There is a strange ritual built into many interactions with government.
You provide your name.
Your date of birth.
Your address.
Your identification number.
Perhaps your company details.
Then you go to another part of government and provide much of the same information again.
And then again.
Sometimes you are even asked to prove to one public institution something that another public institution originally issued.
We have become so accustomed to this that it can feel normal.
It should not.
If government already legitimately holds accurate information about you, and another authorised part of government needs that information to deliver a service, the burden should not automatically fall on you to carry it between institutions.
Why should a citizen become the courier between government databases?
That is why one of the most important pieces of Nigeria's emerging digital state may also be one of the least visible:
the ability of government systems to exchange trusted data safely.
This is the next part of the "shared basics" layer introduced across Parts 1 and 2.
A good Government Service Portal can help you find a service.
But if the systems behind that service still cannot exchange information, the citizen eventually encounters the same old government through a newer screen.
The deeper transformation begins when government stops repeatedly asking people for information it already has.
The promise is simple
Imagine applying for a government service.
You prove who you are.
The service needs to know, for example, whether your identity is valid, whether your company exists, whether a licence has been issued, or whether another authorised public record contains information relevant to the transaction.
Today, that may require you to fetch documents, upload copies, enter information again or physically move evidence between institutions.
A connected system works differently.
Instead of asking you to reproduce information, the service queries an authoritative source.
The institution that owns the record confirms what needs to be confirmed.
The transaction continues.
You do less administrative work.
Government does more of the orchestration.
That is the underlying proposition behind data exchange.
And Nigeria has been moving towards it deliberately.
NITDA's work on Digital Public Infrastructure includes the Nigeria Data Exchange, NGDX, alongside a draft technical standard intended to support secure and interoperable exchange across government systems. NITDA has also been explicit that federal action alone will not be enough. States and other institutions need to participate if the architecture is to function as a genuine whole of government capability.
That could change a great deal.
Tell government once
The phrase is useful because it makes a complicated technology idea human.
Why should I tell one part of government something that another part already knows?
Why should I type my date of birth into five different public systems?
Why should an agency ask me to upload a certificate issued by another government agency if the authenticity of that certificate can be checked directly?
Why should I carry government's information about me back to government?
A mature digital state should progressively remove that burden.
The gains are not merely convenience.
Data reuse can reduce repetitive form filling, shorten processing time and reduce errors introduced when the same information is manually entered again and again.
It can also improve verification.
A scanned document tells an agency what a document appears to say.
A trusted query to the authoritative issuing system can tell the agency whether the underlying record actually exists.
That is a much more powerful capability.
And it creates opportunities for services that are difficult to build when every institution remains a data island.
But "tell government once" is only safe if we add another sentence immediately after it:
Government must not then tell itself the wrong thing everywhere.
Connected bad data is worse than isolated bad data
Suppose a public record contains the wrong date of birth.
Or an incorrect address.
Or somebody has been mistakenly marked deceased.
Or a company record has not been updated.
Or two systems disagree about the same person.
In a fragmented environment, that error is inconvenient.
In a highly connected environment, it can become systemic.
If multiple government services all rely upon the same authoritative record, an error in that source can follow the citizen everywhere.
The very architecture that removes duplication can also amplify mistakes.
That gives connected government a responsibility that disconnected government could sometimes avoid:
data quality becomes service quality.
The ability to exchange information is therefore not enough.
Government needs to know which source is authoritative.
Records need ownership.
Errors need correction mechanisms.
Conflicting records need reconciliation.
Changes need to propagate properly.
And a citizen needs a practical way to challenge information that is wrong.
Otherwise, "tell government once" can become:
Government got it wrong once, and now every service knows.
That is not digital transformation.
It is automated frustration.
Sharing data is not the same thing as sharing everything
There is another misconception worth removing early.
A data exchange does not need to mean that every agency receives a giant copy of everything government knows about you.
That would be a poor model.
The more mature idea is controlled exchange.
A service asks for information it has a legitimate reason to use.
The authoritative system confirms or supplies what is necessary.
Rules determine who can ask, what can be retrieved, why it can be used, and what record is kept of the access.
This distinction matters.
There is a world of difference between:
"Agency A can see everything Agency B knows about me."
and:
"Agency A can securely verify the specific fact it needs for this transaction."
The second is both more useful and potentially much safer.
That is where architecture and law have to meet.
Nigeria's data protection framework already gives data subjects rights and protections around the handling of personal information, including access, rectification, restriction, complaint mechanisms and, in relevant circumstances, portability and erasure.
Those rights become more consequential, not less, as government systems become easier to connect.
Recent events have made the governance question concrete
On 12 August 2026, the Nigeria Data Protection Commission announced an investigation into alleged data protection violations involving the University of Lagos, Lotus Bank and Hackerbella Ltd.
An investigation is not a finding of wrongdoing, and the allegations should be treated accordingly.
But its relevance to the digital state is straightforward.
Data protection obligations are not theoretical requirements waiting for some future connected government. They are active responsibilities in the environment Nigeria is digitising.
A day later, on 13 August, the NDPC met the Securities and Exchange Commission to discuss data protection and compliance within the capital market. NDPC's own published account records the Commission encouraging sector wide compliance with the Nigeria Data Protection Act, while the SEC acknowledged the sensitivity of investor information and expressed willingness to work further with the data protection regulator.
The particular sector is less important here than the institutional lesson.
Nigeria's connected digital state will not operate inside the mandate of one regulator.
Identity touches NIMC.
Personal data brings in NDPC.
Digital platforms, standards and infrastructure involve NITDA.
Financial information may involve sector regulators.
Telecommunications, health, education and other domains bring their own mandates, rules and risks.
Once information begins to cross those boundaries, governance has to become capable of crossing them too.
That same problem can be seen from another direction.
On 10 August 2026, NITDA highlighted work on the National Regulatory Sandbox, a multi agency mechanism intended to allow regulators to coordinate around emerging technologies and test regulatory approaches in a supervised environment rather than addressing overlapping issues entirely in isolation.
These are different initiatives.
But they point towards the same requirement.
Connected systems require connected governance.
Technology may cross institutional boundaries in milliseconds.
Governance cannot afford to discover those boundaries afterwards.
Privacy cannot be bolted on afterwards
That is why privacy by design matters.
The NDPC and the Digital Impact Alliance have already worked together on a privacy by design initiative focused on early stage innovation, including work with Nigerian innovators applying Digital Public Infrastructure and artificial intelligence to real social and economic problems.
Their work argues for privacy safeguards to be designed into services early rather than treated as a compliance exercise at the end.
That principle becomes particularly important for a national data exchange.
If the architecture is built first and privacy controls are added afterwards, some of the most consequential decisions may already have been made.
Who can query whom?
How much information is returned?
How is access authorised?
How long are records retained?
Can one identifier be used to combine datasets that were originally created for completely different purposes?
Are requests logged?
Can unusual access be detected?
Can a citizen discover that their information has been used?
What happens when somebody abuses access they were legitimately given?
These are not merely policy questions.
They become technical requirements.
Privacy has to exist in permissions, APIs, authentication, logging, retention rules and operating processes.
A beautifully written privacy notice cannot rescue an architecture that was designed to expose too much information.
The citizen should be able to see government too
There is an interesting asymmetry in many digital systems.
Government can increasingly see the citizen.
The citizen often cannot see what government has done with their information.
A trustworthy digital state should narrow that gap.
If data exchange becomes a major part of public service delivery, Nigeria should eventually aim for a citizen experience in which people can understand meaningful parts of their own data trail.
Which government institution holds this record?
Who changed it?
Which service used it?
When was it accessed?
For what purpose?
How do I challenge something that is wrong?
Not every technical transaction needs to be exposed in raw form.
But transparency should not be entirely one directional.
If we want citizens to stop carrying documents between institutions because government can exchange information itself, then citizens need confidence that this exchange is happening properly.
Trust grows when accountability is visible.
Consent is important, but it is not the whole answer
There is a temptation in digital services to turn every privacy question into a checkbox.
"I consent."
Problem solved.
It is rarely that simple.
Government sometimes processes information because the law requires it to perform a public function.
In other circumstances, consent may genuinely be appropriate.
What matters is that the lawful basis is clear, that unnecessary information is not collected, and that citizens are not misled into believing they have a meaningful choice where the service or the law leaves little practical alternative.
That matters particularly in government because the relationship is not always equal.
If I must use a service to obtain something essential, consent can become more theoretical than meaningful.
Good data governance therefore requires more than permission screens.
It requires purpose limitation.
Data minimisation.
Access controls.
Security.
Auditability.
Accuracy.
Rights of correction.
And accountability when those controls fail.
The interface is merely where some of those obligations become visible.
Nigeria also has a federal problem to solve
Nigeria is not one administrative system.
It is a federation.
Federal institutions hold important data.
States hold important data.
Local governments hold important data.
And many consequential citizen journeys move across more than one level of government.
That means a genuinely useful national data exchange cannot ultimately stop at Federal Government institutions.
NITDA has already recognised this in its DPI work. During the public review of the draft DPI framework and NGDX technical standard, it explicitly called for sub national participation and described that participation as necessary to achieving a whole of government approach.
The Nigeria Governors' Forum has also been involved in wider DPI readiness work for states.
This may prove to be one of the hardest parts of the project.
Technology can define an API standard.
It cannot, by itself, create institutional readiness.
Different states will have different levels of digitisation.
Different systems.
Different data quality.
Different skills.
Different infrastructure.
Different governance maturity.
A national exchange therefore needs not merely connectivity but a route for less mature institutions to join safely without lowering the standard for everybody else.
Otherwise, Nigerians could encounter a new type of administrative inequality:
excellent connected services where institutional capability is high, and manual fragmentation where it is not.
The architecture may be national.
Its weakest points may often be local.
Then there is security
The value of connected information makes it attractive.
Not only to legitimate public services.
If a data exchange connects high value government datasets, it becomes an obvious target for criminals, hostile actors and insiders.
That does not mean the exchange should not exist.
It means its security model becomes part of national infrastructure.
Authentication needs to be strong.
Privileges need to be narrow.
Access needs to be monitored.
Sensitive transactions may need stronger controls.
Unusual behaviour needs detection.
Connections need testing.
Compromised credentials need rapid revocation.
Incident response needs to cross institutional boundaries.
And the design should assume that some component, somewhere, will eventually be attacked successfully.
NITDA's draft technical standard for Nigeria's DPI explicitly addresses interoperability, security and privacy, scalability, accessibility, governance and compliance, testing and quality assurance, incident response, performance, auditability and integration.
That is important because it returns us to a principle from Part 2.
Digital trust is not built by promising that nothing will ever go wrong.
It is built by designing systems so failures can be detected, contained, understood and recovered from.
The most powerful version is almost invisible
If Nigeria gets data exchange right, the citizen may barely notice it.
That is perhaps the point.
You apply for a service.
You authenticate yourself.
Government securely verifies information it already holds.
You are not asked to upload the same certificate again.
You do not enter the same address for the sixth time.
A discrepancy is identified before it blocks five other services.
You can correct information that is wrong.
You can understand how important information about you is being used.
And the transaction moves.
The infrastructure underneath may be extremely sophisticated.
The citizen experience should feel ordinary.
This is why the Nigeria Data Exchange matters.
Not because Nigerians need another platform name to remember.
But because, eventually, they should need to know less about the platforms government uses at all.
The bargain has to be fair
There is, however, a bargain at the heart of this.
Citizens give government something valuable when public services become connected:
the ability to use information more efficiently across institutional boundaries.
Government has to give something valuable in return.
Less friction.
Better services.
Clear purpose.
Stronger security.
Accurate records.
Visible accountability.
And meaningful rights when something goes wrong.
That is the difference between connected government and merely concentrated data.
The first serves citizens.
The second can make them more vulnerable.
Nigeria's direction is encouraging because the technical conversation about Digital Public Infrastructure is increasingly being accompanied by an active regulatory conversation about privacy, compliance and accountability.
That needs to continue.
Because the real promise of connected public data is not that government will know more about us.
Government already knows a great deal.
The promise is that government will use what it legitimately knows better, ask us for less, protect it more carefully and remain accountable for what happens when information begins to move.
That is what "tell government once" should mean.
Not:
tell government once, and lose control of where the information goes.
But:
tell government once, where appropriate, and make government responsible for using that information properly thereafter.
That is a much more demanding proposition.
It is also a much more worthwhile one.
Next in Building Nigeria's Digital State: Proving You Are You: Why Digital Identity Is Becoming Public Infrastructure
This is an independent view of publicly announced initiatives, not an official government architecture.