Given Nigeria's status as a leader in the fintech industry in Africa with Nigerian fintech’s
processing trillions of Naira in digital transactions yearly and managing the personal and
financial data of millions of Nigerians, the governance of those data by Nigerian fintech’s remains
under-theorized from corporate governance and fiduciary perspectives. This paper argues that
data privacy/protection and information sharing by Nigerian fintech’s are more about fiduciary
accountability than data governance. The paper relied on comparative and doctrinal research of
the Nigeria Data Protection Act (NDPA) 2023, select regulations of the Central Bank of Nigeria
(CBN), the Nigerian Code of Corporate Governance (NCCG) 2018, the General Data Protection
Regulation (GDPR) and the Companies and Allied Matters Act (CAMA) 2020. This paper
discusses how the principles of data protection may be interpreted as fiduciary responsibility. It
highlights the role of fintech boards, including oversight and assurance by the audit committee,
the alignment of executive incentives and Environmental, Social and Governance (ESG) reporting
in the context of Nigeria’s stratified fintech regulatory framework. The paper proffers
recommendations to the boards of fintech companies, the Nigeria Data Protection Commission
(NDPC), the Central Bank of Nigeria (CBN) and the Financial Reporting Council of Nigeria
(FRCN).