UPDATE ON REGULATION OF DIGITAL ASSETS IN NIGERIA: SOME LESSONS FROM SWITZERLAND

By Aderonke Alex-Adedipe and Baraebibai L. Ekpebu

 

DOWNLOAD PUBLICATION

Introduction

Generally, skepticism expressed about cryptocurrencies stems from their classification as high-risk assets’’ which are extremely volatile and speculative in terms of price.[1] The main reason for the existence of Blockchain Technologies is their independence from financial endorsement and their universal nature. This is why the regulation of cryptocurrencies remains an arduous task for financial authorities.

Following the recent announcement of the ban on the dealing or facilitation of cryptocurrency transactions by Nigerian financial institutions by the Central Bank of Nigeria (CBN)[2], the Securities and Exchange Commission (SEC) also announced on 11th February 2020, that its previous decision to regulate cryptocurrency investments in Nigeria has now been suspended. In light of these developments, this article aims to shed light on possible options to aid the crafting of a regulatory regime for blockchain technologies in Nigeria.

There are indeed some valid concerns about cryptocurrency transactions. For instance,  the fact that they create new opportunities for criminals and terrorists to launder their proceeds, or finance their illicit activities.[3] Notwithstanding, the Swiss have built a system that innovatively utilizes pre-existing Swiss law and novel legislation, to regulate the activities of blockchain service providers in Switzerland.

Nigeria is responsible for more cryptocurrency trading than most countries and is currently rated as the third highest globally for trading volumes in cryptocurrency. It is therefore desirable, that a robust regulatory regime exists to govern these transactions, address negative tendencies, and in effect, strengthen the financial services industry and the Nigerian economy in general. For these reasons, it is essential to examine some key aspects of Swiss Blockchain Laws to understand the methodology employed to provide a grounded basis for digital asset exchange and tokenization, while simultaneously addressing the issue of digital currency money laundering.

The Swiss Approach

The Swiss Financial Market Supervisory Authority or ‘FINMA’’ recognises the tendency for block-chain business models to sidestep existing regulations. To put a check on such tendencies, Swiss authorities have successfully placed blockchain service providers under the ambits of the Swiss Anti-Money Laundering Act.[4] Blockchain service providers in Switzerland are mandated to verify all their customers’ identities, monitor business relationships based on risk level, and report to the ‘Money Laundering Reporting Office Switzerland (MROS), where there are reasonable grounds to suspect money laundering. All Virtual Asset Service Providers who intend on doing business in Switzerland are required to apply for a license from FINMA.

The new Swiss laws define ‘exchange digital securities’ and stipulate the legal procedure for the seizure of digital currency assets in bankruptcy proceedings. The roles of digital currency trading platforms and their legal standing on digital securities are also well clarified.

FINMA has currently granted licenses to several financial institutions to carry out cryptocurrency trading activities. This has served to promote distributed ledger technology and incorporate crypto assets into portfolios and Exchange-Traded Funds.

Switzerland is noted to have a comprehensive regime for Initial Coin Offerings (ICOs) which are also regulated under money laundering laws, terrorist financing laws, securities trading laws, banking laws and, Swiss collective investment scheme legislation.

Residents of the Canton of Zug in Switzerland (referred to as the “Crypto Valley”) can now pay their taxes in bitcoin and cryptocurrencies up to 100,000 CHF, under the supervision of the Swiss Federal Tax Administration (SFTA).[5]

Interestingly, like the Nigerian position, cryptocurrencies are still not classed as a legal tender in Switzerland, neither are they considered to be “money” for reasons that their intangible nature stops them from being classified as a “thing” under Swiss civil law.[6]

Conclusion

From the foregoing, it is evident that a technology-neutral legislative approach is needed and can be developed in Nigeria. To achieve this, active steps need to be taken towards streamlining regulations on insolvency, financial market, banking, collective investment, and anti-money laundering into a legal framework for the regulation of cryptocurrency transactions and investments in Nigeria. This is likely to trigger an unprecedented boost in the Nigerian economy which has continuously suffered from currency devaluation over the years.

 

[1] Mario Draghi, President of the ECB, Introductory Statement and Closing Remarks at the European Parliament Plenary Debate on the ECB Annual Report for 2016 (Feb. 5, 2018), https://www.ecb.europa.eu/press/key/date/ 2018/html/ecb.sp180205.en.htmlarchived at http://perma.cc/M6WX-T3RR.

[2] Aderonke Alex-Adedipe and Eustace Aroh, (Pavestoneslegal September 23, 2020) Regulation of Cryptocurrencies and Other Digital Assets in Nigeria accessed 24 March 2021

[3] CGMF’s report, National Risk Assessment: Risk of money laundering and terrorist financing posed by crypto assets and crowdfunding, October 2018

[4] Federal Council report – Legal framework for distributed ledger technology and blockchain in Switzerland, December 2018

[5] Tanzeel Akhtar, (Nasdaq, February 18, 2021)  Switzerland’s ‘Crypto Valley’ Has Started Accepting Bitcoin, Ether for Tax Payments accessed 24 March 2021

[6] Mueller / Reutlinger / Kaiser, p. 86 et seq .; Maurenbrecher / Meier, protection of users of virtual currencies under insolvency law; Eggen, Chain of Contracts – A private law dispute with Distributed Ledgers, AJP 2017, p.14; Bärtschi / Meisser, Virtual Currencies from a Financial Market and Civil Law Perspective, in: Weber / Thouvenin (ed.), Legal challenges through web-based and mobile payment systems, Zurich 2015, p. 141

 

REGULATION OF USSD SERVICES IN NIGERIA – CHARGES ON FINANCIAL TRANSACTION

By Seun Timi-Koleolu and Feyijuwa Akinyanmi

DOWNLOAD PUBLICATION

Unstructured Supplementary Service Data (USSD) has evolved from being a channel employed predominantly by Mobile Network Operators (Telcos) to one deployed by a broad spectrum of service providers. Most financial institutions have sought the services of different Telcos to deploy unique USSD codes, allowing millions of Nigerians to enjoy basic banking services from the comfort of their homes and without the need for internet connection.

How do USSD codes work?
USSDs are sometimes referred to as “quick codes” or “feature codes”. They are communication protocols that allow customers to send queries or requests and receive solutions simply by dialling a short code that begins with an asterisk (*) and ends with a hash(#) symbol. Some examples of USSDs include GTBank’s *737#, Zenith Bank’s *996#, Ghana Commercial Bank’s *422#, Kenya National Bank’s *625# e.t.c. Practical uses of USSDs in the finance space include the transfer of funds, airtime top-ups, account balance checks, BVN checks etc.

 

Are there any regulations on the use of USSD services for financial transactions?
USSDs for financial transactions are majorly regulated by the Central Bank of Nigeria (CBN) Regulatory Framework for the Use of Unstructured Supplementary Service Data (USSD) for Financial Services in Nigeria, 2018; and the Nigerian Communications Commission (NCC) Guidelines on Short Code Operation in Nigeria, 2011.

Financial institutions who wish to provide USSD services to their customers are required to obtain a letter of no objection or introduction from CBN before being considered for the issuance of the USSD shortcodes by the NCC.

 

How have customers been billed for USSD services?
For over two years now, Telcos and Deposit Money Banks (DMBs) in Nigeria have had prolonged disagreements over the appropriate USSD pricing model for financial transactions. The crux of the issue has been whether the Telcos are to adopt the End User billing model i.e. charging customers directly; or the Corporate billing model i.e. charging the financial institution directly. NCC issued a publication on the 24th  day of July 2020[1], prohibiting Telcos from using the End User billing model and instructing that they employ the Corporate billing model. The basis for this was that granting access to USSD channels was a service delivered by Telcos to financial institutions and not customers.

 

What are the current directives by the CBN and NCC on USSD billing?

On the 12th  day of March 2021, the Association of Licensed Telecommunication Operators of Nigeria (ALTON) threatened to withdraw USSD services from DMBs until the ₦42 billion debt they owe for the services is settled[2]. In response to the above, the NCC and CBN on the 16th day of March 2021, issued a joint statement to the effect that DMBs and other financial institutions will be charged a flat fee of N6.98 per transaction; in accordance with the Corporate billing model. The new charge is to be deducted from customers’ accounts by the financial institutions on behalf of the Telcos. Financial institutions are now prohibited from charging customers any other fees for the service.

Conclusion

In response to the above, the joint statement finally brings clarity on how payment is to be made for USSD services and seems to be a win for the Telcos. Although the Corporate billing model appears to have been adopted, customers will ultimately bear the costs. This may adversely affect the popularity of USSD transactions within the general populace, particularly low-income earners.

[1] https://www.ncc.gov.ng/accessible/documents/910-determination-of-ussd-pricing-amended/file

[2]https://www.thisdaylive.com/index.php/2021/03/15/telcos-suspend-withdrawal-of-banks-ussd-services/

SONCAP CERTIFICATE; A REQUIREMENT FOR IMPORTATION OF GOODS INTO NIGERIA

By Aderonke Alex-Adedipe and Eustace Aroh

DOWNLOAD PUBLICATION

1. Introduction
The Standard Organisation of Nigeria (SON) was established by the Standard Organisation of Nigeria Act (No 56) of 1971 with the mandate to set the Standards for manufacturing and sale of products, materials, processes and services amongst others; to certify and provide assistance in the production of quality of goods and services; and improve measurement accuracies and circulation of information relating to standards.

The SON in 2005, introduced the Standards Organisation of Nigeria Conformity Assessment Program (the “Program”) to address the problem of substandard and unsafe products imported into the country. Under the Program, certain imported products[1], are required to be inspected to conform with essential requirements, technical regulations and approved industrial standards before importation into Nigeria.

For convenience and efficiency, the SON accredited some independent firms such as Cotecna, Intertek, SGS, CCIC etc (“Accredited Firms”) to process and issue SONCAP Certificate on behalf of the SON[2].

In this article, we summarise the procedure and steps to obtaining a SONCAP Certificate below.

2. What are the steps to obtaining a SONCAP Certificate?
A Product Certificate (“PC”) is a mandatory requirement for products regulated by the SON. The PC is also a pre-requisite for the issuance of a SONCAP Certificate for imported products. There are three (3) categories of PCs and an importer may make an application based on frequency as described in the table below.
PC type Preference Validity Period

PC type Preference Validity Period
1 Product Certificate one Preferred for one-time importers 6 months
2 Product Certificate two Preferred for occasional importers 1 year
3 Product Certificate three Preferred for frequent importers 1 year

 

3. How should an application for a PC be made?
An application for a PC should be accompanied by the following documents[3];

i. an application form;
ii. an ISO 9001 Certificate of the manufacturer;
iii. a test report of the product from an accredited ISO17025 laboratory[4];

iv. a quality declaration from the manufacturer;
v. a picture of the product or a sample of the product (where the Accredited Firm requests);
vi. all other quality documents available; and
vii. Factory Inspection/Audit (applicable only for PC 3).

4. How long does it take to process a PC?
Provided that all the required information and documentation are satisfactory, the PC will generally applicable issued between three to seven (3-7) days depending on the Accredited Firm.

5. What is the next step after obtaining the PC?
The next step is to obtain an e-Form M[5] required for the clearing of products at the Nigerian port. The PC is used to process the e-Form M on the Nigerian Single window for trade portal or through an authorised dealer (usually a commercial bank). Upon approval by an authorised dealer and registration by the Nigeria Customs Service (NCS), the importer may then proceed to apply for a SONCAP Certificate.
Upon successfully obtaining the e- Form M, the importer may apply for a SONCAP Certificate through one of the Accredited Firms. The SONCAP Certificate is linked to the PC obtained for the product and a particular shipment may or may not be subject to inspection based on the category of the PC obtained as described in the table below.

PC Type Inspection Rate
Product Certificate one 100% inspection rate
Product Certificate two 40% inspection rate
Product Certificate three 20% inspection rate

6. How should an application for SONCAP be made?
To process a SONCAP Certificate, a company will be required to provide the following:

i. SONCAP application/ request for certificate form
ii. A Valid PC for each product;
iii. Tax Identification Number;
iv. Pro forma Invoice; and
v. E-Form M.

7. Conclusion
A SONCAP Certificate is a condition precedent required for the clearance of products at the Nigerian port[1]. This has played a pivotal role in reducing the importation and sale of substandard products in the country. The Program has proven to be a step in the right direction in ensuring the availability of quality products in Nigeria.

 

[1] https://son.gov.ng/soncap_service

[2] These Accredited Firms have offices in several countries across the world.

[3] In some cases, Accredited Firms may request additional information/documentation in respect of certain products.

[4] Where the importer is unable to produce a satisfactory test report, the Accredited Firm shall test the product based on SON standards.

[5] This is used by the Central Bank of Nigeria (CBN) to track and collect import duties.

[6] It is pertinent to note that some products are exempt from the Program pursuant to a SON Circular with reference number SON/SONCAP/EX/Vol. 1/005. These products which include, food, medicine and medical products, chemical products etc, are nonetheless subject to other regulatory requirements.

DATA PROTECTION IN NIGERIA: DISTINGUISHING BETWEEN A DATA CONTROLLER AND A DATA PROCESSOR

By Seun Timi-Koleolu and Praise Adetunmibi

 

DOWNLOAD PUBLICATION

Introduction

In this digital age, data has become a vital asset for both individuals and corporate bodies. It has in fact been regarded as the world’s most valuable resource[1]. The question then is, what is data?

Data can simply be defined as information that has been translated into a form that is efficient for movement or processing[2]. It can be collected, used, shared, measured, analysed, stored and destroyed (data processing). The most common type of data is personal data, which refers to any information related to an identified or identifiable natural person. In Nigeria, the National Information Technology Development Agency (NITDA) through the Nigeria Data Protection Regulation (NDPR)[3], regulates the processing of personal data of Nigerian citizens. Persons who engage in data processing activities can either be Data Controllers or Data Processors.

Under the NDPR, startups, businesses and companies that engage in the processing of personal data of over 1000 Nigerians, are mandated to conduct a detailed annual audit of their data processing activities. This audit is to be conducted by a licensed Data Protection Compliance Organisation (DPCO). Failure to comply with the provisions of the NDPR will result in the payment of a fine of 10 million Naira or 2% of the annual turnover (whichever is greater).

In view of the foregoing, it is useful to understand when you will be considered as a data processor and when you will be considered to be a data controller; for the purpose of complying with the provisions of the NDPR. In this article, we have provided a guide on how to identify each category.

Who is a data controller?

A data controller simply means any person or company that determines “why” data is to be processed and “how” data is to be processed. Most businesses/companies collect the personal data of clients/customers in the course of providing services to them (e.g. by requiring the customers to complete an online or physical, registration form for the service or for the purpose of payment); in all such instances that company/business is a data controller.

Furthermore, where companies/businesses share personal details of their customers, such as names, email addresses, phone numbers to third-party service providers, for various business purposes such as to market their products  (e.g. sharing with a Digital Marketing Agency); or to enhance their service delivery (e.g. sharing with an Information Technology Partner), that company/business remains the data controller in those instances and primarily responsible for the use and protection of the data.

In addition, companies and business owners are data controllers of data they collect in respect of their employees and remain primarily responsible for the use of such data.

Who is a data processor?

Companies/businesses are regarded as data processors when they are involved in the processing of data, on the instruction and on behalf of another person (data controller). Effectively, a data processor cannot act on its own or undertake any data processing activity without the permission of the data controller.

In the scenarios given above, the Digital Marketing Agency and Information Technology Partner are data processors. Also, where a company outsources payroll payment to a third party or other human resource related services, that third party would be seen as the data processor.

Can a data processor be a data controller?

Yes. What distinguishes a data controller from a data processor is control. Where you have control over which data is to be collected and the purpose for which the data is to be collected, you are the data controller. Where all you have is the possession of the data and must act in accordance with the instructions of another person, then you are the data processor.

Where you, however, have both control and possession of data (i.e. the data was given to you by a third party), in such an instance, you act as both a data controller and a data processor.

Conclusion

Under Nigerian law, data controllers and data processors are required to undergo Data Protection Compliance audits and generally adhere to the provisions of the NDPR. Each business should be clear on whether they are handling data in the capacity of a data controller or a data processor as the obligations of a data controller vary from the obligations of a data processor.

If you require clarity as to whether your business would be categorised as a data controller or a data processor, please do not hesitate to contact the team at Pavestones Legal.

[1] The Economist, ‘The World’s Most Valuable Resource is no Longer Oil, but Data’   Economist (6 May 2017) <https://www.economist.com/leaders/2017/05/06/the-worlds-most-valuable-resource-is-no-longer-oil-but-data>

[2] https://searchdatamanagement.techtarget.com/definition/data

[3] To understand more about the NDPR, follow the link to our article https://pavestoneslegal.com/nigeria-data-protection-regulation-2019/