REGULATION OF CONTACTLESS PAYMENTS IN NIGERIA

By Seun Timi-Koleolu and Feyijuwa Akinyanmi

DOWNLOAD PUBLICATION 

Introduction

In our previous article, we examined the Framework issued by the Central Bank of Nigeria (“CBN”) for the regulation of Quick Response Code Payments (a form of contactless payment) in Nigeria. To further protect the general public and drive innovation, the CBN has issued an Exposure Draft of the Guidelines for Contactless Payments in Nigeria (“Draft Guidelines”).

The Draft Guidelines stipulates the minimum standards and requirements for the operation of contactless payments in Nigeria and specifies the roles and responsibilities of stakeholders involved in contactless payments in Nigeria.

Our newsletter highlights notable provisions of the Draft Guidelines which issuers and acquirers of contactless payments should note.

1.What is Contactless Payment?

Contactless payment refers to a method of payment which enables consumers  to make payment for goods and services by tapping a contactless payment enabled credit card, smart card or device over a contactless- enabled payment terminal. It provides an easy, convenient and efficient cashless option for making payment. Examples of  instruments which can be used for contactless payment include,  contactless enabled pre-paid, debit and credit cards,  key fobs, mobile electronic devices, wearable devices etc.

2.What Financial Institutions are Affected by the Draft Guidelines?

The Draft Guidelines are applicable to financial institutions  that are parties to contactless payments. These include: acquirers; issuers; payment schemes; switching companies; Payment Terminal Service Providers (PTSPs); Payment Terminal Service Aggregators (PTSAs) e.t.c.

3.What are the minimum standards for compliance applicable to stakeholders in contactless payment transactions?

The Draft Guidelines require the financial institutions listed in 2 above, whose activities involve the processing and storage of customer information to ensure that their terminals, applications and other systems used for processing customers’ information are compliant with the following minimum standards: (i) Payment Application Data Security Standard (PA DSS); (ii) Payment Card Industry Pin Entry Device PCI PED; (iii) Payment Card Industry Data Security Standard (PCI DSS);(iv)Advanced Encryption Standards (AES); (v) ISO 27001; (vi) and other standards as may be specified by the CBN from time to time.

3.What are the Roles and Responsibilities of Acquirers and Issuers with respect to Contactless Payments?

The Draft Guidelines precludes institutions that are not licensed by the CBN from acting as acquirers or issuers to contactless payment transactions.  Permitted acquirers and issuers that engage in contactless payment are required to ensure that all contactless enabled applications, instruments, and devices deployed have been certified to process contactless payments by the CBN.

The Draft Guidelines also requires issuers and acquirers to ensure that the contactless payment instruments are neutral i.e brand agnostic.

Please note also that permitted issuers are required to only activate contactless payments on the instruction and consent of its customers.

4.What is the Transaction Limit for Contactless payment?

The Draft Guidelines provide that the CBN would determine the transaction and daily limit for contactless payments. Payments below the limit would be consummated without the need for customers verification, while payments above the limit will require customers verification in form of personal identification number, mobile code, or biometrics identifier.

Conclusion

Contactless payment has long before now been accepted as a preferred mode of payment in  technologically advanced climes. It is, therefore, commendable to see that that the CBN has formally accepted contactless payments as a mode of payment in Nigeria.

It is however important to note that the Draft Guidelines is silent on the transaction and daily limit for contactless payments. As the Guidelines are still in draft form, we expect that this grey area will be clarified  in the final guidelines as this may determine the usefulness and the level of acceptance  of contactless payments in Nigeria.

NIGERIA DATA PROTECTION BUREAU; COMPLIANCE DIRECTIVES

By Aderonke Alex-Adedipe and Arisoyin Adedolapo

DOWNLOAD PUBICATION

In February 2022, the Nigeria Data Protection Bureau (the “NDPB”), was established by the Federal Government as the principal data protection regulatory body to implement the objectives of the Nigeria Data Protection Regulation 2019 (“NDPR”), replacing the National Information Technology Development Agency (NITDA).

In furtherance of its objectives, the NDPB on October 5, 2022, issued a compliance directive (the “Directive”) to organisations that collect and or process personal data of Nigerians. (“Regulated Entities”). The Directive mandates Regulated Entities to comply with its provisions on or before November 25, 2022, in order to be included in the National Data Protection Adequacy Programme (“NADPAP”) Whitelist.

This article highlights the compliance requirements of the NDPB as provided in the Directive.

What is the National Data Protection Adequacy Programme (NADPAP)?

The NADPAP is a programme established by the NDPB to create more awareness on the responsibilities of data controllers/processors under the NDPR.  The NDPB through this programme seeks to put together a Whitelist of Regulated Entities in Nigeria which are compliant with the requirements of the NDPR. These Regulated Entities will be published on the NDPB website, in major newspapers, and will be shared with local and international establishments to serve as a reference in relevant transactions.

Regulated Entities are expected to comply with the requirements of the Directive on or before November 25, 2022, to be included in the NDPB’s publication.

What are the Compliance requirements under NADPAP?

i. Notification: Regulated Entities should notify the NDPB on or before November 25, 2022, of the technical and organisational measures it is taking to ensure data privacy and data protection.

ii. Key steps to be taken to avoid legal liabilities: The Directive highlights some key steps to be taken by Regulated Entities in order to avoid legal liabilities and ensure they meet up with the minimum required standard of care required under the NDPR. Regulated Entities are required to: (i) read and understand the NDPR; (ii) develop and implement a privacy policy that is consistent with the NDPR; (iii) notify their employees, customers, and online visitors of their privacy policy; and (iv) designate at least one or two members of staff as Data Protection Contacts (DPCs).

iii. Penalties attached to non-compliance: The Directive reiterates the resulting penalties for non-compliance with the NDPR, which include: payment of a fine of 2% of the annual gross revenue of the preceding year or 10 (ten) million naira (whichever is greater), in the case of a data controller dealing with more than 10,000 (ten thousand) data subjects, and payment of a fine of 1% of the annual gross revenue of the preceding year or 2 (two) million naira (whichever is greater), in the case of a data controller dealing with less than 10,000 (ten thousand) data subjects.

iv. Oversight: Regulated Entities are required to ensure that their service providers (i.e agents, licensees, contractors etc.) comply with the NDPR.

v. Free induction course: Regulated Entities are expected to forward the names of their DPCs (not more than three) to the NDPB for a free induction course in Data Protection Regulation Compliance for Nigeria and the ECOWAS via email to info@ndpb.gov.ng.

Conclusion

From the antecedents of the NDPB since its establishment, it is evident that its mandate to ensure compliance with the NDPR has been prioritized. It is, therefore, important for all Regulated Entities to liaise with relevant Data Protection Compliance Organisations to ensure full compliance with the provisions of the NDPR and avoid the penalties of non-compliance.

 

REGULATORY UPDATE: PROPOSED CBN GUIDELINES FOR THE REGULATION OF REPRESENTATIVE OFFICES OF FOREIGN BANKS IN NIGERIA

By Seun Timi-Koleolu and Sharon Okpo

DOWNLOAD PUBLICATION

On October 12, 2022, the Central Bank of Nigeria (“CBN”) released a draft of the Guidelines for the Regulation of Representative Offices of Foreign Banks in Nigeria (“Draft Guidelines”). This is further to the powers of the CBN under the Banks and Other Financial Institutions Act, 2020 (“BOFIA”) to mandate foreign banks to seek the prior approval of the CBN before operating in representative offices in Nigeria.

We have highlighted below some notable provisions of the Draft Guidelines that may be useful to foreign banks that wish to operate a representative office in Nigeria.

  1. What is an Approved Representative Office of a Foreign Bank (“Representative Office”)?

Under the Draft Guidelines, Representative Office is a liaison office of a foreign bank (the “Foreign Bank”) licensed by the CBN to market the products and services of the Foreign Bank and serve as liaison between the Foreign Bank and local banks, other financial institutions, private companies, and the general public.

  1. Which Foreign Entities will the Draft Guidelines apply to upon Issuance?

Upon issuance, the Draft Guidelines will apply to the following categories of institutions:

  1. a bank licensed under a foreign law with its registered head office outside Nigeria;
  2. a financial institution licensed under foreign law and whose primary business includes receiving deposits, granting loans and provisions of current and savings accounts; and
  3. any foreign-based and foreign-owned operating bank/financial holding company that owns controlling interests in one or more banks or institutions whose primary business is similar to those of a bank.
  1. What are the Permitted and Prohibited Activities of a Representative Office?

The Draft Guidelines provides a list of activities which a Representative Office is permitted to carry out in Nigeria. Some of the activities listed under the Draft Guidelines include:

  1. marketing the products of the Foreign Bank or its licensed affiliate resident outside Nigeria;
  2. serving as a liaison between a foreign bank and local banks, customers of the Foreign Bank in Nigeria and other private institutions;
  3. pursuing business opportunities for the Foreign Bank or its affiliate regarding provision and/or syndication of foreign currency denominated loans;
  4. assisting exporters in Nigeria with information related to the laws and markets of target countries where the Foreign Bank or its affiliate has a subsidiary; and
  5. connecting exporters in Nigeria with potential customers in jurisdictions where the Foreign Bank operates.

It is important to note that Representative Offices are expressly prohibited from:

  1. providing services designated as banking business in Nigeria;
  2. providing or engaging in commercial or trading activity that may lead to the issuance of invoices for services rendered;
  3. accepting orders on behalf of the Foreign Bank; and
  4. engaging directly in any financial transaction.

 

4. What are the Licensing Requirements for a Representative Office?

Foreign banks that wish to establish a Representative Office in Nigeria, are required to apply to the CBN for a license. The procedure for obtaining the license is in three stages, as highlighted below.

  1. Approval-in-Principle Stage: the applicant is required to submit a formal application to the Governor of the CBN accompanied with all the required documents as listed in the Draft Guidelines including a valid memorandum of understanding between the CBN and the home supervisory authority; a no objection letter (or approval) from the home supervisory authority consenting to the establishment of a representative office; a detailed business plan or feasibility report; evidence of name reservation with the Corporate Affairs Commission; and evidence of payment of the application fee.
  2. Final Approval Stage: within 3 months of obtaining the Approval-in-Principle, the applicant is required to apply for the grant of a final license by the CBN. The application should be accompanied with the incorporation documents; names, addresses and curriculum vitae of the management staff; copies of letters of offer and acceptance of employment of the management staff; evidence of payment of license fee amongst other documents.
  3. Pre-licensing Inspection Stage: prior to the grant of the final license, the CBN will conduct an inspection of the premises and facilities of the proposed representative office. This inspection will include a meeting with the Board members and management officials of the Representative Office, and a check of the physical structure of the infrastructure of the office.

Please note that upon receiving a license from the CBN, Approved Representative Offices will be required to observe reporting and operational requirements as provided under the Draft Guidelines after licensing. The CBN is also to have unfettered access to internal systems, documents and premises of the Representative Offices to ensure compliance with the Guidelines and other applicable laws and regulations at all times.

As the Guidelines are still in draft form, we will update you when the approved Guidelines are issued.

REGULATION OF COMMUNICATIONS EQUIPMENT IN NIGERIA: REVIEW OF THE DRAFT TYPE APPROVAL REGULATIONS, 2022

By Aderonke Alex- Adedipe and Feyijuwa Akinyanmi

DOWNLOAD PUBLICATION

Introduction

The primary regulator of the telecommunications industry, the Nigerian Communications Commission (“NCC”) has published a draft of its proposed Type Approval Regulation, 2022 (“Draft Regulations”); and the draft Type Approval Business Rules (“Draft Business Rules”) which seek to replace the extant Type Approval Regulations and Guidelines.

The Draft Regulations set out the requirements for the approval of communications equipment for connection to communications networks in Nigeria.  The Draft Business Rules on the other hand, stipulate the procedure for the type approval process which providers of communications services and manufacturers or suppliers of communications equipment (“Equipment Holders”) must comply with, to use or supply communications equipment in Nigeria.

Today’s newsletter briefly highlights some of the major introductions contained in the Draft Regulations and the Draft Business Rules.

1.Introduction of Provisional Type Approval for Communication Prototypes

To encourage research and development, the Draft Regulations provide for provisional type approvals for communication prototypes for a period not exceeding 6 months. To apply for a provisional type approval, the applicant is required to submit documents that provide the NCC with information on the: a) purpose and duration of the test or research; b) geographic location of the test; c) units of the prototype to be tested and their technical details; and d) details of the proposed recipients of the prototype.

Where the applicant does not wish to apply for a final type approval after the expiration of the provisional type approval, the applicant is required to ensure that all deployed units of its prototype are withdrawn from Nigeria.

2. Application for a Type Approval Modification Certificate

The Draft Regulations require recipients of a type approval to apply for a type approval modification certificate where certain changes to a type approved communication equipment: a) may affect the equipment’s compliance with applied standards to which it had already been tested and validated; or b) may affect a network interface or affect any essential requirements of the equipment in terms of safety, electromagnetic compatibility or radio frequency behaviour. A type approval modification certificate will also be required where the version of the software or firmware of the communication equipment has been changed in a way that affects its basic functionality and information recorded in the type approval register.

3. Introduction of a Device Management System

The Draft Regulations and the Draft Business Rules seek to introduce a Device Management System (“DMS”) and the registration of communications equipment. Although the Draft Regulations and Draft Business Rules do not provide explicit information on the DMS, the DMS is a Central Equipment Identity Register that keeps records of devices (through their International Mobile Equipment Identifiers (IMEI)) and manages their access to mobile networks. It is expected that the introduction of the DMS will reduce phone theft and curb the illicit trade of mobile devices in the country.

4.Introduction of an Expiration Period for Type- Approval Applications

The Draft Business Rules now requires persons applying to the NCC for type approval to submit all requested application documents within sixty (60) days from the date of submission of its application.  Where an applicant fails to comply with the above, its application will be deemed abandoned and the applicant will be required to submit a new application to the NCC.

5. Revocation of Type Approval

In addition to other reasons for the revocation of a type approval (as stated in the extant Type Approval regulations), the Draft Regulations permit the NCC to revoke a type approval where the type approval is obtained by fraud or misrepresentation; or where the communications equipment constitutes a threat to national security or public safety; or has a defect that has become known or which was reported to the NCC or any other competent authority.  Upon revocation, the Equipment Holder is required to modify or dispose of all affected devices in the supply chain.

Conclusion

The introduction of the Draft Regulations and Draft Business Rules is commendable and in line with international best practices and current realities in the Nigerian technology and communication sector.  In view of these, we recommend that all Equipment Holders familiarize themselves with potential developments which may arise upon release of the final version of the Draft Regulations and Draft Business Rules.