its justified purpose is itself a violation, independent of whether a breach ever happens. Three concrete reasons this now bites:

1. NDPC enforcement is real and public. In July 2025 the NDPC fined MultiChoice Nigeria ₦766.2 million over unlawful cross-border data transfers and privacy violations (DataGuidance). On 25 August 2025 it gave 1,368 organisations in banking, insurance, pensions and gaming 21 days to show evidence of compliance (Premium Times). Under Section 48 of the NDPA, the maximum penalty is the higher of ₦10 million or 2% of annual gross revenue for a data controller or processor of major importance, and the higher of ₦2 million or 2% for others.

2. Every extra week of footage is more data that could leak, be subpoenaed, or be mishandled. A breached NVR with a year of every employee's and visitor's face on it is a materially bigger incident, and a bigger fine exposure, than one holding a few weeks.

3. You still have to answer "why do you have this" for every subject access or deletion request. Under Section 34 of the NDPA, data subjects can request access to their personal data and its erasure, and a controller must erase data without undue delay once it is no longer necessary for its purpose (Section 34(2)). If you can't tie the retention period to a documented purpose, you have no defensible answer.

Setting a period you can actually defend

Neither the NDPA nor the GAID publishes a table of "CCTV = X days", and we found no NDPC or CBN rule that fixes a CCTV retention period. Instead, work backwards from the purpose the footage serves and document the reasoning. The ranges below are not legal requirements; they are a way of structuring the decision:

Use caseHow to set the periodReasoning
General perimeter / entrance monitoring (no incident)Short rolling overwrite, measured in weeks; you choose and record the numberLong enough for incidents to be reported and footage pulled; short enough to avoid building an archive of identifiable people
Retail till/POS area, cash handlingTie it to how long your reconciliation and dispute processes actually takeIf disputes are always raised within a known window, that window justifies the period
ATM/banking hall footageCheck your sector regulator's and your bank's own requirements firstCard and fraud dispute timelines may justify a longer period; we found no public CBN rule fixing a number
Workplace/employee monitoringSet in the DPIAThe GAID makes a DPIA mandatory for systematic monitoring
Footage relevant to an ongoing incident, HR case or police reportRetained (segregated) until the matter is resolved, then a defined post-closure periodPurpose limitation still applies: hold that footage, not the whole archive
Footage relevant to a potential or actual civil claimRetained for the defence of the claim, with safeguards (GAID Article 49(4))Take legal advice on the relevant limitation period, which varies by type of claim and by state

Whatever you choose for routine footage, GAID Article 49(3) is the backstop: where no law sets a time limit, storage must end no later than six calendar months after the purpose has been accomplished.

The pattern to notice: routine footage should default to a short window, and only footage genuinely tied to an active purpose — an investigation, a legal claim, a flagged incident — gets carved out and held longer, on its own clock. Bulk-extending retention "because something might come up" is the opposite of what the NDPA asks for.

Building this into your actual systems

A retention policy on paper is not the same as a retention period your NVR actually enforces. In practice, defensible CCTV compliance in Nigeria means:

  • A DPIA filed with the NDPC for any camera covering a place the public can access and for any systematic monitoring (GAID Article 28(3)), vetted by a DPO certified by the Commission and naming the purpose, the retention period and who can access footage.
  • Automated overwrite/deletion configured on the recorder or storage platform, not a manual "someone will clear it eventually" process — auto-enforcement is what actually proves the policy is real.
  • A segregation workflow so that footage relevant to an incident, HR matter, or legal hold is pulled out of the routine deletion cycle before it expires, and tracked separately with its own retention clock.
  • Access logging — who viewed or exported footage, and why — since the NDPA's accountability principle expects you to show controls, not just a policy document.
  • A documented basis for third-party access requests (police, insurers, opposing counsel) before footage is handed over, since disclosure is itself a processing activity under the Act.

This control layer is easy to describe and fiddly to implement correctly across DVR firmware, cloud storage and access logs that were never designed with a data protection statute in mind. If you're formalising a broader data protection and security posture (not just cameras, but client records, HR files and transaction logs), our data protection page explains how Wise Hustlers applies the same purpose-limitation and retention logic across a system.

FAQ

Does Nigerian law require a specific number of days for CCTV retention?

No. The NDPA sets a principle (retain no longer than necessary for a stated purpose) rather than a fixed number, and the GAID adds an outer limit of six calendar months after the purpose has been accomplished where no other law sets one (Article 49(3)). Some sectors (e.g., banking) may have supervisory expectations of their own, so confirm with your regulator or compliance team if you're in a regulated industry.

Do I need a DPIA just to run a shop-entrance camera?

If the camera covers a place members of the public can access, yes. Article 28(3)(k) of the GAID makes a DPIA mandatory, and fileable with the NDPC, for "deployment of surveillance cameras in places that may be accessed by members of the public", which a shop entrance is. For a small single-camera setup the DPIA can be short, but it should exist.

What happens if footage relevant to a police investigation would normally be deleted under our policy?

Segregate it. Pull the specific clips relevant to the matter out of the routine deletion cycle and retain them under a separate, documented legal-hold basis until the investigation or case concludes — don't extend the retention period for your entire camera estate to cover one incident.

Can customers or employees ask us to delete footage of themselves?

Yes. Section 34 of the NDPA gives data subjects rights of access and erasure, and a right to have processing restricted while a request or a legal claim is being resolved. An active investigation or legal claim can be a valid reason to keep specific footage for longer, but record why. Have a documented process for handling these requests rather than deciding case by case.

Sources

Related articles