The Nigerian fashion industry has never been more digital. Brands are selling through e-commerce platforms, building customer databases, running targeted advertising campaigns on social media, managing supplier relationships through cloud-based systems, and collecting more personal data than at any point in the industry’s history. Most of that data collection happens quietly, in the background of everyday business operations, without the brand ever stopping to ask whether it is being handled lawfully.
That question matters more now than it ever has. The Nigeria Data Protection Act 2023 is in force, the Nigeria Data Protection Commission is active, and the consequences of non-compliance are no longer theoretical. For fashion businesses operating in Nigeria, data protection is not a technology problem to hand to an IT department. It is a legal obligation, and it sits squarely within the business.
What Personal Data Does a Fashion Brand Actually Hold?
The starting point for any fashion business is understanding the scope of what it collects. Most brands, when they think carefully about it, are holding far more personal data than they realise.
Customer data is the most obvious category: names, email addresses, phone numbers, delivery addresses, purchase histories, sizing information, payment details, and browsing behaviour on the brand’s website or app. This data is commercially valuable precisely because it enables personalisation and targeted marketing, but that commercial value comes with legal responsibility.
Beyond customers, fashion brands collect data from models and creative talent: photographs, body measurements, identity documents, and financial information for payments. They hold employee and contractor data. They manage supplier and vendor relationships that involve the personal details of individuals at those organisations. And where brands use influencers or brand ambassadors, they hold contractual and financial information about those individuals too.
Each of these categories is personal data under the NDPA 2023. Each carries obligations. And most fashion businesses have never mapped what they hold, where it is stored, or whether the people whose data they are holding ever gave meaningful consent for that specific use.
The Legal Framework: What the NDPA 2023 Requires
The Nigeria Data Protection Act 2023 replaced the earlier Nigeria Data Protection Regulation and significantly strengthened the obligations on businesses that collect or process personal data in Nigeria. It applies to any fashion brand incorporated in Nigeria, any brand outside Nigeria that sells to Nigerian customers or monitors their behaviour, and any platform or app with a Nigerian user base.
The core obligations are not complicated in principle, even if implementing them properly requires care.
You must have a lawful basis for collecting personal data. For most fashion brands, the most relevant bases are consent, the performance of a contract, and legitimate interests. Consent must be freely given, specific, and informed. Pre-ticked boxes, vague language buried in terms and conditions, and assumptions that a customer’s purchase implies consent to marketing are not sufficient.
You must be transparent about what you collect and why. This is where the privacy policy becomes essential, not as a formality but as a genuine communication to your customers about their rights and your practices.
You must keep data secure. The NDPA 2023 requires appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction. What counts as appropriate depends on the sensitivity of the data and the scale of the business, but the baseline expectation is that you have thought about security and implemented it deliberately.
You must respect data subject rights. Customers have the right to access the data you hold about them, to request corrections, to ask for deletion in certain circumstances, and to object to certain uses of their data. Fashion brands need to have processes in place to respond to these requests within the timeframes the law requires.
And if things go wrong, you must act quickly. A data breach that is likely to affect individuals must be reported to the Nigeria Data Protection Commission within 72 hours of the business becoming aware of it. Brands that discover a breach and say nothing face significantly greater regulatory consequences than those that report promptly and manage the situation transparently.
Where Nigerian Fashion Brands Are Most Exposed
Based on how the industry actually operates, there are several areas where Nigerian fashion brands consistently carry data protection risk without realising it.
E-commerce platforms that collect customer data without a compliant privacy policy, or with one that was drafted years ago and never updated, are operating on a weak legal foundation. Every transaction involves the collection of personal data, and every customer has rights over that data that the brand is obligated to respect.
Email marketing and SMS campaigns that rely on purchased lists, or on consent obtained through inadequate means, are a common source of regulatory exposure. Sending marketing communications to people who have not properly consented is a breach of the NDPA 2023, and it is one of the areas the NDPC has indicated it will prioritise in enforcement.
Working with models, photographers, and creative talent without proper data handling agreements means that sensitive personal and financial information is flowing through the business without adequate legal structure around it.
Using third-party platforms, including payment processors, logistics providers, and social media advertising tools, without understanding what those platforms do with your customers’ data creates shared liability that many brands have never considered.
And storing customer data indefinitely, without a retention policy that determines how long different categories of data are kept and when they are deleted, means that brands are holding data they no longer need and carrying the risk that comes with it.
Practical Steps for Fashion Brands
Getting data protection right does not require a complete overhaul of how a fashion business operates. It requires deliberate attention to a set of specific questions.
The first question is what data you actually hold and where it lives. A data mapping exercise, even a basic one, gives a business a clear picture of its exposure and the foundation for everything else.
The second question is whether you have a lawful basis for each category of data you collect and whether that basis is properly documented.
The third question is whether your privacy policy accurately reflects your current practices and meets the standard required by the NDPA 2023. If it was drafted before the Act came into force, or if it was copied from another website, the answer is almost certainly no.
The fourth question is whether your contracts with third parties, including suppliers, platforms, and service providers who access your customer data, include the data processing provisions the law requires.
And the fifth question is whether you have a breach response plan. Not because breaches are inevitable, but because the brands that respond well to breaches are the ones that thought about it before it happened.
How Cardinal Counsel Can Help
We advise Nigerian fashion brands, designers, e-commerce businesses, and creative professionals on data protection compliance under the NDPA 2023. Our work in this area covers data audits and mapping, privacy policy drafting and review, consent mechanism design, third-party data processing agreements, NDPC registration where required, and breach response advisory.
We understand the fashion industry and the specific ways in which data flows through it. We do not offer generic compliance checklists. We advise on the specific obligations that apply to your business, in language that makes sense for how you actually operate.
If your brand has not yet assessed its data protection position under the NDPA 2023, that assessment is the right place to start.
Written by Ladipo-Scott Sharon, Esq.
Email: info@cardinalcounsel.co
Phone: +234 (0) 90 5262 8465
Website: www.cardinalcounsel.co
Address: Suite D14, Adeniran Ogunsanya Mall, Inside Shoprite Complex, 87 Adeniran Ogunsanya Street, Surulere, Lagos, Nigeria.
Cardinal Counsel. Fashion Law. Done Properly.
