Skip to content
Quiet legal library with an open book, brass lamp and leather-bound volumes

Insights | 24 August 2026

NDPC Registration for Data Processors of Major Importance: What Nigerian Businesses Should Know

What the Federal High Court’s decision on NDPC registration means for POS operators and other businesses processing personal data.

Schedule a Consultation

By Lummina Law Firm

24 August 2026

Practical perspective for the decisions ahead.

EMMANUEL HARUNNA v. NDPC Suit No. FHC/L/CS/1116/2024

On 28 July 2026, the Federal High Court, Lagos, dismissed a challenge to the authority of the Nigeria Data Protection Commission (NDPC) to require certain entities to register as: Data Controllers or Processors of Major Importance (DCPMIs). The case specifically concerned POS operators and similar entities.

WHAT WAS CHALLENGED?

The applicant challenged the NDPC's authority to require POS agents and similar operators to register as DCPMIs. The argument was essentially that these operators did not fall within the category of entities that could be subjected to the registration requirement. The Court disagreed.

WHAT DID THE COURT DECIDE?

The Court upheld the NDPC's regulatory authority. It recognised registration as a legitimate mechanism for:

  • Accountability
  • Transparency
  • Responsible data governance
  • Regulatory oversight

The Court further found that the registration framework serves to protect—not undermine— the privacy rights guaranteed by the Constitution.

WHY DOES THIS MATTER?

The judgment sends a clear message:

DATA PROTECTION COMPLIANCE IS NOT JUST A BIG-CORPORATE ISSUE.

Businesses that process personal data may come within the NDPC's regulatory framework regardless of how traditional or small their business model appears. POS operators are only one example.

The real question is: What personal data does your business process, and what regulatory obligations arise from that processing?

WHAT IS A DCPMI?

A Data Controller or Processor of Major Importance (DCPMI) is an organisation that falls within the applicable statutory and regulatory criteria because of the nature, scale or circumstances of its personal-data processing. The designation carries additional compliance obligations. Being a small business does not automatically mean being outside the framework.

WHAT SHOULD YOUR BUSINESS CHECK?

RUN A DATA COMPLIANCE AUDIT

Review your: NDPC registration status Data-processing activities Privacy notices Lawful basis for processing Data security measures Data retention practices Third-party processor agreements Data-subject rights procedures Incident and breach response mechanisms

THE REGULATORY MESSAGE

Following the judgment, the NDPC directed unregistered DCPMIs to register and warned of the legal consequences of non-compliance.

The practical lesson is straightforward:

DO NOT WAIT FOR ENFORCEMENT TO DISCOVER YOUR OBLIGATIONS.

Determine your status. Assess your exposure. Close your compliance gaps.

THE BUSINESS RISK

Non-compliance can expose a business to: Regulatory action Financial penalties Operational disruption Reputational damage Potential legal proceedings For businesses that rely heavily on customer or transaction data, a weak data-governance framework can become a significant commercial risk.

THE TAKEAWAY — THE NDPC'S REGULATORY AUTHORITY HAS RECEIVED JUDICIAL AFFIRMATION.

The question for businesses is no longer: “Will the NDPC regulate businesses like ours?”

The better question is: “Are we prepared for the obligations that apply to us?”

CHECK YOUR COMPLIANCE BEFORE THE REGULATOR DOES.

Build with clarity

A legal partner for every stage of growth.

Whether you are building, investing, evolving or protecting what matters, Lummina provides clear, commercially intelligent guidance for what comes next.

Schedule a Consultation