The concurrent operation of the Companies and Allied Matters Act (CAMA) 2020 and the Nigeria Data Protection Act (NDPA) 2023 has created a complex environment of legislative inconsistency and legal uncertainty. While CAMA mandates the disclosure and public accessibility of directors' personal information, Persons with Significant Control, and age requirements, the NDPA imposes data minimisation, storage limitation, and privacy protections. This paper examines this normative fragmentation through doctrinal analysis of statutory provisions, case law, and comparative insights from South Africa, Kenya, and the European Union. The paper identifies three core conflicts: (1) the tension between CAMA's transparency mandate and the NDPA's data minimisation principle; (2) the retention period conflict between CAMA's six-year mandatory retention and the NDPA's "as long as necessary" principle; and (3) the unresolved constitutional tension between Section 37 privacy rights and public access to corporate records. The paper finds that these conflicts create irreconcilable compliance obligations for regulators and companies, expose individuals to identity theft risks as demonstrated by the April 2026 CAC data breach, and operate without any statutory harmonisation mechanism, thereby undermining both regulatory effectiveness and constitutional rights protection. The research recommends targeted legislative amendments to CAMA 2020 replacing residential addresses with service addresses, binding NDPC regulations establishing tiered access and retention schedules, technological integration with NIMC to minimise data collection, and strategic litigation to develop constitutional privacy jurisprudence under Section 37.