High-resolution Earth Observation (EO) platforms routinely capture spatial Data
capable of identifying individual structures and human activities, creating tension
between open-Data mandates and privacy rights. While international agencies align
with frameworks like the General Data Protection Regulation (GDPR), mechanisms
for embedding privacy into national satellite workflows remain underdeveloped. This
paper examines the misalignment between Nigeria’s Data Protection Act (NDPA)
2023 and EO operations, particularly in rapid disaster response. Using statutory
analysis and synthesis of geospatial privacy and GeoAI literature, we evaluate risks
across upstream, midstream, and downstream segments of Earth Observation. To
overcome manual compliance latency, we propose the Data Protection for Earth
Observation Data (DP-EO Data) Architecture, a Privacy-by-Design framework that
integrates geographic zoning at sensor-tasking, end-to-end encrypted telemetry, and
automated GeoAI spatial anonymization with tiered role-based access control. This
architecture operationalizes the NDPA 2023 across the EO value chain, transforming
legal obligations into technical safeguards for responsible satellite Data use in
national contexts. It enables Nigeria to reconcile Data sovereignty with multilateral
commitments under the United Nations Platform for Space-based Information for
Disaster Management and Emergency Response (UN-SPIDER) and the Committee
on the Peaceful Uses of Outer Space (UN COPUOS), ensuring responsible use of
satellite Data without compromising spatial personal information. The DP-EO Data
Architecture offers a transferable model for African space programs seeking to
innovate responsibly within domestic legal frameworks.