By Lummina Law Firm
24 August 2026
Practical perspective for the decisions ahead.
EMMANUEL HARUNNA v. NDPC Suit No. FHC/L/CS/1116/2024
On 28 July 2026, the Federal High Court, Lagos, dismissed a challenge to the authority of the Nigeria Data Protection Commission (NDPC) to require certain entities to register as: Data Controllers or Processors of Major Importance (DCPMIs). The case specifically concerned POS operators and similar entities.
WHAT WAS CHALLENGED?
The applicant challenged the NDPC's authority to require POS agents and similar operators to register as DCPMIs. The argument was essentially that these operators did not fall within the category of entities that could be subjected to the registration requirement. The Court disagreed.
WHAT DID THE COURT DECIDE?
The Court upheld the NDPC's regulatory authority. It recognised registration as a legitimate mechanism for:
- Accountability
- Transparency
- Responsible data governance
- Regulatory oversight
The Court further found that the registration framework serves to protect—not undermine— the privacy rights guaranteed by the Constitution.
WHY DOES THIS MATTER?
The judgment sends a clear message:
DATA PROTECTION COMPLIANCE IS NOT JUST A BIG-CORPORATE ISSUE.
Businesses that process personal data may come within the NDPC's regulatory framework regardless of how traditional or small their business model appears. POS operators are only one example.
The real question is: What personal data does your business process, and what regulatory obligations arise from that processing?
WHAT IS A DCPMI?
A Data Controller or Processor of Major Importance (DCPMI) is an organisation that falls within the applicable statutory and regulatory criteria because of the nature, scale or circumstances of its personal-data processing. The designation carries additional compliance obligations. Being a small business does not automatically mean being outside the framework.
WHAT SHOULD YOUR BUSINESS CHECK?
RUN A DATA COMPLIANCE AUDIT
Review your: NDPC registration status Data-processing activities Privacy notices Lawful basis for processing Data security measures Data retention practices Third-party processor agreements Data-subject rights procedures Incident and breach response mechanisms
THE REGULATORY MESSAGE
Following the judgment, the NDPC directed unregistered DCPMIs to register and warned of the legal consequences of non-compliance.
The practical lesson is straightforward:
DO NOT WAIT FOR ENFORCEMENT TO DISCOVER YOUR OBLIGATIONS.
Determine your status. Assess your exposure. Close your compliance gaps.
THE BUSINESS RISK
Non-compliance can expose a business to: Regulatory action Financial penalties Operational disruption Reputational damage Potential legal proceedings For businesses that rely heavily on customer or transaction data, a weak data-governance framework can become a significant commercial risk.
THE TAKEAWAY — THE NDPC'S REGULATORY AUTHORITY HAS RECEIVED JUDICIAL AFFIRMATION.
The question for businesses is no longer: “Will the NDPC regulate businesses like ours?”
The better question is: “Are we prepared for the obligations that apply to us?”
CHECK YOUR COMPLIANCE BEFORE THE REGULATOR DOES.



