Digital Identity Brief
NIMC Act 2026: What Nigeria's new digital identity law changes
President Bola Ahmed Tinubu assented to the National Identity Management Commission Act 2026 on 26 June 2026. The law replaces the 2007 Act and expands the legal foundation for digital identity, authentication and trusted data exchange in Nigeria.
Executive assessment
The Act signals a shift from identity enrolment as a standalone government function toward identity as shared national digital infrastructure. Its practical significance will depend on implementation rules, technical standards, oversight and the security of every organisation connected to the ecosystem.
What is new
01
Stronger data-protection safeguards
The announced framework introduces stronger safeguards for how personal data is processed, stored and protected, with alignment to the Nigeria Data Protection Act and recognised privacy standards.
02
A central role in digital trust
NIMC is designated as the Root Certification Authority for Nigeria's National Public Key Infrastructure and Digital Public Infrastructure, placing it at the centre of secure identity, authentication and electronic trust services.
03
Interoperable data exchange
The Commission is empowered to support secure and seamless data exchange among authorised public institutions, private organisations and other approved entities.
04
One card, multiple uses
The NIMC General Multipurpose Card is positioned as a versatile credential for identity verification and access to services across the country.
Why it matters to Nigerians
The stated goal is a trusted, secure and interoperable identity ecosystem that makes public- and private-sector services easier to access. If implemented effectively, it could improve identity services for Nigerians at home and abroad, strengthen privacy and cybersecurity, and make digital verification faster and more dependable.
What organisations should do now
- Organisations should review every workflow that collects, verifies, stores or shares identity data.
- Privacy notices, consent records, access controls and retention schedules may need to be reassessed against the new framework.
- Identity-verification providers and connected systems should be examined for security, interoperability and clear accountability.
- Implementation guidance and the gazetted text should be monitored before making final compliance decisions.

About the author
Tomi Tawose
Director of Research & Policy
Policy and research executive focused on institutional resilience, governance analysis and practical risk intelligence for complex environments.
View research profilePrepare for a more connected identity ecosystem.
Foxtrot Shield helps organisations assess privacy, security, third-party and operational risks as regulatory and digital infrastructure evolves.
Request a Consultation