Is it legal to use AI to screen job applicants in Nigeria?
Yes, provided you comply with the Nigeria Data Protection Act 2023. You need a lawful basis to process applicant data, you must tell applicants how their data is used, and an applicant is entitled not to be subject to a decision based solely on automated processing that significantly affects them without safeguards such as human review. In practice: use AI to organise and score evidence, keep a human making the decision, and say so in the application.
The NDPA governs the applicant data, not the algorithm
The Nigeria Data Protection Act 2023 is the law that matters here, and it applies to you the moment a CV lands in your inbox. A job application is personal data: name, phone number, employment history, sometimes a photograph, sometimes a date of birth. Whether you review it by hand, in a spreadsheet or with an AI model, you are processing personal data and the same obligations apply. Nothing about the law is triggered by the word AI. It is triggered by the applicant.
The principles are the familiar ones. You need a lawful basis for the processing - for recruitment this is usually the steps taken at the applicant's request before entering a contract, or a legitimate interest, and consent is not the only route and often not the strongest one. You must be transparent, meaning applicants are told who is processing their data, why, and what happens to it. You must minimise, collecting only what the role actually requires. You must keep it only as long as you need it. And applicants keep their rights over that data: to know what you hold, to have errors corrected, to have it deleted when the purpose has ended.
The Act also sets up the Nigeria Data Protection Commission as the regulator, and organisations above certain processing thresholds carry extra obligations such as registration and appointing a data protection officer. Whether that catches you depends on your scale, so check your own position rather than assuming a five-person company and a bank are treated identically. This page is general information, not legal advice - if the decision carries real risk for your business, take advice from a Nigerian lawyer who works in data protection.
- Lawful basis: know which one you are relying on, and write it down
- Transparency: a privacy notice the applicant can actually read, on the application itself
- Minimisation: do not collect a date of birth, marital status or a photograph you have no use for
- Retention: a defined period after which unsuccessful applications are deleted
- Rights: be able to answer an applicant who asks what you hold and to delete it on request
The automated-decision provision is the clause that decides your design
The NDPA carries a provision on automated decision-making: broadly, a person is entitled not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects or similarly significant effects on them, unless safeguards are in place. Being rejected for a job is exactly the kind of significant effect the provision has in mind. Safeguards in practice mean a human who can review the decision, and an applicant who can contest it and get an explanation.
That sounds restrictive until you notice what it actually forbids. It does not forbid AI in hiring. It forbids the machine being the entire decision with no human anywhere in it. Almost every sensible screening design already satisfies this, because a hiring manager reading a ranked shortlist and choosing who to interview is a human decision informed by automation, not an automated decision.
Where employers get exposed is the auto-reject rule: a threshold score, or a filter that discards anyone below a cut-off, with no person ever seeing those applications. That is a decision made solely by automated processing, it significantly affects the applicant, and it is the pattern the provision is written about. If you want a cut-off for volume reasons, keep the rejected set reviewable, have a human sign off the batch, and be able to explain what the score measured.
Filtering people out is a different act from analysing evidence for a human
Two tools can both be described as AI screening and sit on opposite sides of this line. The first filters: it reads applications, applies rules or a model, and removes candidates from your view. You never see them, so you cannot review the decision or explain it. The second analyses: it reads the same applications, scores them against criteria you defined, shows you the evidence behind each score, and leaves every candidate visible and every decision yours.
The second design is easier to defend for a reason beyond compliance. It is also better hiring. A filter can only be as good as the rules it was given, and a rule that discards anyone without a named degree or a two-year gap in employment will discard good people confidently and silently. Evidence with a score attached lets you notice when the model and your judgement disagree, which is exactly the moment worth paying attention to.
Tezera is built on the second pattern: it analyses each application against the criteria drawn from the outcomes you defined, surfaces the evidence and contradictions behind every score, and leaves the decision with the employer, who owns the criteria. Its limitation is that it cannot score anyone against outcomes you have not defined, so the quality of what it produces depends on the work you do before the first application arrives. Whatever tool you use, the compliance question is the same one: can a human see everybody, and can you explain a rejection?
- Filters out automatically: rejected candidates invisible, no explanation available, hardest to defend
- Ranks and scores for a human: everyone visible, evidence attached, decision made by a person
- Either way, the criteria must be job-related and defined by you before applications arrive
Discrimination law applies to the AI exactly as it applies to a manager
The Labour Act is the main statute for employment conditions in Nigeria, and it governs the employment relationship rather than the screening technology. It does not regulate AI. That does not put your screening outside the law, because the Constitution prohibits discrimination against a citizen on grounds such as ethnic group, place of origin, sex, religion or political opinion, and there is separate legislation addressing discrimination in specific contexts. The general position is straightforward: a screening criterion that would be unlawful if a manager applied it by hand does not become lawful because software applied it at scale.
The practical risk with AI is indirect rather than deliberate. Nobody sets out to build a filter that disadvantages a group. But a model trained on who you have hired before will learn who you have hired before, and a criterion like a specific set of universities or continuous employment history can act as a proxy for something you are not allowed to select on. This is why criteria have to be job-related and traceable to an outcome. If you cannot say which outcome a criterion serves, it should not be scored.
Keep the audit trail as you go. If a rejected applicant asks why, or a regulator asks how the process worked, the answer you want to give is a written scorecard with criteria tied to the role's outcomes and a record of who reviewed what. That record is not bureaucracy for its own sake. It is the same document that makes your hiring better, which is why the compliant design and the effective design keep turning out to be the same design.
A practical compliance checklist, and what to ask a vendor
None of this requires a legal department. It requires six things done deliberately and written down once, then reused for every role you post.
- Ask a vendor: where is applicant data stored and processed, and under whose control?
- Ask a vendor: can I see and export every candidate, including the low-scoring ones?
- Ask a vendor: who sets the criteria, you or the model, and can I see what each score is based on?
- Ask a vendor: what happens to applicant data when I stop using you, and how do I honour a deletion request?
- Ask a vendor: will you sign a data processing agreement referencing the NDPA?
- Put a short privacy notice on the application form: who you are, what you collect, why, how long you keep it, and that AI assists the review while a person decides
- Keep a human in the loop on every rejection, and make sure someone can see the candidates a score pushed to the bottom
- Tie every criterion to something the job actually requires, and drop anything you cannot trace to an outcome
- Set a retention period for unsuccessful applications and actually delete on schedule
- Collect only what you need: no date of birth, marital status, state of origin, religion or photograph unless the role genuinely requires it
- Be able to explain any rejection in one paragraph, using the criteria and the evidence behind the score
Also asked as
The same question, phrased the other ways people ask it. Every one of them lands on this page.
- Can I use AI to shortlist candidates in Nigeria?
- Does the NDPA allow automated candidate screening?
- Is AI recruitment software compliant with Nigerian data protection law?
- Do I need consent to run AI screening on job applications?
Questions people ask next
Do I need an applicant's consent to run AI screening on their application?
Not necessarily. Consent is one lawful basis, but recruitment processing usually rests on the steps taken at the applicant's request before a contract, or on a legitimate interest. What you always owe them is transparency: tell them in the privacy notice on the form that AI assists the review and a person makes the decision.
Can I automatically reject candidates below a score?
That is the design most exposed to the NDPA's automated-decision provision, because rejection is a significant effect and nobody human was involved. If you need a cut-off for volume, keep the rejected candidates visible and reviewable, have a person sign off the batch, and be able to explain what the score measured.
How long can I keep applications from people I did not hire?
The Act requires you to keep personal data no longer than the purpose needs, rather than naming a fixed number of months for recruitment. Set your own defined period, state it in the privacy notice, and delete on schedule instead of leaving a Drive folder of CVs from three years ago.
Does this apply if I only use Google Forms and a spreadsheet?
Yes. The NDPA applies to the personal data, not to the sophistication of the tool. A spreadsheet of applicants needs the same lawful basis, privacy notice, minimisation and retention discipline as any hiring platform.
What if my AI vendor stores data outside Nigeria?
Cross-border transfers are permitted but conditioned, so the vendor needs to be able to tell you where data goes and on what basis. Ask before you sign, get it into the data processing agreement, and treat an evasive answer as the answer.
Go deeper
- →Can I use Google Forms to collect job applications?
- →How do I screen hundreds of job applications quickly?
- →What is the best AI recruitment software in Nigeria?
- →Tezera pricing
Everything else we have written like this sits on the answers index.
AI that gathers the evidence, while you make the decision
Tezera scores every applicant against criteria you define, shows the evidence behind each score, and keeps every candidate visible so a person signs off the call. Built for the way the NDPA expects screening to work.
See how Tezera screens