On 26 June 2026, President Bola Ahmed Tinubu, GCFR, assented to the National Identity Management Commission (Establishment) Act, 2026 (the “Act”). The Act formally repeals the long-standing National Identity Management Commission Act, No. 23, 2007, establishing a modernized legal and operational framework for identity governance, biometric data management, and digital infrastructure in Nigeria.
Designed to foster universal digital inclusion, align with data protection best practices, and facilitate cross-sectoral integration, the 2026 Act positions the National Identity Management Commission (“NIMC” or the “Commission”) as the root issuing authority for digital public infrastructure (DPI) and public key infrastructure (PKI).
This publication provides a structured overview of the principal legal reforms, statutory mandates, data protection requirements, and corporate liability exposure introduced under the new Act.
Key Legislative Objectives & Scope
CORE OBJECTIVES (SEC. 1)
i. Establish an inclusive, universal foundational identification ecosystem
ii. Serve as the root authority for Digital Public Infrastructure (DPI) & PKI
iii. Enforce a data-protection driven, non-punitive, and cost-effective ID regime
iv. Modernise identity verification across all commercial and public transactions
1. Universal and Extra-Territorial Application
The Act applies to the registration of all registrable persons—citizens and resident non-citizens alike—both within and outside Nigeria. Notably, Section 2(2) extends statutory jurisdiction extra-territorially, establishing that an act or omission constituting an offence under the Act is punishable regardless of whether it was committed inside or outside Nigeria.
2. Precedence Over Conflicting Identity Laws
In a clear effort to eliminate statutory fragmentation across federal agencies, Section 36 establishes that where any other law or enactment relating directly or indirectly to the registration of individuals or identity database management is inconsistent with this Act, the provisions of the 2026 Act shall prevail.
Principal Institutional & Operational Reforms
Expanded Governance Structure
The Governing Board of the Commission has been expanded to ensure inter-agency alignment across regulatory, tax, financial, and security organs. Under Section 4, the Board includes representatives (not below the rank of Director) from:
i. Central Bank of Nigeria (CBN)
ii. Nigeria Revenue Service (NRS)
iii. Corporate Affairs Commission (CAC)
iv. Economic and Financial Crimes Commission (EFCC)
v. State Security Services (SSS) & Nigeria Police Force
vi. Independent National Electoral Commission (INEC)
vii. Office of the National Security Adviser (ONSA)
viii. National Population Commission & National Pension Commission
To elevate leadership standards, both the Chairman of the Board and the Director-General must possess at least 15 years of cognate experience in ICT, engineering, law, management, economics, or related fields.
DPI Anchor and PKI Root Certification Authority
Under Sections 7(j) and 8(f), NIMC is statutory mandated to serve as the Root Certification Authority and issuing authority for the national Public Key Infrastructure (PKI) and Digital Public Infrastructure (DPI). This formalizes NIMC’s power to set technical specifications, establish communication links with state and private databases, and govern national digital authentication systems.
Critical Provisions for Commercial Operators & Businesses
1. Broadened Mandatory Use of National Identification Number (NIN)
Section 26(1) mandates the presentation of a NIN for verifying identity across a comprehensive list of commercial, financial, and public sector transactions, including:
i. Financial & Credit Services: Opening bank accounts, consumer credit transactions, and tax payments.
ii. Statutory Schemes: Contributory Health Insurance, social security, and transactions governed by the Pension Reform Act.
iii. Official Documentation: Issuance of international passports, voters’ cards, and government-endorsed programs.
Entity Obligation: Any entity facilitating these transactions is legally required to verify the identity of participating parties using their NIN.
Key Legal Distinction (Sec. 26(2)–(3)): The Act explicitly clarifies that proof of identity via NIN does not constitute proof of citizenship, nor does it automatically establish eligibility for government benefits.
2. Third-Party Agent Licensing & Restrictions
NIMC retains the statutory power to license private sector entities and corporate bodies as agents to conduct enrolment, authentication, and identity verification. However, Section 25(3) imposes a strict operational prohibition: neither NIMC nor any licensed agent may collect, maintain, or keep information regarding the purpose of an authentication request.
3. Enrolment Safeguards and the “Identifier” System
To address identity exclusion among vulnerable populations, Section 18 establishes:
i. The “Identifier” Mechanism: Registrable persons lacking standard government-issued documentation can be identified under oath by an adult relative who is already registered, or by designated classes of Identifiers.
ii. Statutory Disclosure Rights: At the point of enrolment, individuals must be formally notified of how their data will be used, the categories of recipients with whom it will be shared, and the procedures for exercising access rights.
Data Privacy, Disclosure, and Security Framework
While facilitating data exchange across government and corporate bodies, Section 24 introduces strict parameters around data disclosure:
STATUTORY DATA DISCLOSURE TRACKS
-
CONSENT-BASED ACCESS
i. Requires explicit consent of the registered individual.
ii. Restricted solely to requested purpose. -
EXCEPTIONAL DISCLOSURE
i. Compliance with legal obligations.
ii. Prevention, detection, or prosecution of criminal offences.
iii. High Court Order (Sec. 24(3))
Where disclosure is permitted under statutory exceptions or court orders, recipients are required to implement robust technical and organizational measures to safeguard individual rights and freedoms.
Penalties, Enforcement, and Corporate Liability
Part VII introduces stringent penal sanctions targeting unauthorized access, data alteration, impersonation, and overcharging. Crucially, corporate entities face substantial direct fines, while their principal officers (directors, managers, and executive officers) face joint criminal exposure.
| Offence | Statutory Provision | Penalty for Individuals | Penalty for Corporate Entities | Principal Officer Liability |
|---|---|---|---|---|
| Unauthorized Access / Hacking Database | Section 27 | Fine of not less than ₦10,000,000 or imprisonment for not less than 5 years | Fine of not less than ₦20,000,000 | Fine of not less than ₦10,000,000 or imprisonment for not less than 5 years |
| Giving False Information | Section 28 | Fine of not less than ₦2,000,000 or imprisonment for not less than 2 years | Fine of not less than ₦10,000,000 | Fine of not less than ₦2,000,000 or imprisonment for not less than 2 years |
| Multiple Registration / Forgery of NIN | Section 29 | Fine of not less than ₦10,000,000 or imprisonment for not less than 5 years | Fine of not less than ₦20,000,000 | Fine of not less than ₦10,000,000 or imprisonment for not less than 5 years |
| Impersonation of NIMC Officer or Agent | Section 30 | Fine of not less than ₦10,000,000 or imprisonment for not less than 5 years | Fine of not less than ₦20,000,000 | Fine of not less than ₦10,000,000 or imprisonment for not less than 5 years |
| Charging Unauthorized Fees for Services | Section 31(2) | Fine of ₦50,000 per reported contravention | Fine of ₦200,000 per reported contravention | Not expressly provided |
Investigative Powers and Search Warrants
Under Section 33, NIMC is empowered to apply ex-parte to a High Court for search warrants. The Commission’s investigative teams, in collaboration with law enforcement agencies, possess broad statutory authority to:
i. Access, search, and seize electronic storage media and computer systems.
ii. Deploy technical tools to decode or decrypt encrypted data relevant to an investigation.
Limitation of Legal Actions Against the Commission
Under Section 34, any civil action against the Commission, a Board member, or NIMC staff must be instituted within three (3) months of the act or default, following the service of a one (1) month written notice of intention to sue.
Operational Action Items for Commercial Entities
i. Review KYC and Identity Onboarding Workflows: Financial institutions, fintechs, telecom operators, and healthcare providers must audit their onboarding processes to ensure full compliance with mandatory NIN verification workflows under Section 26.
ii. Data Retention & Purpose Tracking Audit: Private verification agents and licensed entities must ensure their technology stacks do not retain metadata or logs concerning the specific purpose of an identity verification request, avoiding direct contravention of Section 25(3).
iii. Enhance Technical Security Protocols: Organizations receiving data from the National Identity Database must verify that their technical and organizational safeguards meet standard data protection frameworks to prevent unauthorized access and corporate exposure.
Comparative Overview: Key Regulatory Shifts (2007 vs. 2026)
| Structural Dimension | NIMC Act 2007 (Repealed) | NIMC Act 2026 (Current) | Impact on Operations |
|---|---|---|---|
| Institutional Mandate | Focused primarily on issuing physical identity cards and basic enrolment. | Formally establishes NIMC as the Root Certification Authority for national PKI and Digital Public Infrastructure (DPI). | Expands regulatory oversight into digital signature ecosystems and public-private API integrations. |
| Governance Structure | Standard inter-agency participation focused on security and general public administration. | Modernised board composition explicitly integrating financial, corporate, tax, and cyber enforcement regulators (e.g., NRS, CAC, EFCC, ONSA). | Facilitates cross-regulatory coordination for enterprise enforcement and automated tax/corporate identity verification. |
| Data Protection Alignment | Basic privacy provisions without explicit data protection architecture. | Fully integrated data protection requirements under Section 24, including strict disclosure exceptions and operational transparency. | Requires enterprise-wide alignment between identity management workflows and national data privacy standards. |
| Sanctions & Penal Fines | Moderate monetary fines for statutory breaches. | Multi-million Naira sanctions (up to ₦20m) and direct personal liability/imprisonment for principal officers. | Elevates compliance risks to board-level exposure for non-compliant corporations and licensed agents. |
Transitional Provisions & Legal Continuity
Section 38 of the Act sets out robust savings and transitional mechanisms designed to prevent operational disruption within the national identity ecosystem:
i. Validity of Existing Identification: All National Identification Numbers (NINs), credentials, registrations, and administrative actions issued or performed under the repealed 2007 Act remain fully valid and are deemed to have been executed under the 2026 Act.
ii. Pending Litigation & Proceedings: Any judicial proceeding, administrative inquiry, or cause of action existing immediately prior to the commencement of the 2026 Act continues unimpeded under the new legal framework.
iii. Transfer of Assets & Liabilities: All assets, statutory rights, contractual commitments, and liabilities of the former Commission automatically vest in the newly re-established Commission.
Governance & Financial Sustainability
Part V of the Act establishes the financial framework governing the Commission’s operations, ensuring statutory independence and operational capacity:
SOURCES OF FUNDING (SEC. 12)
i. Annual budgetary subventions from the Federal Government
ii. Statutory fees and charges collected for verification/authentication
iii. Grants, endowments, and donations approved by the Board
Budgetary & Reporting Cycles: The Commission must submit its annual expenditure estimates to the President no later than 30 September each year. Audited accounts must be prepared annually in accordance with Auditor-General guidelines and presented alongside an annual activities report within six (6) months of the end of each financial year.
How We Can Help
Our Regulatory & Technology Practice Group advises multinational corporations, financial institutions, fintech platforms, and telecommunications operators on navigating digital governance and regulatory compliance across emerging markets.
We are available to assist clients with:
i. Regulatory Audits: Performing comprehensive gap analyses on current identity verification (KYC/AML) protocols to ensure alignment with Sections 25 and 26.
ii. Data Governance & Privacy Safeguards: Structuring third-party verification data flows and API frameworks to ensure compliance with Section 24 data protection limitations.
iii. Licensing & Enforcement Advisory: Representing identity verification agents and digital infrastructure providers in licensing applications, compliance reviews, and enforcement inquiries before the NIMC.
Key Contacts
For further information or specific advice regarding the implications of the NIMC Act, 2026, please contact:
Regulatory & Technology Practice Group
Email: info@progressionlawfirm.com
Direct: +234 9022514760
