A modelling agency is, among other things, a data processing operation. Before a model ever walks into a studio or appears on a runway, the agency has collected their full name, date of birth, nationality, residential address, passport details, physical measurements, bank account information, and a substantial archive of photographic images. During the course of the relationship, the agency processes health information, travel documents, visa applications, and detailed records of the model’s commercial activities and earnings. When it places the model internationally, it shares significant portions of this data with foreign booking agencies, clients, photographers, and casting directors.
Under the Nigeria Data Protection Act 2023, every organisation that collects and processes personal data in this way is a data controller with specific, enforceable obligations under Nigerian law. The Act came into force in June 2023 and is administered by the Nigeria Data Protection Commission, which has powers of investigation, audit, enforcement, and sanction. Non-compliance is not a theoretical risk. It is an active regulatory exposure that most Nigerian modelling agencies are currently carrying without being aware of it.
This article explains what the NDPA 2023 requires of a modelling agency specifically, identifies the most common compliance failures in the industry, and sets out a practical framework for achieving the basic compliance standard the Act demands.
WHAT THE NDPA 2023 ACTUALLY REQUIRES
The NDPA 2023 imposes obligations on any person or organisation that determines the purposes for which and the means by which personal data is processed. A modelling agency that decides to collect a model’s passport copy for visa applications, share the model’s photographs with an international booking agency for placement purposes, or retain a model’s bank account details for payment processing, is determining the purpose and means of processing and is therefore a data controller within the meaning of the Act.
As a data controller, a modelling agency is required to comply with the following core principles under the NDPA 2023. Personal data must be processed lawfully, fairly, and transparently. It must be collected only for specified, explicit, and legitimate purposes and not processed in any manner incompatible with those purposes. The data collected must be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. It must be accurate and kept up to date. It must not be retained for longer than is necessary for the purposes for which it was collected. And it must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
These principles translate into specific operational requirements. An agency must be able to identify and articulate its lawful basis for processing the personal data of each model it represents. It must obtain meaningful, informed consent from models where consent is the lawful basis relied upon. It must have a privacy policy or data protection notice that explains to models how their data is used. It must implement technical and organisational measures adequate to protect the data it holds. It must have a process for responding to models’ data subject rights requests. And it must have a data breach response procedure capable of meeting the NDPA 2023’s notification timelines.
THE FIVE MOST COMMON COMPLIANCE FAILURES
First: Processing personal data without a lawful basis
The NDPA 2023 requires that every instance of personal data processing has a lawful basis. For a modelling agency, the most relevant lawful bases are consent, contract performance, and legitimate interests. Collecting a model’s bank account details to process payments is justified by contract performance. Using a model’s photographs to pitch them to a booking agency is justified by contract performance and potentially by legitimate interests. Collecting health information requires explicit consent, given the sensitive nature of this category of data under the Act.
Most Nigerian modelling agency contracts do not identify a lawful basis for any of this processing. They simply collect the data. An agency that cannot identify the lawful basis for each category of data it processes is in breach of the Act’s most fundamental requirement.
Second: Inadequate consent
Where consent is the lawful basis relied upon, it must meet the NDPA 2023 standard for valid consent. It must be freely given, specific, informed, and unambiguous. A general consent buried in the boilerplate of a model agreement, stating that the model agrees to the agency using their data as required, does not meet this standard. Consent must be obtained for specific purposes, must be as easy to withdraw as to give, and must be separate from other terms of the agreement so that the model understands what they are consenting to.
An agency that relies on invalid consent as its lawful basis for processing has no lawful basis at all. This is a breach of the Act and, in a dispute with a model, it hands that model a regulatory compliance argument that sits alongside whatever commercial dispute they are pursuing.
Third: Sharing data with international booking agencies without adequate safeguards
When a Nigerian mother agency shares a model’s photographs, measurements, and personal details with a booking agency in Paris, London, or New York, it is transferring personal data outside Nigeria. The NDPA 2023 imposes specific conditions on international data transfers. The receiving country must offer an adequate level of data protection, or appropriate safeguards must be in place, such as contractual clauses that bind the receiving party to data protection standards equivalent to those required by the Act.
Most Nigerian mother agencies transfer model data internationally every day, with no consideration of whether the receiving country’s data protection framework is adequate and no contractual safeguards in place. This is a straightforward breach of the Act’s international transfer provisions.
Fourth: No mechanism for data subject rights
Under the NDPA 2023, a model has the right to access the personal data the agency holds about them, to request correction of inaccurate data, to request deletion of data that is no longer necessary, to restrict processing in certain circumstances, and to withdraw consent where consent is the lawful basis for processing. An agency that has no process for receiving and responding to these requests, no designated contact point, and no timeline for response is non-compliant with this aspect of the Act.
Fifth: No data breach response procedure
The NDPA 2023 requires that a data controller that experiences a personal data breach notify the Nigeria Data Protection Commission within seventy-two hours of becoming aware of the breach, where the breach is likely to result in a risk to the rights and freedoms of individuals. It also requires notification to the affected individuals where the breach is likely to result in a high risk to their rights and freedoms. An agency that has no procedure for detecting, assessing, and responding to data breaches cannot meet this obligation and is exposed to regulatory sanction if a breach occurs and is not reported in time.
The Law Applies to You From Day One
The NDPA 2023 does not have a grace period. A modelling agency comes under its provisions from the very first moment it collects or processes the personal data of anyone in Nigeria, whether that is through a physical audition form, a website registration portal, a WhatsApp submission, or a scouting conversation. The law applies regardless of whether the agency is incorporated in Nigeria or operating from outside the country, provided it is offering services to people in Nigeria or monitoring their behaviour in any way.
The categories of data that modelling agencies routinely handle sit at the more sensitive end of the spectrum. Visual data, including headshots, body measurement records, and video footage, is personal data. So are passport numbers, BVN details, and NIN. Financial information used to process model payments is personal data. Even a model’s home address or emergency contact is captured by the law. Agencies that have not taken stock of what they are holding, where it is stored, and who has access to it are already exposed.
How the NDPA 2023 Affects Your Daily Operations
The practical obligations under the Act are not abstract. They touch the way an agency operates every single day, and understanding where the pressure points are is the first step toward managing them properly.
Audition forms are the most immediate compliance touchpoint. Every form, whether a physical document handed to a model at a casting or a digital intake form on your website, must include a clear and plain-language consent clause before any data is submitted. The clause needs to tell the individual what their information will be used for, who it may be shared with, and how long it will be retained. Assuming that submitting a form constitutes consent is not sufficient under the Act.
Portfolio sharing is another area where agencies routinely and often unknowingly breach the law. You cannot send a model’s portfolio, contact information, or measurements to international clients or local casting directors without the model’s explicit prior permission for that specific purpose. This is not a formality. It is a legal requirement, and it applies whether the recipient is a brand in Lagos or an agency in Milan.
Where an agency works with anyone under the age of 18, the obligations are stricter still. Verified consent from a parent or legal guardian must be obtained before any data is collected, including photographs, measurements, and identity documents. This applies at audition stage, not just at the point of signing a contract. The protections around child data are among the most seriously enforced provisions of the Act, and agencies that work with young talent need clear internal processes to ensure compliance at every stage.
On storage, the standard the law expects is reasonable security. Cloud folders containing headshots, portfolios, and contracts must be password-protected or encrypted. Shared drives with open access, unprotected email attachments, and physical files left without proper controls all represent exposure. An agency that experiences a data breach and cannot demonstrate that appropriate safeguards were in place faces significant regulatory and reputational consequences.
Do You Need to Register with the NDPC?
All agencies are bound by the rules of the NDPA 2023, but formal registration with the Nigeria Data Protection Commission is determined by the volume of personal data an agency processes.
A smaller agency maintaining a modest roster and processing the data of fewer than 200 individuals within any six-month period is not required to formally register, but must still comply with all substantive obligations under the Act: proper consent, secure storage, lawful sharing, and accurate record-keeping.
Once an agency crosses the 200-person threshold within a six-month period, registration with the NDPC becomes mandatory. For most agencies that run regular castings, maintain an active talent database, or accept applications through a digital platform, this threshold will be reached faster than expected.
Agencies that process the personal data of between 1,000 and 5,000 individuals within a six-month period are classified as Data Controllers of Major Importance, a designation that carries a higher tier of obligation. Registration requirements are more extensive, a dedicated Data Protection Officer must be appointed, and annual data protection audits become compulsory. Any agency running large-scale open casting calls, nationwide pageants, or digital talent platforms will in all likelihood fall into this category and should take steps to understand what that classification requires.
The consequences of failing to register, or of operating at the wrong tier without knowing it, go beyond administrative inconvenience. The NDPC has meaningful enforcement powers, and penalties under the Act are substantial.
WHAT NEEDS TO BE IN THE MODEL CONTRACT
Beyond operational compliance measures, the model contract itself must address data protection adequately. The contract should contain an express data protection clause that identifies the lawful basis for processing each category of personal data collected from the model. It should specify the purposes for which the data will be used. It should address international transfers and the safeguards that will be applied. It should set out the model’s rights as a data subject and identify how those rights may be exercised. It should confirm the agency’s obligation to implement appropriate security measures. And it should address what happens to the model’s data on termination of the agreement, including the period for which data may be retained and the basis for any continued retention.
The data consent should be obtained separately from the main contract signature, in a form that meets the NDPA 2023 standard. The model should tick a consent box and sign separately, and the consent should clearly identify the specific purposes for which consent is given and confirm that it may be withdrawn at any time. This separation is important both for legal validity and as evidence of genuine informed consent if the question is ever raised in a regulatory or dispute context.
THE ENFORCEMENT LANDSCAPE
The Nigeria Data Protection Commission has investigative and enforcement powers under the NDPA 2023 that include the authority to conduct audits, issue compliance orders, and impose administrative fines. The Act provides for fines of up to two per cent of annual gross revenue or ten million Naira, whichever is greater, for specified breaches. For more serious violations, fines of up to four per cent of annual gross revenue or twenty million Naira may apply.
Non-compliance with the NDPA 2023 is not a theoretical risk. It is an active regulatory exposure that most Nigerian modelling agencies are currently carrying without being aware of it.
Beyond the financial penalties, a regulatory investigation by the NDPC creates reputational and operational disruption that is disproportionate to the cost of compliance. An agency that is publicly investigated for data protection failures, even if the investigation does not result in a fine, faces questions from models, international partners, and clients about its professional standards and its commitment to the welfare of the talent it represents.
A PRACTICAL COMPLIANCE FRAMEWORK
Achieving basic NDPA 2023 compliance does not require a large compliance infrastructure. For a modelling agency of the size typically operating in Nigeria, the following five steps represent the minimum adequate response to the Act’s requirements.
The first step is to register with the Nigeria Data Protection Commission as a data controller. Registration is a basic requirement of the Act and establishes the agency’s formal recognition as a data processing entity.
The second step is to conduct a data mapping exercise, identifying every category of personal data the agency collects, the purpose for which it is collected, the lawful basis for processing, who it is shared with, and how long it is retained. This exercise, which need not be technically complex, provides the foundation for all other compliance activities.
The third step is to update the model contract to include a compliant data protection clause and to revise the consent mechanism to meet the NDPA 2023 standard for valid, specific, informed, and freely given consent.
The fourth step is to implement basic technical and organisational security measures, including password protection for devices holding model data, restricted access to model files on a need-to-know basis, and a secure method for sharing model data with international partners.
The fifth step is to designate a data protection contact within the agency, even if this is simply the director herself in the early stages, with responsibility for receiving and responding to data subject rights requests and for implementing the data breach notification procedure.
CONCLUSION
The Nigeria Data Protection Act 2023 is not new legislation. It has been in force since June 2023 and its requirements apply to every Nigerian modelling agency that processes the personal data of models, staff, and clients. The question for agency directors is not whether the Act applies to them but whether they are complying with it and, if not, what it will cost them when the gap between their current practice and the Act’s requirements becomes visible to a regulator, a model in dispute, or an international partner conducting due diligence.
The cost of compliance is modest. The cost of a regulatory investigation, a data breach, or a model who uses data protection non-compliance as an argument in a commercial dispute is not. For an agency that is building an international business and a professional reputation simultaneously, compliance with the NDPA 2023 is not optional. It is part of the foundation on which that business and that reputation rest.
How We Can Help
At Cardinal Counsel, we specialise in fashion and modelling law. Whether you are a brand, an agency, or a model, we understand the industry you operate in and the legal issues that arise within it.
We advise on booking disputes, contract drafting and review, intellectual property protection, image rights, regulatory compliance, and dispute resolution. If something has gone wrong with a booking, an agreement, or a professional relationship, we can help you understand your position and your options.
For specialist fashion law advice, contact Cardinal Counsel at info@cardinalcounsel.co.
Email: info@cardinalcounsel.co
Phone: +234 (0) 90 5262 8465
Website: www.cardinalcounsel.co
About the Author
Bernice Ofunre Asein, Esq. is the Managing Partner of Cardinal Counsel (Barristers and Solicitors), a boutique commercial law firm specialising in fashion law, intellectual property, and creative economy transactions. She is the Founder and Executive Director of the Fashion Law Institute Africa and the author of Fashion Law in Africa (FLIAfrica Imprint, 2025). Cardinal Counsel advises modelling agencies, fashion brands, designers, and creative industry businesses on contract drafting, intellectual property protection, regulatory compliance, and dispute resolution.
