…Warns Of Risks To Digital Rights
THE CENTRE for Information Technology and Development (CITAD) has rejected a proposed amendment to the Nigeria Data Protection Act, 2023, which would require social media platforms, data controllers and data processors to establish and maintain physical offices in Nigeria, describing the measure as a threat to digital rights, innovation, competition and digital inclusion.
The organisation made its position known in a press statement signed by its Digital Rights Lead, Ali Sabo, in response to a bill sponsored by Senator Ned Munir Nwoko.
According to CITAD, while the objective of strengthening data protection, improving regulatory oversight and ensuring accountability is commendable, the proposed blanket requirement for all affected entities to maintain physical offices in Nigeria is excessive and could have far-reaching negative consequences for the country’s digital ecosystem.
The proposed legislation seeks to amend the Nigeria Data Protection Act, 2023, by making it mandatory for all data controllers, data processors and operators of social media platforms to establish physical offices within Nigeria.
It also proposes that any affected organisation that fails to maintain a physical office in the country for a continuous period of 30 days should be prohibited from operating in Nigeria.
CITAD argued that such a requirement would create unnecessary barriers for digital platforms and technology companies operating across borders, particularly smaller firms, start-ups, non-profit organisations, open-source projects and emerging digital platforms that may lack the financial resources to establish physical offices in Nigeria.
The organisation warned that the amendment could unintentionally strengthen the market dominance of large multinational technology companies while making it more difficult for smaller competitors and local innovators to thrive.
“It would create an uneven digital environment where only the largest corporations can afford to comply,” the organisation said, adding that such an outcome would undermine competition, innovation and the growth of home-grown digital solutions.
CITAD also faulted the proposed legislation for adopting what it described as a “one-size-fits-all” regulatory approach by imposing identical obligations on all data controllers, data processors and social media platform operators regardless of their size, operational scope, level of data processing or associated risks.
Instead, the organisation advocated a risk-based regulatory framework that would impose obligations proportionate to the level of risk posed by an organisation’s activities, particularly where such activities significantly affect the privacy and rights of Nigerians.
The digital rights organisation further noted that the existing Nigeria Data Protection Act already provides a comprehensive legal framework governing the processing of Nigerians’ personal data. Rather than introducing additional physical presence requirements, CITAD urged authorities to focus on strengthening the implementation and enforcement of existing provisions.
It also questioned the argument that physical offices are necessary for effective regulatory oversight and consumer protection, noting that technological advancements now make it possible for regulatory engagement, legal notices, complaint resolution and enforcement actions to be conducted efficiently through digital channels.
As an alternative, CITAD proposed that high-risk or large-scale foreign data controllers and processors should be required to appoint authorised representatives in Nigeria, maintain accessible communication channels for regulators, comply with lawful requests from Nigerian authorities and establish effective mechanisms for handling user complaints.
The organisation expressed concern that excessive regulatory obligations could discourage some global digital platforms and service providers from operating in Nigeria or lead them to restrict services available to Nigerian users.
According to CITAD, such an outcome would negatively affect millions of Nigerians, particularly young people, entrepreneurs, small businesses, civil society organisations and communities that rely on digital platforms for education, communication, advocacy and economic activities.
It therefore called on the National Assembly to undertake broad stakeholder consultations before proceeding with the amendment. It urged lawmakers to engage digital rights advocates, technology companies, data protection experts, consumer groups, civil society organisations, start-ups and other relevant stakeholders in developing a balanced regulatory framework.
CITAD further recommended strengthening the Nigeria Data Protection Commission, improving cross-border regulatory cooperation, establishing accessible digital channels for complaints and regulatory engagement, adopting risk-based compliance measures for high-impact data processing activities and enhancing enforcement of existing data protection obligations.
It maintained that Nigeria requires a regulatory environment capable of protecting citizens’ privacy and ensuring accountability without unnecessarily limiting access to digital services or stifling technological innovation.
It consequently urged Senator Nwoko and the National Assembly to reconsider the proposed blanket physical-office requirement and instead pursue policy measures that safeguard personal data while promoting digital rights, inclusion, innovation and fair competition within Nigeria’s growing digital economy.


