National Assembly seeksstronger data protection laws amid rising cyber threats

2 months ago 26
ARTICLE AD BOX

The National Assembly has begun reviewing the National Data Protection Act (2023) as Nigeria confronts a surge in cyber threats, heightened concerns over digital privacy, and rapid advances in technologies such as artificial intelligence.

Senator Afolabi Salisu (APC, Ogun), chairman of the Senate Committee on ICT and Cyber Security, announced the initiative in Abuja on Tuesday during the launch of a three‑day Data Protection Awareness Workshop for members of the Joint National Assembly Committee on ICT.

The workshop is being run by the Nigeria Data Protection Commission in partnership with Ampersand Development Partners.

Salisu said the review is warranted by emerging global realities, including AI advancements, increasing cross‑border cyber threats, and new international instruments such as the United Nations Convention on Cybercrime.

“There is a nexus between data governance and cybercrime, hence the need to review the Act and strengthen it where necessary to protect our national interest,” he said.

The senator noted that cybercrime has become more sophisticated worldwide, with perpetrators exploiting AI tools, digital platforms, and weak data‑governance frameworks to target individuals, businesses and governments.

In recent years Nigeria has experienced a steady rise in cyber‑related offenses, ranging from identity theft and financial fraud to ransomware attacks, data breaches and digital espionage. Financial institutions, telecom operators, government agencies and private citizens have all been targeted.

There is growing concern about the misuse of personal data by digital platforms, mobile applications and online service providers, many of which collect users’ information without adequate safeguards or consent mechanisms.

Security experts repeatedly warn that Nigeria’s expanding digital economy and increasing internet penetration make the country more vulnerable to cyber threats unless regulatory systems are reinforced.

Salisu emphasized that lawmakers need a solid understanding of the digital ecosystem to legislate effectively in this sector.

“As legislators, we need to understand data privacy and protection. You cannot legislate in an area you are not sufficiently knowledgeable about,” he said.

He explained that the workshop will enable lawmakers to evaluate the implementation of the National Data Protection Act since its 2023 enactment and identify areas for improvement in line with global best practices.

The discussions are expected to produce a roadmap and timetable for amending the law.

The lawmaker also warned Nigerians about hidden risks linked to digital platforms and free online services.

He said many mobile applications, public Wi‑Fi networks and online platforms collect and process personal data, often without users fully understanding the consequences.

Speaking also at the event, Stanley Olajide (APC, Oyo), chairman of the House Committee on ICT and Cyber Security, described data as one of the most valuable assets in the modern global economy.

“Data is gold. Nigeria’s next prosperity will not be oil but data,” Olajide said.

He stressed the need for stronger legal and institutional frameworks to protect sensitive digital assets and ensure accountability for data breaches.

Olajide noted that developed countries already operate strict data‑governance systems designed to safeguard national interests, particularly in cloud storage, digital transactions and cross‑border information flows.

“Anything that resides in Nigeria and is generated here must be protected by our laws. That is why we must strengthen our legal frameworks,” he said.

Nigeria enacted the National Data Protection Act in 2023 to regulate personal data processing, safeguard privacy rights, and establish the Nigeria Data Protection Commission as the primary data‑protection regulator.

Nevertheless, stakeholders in technology and cybersecurity continue to call for stronger enforcement mechanisms, enhanced institutional capacity, and regular updates to the law to keep pace with emerging technologies and increasingly complex cyber threats.

Read more on this