PUBLIC PRIVATE PARTNERSHIP: LEGAL AND REGULATORY FRAMEWORK IN NIGERIA

BY ADERONKE ALEX-ADEDIPE AND EBIKENIYE BEST

DOWNLOAD PUBLICATION

Introduction

Generally, the government is primarily responsible for providing basic social amenities, public infrastructure and utilities to its citizenry. The ability to provide such needs is often impacted by financial constraints. The inability to fulfil these obligations as well as private sector contribution to public infrastructure development and enhancement has therefore birthed the concept of public private partnership. In this article, we define the concept of Public Private Partnership, and discuss some of the key laws and regulations in respect of Public Private Partnerships in Nigeria.

1.What is Public Private Partnership?
A Public Private Partnership (PPP) is a contractual agreement between a public agency (federal, state or local) and a private company. Typically, the terms and conditions of PPPs terms are incorporated into a contract which sets out the mutual agreements and understandings of the parties to establish their obligations, rights and duties. An example of a PPP in Nigeria, is the contractual agreement between The
Federal Airports Authority of Nigeria (FAAN) and Bi-Courtney Aviation Services for the Build Operate and Transfer (BOT) of Murtala Muhammed Airport 2 terminal in Lagos.

2. Why should PPPs be considered?
Some of the reasons why governments execute PPPs for infrastructure and service include;
2.1. To attract private expertise and/or capital investment for infrastructure and service delivery improvements;
2.2. To increase efficiency and use available resources for infrastructure and service delivery more effectively; and
2.3. To reform sectors through a reallocation of roles, incentives and improve accountability.

These are very crucial as in most cases, the government lacks capacity to achieve some of these objectives.

3. What is the Legal Framework for PPPs in Nigeria?
a. The Infrastructure Concession Regulatory Commission (Establishment Etc.) (ICRC) Act of 2005; This is the principal legislation for the regulation of PPP contracts involving Federal Government infrastructure. The Act provides for the participation of the private sector in financing the construction, development, operation or maintenance of infrastructure or development of Federal Government projects through concessions or other contractual arrangements.
b. The National Policy on PPPs: This policy was approved by the Federal Executive Council (FEC) in 2009 and the policy aims to provide a conducive environment for private sector’s involvement in the delivery of infrastructure development services in Nigeria.
c. The Public Procurement Act (PCA), 2007: The Act established the Bureau of Public Procurement (BPP) as the regulatory body responsible for monitoring and overseeing public procurement activities, harmonizing existing government policies and practices by regulating, setting standards and developing a legal framework and professional capacity for public procurement in Nigeria

d. The Fiscal Responsibility Act 2007: This is another relevant legislation which provides for rules to ensure the accountability, transparency and prudence of government in the preparation of budgets and expenditure frameworks.
e. The Debt Management Office Act 2003: This legislation governs all Federal Government loans, borrowings, guarantees and other long-term contingent liabilities.
f. There are also sector-specific legislations and authorities which regulates different services such as; the Electric Power Sector Reforms Act (EPSRA) 2005, which provides a statutory framework for the participation of private companies in electricity generation, transmission and distribution. The Federal Highways Act, which empowers the Minister of Transport to construct federal highways and operate toll gates and collect tolls on the federal highways.

Some state governments also operate their own PPP laws. For instance, the Lagos State Public Private Partnership Law 2011 and the Rivers State Public-Private Participation in Infrastructure Development Law 2009.

4. Which Agencies are Responsible for Regulating PPPs in Nigeria?
a. The ICRC Act established the Infrastructure Concession Regulatory Commission (ICRC) which functions as the regulatory body with the power to amongst others, inspect, provide general policy guidelines, rules and regulations, to take custody of every concession agreement, to ensure compliance with the provisions of the Act, to ensure efficient execution of any concession agreement or contract executed between the Federal Government and private sector. The ICRC also guides the Ministries, Departments and Agencies (MDAs) in structuring PPP transactions. Importantly, only federal bodies undertaking federal projects fall under the scope of the ICRC.
b. The Bureau of Public Enterprises (BPE) established by the PCA is also responsible for the
implementation of full or partial privatization and commercialization of the list of public enterprises set out
in the PCA. The ICRC and BPE collaborate when assets specified within the PCA are required to be
developed as PPPs.

In addition, the EPSRA established the Nigerian Electricity Regulatory Commission (NERC) to regulate the
activities in the electricity sector.

Conclusion

While there have been a number of notably successful PPP infrastructure projects across Nigeria, research also indicates that there is a continuous decline in PPP projects in Nigeria. To encourage private sector participation in public projects, it is important that the Government considers the development of certain areas within the Nigerian business environment including; (i) expedited hearings and a trusted judicial system, (ii) clarity on economic and fiscal policies and (iii) ease of doing business. Focusing on these. The Fiscal Responsibility Act 2007: This is another relevant legislation which provides for rules to ensure the accountability, transparency and prudence of government in the preparation of budgets and expenditure frameworks.

CHECKLIST FOR FILNG DATA PROTECTION COMPLIANCE AUDIT RETURNS IN NIGERIA

BY SEUN TIMI-KOLEOLU AND SHARON OKPO

DOWNLOAD PUBLICATION

Introduction

With the beginning of a new year comes the requirement to adhere to various regulatory and compliance provisions governing their sector generally and specifically. One of such compliance requirements is the filing of data protection compliance audit returns with the Nigerian Data Protection Commission (NDPC). Organisations are mandated to file their data protection compliance audit return on or before the end of March 2024, and are expected to have commenced their audit process to meet this deadline.

In this publication, we have set out some information which should help you in your data protection compliance audit.

  1. What type of companies are to adhere to this data protection compliance requirement?

The obligation to adhere to this compliance requirement is imposed on organisations who collect and process personal  data of Nigerians, simply referred to as data processors and data controllers. Foreign companies are also caught in this blanket if they process the data of data subjects resident in Nigeria (whether or not they have a subsidiary in Nigeria).

Examples of these companies include: banks and other financial institutions, technology companies, health institutions, insurance companies, gaming and betting companies, religious institutions, all employers of labour, etc.

  1. What steps are Data Processors and Controllers required to take to adhere to this compliance requirement?
    1. The first step to take in this regard would be to engage the services of a data protection compliance organization (DPCO). DPCOs are organisations licensed by the NDPC to facilitate the filing of data protection compliance audit returns with the NDPC. The DPCO will provide guidance on the audit process best suited for your organisation.
    2. In order to commence the data protection compliance audit process, the DPCO may require that you provide the following documents and information:
      1. Documents:
        • Data protection policy
        • Data impact assessment procedure and workbook
        • Privacy policy
        • Data subject consent form
        • Internal breach register
        • Data subject access request procedure and form
        • Subject access request record
        • Document stipulating the management of sub-contract processing
        • Data breach notification procedure
        • Retention schedule
        • Audit schedule

ii. Information: Your organization will be required to provide the following information during the audit process:

        • Information regarding the training and awareness of the organisation’s staff on data protection requirements and process
        • Information on the category of personal data processed by the organization and how they are stored
        • Information on how the organization determines the relevance and adequacy of the personal data obtained for each processing purpose
        • Contingency plans put in place/implemented by the organization to handle data breach, loss, destruction, and damage, and security measures established to mitigate against same
        • Where the organization is a data controller, the list of its agents and contractors engaged for data processing is required. In addition to this, the organization will be required to highlight the considerations made in choosing a data processor, and steps taken to ensure that the data processor complies with data protection requirements
        • How the organization determines the lawful basis for processing personal data, etc.

Please note that the above documents and information are not exhaustive and only serve as a guide in preparation for your data protection compliance audit. The documents and information required may vary depending on your organisation’s business and operations, and on the specific preference of the DPCO conducting the audit.

  1. What happens where I do not have all the documents or information required?

In cases where you have not fully developed all the required documents or do not have the required information, the DPCO will make some recommendations on the documents to be developed or updated by you.

Please note however that you will incur no penalties where these documents are not available, although the NDPC would expect to see improvements in your data protection practices at the next audit.

  1. How long does the audit process take?

The audit process typically takes about 3 weeks if you have and promptly furnish the DPCO with all the required documents and information.

  1. What happens if I fail to fulfill the requirements before the March 2024 deadline?

The NDPC stipulates that failure to file CAR within the March 2024 deadline will result in a default fee of 50% of the filling fee being imposed on the data controller/processor.

 

If you require further information on the data protection audit process you can reach out to the DPCO arm of our practice at dpo@pavestoneslegal.com copying info@pavestoneslegal.com , and we will be happy to provide any assistance you may need.

REGULATORY UPDATE: CENTRAL BANK OF NIGERIA GUIDELINES ON OPERATION OF BANK ACCOUNTS FOR VIRTUAL ASSETS SERVICE PROVIDERS

BY ADERONKE ALEX-ADEDIPE AND QASIM OGUNJINMI

DOWNLOAD PUBLICATION

INTRODUCTION

In response to global trends and the increasing need for the regulation of Virtual Assets Service Providers (VASPs), including cryptocurrencies and crypto assets, the Central Bank of Nigeria (CBN) issued its “Guidelines on Operations of Bank Accounts for Virtual Assets Service Providers” on December 22, 2023. This marks a significant shift from the CBN’s previous stance in its February 2021 circular, where it restricted banks and financial institutions from operating accounts for cryptocurrency service providers due to potential risks and the absence of regulations and consumer protection measures.

In this newsletter, we summarise  the key provisions of the Guidelines and their implications.

BACKGROUND

The journey towards regulating virtual assets in Nigeria has been dynamic. To provide context, it is important to highlight the various events leading up to the issuance of the Guidelines. These events are highlighted below:

  1. On the 12th of January 2017, the CBN issued its initial circular on virtual currency operations in Nigeria. This circular outlines the risks associated with crypto transactions, emphasizing concerns about money laundering and illicit activities.
  2. Some three years later, the Securities and Exchange Commission (“SEC”), on September 14, 2020, issued a “Statement on Digital Assets and their Classification and Treatment,” recognizing cryptocurrencies, and digital assets as securities, bringing them under SEC’s regulatory purview via Section 13 of the Investment and Securities Act, 2007.
  3. In February 2021, through a circular, the CBN restricted banks from facilitating crypto transactions due to identified risks and vulnerabilities associated with virtual assets.
  4. Recognizing VASPs, the Money Laundering (Prevention and Prohibition) Act, 2022 included VASPs as part of the definition of “Financial Institutions”.
  5. In 2022, SEC released the New Rules on Issuance, Offering Platforms, and Custody of Digital Assets (the “SEC New Rules”), providing a regulatory framework for the sector.
  6. In May 2023, the Federal Executive Council (FEC) approved the National Blockchain Policy, indicating a broader acknowledgment of the significance of blockchain technology.
  7. In June 2023, the Capital Gains Tax Act was amended to include digital assets in the list of chargeable assets.

THE GUIDELINES: KEY PROVISIONS AND IMPLICATIONS

The primary implications of the Guidelines is to effectively lift the ban on banks and other financial institutions from facilitating crypto transactions on the one hand, and provide a framework for banking relationships and account opening for SEC-licensed VASPs in Nigeria, on the other hand. Some of the key provisions of the Guidelines include:

  1. SCOPE AND APPLICATION: As stated in paragraph 3.0 of the Guidelines, the Guidelines applies to banks and other financial institutions which are within the regulatory purview of the CBN. Specifically, the Guidelines applies to banks, payment service providers licensed by the CBN, and entities registered by the SEC for digital/virtual assets services. It also encompasses SEC-registered Virtual Assets Service Providers, Digital Asset Custodians, Digital Asset Offering Platforms, and more.

The importance of synergy among regulators within the virtual assets space cannot be overemphasized. To this end, the Guidelines seeks to complement the other relevant provisions in the Money Laundering (Prevention and Prohibition) Act, Central Bank of Nigeria (Anti-Money Laundering (AML), Combating the Financing of Terrorism (CFT) and Countering Proliferation Financing of Weapons of Mass Destruction in Financial Institutions(CPF)) Regulations, Customer Due Diligence Regulations and other relevant and regulations issued by competent authorities like SEC.

  1. PERMISSIBLE ACTIVITIES: In their operation of accounts for VASPs, financial institutions are permitted to carry out activities which include opening designated accounts, providing settlement services, acting as channels for foreign exchange flows, among others. Please note, however, that financial institutions are prohibited from holding, trading, or transacting in virtual currencies on their own account.
  2. OPERATION OF BANK ACCOUNT BY VASPs: In line with the Guidelines, VASPs can operate designated accounts for virtual/digital assets. It is important to note that these accounts may only be validly opened with the approval of the senior management of the financial institution. Furthermore, an application for the opening of any such account should be accompanied by the documents listed in paragraph 7.3 of the Guidelines which includes SEC license, corporate documents, AML policies, amongst others.
  3. CONSUMER PROTECTION: Further to the Guidelines, financial institutions are required to establish consumer protection systems, complaint channels, and redress mechanisms. Please note that adherence to CBN circulars on consumer complaints management is a major requirement.
  4. SANCTIONS: In addition to the powers of the CBN to penalize license-holders for non-compliance with laws and regulations, the Guidelines provides that the CBN may in the event of non-compliance, issue any or all of the following sanctions against a financial institution, its board of directors, officers or staff:
    1. Prohibition from opening any further designated account.
    2. Monetary penalty not below the sum of N2,000,000.00 (Two Million Naira) against the financial institutions, members of its board, senior management, and any staff, for any infraction.
    3. Suspension of operating licence of a financial institution.

CONCLUSION

In conclusion, it is pertinent to note that the Guidelines activate the SEC New Rules and participants in the sector must comply with both the SEC New Rules and the Guidelines. While blending tradition with innovation might be a daunting task for regulators, we note that collaboration and cooperation among regulators is essential to the successful implementation of the Guidelines and other relevant virtual assets related laws, regulations and strategies.