Foxtrot Shield
← Back to Insights

Digital Identity Brief

NIMC Act 2026: What Nigeria's new digital identity law changes

President Bola Ahmed Tinubu assented to the National Identity Management Commission Act 2026 on 26 June 2026. The law replaces the 2007 Act and expands the legal foundation for digital identity, authentication and trusted data exchange in Nigeria.

Tomi Tawose4 minute read
Download analysis as PDF ↓

Executive assessment

The Act signals a shift from identity enrolment as a standalone government function toward identity as shared national digital infrastructure. Its practical significance will depend on implementation rules, technical standards, oversight and the security of every organisation connected to the ecosystem.

What is new

01

Stronger data-protection safeguards

The announced framework introduces stronger safeguards for how personal data is processed, stored and protected, with alignment to the Nigeria Data Protection Act and recognised privacy standards.

02

A central role in digital trust

NIMC is designated as the Root Certification Authority for Nigeria's National Public Key Infrastructure and Digital Public Infrastructure, placing it at the centre of secure identity, authentication and electronic trust services.

03

Interoperable data exchange

The Commission is empowered to support secure and seamless data exchange among authorised public institutions, private organisations and other approved entities.

04

One card, multiple uses

The NIMC General Multipurpose Card is positioned as a versatile credential for identity verification and access to services across the country.

Why it matters to Nigerians

The stated goal is a trusted, secure and interoperable identity ecosystem that makes public- and private-sector services easier to access. If implemented effectively, it could improve identity services for Nigerians at home and abroad, strengthen privacy and cybersecurity, and make digital verification faster and more dependable.

What organisations should do now

  • Organisations should review every workflow that collects, verifies, stores or shares identity data.
  • Privacy notices, consent records, access controls and retention schedules may need to be reassessed against the new framework.
  • Identity-verification providers and connected systems should be examined for security, interoperability and clear accountability.
  • Implementation guidance and the gazetted text should be monitored before making final compliance decisions.
Tomi Tawose

About the author

Tomi Tawose

Director of Research & Policy

Policy and research executive focused on institutional resilience, governance analysis and practical risk intelligence for complex environments.

View research profile

Prepare for a more connected identity ecosystem.

Foxtrot Shield helps organisations assess privacy, security, third-party and operational risks as regulatory and digital infrastructure evolves.

Request a Consultation