NIMC Act, 2026:  What Every Stakeholder Should Know

30 Jun 2026

By William Umoh

 

Background

Last week, President Bola Tinubu signed into law the repealed and re-enacted National Identity Management Commission (NIMC) Act, 2026. The new Act supersedes the NIMC Act of 2007 and concludes a legislative process that was briefly interrupted in May 2026 when the President withheld assent to an earlier version of the bill, citing drafting errors and structural inconsistencies, and returned it to the National Assembly for correction. The amended bill was subsequently revised and has now received full presidential assent.

 

 Key Provisions and Reforms

 

1. The NIMC Act of 2007 has been repealed and re-enacted to reflect modern realities, incorporating provisions from the Cybercrimes Act and the Data Protection Act of 2023.

2. The Act empowers NIMC to harmonise identity records, synchronise government databases, and improve interoperability among public institutions.

3. NIMC now operates across five statutory pillars: issuance of the National Identification Number (NIN); development and protection of a secure national identity database; issuance of the General Multi-Purpose Card (GMPC); harmonisation of identity data across MDAs; and provision of authentication and verification services.

4. The Act also resolves the structural and constitutional defects that prompted the earlier veto, including clarifications on board composition (ex-officio versus appointed members), the role of the Director-General, presidential appointment powers under Sections 171(1) and (2) of the Constitution, and supremacy clause provisions for conflict resolution with other legislation.

 

Legislative Reform Significance

 

The signing of this Act is significant on at least three levels.

First, it resolves the longstanding inadequacy of an 18-year-old statute that predated the Nigerian Data Protection Act 2023 and the Cybercrimes (Prohibition, Prevention, etc.) Act.

Second, it provides a clearer statutory basis for NIMC's database harmonisation mandate, which has historically been hampered by siloed agency databases and inconsistent biometric standards.

Third, it strengthens the constitutional footing of NIMC's governance framework, correcting the board composition ambiguities and supervisory authority provisions that the Presidency had flagged.

 

 Watch Points for Stakeholders

 

1. Implementation of the interoperability mandate across MDAs, particularly real-time database linkage with INEC, FRSC, CBN/BVN, and NCC, will be a key indicator of whether the Act translates into operational change.

2. Compliance timelines for MDAs under the earlier April 2024 Presidential Directive on NIN integration should now be read alongside the new statutory framework.

3. Data protection practitioners should note the Act's incorporation of NDPA 2023 principles, which creates new obligations around consent, access, and disclosure in the identity verification ecosystem.

4. The Act's provisions on penalties for unauthorised access and non-compliance with NIN usage in transactions carry enforcement implications for financial institutions, telecoms operators, and other regulated sectors.

 

Umoh is the Legislative Reform Analyst, Ernest Shonekan Centre (ESC)