NigeriaPolls
All articles
methodology

Running Survey Research Under the Nigeria Data Protection Act

Survey research sits squarely inside the Nigeria Data Protection Act 2023. The six obligations that matter to fieldwork, why political opinion counts as sensitive data, and the two traps specific to Nigeria.

NigeriaPolls Research Desk1 October 202613 min read

In short

The Nigeria Data Protection Act 2023 is the country's primary data protection law. It created the Nigeria Data Protection Commission, which succeeded the Nigeria Data Protection Bureau, and it sits above the earlier Nigeria Data Protection Regulation 2019 that NITDA issued. Survey research sits squarely inside its scope, because a respondent's phone number, their answers and often their location are all personal data.

The six obligations that matter most to anyone running fieldwork in Nigeria: establish a lawful basis before you collect anything, tell respondents clearly who you are and what happens to their data, collect only what the research actually needs, honour data-subject rights when they are exercised, protect the data and report a breach promptly, and be careful about moving the data out of the country.

Two things trip up research teams specifically. Consent to be surveyed is not consent to be marketed to, and treating a research panel as a marketing list is where the regulatory and reputational risk concentrates. And the Do Not Disturb regime run by the Nigerian Communications Commission is a separate obligation from data protection, with its own rules about unsolicited contact.

This is a practical summary for research practitioners, not legal advice. Anyone making compliance decisions should take advice on their specific circumstances.

What the law covers, and who it applies to

The Act applies to the processing of personal data, which is any information relating to an identifiable individual. In a survey that includes the obvious identifiers, the phone number or email you contacted them on, and the less obvious ones: the answers themselves, device information, and any geographic detail fine enough to single someone out.

Two roles matter.

A data controller decides why and how personal data is processed. The organisation commissioning or running the research is normally the controller.

A data processor processes data on the controller's behalf. A fieldwork subcontractor, a survey platform, a hosting provider or a transcription service is normally a processor, and the relationship needs to be governed by a written agreement.

The Act also recognises a category of data controllers and processors of major importance, defined by the scale or sensitivity of what they handle. Organisations in that category carry additional duties, including registration with the Commission, appointing a data protection officer and filing periodic compliance returns. Whether a particular research operation falls inside that category depends on its scale and the nature of the data, and it is a question worth settling early rather than assuming.

Lawful basis: the thing to settle first

You cannot process personal data without a lawful basis, and the basis has to be identified before collection, not reconstructed afterwards.

The Act recognises a set of bases broadly familiar from comparable regimes: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, a task in the public interest or exercise of official authority, and the legitimate interests of the controller where those are not overridden by the rights of the individual.

For survey research, consent is the usual and cleanest basis, because a respondent participates voluntarily and can be told exactly what is happening. Where consent is the basis, it has to be freely given, specific, informed and capable of being withdrawn, and you have to be able to show that you obtained it. A tick box with no record behind it is not evidence of consent.

Two practical points.

Consent must be recorded in a form you could produce on request. The useful standard is to store what the respondent was shown, not merely that they agreed. If the wording of your consent statement changes, the version shown to each respondent should be recoverable.

Legitimate interest is not a shortcut. It can be a valid basis for some processing, but it requires an assessment balancing your interest against the respondent's rights, and that assessment has to exist as a document rather than as an intention.

Sensitive personal data

Some categories carry heightened protection, including data revealing health, religious or political beliefs, ethnic origin, trade union membership and sexual life, and data concerning children.

This matters more in Nigerian research than it might appear, because political opinion and ethnicity are routinely collected in exactly the kind of study a pollster runs. A questionnaire that asks about voting intention and ethnic group is processing sensitive data, and the basis, the security measures and the retention period all need to reflect that. In practice it means explicit consent, a clear reason for collecting each sensitive field, and a willingness to drop a field that is merely interesting.

What you must tell respondents

Transparency is the obligation that research teams most often discharge badly, usually by compressing it into a sentence.

Before or at the point of collection, a respondent should be able to find out:

  • who the controller is, by name, and how to contact them
  • what the data will be used for
  • the lawful basis you are relying on
  • who else will receive it, including the client where the research is commissioned, and any processors
  • whether it will leave Nigeria, and under what protection
  • how long it will be kept
  • what rights they have and how to exercise them, including the right to withdraw consent and the right to complain to the Commission

None of this requires reading a legal notice down a phone line. The workable pattern is a short spoken or on-screen statement covering who is calling, what the survey is about, that participation is voluntary, that answers will be reported in aggregate, and where the full privacy notice can be read, with the full notice published and reachable.

One detail worth getting right: if a respondent asks who commissioned the research, you need a position on that which is both honest and agreed with the client in advance. "We cannot say" is a legitimate position in some commercial research and it should be a deliberate one, not an improvisation.

Collect less

Data minimisation is the principle with the biggest practical payoff, because the data you did not collect cannot leak, cannot be misused and does not need protecting.

Questions worth asking of every field in an instrument:

  • Does this answer a research question, or is it interesting?
  • Could a band do the work of an exact value? Age bracket rather than date of birth, income band rather than exact income, state or LGA rather than full address.
  • Do we need an identifier at all after fieldwork closes, or can the dataset be de-identified once quality checks are done?
  • How long does each field need to be kept, and who deletes it?

Pseudonymisation after quality control is the single most useful technical measure in survey research. Once back-checks are complete, separating the contact details from the responses, keeping them in different places under different access controls, reduces the consequence of almost every plausible failure.

Retention needs a stated period rather than a default of forever. An indefinitely retained respondent database is a growing liability and, where consent was the basis, an increasingly stale one.

Respondent rights

Respondents can exercise rights, and those requests arrive by whatever channel is easiest for them, which means a WhatsApp reply or a phone call rather than a formal letter. The rights broadly include access to their data, correction of inaccurate data, erasure in defined circumstances, restriction of processing, objection to processing, and portability.

What this requires operationally:

A route in that a respondent can actually find. A published email address that is monitored. A route that bounces is worse than none, because it converts a simple request into a complaint.

The ability to locate one person's records. If you cannot find every record relating to a given phone number across your systems, you cannot honour an access or erasure request. This is a data-architecture question that should be answered before the first request arrives, not during it.

Withdrawal of consent that actually works. If someone says stop calling, that has to propagate to every list they could be drawn from, including lists held by a fieldwork subcontractor.

Response within the statutory timeframe, with a record of what was asked and what was done.

Security and breach reporting

The Act requires appropriate technical and organisational measures, judged against the risk. For a research operation the measures that matter most are mundane: encryption in transit and at rest, access control so field staff see only their own assignments, named accounts rather than shared ones, logging, no respondent data on personal devices or in personal cloud accounts, and vetted subcontractors under written agreement.

On a breach, the obligation is to notify the Commission promptly, within 72 hours of becoming aware where the regime requires it, and to inform affected individuals where the risk to them is significant. Two preconditions make that achievable: a defined internal escalation path so whoever notices knows who to tell, and a log of processing activities detailed enough that you can establish what was actually exposed. Most organisations fail the second one, and that is what turns a contained incident into an unbounded disclosure.

Cross-border transfer

Research data frequently needs to move, to an international client, an offshore analytics team, or a cloud region outside Nigeria.

Transfers out of Nigeria require a legal footing, which may be an adequacy determination covering the destination, appropriate contractual safeguards, or one of the specific derogations the Act provides. In practice the things to establish before fieldwork begins are where the survey platform physically stores data, where the client will hold its copy, and whether your privacy notice told respondents this would happen. A notice that is silent on international transfer while the data sits in another jurisdiction is a straightforward transparency failure.

Where a dataset can be properly anonymised, so that no individual is identifiable and cannot be re-identified, it falls outside personal data and the transfer problem largely dissolves. That bar is higher than removing names, and aggregate tables generally clear it where individual-level records do not.

The two Nigeria-specific traps

Research consent is not marketing consent

This is the one that causes real damage.

A respondent who agrees to answer a survey has agreed to answer a survey. They have not agreed to receive product offers, to have their number passed to a client's sales team, or to be enrolled in a mailing list. Doing any of those on the strength of research consent is both a compliance problem and the fastest way to destroy a panel, because respondents who feel misled stop answering and tell other people to stop answering.

The professional standard in survey research, and the position any credible research house should hold, is a hard separation: research data is used for research, and any marketing use requires its own separate, explicit consent that the respondent could decline while still participating.

Do Not Disturb is a separate regime

The Do Not Disturb service operated under the Nigerian Communications Commission lets subscribers opt out of unsolicited messages and calls from particular categories. It is a telecommunications regulatory obligation, enforced separately from data protection, and the practical consequence is that compliance with the Act does not by itself make a contact programme lawful.

For a research operation that reaches respondents by phone or SMS, this means screening against the applicable opt-out registers, keeping your own internal suppression list and honouring it permanently, respecting reasonable contact hours, and identifying yourself at the start of every contact. An internal suppression list that is cleared when a new sample is loaded is not a suppression list.

A practical compliance checklist

  1. Lawful basis identified and documented for every processing activity, before collection.
  2. Privacy notice published, specific, and reachable from the point of contact.
  3. Consent statements recorded by version, so you can show what each respondent saw.
  4. Sensitive fields justified individually, with explicit consent and tighter handling.
  5. Minimisation applied field by field; bands instead of exact values wherever they suffice.
  6. Pseudonymisation at the point quality control completes.
  7. Stated retention periods, with deletion actually executed.
  8. A monitored route for rights requests, and the technical ability to find one person's records.
  9. Written agreements with every processor, including fieldwork subcontractors.
  10. Security basics: encryption, named accounts, least privilege, logging, no respondent data on personal devices.
  11. A breach escalation path and a processing log good enough to scope an incident.
  12. Transfer footing established and disclosed before any data leaves Nigeria.
  13. Hard separation between research use and marketing use.
  14. Opt-out screening and a permanent internal suppression list.
  15. Registration, data protection officer and compliance filings where the organisation falls within the major-importance category.

Related reading

Frequently asked questions

Does the Nigeria Data Protection Act apply to survey research?

Yes. The Act governs the processing of personal data, and survey research processes personal data at several points: the phone number or email used to reach a respondent, the answers they give, and often location or device information. Both the organisation commissioning the research and the organisation conducting it have obligations, usually as controller and processor respectively, and that relationship needs a written agreement.

What is the difference between the NDPA and the NDPR?

The Nigeria Data Protection Regulation 2019 was issued by NITDA and was the main instrument before primary legislation existed. The Nigeria Data Protection Act 2023 is an Act of the National Assembly and is now the primary law, and it established the Nigeria Data Protection Commission as the regulator, succeeding the Nigeria Data Protection Bureau. The Act sits above the earlier regulation, and compliance programmes built only against the 2019 regulation need to be reviewed against it.

What lawful basis should be used for a survey?

Consent is the usual and cleanest basis for survey research, because participation is voluntary and the respondent can be told exactly what will happen to their answers. Where consent is relied on it must be freely given, specific, informed, withdrawable, and demonstrable, which means recording what the respondent was shown rather than only that they agreed. Other bases exist, including legitimate interests, but legitimate interests requires a documented balancing assessment and is not a shortcut.

Is political opinion sensitive data under Nigerian law?

Data revealing political opinions falls within the categories carrying heightened protection, as does data on ethnic origin, religious belief and health. This matters directly to polling, where voting intention and ethnic group are standard fields. Collecting them calls for explicit consent, a clear reason for each field, tighter security and a defined retention period, and it is a good reason to drop any sensitive field that is merely interesting rather than necessary.

Can survey respondents be added to a marketing list?

Not on the strength of research consent. Agreeing to answer a survey is not agreeing to receive offers, to be contacted by a sales team, or to be added to a mailing list. Any marketing use needs its own separate and explicit consent that a respondent can decline while still taking part in the research. Beyond the compliance exposure, blurring the two is the quickest way to lose a panel, because respondents who feel misled stop answering.

How long must a breach be reported in?

Where the regime requires notification, the Commission should be informed promptly and within 72 hours of the organisation becoming aware of the breach, and affected individuals should be told where the risk to them is significant. Meeting that in practice depends on two things being in place beforehand: an internal escalation path so whoever notices knows who to tell, and a processing log detailed enough to establish what was actually exposed.

Can survey data be transferred outside Nigeria?

Yes, with a legal footing. That may be an adequacy determination covering the destination, appropriate contractual safeguards, or one of the derogations the Act provides. The practical requirements are to know where the survey platform and the client will physically hold the data, to establish the footing before fieldwork begins, and to have disclosed the transfer in the privacy notice. Properly anonymised data that cannot be re-identified falls outside personal data, and aggregate tables generally clear that bar where individual-level records do not.

Is Do Not Disturb part of data protection compliance?

No, it is a separate obligation. The Do Not Disturb service operates under the Nigerian Communications Commission and governs unsolicited calls and messages, enforced independently of the data protection regime. Complying with the Act does not by itself make a telephone or SMS contact programme lawful. A research operation contacting respondents by phone needs to screen against the applicable opt-out registers, maintain a permanent internal suppression list, keep to reasonable contact hours, and identify itself at the start of every contact.

Auto-generated from the source poll results. NigeriaPolls

Tags

#ndpa#data protection#compliance#survey methodology

Cite this article (CC BY 4.0)

NigeriaPolls Research Desk. (1 October 2026). "Running Survey Research Under the Nigeria Data Protection Act." NigeriaPolls. CC BY 4.0. https://nigeriapolls.com/blog/ndpa-compliance-survey-research

Free to share, remix, and republish with attribution. See terms.