This article is not legal advice. Sephora Systems builds AI hardware and private AI systems; we are not lawyers. What follows is a practical, conservative overview to help you ask the right questions of your legal and compliance advisers. Where we describe the law, we describe it in general terms, and you should check the current text of the Act and the latest guidance from the Nigeria Data Protection Commission before relying on it.
With that said, the question is a real one for Nigerian companies. Staff are putting company information, much of it personal data about clients, patients, employees and customers, into generative AI tools hosted abroad. The Nigeria Data Protection Act 2023 is the framework that governs that personal data. This piece explains how the two meet, and why many companies are choosing to keep sensitive AI workloads on hardware inside Nigeria. It is part of our series on why Nigerian companies need private AI.
The NDPA in brief
The Nigeria Data Protection Act was signed into law in June 2023. It established the Nigeria Data Protection Commission (NDPC) as the regulator and set out how personal data of people in Nigeria must be handled. In broad terms, it:
- Sets processing principles · Personal data must be processed lawfully, fairly and transparently, for specified purposes, limited to what is necessary, kept accurate, retained no longer than needed and kept secure.
- Requires a lawful basis · Such as consent, performance of a contract, a legal obligation, vital interests, public interest or legitimate interests.
- Gives data subjects rights · Including access, correction, deletion and objection in defined circumstances.
- Regulates cross-border transfers · Personal data may leave Nigeria only where specific conditions are met.
- Imposes accountability · Controllers must be able to show compliance, with extra obligations for data controllers and processors of major importance, such as registration with the Commission and appointing a data protection officer.
- Requires breach notification · Certain personal data breaches must be reported to the Commission within a short window, which the Act sets at 72 hours from awareness.
The Commission has also issued implementation guidance since the Act came into force, and that guidance continues to develop. Treat any summary, including this one, as a starting point.
Where generative AI meets the Act
When an employee pastes a client's details into a cloud AI tool, several things happen at once from a data protection point of view, whether or not anyone thinks of it that way.
1. It is processing
Summarising, analysing or rewriting personal data with an AI tool is processing. It needs a lawful basis and must fit the purpose for which the data was collected. A client who gave you their details to open an account did not obviously agree to have them analysed by a third-party chatbot.
2. A third party is involved
A cloud AI provider processing data on your behalf is acting as a processor. The Act expects controllers to use processors that provide adequate safeguards, typically set out in a contract. A business or enterprise agreement can do this. A personal account signed up with a Gmail address, outside any company agreement, generally cannot.
3. The data probably leaves Nigeria
Most major AI services process data in data centres outside Nigeria. Under the Act, transferring personal data abroad requires a recognised basis, for example the recipient being subject to an adequate level of protection through law, binding rules, contractual clauses or certification, or one of the specific exceptions the Act lists, such as informed consent. The company has to be able to show which basis applies.
4. Retention and deletion are outside your control
Chat histories on personal accounts persist until the individual deletes them. If a data subject asks you to delete their data, you cannot reach copies sitting in an ex-employee's personal AI history.
| NDPA consideration | Staff using personal cloud AI accounts | Approved cloud AI under a business agreement | Private AI on company hardware in Nigeria |
|---|---|---|---|
| Lawful basis and purpose | Hard to show; use is invisible to the company | Can be assessed and documented | Can be assessed and documented |
| Processor safeguards | No company contract | Covered by the vendor agreement, if reviewed | No external processor for the AI workload |
| Cross-border transfer | Likely occurs, with no documented basis | Likely occurs; basis must be documented | Data stays on premises in Nigeria |
| Retention and deletion | Controlled by the individual | Set by vendor terms and admin settings | Set by company policy on company hardware |
| Audit and access logs | None available to the company | Depends on the plan | Fully under company control |
The stakes are not trivial. The Act gives the Commission power to impose penalties, and for the largest organisations the ceiling scales with revenue:
| Category | Maximum penalty under the NDPA 2023 |
|---|---|
| Data controller or processor of major importance | The higher of ₦10,000,000 or 2% of annual gross revenue in the preceding financial year |
| Other data controllers and processors | A lower fixed figure or a percentage of revenue; confirm the current figure with your adviser |
Note what the table does and does not say. It does not say cloud AI is unlawful. An approved cloud tool under a properly reviewed business agreement, with the transfer basis documented, can be a perfectly defensible choice for many workloads. What the table shows is that personal accounts are the weak point, and that private AI removes two of the hardest questions, the processor relationship and the cross-border transfer, for the workloads you put on it.
Private AI does not switch the Act off
It is worth being clear about this, because it is a common misunderstanding. Running AI on your own server in Abuja or Lagos is still processing personal data. You still need:
- A lawful basis and clear purpose · Document which AI uses are permitted with which kinds of data.
- Access control · Staff log in with individual accounts, and document collections are restricted to the teams entitled to see them. An HR knowledge base should not be searchable by the whole company.
- Security · The server sits in a locked room or cabinet, disks are encrypted, the interface is reachable only on the office network or VPN, and software is kept updated.
- Retention rules · Decide how long chat histories are kept and configure automatic deletion. Open WebUI and similar tools let administrators manage this.
- Logging · Keep enough logs to investigate an incident, without turning the logs themselves into a new store of sensitive data.
- A data protection impact assessment where appropriate · Using AI on sensitive categories of data, such as health or financial records, is the kind of processing where an assessment is sensible and may be expected.
The difference is that every one of these is something your company can actually configure, verify and show to an auditor, because the system belongs to you.
A practical approach for Nigerian companies
- Classify your data · Public, internal, and confidential or personal. Most of the AI value and most of the risk sits in the third category.
- Route by class · Confidential and personal data goes only to private AI. Internal data may go to approved cloud tools under a business agreement. Public data can go anywhere approved.
- Close personal accounts for work use · State in policy that personal AI accounts must not be used with company data, and give staff a sanctioned alternative so the rule is realistic. Our article on shadow AI in Nigerian workplaces explains why the alternative matters more than the ban.
- Involve your DPO or adviser early · Especially if you are, or may be, a data controller of major importance.
- Document it · A short record of what AI systems you use, for what, with which data and on what basis, is the backbone of accountability.
Sectors with professional confidentiality on top of data protection, such as banking, law and healthcare, have additional considerations, which we cover in Private AI for Banks, Law Firms and Hospitals in Nigeria.
What keeping AI in Nigeria looks like technically
A private AI system is an on-site GPU server running open models, such as Llama, Qwen, Mistral or Gemma, through an engine like Ollama or vLLM, with a ChatGPT-style web interface such as Open WebUI served on your LAN. Optional retrieval over company documents lets staff chat with company files privately. The servers we build for this come from our AI Series, sized to your headcount, and are installed with UPS protection and inverter planning for Nigerian grid conditions.
For background on the privacy case for on-premise compute generally, see data privacy and on-premise AI training and on-premise AI compute versus cloud. To see how this fits into a staged rollout, read our 30-day private AI rollout plan.
The honest summary
The NDPA does not stop Nigerian companies using generative AI. It asks them to know what personal data they are processing, why, where it goes and who protects it. Personal AI accounts make those questions almost impossible to answer. A private AI server makes the most sensitive ones simple: the data is processed here, on hardware you own, under rules you set.
Sephora Systems designs, builds and installs private AI servers that keep sensitive data inside your building, from Abuja with nationwide delivery. We work alongside your legal and compliance advisers rather than replacing them. Book a private AI consultation, ask Kitan, our site assistant, or WhatsApp us on +234 707 096 6669.