# NDPA 2023 and CCTV: What Nigerian Businesses Must Do Before Installing Cameras
TL;DR: If your cameras can identify a person — staff, customer, or passerby — the footage is personal data under the Nigeria Data Protection Act 2023, and you need a documented lawful basis and visible notice. If the cameras cover any place the public can enter, the NDPC's 2025 implementation directive (GAID) makes a Data Privacy Impact Assessment mandatory and requires it to be filed with the Commission before you switch the system on.
This article is general information, not legal advice.
CCTV footage is personal data, not just "security video"
A lot of Nigerian business owners still think of CCTV as a physical-security purchase — cameras, a DVR, a technician to wire it up — with no legal paperwork attached. That assumption is wrong under the Nigeria Data Protection Act 2023 (NDPA), which was signed into law on 12 June 2023 and now sits above the older NDPR 2019 regime (the NDPC stopped applying the NDPR as a legal instrument when it issued the GAID in 2025). Section 65 of the NDPA defines personal data as any information relating to an individual who can be identified directly or indirectly, and a camera recording a recognisable face, gait, number plate, or badge easily meets that bar. The Nigeria Data Protection Commission (NDPC), the regulator created by the Act, names surveillance cameras explicitly in its implementation directive (see the DPIA section below), so camera footage is subject to the same lawful-basis, transparency and accountability rules as a customer database or an HR system.
This matters for retail shops in Lagos and Port Harcourt installing cameras against theft, estate management companies covering gates and lobbies, banks and fintechs monitoring branches and agent locations, schools watching entrances, and manufacturing or logistics firms tracking warehouses. All of them are now "data controllers" the moment the camera starts recording identifiable people.
On 20 March 2025, the NDPC issued the General Application and Implementation Directive (GAID), which took effect on 19 September 2025. It is a detailed operational rulebook for how the NDPA's principles apply in practice, including lawful-basis documentation and impact assessments that are directly relevant to CCTV deployments.
Pick a lawful basis before you buy the cameras
Section 25 of the NDPA and Article 16 of the GAID set out the lawful bases a controller can rely on, and the GAID makes the controller responsible for assessing and choosing one before processing starts: consent, contractual necessity, legal obligation, protection of vital interest, public interest, or legitimate interest. For ordinary security CCTV, legitimate interest is almost always the workable basis — you don't need everyone who walks past your shopfront to sign a consent form, and consent is a poor fit for surveillance anyway (it can't be freely given by an employee under an implicit threat of discipline, and it can't realistically be collected from a customer walking through a door).
But "legitimate interest" is not a blank cheque. Article 26 of the GAID makes a Legitimate Interest Assessment (LIA) mandatory before processing that relies on legitimate interest, and says a compliance audit will ask you to justify that choice. The template in Schedule 8 of the GAID walks through three tests:
1. Purpose test — what specific problem does the camera solve (theft, safety, access control)?
2. Necessity test — is CCTV actually needed for that purpose, and is the coverage proportionate (e.g., not filming a public street or a neighbour's compound when your entrance would suffice)?
3. Balancing test — does the business's interest in recording outweigh the privacy interest of employees, customers, and bystanders who didn't choose to be filmed?
If you can't write a coherent answer to all three, you don't have a defensible lawful basis yet — and "everyone else has cameras" is not one of the six options in Section 25 of the NDPA.
Signage, notice, and the employee question
Transparency is a standalone obligation, separate from picking a lawful basis. Before recording starts, people entering a monitored space need to know:
- That CCTV is in operation (visible signage at entrances, not just a note in a manual nobody reads).
- Who operates it and how to contact them.
- The purpose of the monitoring (security, not "monitoring your break times" if that's not what the sign says).
- The lawful basis relied on, and how long footage is kept.
This is not just good practice: Section 27 of the NDPA requires a controller to tell people, before collecting their data, who it is, the lawful basis and purpose, the recipients, their rights, the retention period and their right to complain to the NDPC, and Article 27 of the GAID says this information must be given in a form people can actually understand.
For staff specifically, this gets sharper. The same notice duty applies to employees, so they should be told in advance what is being monitored, why, and on what legal basis, rather than a justification being written after footage has been used to discipline someone. Cameras pointed at desks, till points, or break areas need to be in the employee handbook or a surveillance policy that staff have actually seen, not just a sign at the front door. Employees also have a right to request access to footage in which they appear, like any other data subject access request under Section 34 of the Act.
When a DPIA is mandatory, and why facial recognition raises the bar again
Section 28 of the NDPA requires a Data Privacy Impact Assessment (DPIA) before processing that is likely to result in high risk to individuals' rights. The GAID turns that into a concrete list. Under Article 28(3), a DPIA is mandatory and must be filed with the NDPC for, among other things, systematic monitoring, processing that involves sensitive personal data, and the deployment of surveillance cameras in places that may be accessed by members of the public. The DPIA must be vetted by a DPO certified by the Commission (Article 28(4)) and, where required, submitted before processing starts (Article 28(9)). So a shop, bank hall or estate gate camera that the public walks past is in scope, not only sophisticated systems.
Facial recognition, automated number-plate recognition and biometric access control (fingerprint or face-based door entry) go further. Biometric data processed to uniquely identify a person is sensitive personal data under Section 65 of the NDPA, and Section 30 only allows sensitive data to be processed on one of a closed list of grounds, such as consent or obligations under employment law. Legitimate interest is not on that list, and Article 18 of the GAID lists the processing of sensitive personal data among the activities that require consent. Before you deploy facial-recognition-enabled cameras or a face or fingerprint attendance system, you need the DPIA to cover what is collected, why, the risks (misidentification, function creep, breach exposure) and the controls, plus a documented Section 30 ground for the biometric processing itself. If your integrator is proposing a facial-recognition upsell alongside a standard CCTV install, that's the moment to loop in whoever owns compliance, not after go-live.
Are you a "data controller of major importance"?
Separately from the CCTV-specific questions, the NDPA created a category of Data Controllers and Processors of Major Importance (DCPMI) that must register with the NDPC under Section 44. The NDPC's Guidance Notice on registration, now reproduced as Schedule 7 of the GAID, designates an organisation that keeps a filing system as being of major importance if it processes the personal data of more than 200 data subjects in six months, or operates in listed sectors such as finance, health, education, hospitality and e-commerce. It then sorts them into three tiers: Ordinary High Level (over 200 data subjects), Extra-High Level (over 1,000) and Ultra-High Level (over 5,000, plus named sectors such as commercial banks, telecoms and fintechs). The first registration window closed on 31 October 2024 after two extensions from the original 30 June 2024 deadline; organisations that meet the threshold later must register on becoming a DCPMI. A business with CCTV across several branches, plus a customer or HR database, will often cross the 200-person line on those records alone.
Section 48 of the NDPA caps the penalty or remedial fee the NDPC can impose:
| Category | Maximum penalty (NDPA s.48) |
|---|---|
| Data controllers/processors of major importance | ₦10,000,000 or 2% of prior-year annual gross revenue, whichever is higher |
| Other data controllers/processors | ₦2,000,000 or 2% of prior-year annual gross revenue, whichever is higher |
The NDPC has shown it will use these powers. In July 2025 it fined MultiChoice Nigeria ₦766.2 million over privacy violations and unlawful cross-border transfers (Nairametrics). On 25 August 2025 it published a notice giving 1,368 organisations in banking, insurance, pensions and gaming 21 days to show evidence of compliance (Premium Times). (The separate $220 million penalty on Meta and WhatsApp, upheld by a tribunal in April 2025, was imposed by the competition regulator FCCPC after a joint investigation with the NDPC.) Enforcement is moving from "capacity building" toward active audits, and video surveillance — being one of the most visible, easy-to-inspect forms of processing — is a natural early check for an investigator walking into your premises.
A practical pre-installation checklist
Before the installer arrives, a Nigerian business should be able to check off:
- Lawful basis documented (an LIA on file if relying on legitimate interest).
- Purpose defined and coverage scoped — cameras aimed at what you actually need to protect, not blanket coverage of public areas.
- Signage drafted for every monitored entrance, stating purpose, operator, and contact details.
- Employee policy updated if any camera covers a workspace, break area, or entrance staff use daily.
- Retention period set: footage isn't kept indefinitely "just in case". Section 24(1)(d) of the NDPA limits retention to what is necessary for the purpose, and Article 49(3) of the GAID says that where no law sets a time limit, storage must end no later than six calendar months after the original purpose has been accomplished. The law sets no fixed number of days for CCTV, so choose one, write down why, and configure the recorder to enforce it.
- DPIA completed, vetted by a certified DPO and filed with the NDPC if any camera covers a place the public can access, and in every case where facial recognition, number-plate recognition or biometric access is involved.
- DCPMI status assessed — and registered with the NDPC if the threshold is met.
- Access-request process ready — a way to locate and provide footage if someone exercises their access right.
For businesses without an in-house data protection lead, the risk is that the cameras go in, work fine technically, and the paperwork never gets written until an audit, a labour dispute or a breach forces the question. Our data protection page sets out how Wise Hustlers approaches the technical side (access control, encryption, retention enforcement and logging) of systems that have to meet NDPA requirements like these. For the legal documents themselves, work with a licensed Data Protection Compliance Organisation or a Nigerian lawyer.
FAQ
Does a small shop with two CCTV cameras really need to worry about NDPA?
Yes. The NDPA doesn't exempt businesses by size from basic obligations like having a lawful basis and giving notice, and if the cameras cover an area the public can enter, the GAID's mandatory DPIA list applies too. Registration depends on volume and sector (more than 200 data subjects in six months is the entry threshold), but "we're small" isn't a defence against the core requirement to process personal data lawfully and transparently.
Can we rely on legitimate interest for all our CCTV, or do we need consent?
Legitimate interest is the normal basis for security CCTV — consent is impractical for footage of the general public and legally shaky for employees. What you need instead of consent is a documented Legitimate Interest Assessment (mandatory under GAID Article 26) showing the purpose is real, the coverage is necessary, and it doesn't disproportionately intrude on people's privacy.
Does using facial recognition instead of plain recording change anything?
Yes. Biometric data used to identify people is sensitive personal data under the NDPA, so you need one of the Section 30 grounds (in practice usually consent), and the GAID makes a DPIA filed with the NDPC mandatory whenever sensitive data is processed.
What happens if we just don't register or document anything?
The NDPC can impose fines up to ₦10,000,000 or 2% of annual gross revenue (whichever is higher) for controllers of major importance, and ₦2,000,000 or 2% for others. Given the NDPC's 2025 enforcement activity (a compliance notice naming 1,368 organisations and a ₦766.2 million fine against MultiChoice), "we'll deal with it if asked" is a materially riskier bet than it was in 2023.
Sources
- Nigeria Data Protection Act, 2023 – Nigeria Data Protection Commission
- NDP Act General Application and Implementation Directive (GAID) 2025, NDPC (Articles 16, 18, 26, 27, 28; Schedules 7 and 8)
- NDPC-GAID Takes Effect on 19 September — Aluko & Oyebode
- NDPC Extends Deadline for Registration of DCPMIs — Mondaq
- NDPC fines Multichoice Nigeria N766.2 million — Nairametrics
- NDPC issues compliance notices to banks, insurers, pension and gaming firms — Premium Times
- Tribunal Upholds FCCPC's $220 Million fine Against Meta/WhatsApp — FCCPC
- Nigeria's New Data Protection Act, Explained - Future of Privacy Forum