NDPC Wins Landmark Court Victory Affirming Authority to Register PoS Agents as Data Controllers of Major Importance
Introduction
On July 27, 2026, the Federal High Court sitting in Lagos delivered a judgment that significantly strengthens the regulatory reach of the Nigeria Data Protection Commission (NDPC) over Nigeria's point-of-sale agent ecosystem. In Emmanuel Harunna v. Nigeria Data Protection Commission (Suit No. FHC/L/CS/1116/2024), Justice F.N. Ogazi dismissed a suit that sought to exempt PoS agents from mandatory registration as Data Controllers and Processors of Major Importance under the Nigeria Data Protection Act 2023. The applicant had asked the court for a declaration that PoS agents do not qualify as such entities, together with a perpetual injunction restraining the NDPC from compelling them to register.
The court disagreed on every count. Reduced to its essentials, the case turned on a single, consequential question: do the ubiquitous roadside operators who process withdrawals, deposits, and transfers for a fee qualify as "Data Controllers and Processors of Major Importance" under the NDPA? Harunna's answer was no; he asked the court to carve an entire category of grassroots financial intermediaries out of Nigeria's still-maturing data protection framework. Justice Ogazi's answer was an emphatic yes, and the reasoning she used to reach it is what makes this judgment worth analysing closely rather than simply noting as a Commission win.
The Decision of the Court
Justice Ogazi examined Sections 5(d), 6(c), 44, 45, and 65 of the NDPA alongside the Commission's Guidance Notice on Registration, and held that the Commission had acted squarely within its statutory mandate in designating PoS agents as falling within the Major Data Processing, Ordinary High Level category.
First, on classification, the court accepted that the NDPA empowers the Commission to designate as DCPMIs those entities that process significant volumes of personal data, and that PoS agents fall within that class by virtue of what passes through their terminals. The designation attaches to the Ordinary High Level tier of the DCPMI regime, the lowest of the three registration bands the Commission operates.
Under the framework introduced in 2024, DCPMIs are grouped into Ultra High Level, Extra High Level, and Ordinary High Level categories, with registration fees scaled to the nature and volume of processing. Placing PoS agents in the Ordinary High Level band matters: the court did not treat them as equivalent to banks or telecoms, but it did hold that they clear the threshold for inclusion in the net.
Second, on the constitutional challenge, the court held that mandatory registration does not infringe the right to privacy guaranteed by Section 37 of the 1999 Constitution. This is the pivot of the judgment, and the court's move here is worth stating plainly because it inverts the applicant's framing. Harunna advanced registration as a burden on privacy; Justice Ogazi held it to be a mechanism that protects privacy, by bringing high-volume processors under regulatory visibility so that the Commission can monitor how they handle the personal data flowing through their operations. Registration, on this reasoning, is not adverse to the constitutional right at all. It is one of the instruments through which the right is made effective. That reframing is what allows the Commission to argue, credibly, that widening the net serves data subjects rather than merely expanding the regulator's reach.
Third, on statutory supremacy, the court confirmed that Section 65 of the NDPA gives the Act primacy over any conflicting legislation on the processing of personal data. This holding travels well beyond PoS agents. It means that where any other statute or subsidiary instrument touching on personal data conflicts with the NDPA, the NDPA governs, a point of general application that advisers across regulated sectors should file away.
The Functional Test, and Why It Matters
The substantive holding worth isolating is the functional basis of the court's reasoning. The judgment ties DCPMI status to the volume and sensitivity of the data an entity processes, not to its corporate form, size, or sophistication. It means the test the NDPC and the courts are now applying looks past who a PoS agent is and asks only what data flows through their terminal. A roadside operator with a single device and no corporate structure is assessed on the same axis as a licensed institution: what personal data do they handle, in what quantity, and how sensitive is it?
This has implications the judgment does not spell out but that flow directly from its logic. If status turns on data processed rather than on who is doing the processing, then informality is not a defence. An operator cannot escape the regime by pointing to the absence of a company, a board, or a compliance department, because none of those features is what triggers designation in the first place. The functional test is, in that sense, precisely engineered to reach the population the Commission is trying to reach.
Harunna Against the Ijege Precedent
This case is worth reading alongside an earlier decision on the same Guidance Notice. In Frank Ijege v. Nigeria Data Protection Commission (Suit No. FHC/KD/CS/34/2024), decided by the Federal High Court in Kaduna on November 22, 2024, the applicant challenged the NDPC's original Guidance Notice on Registration directly, seeking a declaration that the Notice violated his right to privacy, an order clarifying its confusing provisions, and a finding that not all individuals or entities the Commission had swept into the DCPMI category actually belonged there.
The court granted nearly every relief sought, declaring paragraph 1(2) of the original Guidance Notice invalid, though it declined to grant an injunction halting registration altogether. In response, the NDPC issued an Updated Guidance Notice on the Registration of Data Controllers and Processors of Major Importance (NDPC/HQ/GN/.VOL.03/B/24), together with the NDPA 2023 General Application and Implementation Directive 2025, refining the instrument to address the concerns the Kaduna court had raised. That is the version of the Guidance Notice the Harunna case was decided under, and the Commission's willingness to revise its framework following Ijege reflects a regulator that has been responsive to judicial guidance as the DCPMI regime matures.
Read together, the two cases tell a coherent story about how the DCPMI registration framework has actually developed: not as a single settled rule, but as an administrative instrument that has already been successfully challenged once, revised in response, and is now being tested provision by provision as different categories of affected entities bring their own cases. Harunna is a win for the Commission on the specific question it raised, but the Commission's own conduct after Ijege, rewriting rather than defending the original Notice, is a useful signal that the Guidance Notice remains a live and contestable document rather than a fixed one. Advisers should treat the DCPMI framework as still in motion, not as fully settled law.
The Rationale Behind the Registeration
To understand why the Commission is willing to fight for jurisdiction over the sector, and why the court found the argument persuasive, it helps to look closely at what actually happens at a PoS terminal, because the data rationale is the strongest part of the Commission's case.
A single PoS transaction is a data-collection event. When a customer approaches an agent to withdraw cash, make a transfer, or pay a bill, the operator captures and routes a cluster of personal and financial identifiers: the customer's name, phone number, bank account number, card details, transaction amount, and, in many workflows, biometric or Bank Verification Number (BVN) authentication. Each of these is personal data under the NDPA, and several, BVN and biometrics in particular, sit at the sensitive end of the spectrum. The terminal does not merely pass this information through; transaction records, customer details, and settlement data are logged and retained, both on the device and across the settlement chain, creating a durable financial record of who paid whom, how much, when, and where.
Now multiply that by scale. The PoS layer is one of the densest, least formally supervised points of personal and financial data collection in the country. Nigeria has millions of active terminals in the field, and the sector processes trillions of naira across enormous transaction volumes each quarter, with a customer's phone number, account number, and often BVN changing hands at street level, tens of millions of times a day, through operators who in many cases hold no corporate structure at all. Geographically, this collection reaches into more than 300 local government areas that have no bank branch, meaning that for a large share of Nigerians, the roadside PoS agent is the primary handler of their financial data, not a bank.
That combination, sensitive data, retained records, and immense volume, is exactly the profile the DCPMI regime was built to capture. From the Commission's perspective, a data-collection surface this large and this granular cannot sit outside the registration net simply because the individual operators are small or informal. The whole point of a volume-and-sensitivity test is that it catches diffuse, high-frequency processing of the kind the PoS layer represents. Seen this way, the court's functional reasoning and the Commission's regulatory instinct converge: the risk to data subjects is a function of what is being collected and how often, and on that measure the PoS sector is squarely within scope.
Enforcing Compliance Across an Informal Economy
The overwhelming majority of PoS operators sit within Nigeria's informal economy. Industry bodies estimate the sector supports well over two million agents and has created a comparable number of jobs, most of them individuals running a single kiosk or table rather than registered businesses with constitutional documents and tax files. Enforcing uniform compliance across a population that large and that informal looks, at first glance, close to impossible.
The compliance apparatus underscores the mismatch. The standard registration pathway was built around a Certificate of Incorporation, constitutional documents, a Tax Identification Number, Tax Clearance Certificate, and an internal data protection policy, requirements plainly designed with corporate entities in mind. Asking a roadside operator with one terminal to assemble that package creates a real and unresolved gap between what the law now requires and what the affected population can practically deliver. It is easy to see why enforcement at the level of the individual agent looks like a hard ask.
But the Commission may have a more workable plan than an agent-by-agent sweep, and it runs through the principals. Almost every PoS agent in Nigeria operates a device owned and issued by a principal fintech, overwhelmingly Moniepoint, OPay, or PalmPay, each of which is already registered with the NDPC as a DCPMI, and each of which already sits under CBN supervision. The regulatory architecture around these principals has tightened sharply through 2025 and 2026: the CBN's agent-banking overhaul now requires every agent to operate exclusively under a single principal, and mandates that all agent transactions run through a dedicated account or wallet held with that principal. The practical effect of the exclusivity rule is that every agent is now cleanly mapped to exactly one supervised platform, and every transaction that agent processes is visible to, and settled through, that platform.
Rather than chasing two million individuals, the Commission can work through the handful of principals that own the terminals, hold the settlement data, and already carry DCPMI obligations. The principals are the natural chokepoint: they know exactly who their agents are, they control the devices, and they process the data centrally. This is the same logic already visible elsewhere in the ecosystem, where the Corporate Affairs Commission has pressed the major fintechs directly over unregistered operators on their networks rather than pursuing agents one by one. A registration model that flows through principals, whether by extending principal-level registration to cover their agent networks or by making principals responsible for onboarding their agents into the regime, would be far more enforceable than a scheme that depends on millions of informal operators each filing corporate paperwork they do not have.
That said, the court's functional test cuts slightly against assuming the problem solves itself. Because DCPMI status turns on data processed at the point of transaction, we would not assume agents are automatically covered simply because their principal is registered. Whether principal-level registration is treated as extending to agents, or agents are expected to register in some simplified individual capacity, is exactly the kind of question on which further guidance from the Commission would be genuinely welcome, both for agents and for the platforms managing them.
Next Steps For PoS Agents and Platforms
The Commission has been moving through 2026 toward active enforcement, with monetary penalties available against entities that remain unregistered, and Dr. Vincent Olatunji, the NDPC's National Commissioner and Chief Executive Officer, has already directed all outstanding DCPMIs to register without delay. Rather than waiting for further clarity on how registration will ultimately be allocated between agents and their principals, the better course is to register now and adjust as the Commission's guidance develops, which is consistent with how the framework has evolved so far. Principals, in particular, should anticipate that regulatory attention will land on them first, and would be well advised to get ahead of the question of how their agent networks are brought into the regime.
This update is for general information only and does not constitute legal advice. For guidance tailored to your circumstances, please contact Kiet Business Attorneys directly
References
Emmanuel Harunna v. Nigeria Data Protection Commission, Suit No. FHC/L/CS/1116/2024, Federal High Court, Lagos (judgment delivered July 27, 2026, per Ogazi J.)
Nigeria Data Protection Act 2023, ss. 5(d), 6(c), 44, 45, 65
Frank Ijege v. Nigeria Data Protection Commission, Suit No. FHC/KD/CS/34/2024, Federal High Court, Kaduna (judgment delivered November 22, 2024)
Nigeria Data Protection Commission, Updated Guidance Notice on the Registration of Data Controllers and Processors of Major Importance (NDPC/HQ/GN/.VOL.03/B/24), issued together with the Nigeria Data Protection Act 2023 General Application and Implementation Directive 2025
Nigeria Data Protection Commission, statement of Dr. Vincent Olatunji, National Commissioner and Chief Executive Officer, on directive to unregistered Data Controllers and Processors of Major Importance, July 2026, as reported in "Data commission issues fresh registration directive following court victory," Punch, July 29, 2026, https://punchng.com/data-commission-issues-fresh-registration-directive-following-court-victory/