Nigeria is approaching a consequential point in its genomic future. Advances in precision medicine, disease surveillance, biotechnology and artificial intelligence are transforming genomic data from a specialist research resource into an asset with significant public health, economic and strategic value.
For Nigeria, therefore, the question is no longer whether genomic data should cross borders. International scientific collaboration makes such a movement both necessary and beneficial. The more difficult policy question is whether Nigeria can participate fully in global genomic science while retaining meaningful control over the biological data of its population and ensuring that Nigerians share equitably in the value created from it.
Nigeria is not starting from an empty regulatory landscape. The Nigeria Data Protection Act 2023 recognises genetic information within its framework for sensitive personal data and establishes safeguards for international transfers. Sections 41–43 create requirements around the level of protection afforded to personal data transferred outside Nigeria, while the Nigeria Data Protection Commission’s regulatory approach considers matters including enforceable data-subject rights and the circumstances in which foreign public authorities may obtain access.
Nigeria’s National Code of Health Research Ethics provides another important layer, requiring Material Transfer Agreements for biological samples transferred abroad and addressing their purpose, storage and subsequent use. These instruments provide an important foundation, but genomics increasingly presents questions that conventional data-protection and research-ethics mechanisms were not designed to answer alone.
A genome is fundamentally different from an email address, telephone number or payment record. It is permanent, highly identifying and increasingly predictive. Importantly, it can reveal information about biological relatives who never consented to the original processing. When aggregated across thousands or millions of people, genomic information can also reveal characteristics of communities and populations.
The governance question therefore extends beyond individual privacy towards what might properly be described as bio-sovereignty: Nigeria’s ability to exercise legitimate stewardship over genomic resources derived from its population while respecting the fundamental rights of the individuals from whom those resources originate.
Bio-sovereignty, however, should not become a sophisticated term for data localisation. Nigeria needs international research partnerships, investment, computational infrastructure and access to global scientific expertise. Attempting to prevent genomic information from leaving Nigeria could ultimately disadvantage the very citizens that regulation seeks to protect.
A more credible principle is sovereignty over access rather than sovereignty merely over storage. Nigerian genomic information may legitimately travel, but the governance conditions attached to that information—including accountability, security, permitted purposes, onward transfer, commercial exploitation and benefit-sharing—should travel with it.
There are encouraging signs that Nigerian policy is already moving in this direction. The National Genomics Surveillance Strategy contemplates stronger frameworks governing genomic data and material transfers, fair benefit-sharing, protection against discrimination, intellectual-property arrangements, cybersecurity and harmonised data-sharing agreements.
The policy challenge now is to convert these principles into an operational governance architecture. Nigeria should establish a National Genomic Data Governance Framework that connects data protection, health research, cybersecurity, biotechnology, national security and economic development, rather than allowing these issues to develop within separate regulatory silos.
At the centre of that framework should be a mandatory Genomic Data Transfer Impact Assessment for high-risk international transfers.
Before population-scale or strategically significant genomic datasets leave Nigerian jurisdiction, or become remotely accessible from overseas, the transferring organisation should be required to demonstrate why the transfer is necessary, where the information will be stored, who will access it, whether foreign authorities can compel disclosure, what protections exist against re-identification and onward transfer, whether artificial intelligence will be applied to the dataset, and how Nigeria and participating communities will benefit from the resulting research.
This would move regulatory scrutiny beyond the narrow question of whether a transfer is legally permissible towards the more important question of whether its entire lifecycle is responsibly governed.
Nigeria should also establish a National Genomic Data Access Committee, bringing together the NDPC, NHREC, NCDC, relevant biotechnology institutions, cybersecurity experts, researchers and public-interest representatives.
This would not require another bureaucracy to approve every university research project. Its mandate should instead focus on population-scale datasets, strategic genomic repositories and transfers presenting elevated national or societal risk.
There is useful African precedent. H3Africa developed governance mechanisms for access to genomic data and biospecimens that recognised researchers, participants, communities, ethics bodies and governments as legitimate stakeholders. Nigeria can build upon that experience while developing a model appropriate to its own regulatory and strategic environment.
A further requirement is classification. Not every genomic dataset carries identical risk, and treating them as though they do will either produce weak protection or excessive regulation.
Nigeria should develop tiered genomic-data classifications under which population-scale repositories and strategically significant datasets receive enhanced safeguards, including encryption, privileged-access management, immutable audit trails, restrictions on onward transfer, domestic retention of critical copies and heightened scrutiny where foreign governments, defence-linked entities or other strategically sensitive organisations could obtain access.
National security should not become a blanket justification for state control. At the same time, Nigeria cannot ignore the geopolitical value that large genomic datasets may acquire as biotechnology and artificial intelligence converge.
Perhaps the most important shift, however, is economic.
Major international genomic partnerships involving Nigerian populations should contain enforceable benefit-sharing provisions covering Nigerian scientific participation, technology transfer, domestic research capacity, intellectual-property arrangements, skills development and equitable access to resulting diagnostics or therapies.
Nigeria should avoid a future in which its citizens provide biological data, foreign institutions transform that data into valuable intellectual property, and Nigerian health systems subsequently purchase the resulting innovations.
Data protection, viewed through this lens, is not simply a compliance function. It becomes part of national research, industrial and economic strategy.
Nigeria therefore does not face a choice between privacy and science, or between sovereignty and international collaboration. The opportunity is to construct a governance model capable of accommodating four interests: individual dignity, scientific advancement, national security and economic participation.
The strategic principle underpinning that model should be clear: Nigerian genomic data can cross borders where legitimate science requires it, but Nigeria should retain meaningful governance over how that data is accessed, exploited, secured and converted into value.
If genomic information is becoming one of the defining strategic resources of 21st-century medicine, Nigeria should not merely contribute to that future. It should help govern it.
- business a.m. commits to publishing a diversity of views, opinions and comments. It, therefore, welcomes your reaction to this and any of our articles via email: comment@businessamlive.com
Michael Irene, CIPM, CIPP(E) certification, is a data and information governance practitioner based in London, United Kingdom. He is also a Fellow of Higher Education Academy, UK, and can be reached via moshoke@yahoo.com; twitter: @moshoke







