Data Protection In Nigeria; Impact On Open Banking Regulation

By Aderonke Alex-Adedipe and Eustace Aroh

Introduction

The rapid growth of finance and technology (fintech) companies in the last decade have been necessitated by consumers’ needs for faster and more convenient financial services. These needs continue to evolve over time and traditional financial institutions struggle to keep up. Open banking offers financial institutions who have access to information of customers (“Providers”) the opportunity to share such information with other financial institutions (“Consumers”) to keep them aware of those needs and enable them offer optimum services.

In our previous article, we highlighted the provisions of the recent Central Bank of Nigeria’s (CBN) Regulatory Framework for Open Banking in Nigeria (“Framework”). In today’s article, we consider specifically, the implication of data sharing under the Framework in light of the Nigeria Data Protection Regulation 2019 (NDPR).

NDPR
The NDPR was issued by the National Information Technology Development Agency (NITDA) in 2019 to regulate the collection, processing and storage of personal data. Personal data is information relating to an individual who can be identified, directly or indirectly, in particular by reference to an identifier. It includes a name, address, a photo, an email address, bank details, medical information, IP address, IMEI number, IMSI number, SIM, and others.

Due to the fact that the damage an individual may suffer in the course of breach of some personal data may be higher, data such as ethnic and racial information, religious beliefs, biometric and health information are categorized as sensitive data. These data must, therefore, be subject to a higher level of protection. Although the NDPR does not classify financial data as sensitive data, financial institutions have access to a number of sensitive data such as ethnicity and biometrics.

Applicable Personal Data
Under the Framework, four types of data qualify for the open exchange of data. These are Product Information and Service Touchpoints (PIST), Market Insight Transactions (MIT), Personal Information and Financial Transaction (PIFT), Profile, Analytics and Scoring Transaction (PAST). Only the PIFT and PAST, however, involve the sharing of personal data of consumers amongst participants.

The PIFT deals with the sharing of customer’s information provided during the Know Your Customer (KYC) process and information of the customer’s transactions such as account balance, payments, loans, recurring transactions etc. The PAST involves the sharing of information on the customer which analyses, provides scores and gives an opinion on customer behaviour (profiling).

Safeguards of the Framework
The Framework stipulates a number of security standards and protocols with respect to sharing of personal information over the Application Programming Interface (API) as it relates to authentication, authorisation, encryption, and secure hosting of data. The Framework also provides for a risk management system for each participant to, among others, track the risk of data sharing with other participants, comply with data privacy laws such as the NDPR, and report such associated risks to the CBN.

Consent
Irrespective of the data protection requirements under the Framework, the Framework specifically requires participants to comply with all extant laws on data privacy such as the NDPR and the NDPR Implementation Framework. Under the NDPR, before personal data of a customer can be used for a purpose different from that which it was initially given, the data controller, (in this case, the financial institution) is required to inform the customer of:

  1. the purpose for which the data was originally collected;
  2. if there is any connection between the original purpose and the proposed purpose;
  3. the possible impact of the new processing on the data subject; and
  4. the existence of security safeguards to protect the data.

The Framework further requires participants to list the specific rights which customers may grant to the participants and obtain the consent of the customer for each right separately.

Providers are also expected to ensure that customers revalidate their consent annually or after 180 days in cases where the services of the provider have not been used.

Conclusion
While the Framework seeks to support innovation in the Nigerian financial sector, participants of the open exchange of data are expected to reassess their data privacy practices to ensure they meet data compliance requirements of the NDPR and the Framework.

THE REGULATION OF OPEN BANKING IN NIGERIA

By Seun Timi-Koleolu and Praise Adetunmibi
Introduction

The Banking sector worldwide is undergoing major changes and the key drivers of these change are You and I. In today’s world (described as the Experience Economy by Pine and Gilmore, Harvard Business Review 1998), we all want easier, seamless and personalised digital banking experiences.

One way banks in the United Kingdom and other countries are meeting this need is with the use of Open Banking. Open Banking is the banking practice that grants third-party financial service providers access to consumer banking transactions and financial data through the use of Application Programming Interfaces (APIs). Such access must be only to the extent approved by customers.

It is expected that with Open Banking, customers would: (i) view and manage their various bank accounts from one centralized location; (ii) grant easy access of account information to creditors when applying for a loan rather than gathering reports from various banks; (iv) have easier accounting processes; and (v) enjoy competitive banking rates, amongst other benefits.

In view of the foregoing and with a view to enhance financial inclusion, improve competition in the financial services space and promote efficient services, the Central Bank of Nigeria (CBN) on the 17th day of February 2021, issued the Regulatory Framework for Open Banking in Nigeria (“Framework”).

In this article, we have highlighted some of the key provisions of the Framework.

1.Scope – The Framework applies to banking and other related services including: (i) payments and remittance services; (ii) collection and disbursement services; (iii) deposit-taking; (iv) credit; (v) personal finance advisory and management; (v) credit ratings/scoring; (vi) leasing/hire purchase; and (vii) mortgages.

2.The Participants – The Framework regulates the following 4 Participants in Open Banking: (i) The Providers (who use API to provide data or a service to another participant); (ii) The Consumers (who uses API released by the providers to access data or service); (iii) The Fintech companies (they may be Providers or API Users; in such instance, they assume the responsibilities of the role they play at any point in time); (iv) the Developer Community (individuals and entities that develop APIs for participants based on requirements). The responsibilities of each of the Participants are set out in the Framework.

3.The Regulator – Though not listed as a Participant, it is pertinent to note that the CBN is the primary regulator of Open Banking in Nigeria. The CBN is to be responsible for the maintenance of an Open Banking Registry and the development of the Common Banking Industry API Standards. These Standards are to be developed within 12 months of issuance of the Framework.

4.Categories of Financial Data that can be shared through APIs – The Framework divides data and services that can be shared through APIs into four broad categories and defines the risk level associated with each category.

S/N Data and Service Category Risk Rating Participants who can access this data
i. Product Information and Service Touch Points – includes data on products provided by Participants to their customers and the access points e.g. ATM/POS/Agents locations, website/app addresses, fees, rates etc. Low All Participants (including participants without licences and those in the CBN Sandbox).
ii. Market Insight Transactions (MIT) – this includes data exchanged for the purpose of gathering statistics of products, services and segments. Such information must not be associated to any individual, customer or account. Moderate All Participants (as above).
iii. Personal Information and Financial Transaction (PIFT) – this includes data at an individual customer level either on general information on the customer (e.g., KYC data, total number of accounts held, etc) or data on the customer’s transaction (e.g., balances, bill payments, loans, recurring transactions on customer’s accounts, etc). High These can be accessed by Participants in the CBN Sandbox; licenced Payment Service Providers and other financial institutions; and Deposit Money Banks.
iv. Profile, Analytics and Scoring Transaction (PAST) – this includes data of a customer that analyses, scores or gives an opinion on the customer e.g., credit score, incoming ratings etc. High and Sensitive These can only be accessed by licenced Payment Service Providers and other financial institutions; and Deposit Money Banks.

5. Customer Protection – The implementation of Open Banking is hinged on the explicit consent of the customers/end users of financial products. The Framework mandates Participants to obtain the consent of customers in the customer’s preferred language and to ensure the security of financial data of such customer.

6. Liability for Misuse of Data – Participants and their partners would be jointly liable for any loss occurring to the customer as a result of data sharing; save for where the Participant can prove wilful negligence or fraudulent act against the customer.

Conclusion

As earlier stated, there are various benefits attributable to Open Banking including more ease in banking transactions. There is, however, a major risk of data breach or the misuse of consumer data. It is imperative that data protection regulations are properly implemented in Nigeria to avoid grave financial losses to consumers.

Data Protection Compliance Organisations and Legal Advisers1 will be expected to play a major part in supporting Participants and regulators in protecting consumers, as Open Banking develops in Nigeria.

PROHIBITION OF CRYPTOCURRENCY TRANSACTIONS BY THE CENTRAL BANK OF NIGERIA

By Aderonke Alex-Adedeipe and Olawale Atanda

On the 5th of February 2021, the Central Bank of Nigeria (CBN)[i] released a letter addressed to banks and other financial institutions which stated that dealing in cryptocurrencies and facilitating payment for cryptocurrency exchanges are prohibited. The CBN further instructed all banks and other financial institutions to identify individuals or entities who transact in cryptocurrency or operate cryptocurrency exchanges and close the accounts of such persons or entities.

Not surprisingly, the letter elicited major concern amongst the public with many concerned about the potential negative effect it could have on Nigeria’s growing cryptocurrency market and innovation in the fintech industry.

In response, the CBN issued a press release (the “Press Release”) on the 7th of February 2021, addressing its earlier directive and providing reasons for its prohibition of cryptocurrency transactions by banks and other financial institutions.

In this article, we shed light on the directive of the CBN, its effect on cryptocurrency trading in Nigeria, and the Securities and Exchange Commission’s (SEC) stance on cryptocurrency in Nigeria.

What are the Justifications for the Prohibition of Cryptocurrency Transactions?

The CBN stated in the Press Release that cryptocurrencies are issued by unregulated and unlicensed entities and as such, the use of cryptocurrencies in Nigeria contravened existing law as they are not legal tender. It also identified the anonymity of cryptocurrency as an issue. It stated that anonymity and the lack of KYC made it susceptible to illegal use such as money laundering and the financing of terrorism. Another justification was the volatility of cryptocurrencies which it said has threatened the stability of financial systems in other countries.

The Effect on Cryptocurrency Trading in Nigeria

Nigeria has the second largest Bitcoin market in the world with over $500 million worth of Bitcoin traded over the last five years. The CBN’s directive on cryptocurrency transactions will understandably have an effect on the cryptocurrency market in Nigeria as it essentially prevents traders from buying cryptocurrencies with their credit/debit cards issued by Nigerian banks or receiving proceeds of cryptocurrency sales from exchanges which facilitate the buying and selling of cryptocurrency.

It appears However some exchanges have found a way around the restriction by switching to peer-to-peer trading which enables individuals buy or sell cryptocurrency from individual traders as opposed to the exchanges. In effect, this does away with the need for exchanges to operate settlement accounts in Nigerian banks.

In response to the CBN’s directive, banks have begun to identify and deactivate the account of individuals with inflows/outflows from/to cryptocurrency exchanges. It is unclear if affected individuals would be able to reopen accounts with these banks in future.

SEC’s Intention to Regulate Cryptocurrencies

On September 14 2020, the SEC issued a statement[2] announcing its intention to regulate “digital assets” which includes cryptocurrencies. In light of the CBN’s directive, the SEC faced calls to clarify whether there was a contradiction in the policies of the two regulators.

Subsequently, on February 11 2021, the SEC issued a statement stating that it would partner with the CBN to analyse and better understand the identified risks of cryptocurrency to ensure that appropriate regulations are put in place if cryptocurrency transactions are allowed in future.

Conclusion

The CBN’s decision on cryptocurrency has also attracted attention from the highest levels of government. On the 11th of February, the Nigerian Senate deliberated on the CBN’s directive, with some senators expressing reservations about the ban on cryptocurrency transactions.The Senate thereafter resolved to invite the CBN Governor to give a briefing on the actions of the CBN.

More interventions like this may be seen as stakeholders deliberate on the potential far-reaching effects of the CBN’s stance on cryptocurrency in Nigeria

 

[i] Pavestones has written several articles on CBN regulations and licenses. You can view them at https://pavestoneslegal.com/tag/cbn/

[2] Pavestones wrote on the statement here https://pavestoneslegal.com/regulation-of-cryptocurrencies-and-other-digital-assets-in-nigeria/

 

CONTACTLESS PAYMENT METHODS – THE REGULATION OF QUICK RESPONSE (QR) CODES IN NIGERIA

By Seun Timi-Koleolu and Eustace Aroh

Introduction

A cashless world was hard to imagine in the 80s and 90s (at least for most of us). It was unimaginable for you to successfully make payments, without cash, a debit or a credit card. What exactly were you to use then?! Right before our eyes, the world began to change, the mobile phone became more than a phone, it became your everything; your notepad, your office, your camera and your payment device (with the use of Quick Response [QR] Codes and Near Field Communication [NFC] tags).

The use of QR Codes as a payment method was introduced by Alipay in 2011 and became a widely used method of payment in China. NFC tags (which are chips built into smartphones) were used in countries like the United Kingdom first.

In Nigeria, QR Codes as a payment method is gradually gaining traction. Fintech companies such as Paystack and Flutterwave now offer sellers and service providers the ability to receive payment by generating and printing or sending a QR Code to their customers even over social media platforms such as Facebook. Many of the traditional financial institutions (such as First Bank and Guaranty Trust Bank) have updated their mobile applications to enable Customers utilize QR Codes as a payment method.

To properly regulate the use of QR Codes as a payment means in Nigeria, the Central Bank of Nigeria (CBN) on January 13, 2021, issued a Framework for QR Code Payments in Nigeria (“Framework”). We have highlighted some salient provisions of the Framework below.

Who are the Participants?

The major participants to a QR Code transaction as stated in the Framework are:

  1. The Merchant – this is the store owner, seller or service provider that has requested for payment through a QR Code.
  2. The Customer – this is the individual who is to pay the Merchant using the QR Code.
  3. The Issuer – this is the financial institution of the Customer.
  4. The Acquirer – this is the financial institution of the Merchant.
What are their Obligations?
  1. Where a Merchant elects to receive payment through QR Codes, he can only display QR Codes approved in Nigeria.
  2. The Merchant is also expected to comply with all extant CBN regulations and the rules of the Acquirer.
  3. The Customer is expected to use the QR Code application (provided by its financial institution i.e. the Issuer) without modifications and adhere to any security protocol of the Issuer.
  4. The Issuer is required to provide the Customer, upon request, with a QR Code Payment application that complies with the QR Code regulations; and ensure that all Customers update the application within 14 days of deployment of an update or patch.
  5. Issuers are also required to send a quarterly risk management assessment report to the Director, Payments System Management Department, CBN.
  6. The Acquirer is expected to ensure the proper use of the QR codes at the Merchant’s location or platform; and ensure the technology and protocol used for QR code conforms with the QR Code payment regulations.
  7. The value of each QR Code transaction must be delivered by the Acquirer to the Merchant within a day after the transaction.
  8. Both the Acquirer and the Issuer are to ensure the security of their system in such transactions.
  9. Where a switch or payment service provider is involved, they are required to facilitate interoperability between the Issuer and Acquirer and comply with the Framework and other CBN regulations on electronic payments.
Other Provisions of the Framework

The Framework adopts the Merchant-presented mode specification for Nigeria (as opposed to the customer-presented mode) which means the Merchant has to present the QR Code for buyers to scan in order to conclude the payment transaction.
Please also note that the Nigeria Inter-Bank Settlement System Plc (as the Payment Terminal Service Aggregator) is to certify QR Codes, the payment applications, updates and patches.

Conclusion

Payment with the use of QR Codes in Nigeria is gradually becoming the preferred choice for businesses in Nigeria as it is an affordable alternative to utilizing POS solutions. The issuance of the Framework is a positive step to encourage innovation in financial services and promote the secured use of QR Codes in Nigeria