Where Nigeria's Genomic Data Should Live
Nigeria's data protection framework already answers the question of whether population genomic data can be processed abroad. The answer is more restrictive than most programmes are designed for, and it is better to build for it than around it.
Most conversations about health data sovereignty in Nigeria are conducted as though sovereignty were an aspiration. It is not. Since 2023 it has been a statutory framework with defined obligations, and since September 2025 it has had an operational directive attached to it. The question for anyone designing a national genomic programme is not whether Nigeria will one day regulate this. It is whether the architecture being drawn today already complies.
Genetic data is not ordinary personal data
The Nigeria Data Protection Act 2023 treats a defined set of categories as sensitive personal data, and genetic data sits inside it alongside biometric data, health status, race and ethnic origin. Sensitive personal data attracts heightened requirements for lawful processing.
This has a practical consequence that catches programmes late. A consent form that would be adequate for a customer database is not adequate for a genomic cohort. Nor is a lawful basis inherited from a broader research approval. Sensitive data processing needs its own basis, its own documentation, and its own risk assessment.
The GAID replaced the NDPR, and a lot of Nigerian paperwork has not caught up
On 20 March 2025 the Nigeria Data Protection Commission issued the General Application and Implementation Directive, which took effect after a six-month transition on 19 September 2025. The GAID is the operative administrative instrument implementing the Act, and on its application the Commission ceased to apply the 2019 Nigeria Data Protection Regulation.
That last point matters more than it sounds. A significant amount of Nigerian contractual boilerplate, including agreements drafted in 2026, still commits parties to comply with "the NDPR." Those clauses now point at an instrument that is no longer operative. It is a small drafting failure that signals a larger one: the compliance framework was copied rather than read.
The GAID's operative requirements for an organisation running a programme of this kind include registration as a data controller or processor of major importance, a data privacy impact assessment in defined high-risk circumstances, breach notification to the Commission within seventy-two hours, immediate notification of data subjects where a breach is likely to create high risk to their rights, data processing agreements with third parties reflecting the Act's obligations, and data protection by design.
Two details are worth isolating because they have staffing implications. A DPIA must be signed by a certified Data Protection Officer and filed with the Commission, following the template in the directive's schedules. And the GAID provides that a controller or processor deploying software to process sensitive personal data must carry out a DPIA and submit it to the Commission within four months. If you are building software that will touch genomic data, you need a certified DPO before you need most of your engineering team.
Part VIII is the part that decides your architecture
Sections 41 to 43 of the Act govern cross-border transfer. Section 41 prohibits a controller or processor from transferring personal data out of Nigeria unless the recipient is subject to a law, binding corporate rules, contractual clauses, code of conduct, or certification mechanism affording an adequate level of protection under the Act, or unless one of the conditions in section 43 applies. Controllers must record both the basis for the transfer and the adequacy of protection relied on.
Section 43 provides the alternative grounds, which include informed consent that has not been withdrawn, necessity for performance of a contract involving the data subject, the data subject's sole benefit where obtaining consent is not practicable, public interest, legal claims, and vital interests where the subject cannot consent.
Read that list against a population genomics programme and the difficulty becomes visible. Consent is available as a ground, but it is the weakest one to build a national infrastructure on, because it is withdrawable by definition. A programme whose lawful basis for offshore processing is participant consent has architected a system that a sufficient number of withdrawals can break.
The stronger position is not to rely on section 43 at all. It is to design so that the transfer does not occur.
Analysis without transfer is a solved problem
The instinct that domestic processing means rejecting international collaboration is wrong, and the standards community solved this a decade ago.
Federated analysis lets external researchers query and compute against data that never leaves its jurisdiction. Discovery happens through a standardised query interface. Authorisation is carried by the researcher rather than granted by copying the dataset. Computation is dispatched to the data instead of the data being shipped to the computation. Only reviewed, aggregated results leave the environment.
That model satisfies Part VIII by not engaging it, and it satisfies international collaborators because it is what they already use. The second article in this series covers the specific standards involved.
What the collapse of a Nigerian biobank actually demonstrated
The strongest argument for domestic infrastructure is not legal. It is a matter of public record.
A Nigerian genomics company built a biorepository containing samples and clinical data from roughly 130,000 West African participants. Its holding company was incorporated in the United States while its operations, assets and biobank were in Nigeria. After the founder's departure in 2022, control passed to investors through the offshore structure. By late 2023 the company was seeking buyers for the repository. Reporting on the subsequent dispute described the genomic data of 100,000 Nigerians offered at three million dollars, against a peak company valuation of a hundred and seventy million. In 2025 a Federal High Court in Lagos granted an injunction preventing the sale pending resolution.
Set aside the specific allegations, which remain before a court. The structural lesson stands on its own. When the entity that controls health data is constituted under foreign law, the data becomes an asset on a foreign balance sheet, subject to foreign insolvency processes and foreign investor priorities. Nigerian participants who consented to research had no mechanism in that structure. What eventually protected them was a court order, obtained late, in litigation they were not party to.
Consent forms do not survive a liquidation. Corporate structure does.
The design conclusion
For any Nigerian programme handling population-scale genomic data, four things follow.
Data residency should be an architectural constraint set on day one, not a compliance question asked before launch. Cross-border access should be designed as federated query rather than transfer, so that Part VIII is never the load-bearing element. The controlling entity should be Nigerian, because jurisdiction over the operator is what jurisdiction over the data ultimately rests on. And a certified DPO with a filed DPIA should exist before the first sensitive record is processed, because the four-month clock in the GAID is shorter than most build timelines.
None of this is burdensome once it is designed in. All of it is very expensive to add later.
Contact