The Nigeria Data Protection Commission (NDPC) has issued a Guidance Notice providing further clarity on the obligation of data controllers and data processors to train employees on data privacy and protection in accordance with the Nigeria Data Protection Act (NDPA) and in line with Schedule 3 to the Nigeria Data protection Act General Application and Implementation Directive (GAID) 2025.

The Guidance is intended to ensure Continuous Professional Development (CPD) for Data Protection Officers (DPOs) and ensure that, the skills and knowledge needed to keep pace with evolving privacy laws, technologies, and regulatory expectations are attained.

In this light, Article 30(1) of the GAID requires organisations to develop and implement an internal schedule for data protection awareness and training, while Article 46(3) mandates the periodic training of employees and contractors to keep them informed of emerging developments in data processing.

  • Mandatory learning process : Certified DPOs are expected to undertake ongoing learning and skills development to remain abreast with evolving data protection laws, technologies, and best practices.
  • CPD credit framework: The Guidance requires DPOs to obtain CPD credits through recognized professional development activities to demonstrate continuous competence.
  • Engagement in eligible activities: These included courses offered through the NDPC’s Virtual Privacy Academy (VPA), NDPC-approved training programmes, conferences, workshops, seminars, research, publications, and other approved professional events. 
  • Enhancement of Professional Standards : The framework reinforces the need for DPOs to continuously enhance their expertise in legal developments, cybersecurity, governance, and emerging privacy risks to effectively fulfill their responsibilities.

The Guidance underscores the NDPC’s commitment to strengthening and professionalizing Nigeria’s data protection ecosystem. Organizations that appoint Data Protection Officers (DPOs) should ensure they maintain the knowledge and competencies expected by the Commission, supporting compliance with the Nigeria Data Protection Act 2023 and enhancing organizational privacy governance.

For DPOs, implementation of the Guidance Notice makes clear that professional competence is an ongoing regulatory obligation rather than a one-time certification requirement. To support this, the NDPC has expanded its DPO training and certification programs to help develop and sustain a highly qualified community of privacy professionals across Nigeria.

Leave a Reply

Your email address will not be published. Required fields are marked *