One of the most persistent errors I encounter in advisory work with Nigerian organisations is the reflexive reliance on consent as the legal basis for processing employee data. It is intuitive. It feels procedurally safe, and HR teams are accustomed to collecting signatures. It is also, in most employment contexts, the wrong choice and getting it wrong exposes an organisation to real compliance risk under the Nigeria Data Protection Act 2023 (NDPA).
Why Consent Is the Wrong Default
Section 25 of the NDPA sets out six lawful bases for processing including consent, contractual necessity, legal obligation, vital interest, public interest, and legitimate interest. Consent sits alongside the other five as an equal option, not a superior one, yet employers routinely reach for it first.
The problem is structural. Valid consent under the NDPA must be freely given, specific, informed, and unambiguous. In an employment relationship, the inherent power imbalance between employer and employee makes “free” consent difficult to establish. An employee who is asked to consent to data processing as a condition of employment, or under implicit pressure from a superior, has not given consent that meets the legal threshold. If an employee can withdraw consent without detriment and struggles to do so in practice within an employment context, then consent was arguably never valid to begin with.
This is not a uniquely Nigerian position. It mirrors the reasoning that has shaped GDPR guidance from European data protection authorities for years, and Nigerian practitioners should expect NDPC enforcement posture to converge in the same direction as the regulator matures.
Matching the Basis to the Processing Activity
A more defensible approach is to map each category of employee data processing to the lawful basis that actually fits the purpose:
Contractual necessity covers the bulk of routine HR processing such as payroll, statutory deductions, leave administration, performance management tied to employment terms, and onboarding documentation. If the processing is required to perform the employment contract or to take steps before entering one, this is usually the correct basis, not consent.
Legal obligation applies where processing is mandated by other laws like tax remittance to NRS, pension contributions under the Pension Reform Act, National Housing Fund deductions, or NSITF compliance. Here, the employer has no discretion; the law compels the processing, so this is the appropriate basis rather than seeking employee agreement for something that isn’t optional in the first place.
Legitimate interest is often the most defensible basis for processing that falls outside strict contractual or statutory necessity. Section 25(1)(v) permits this basis, but it is not a blank cheque. It requires a documented legitimate interest assessment (LIA) balancing the employer’s interest against the employee’s rights and reasonable expectations.
Vital interest is narrow and situational, especially when processing health data in a medical emergency. This should not be stretched to cover routine health data collection.
Consent retains a proper, narrower role where, for instance, there are optional employee wellness programmes, internal social activities, use of an employee’s image in marketing materials, or participation in initiatives genuinely outside the scope of the employment relationship. Where the processing is truly optional and refusal carries no employment consequence, consent becomes appropriate again.
Special Category Data Requires Extra Care
Where employee processing touches health data, biometric data, or other special category data under Section 30 of the NDPA, the analysis does not stop at identifying a Section 25 basis. A separate condition for processing special category data is required and employers frequently overlook this second layer, assuming that having sorted out the primary lawful basis is sufficient.
Practical Guidance for Employers
I typically advise organisations to build a data processing activity register that maps each category of employee data, including recruitment records, payroll, performance data, biometric attendance data, exit records against its specific lawful basis, retention period, and any special category condition, rather than applying a single blanket basis across the entire employment lifecycle. This activity-by-activity mapping does three things: it withstands regulatory scrutiny, it clarifies retention obligations (since retention periods often differ by basis and purpose), and it prevents the common trap of asking employees to “consent” to things the organisation is already legally entitled, or obligated, to do.
Getting the legal basis right is not a formality. It is the foundation on which every other compliance obligation is built. Organisations that get this wrong at the outset tend to discover the cost later, usually during an NDPC inquiry or an employee data subject access request that exposes the gap.

