COMPLIANCE REQUIREMENTS FOR DOING BUSINESS IN NIGERIA

BY ADERONKE ALEX-ADEDIPE AND OLAWALE ATANDA

DOWNLOAD PUBLICATION

INTRODUCTION

Upon the incorporation and commencement of business in Nigeria, companies are required to adhere to certain regulatory requirements. These regulatory requirements involve filing returns or remitting levies to bodies established by law. In this newsletter, we examine the various compliance obligations of companies doing business in Nigeria by detailing the relevant regulatory bodies and the filing responsibilities associated with them.

1. Federal Inland Revenue Service (FIRS)

Companies are required to file the following taxes to the FIRS either monthly or yearly.

• Companies Income Tax (CIT). Companies are obligated to file their annual returns within 18 months of incorporation. Subsequent filings are to be made within 6 months following the end of the financial year which is typically by June 30 of every year. The penalty for failure to file CIT returns is ₦25,000 for the first month and ₦5,000 for each subsequent month of default. While late payment of CIT attracts a 10% penalty and interest at the prevailing bank rate.

•  Withholding Tax (WHT). This serves as an advanced method for the collection of CIT. It is deducted at rates which vary between 5% and 10%, depending on the nature of the transaction and the parties involved. The deadline for filing WHT returns falls on the 21st day of each subsequent month after the deduction. The failure to meet this deadline will result in a late filing penalty of ₦25,000 for the first month and an additional ₦5,000 for each month during which the failure persists.

Value Added Tax (VAT). This is a consumption tax levied on the value of goods and services provided in or imported into Nigeria. It is charged at a rate of 7.5% which is applicable to all goods and services provided to individuals and companies. The deadline for filing VAT returns is the 21st day of the month following the month of transaction. Failure to meet this deadline will result in a late filing penalty of ₦50,000 for the first month and an additional ₦25,000 for each subsequent month during which the failure continues. However, VAT is not paid on all goods and services. Some of the exempt goods and services are medical and pharmaceutical products, basic food items, books and educational materials, tuition from nursery to tertiary education, baby products, all exported goods and services, amongst others provided in the VAT Act.

2. Internal Revenue Services of States

Companies are required to withhold and file personal income tax of their employees to the internal revenue service of the state where employees reside. This income tax is also known as Pay As You Earn (PAYE). In Lagos State for instance, employers must begin deducting tax from the salaries and wages of their employees after 6 months of the company commencing operations. The deducted taxes are remitted to the Lagos Internal Revenue Service (LIRS).

The deadline for remitting PAYE is before the 10th of the month following the month when the deductions were made. For example, January PAYE must be remitted on or before February 10th. At the end of the year, employers in Lagos are expected to file duly updated returns on all salaries and wages paid to the employees on their payroll within the preceding tax year. Returns must be filed at the LIRS before January 31st for the preceding year.

The PAYE requirements in Lagos are the same in Abuja and many other states in Nigeria, however, the implementation of PAYE (i.e. how it is filed) varies from state to state.

3. Corporate Affairs Commission (CAC)

All companies registered in Nigeria are required to file annual returns to the CAC. Companies are to file their annual returns within 18 months of incorporation and subsequently on an annual basis. The filing of the annual return should be accompanied by the Audited Financial Statement/Audited Account of companies for the financial year end.

The deadline for filing annual returns at the CAC is 14 days after the date of the general meeting for the year and in any case, before June of the current year. Failure to file annual returns attracts a penalty of either ₦3,000 or ₦5,000 for each year of non-compliance depending on whether the company is regarded as a small or large company. However, in November 2023, the CAC announced that by April 2024, it would start penalizing companies and their directors for failure to file their annual returns.

4. Industrial Training Fund

Every company is required to contribute 1% of the total sum of its annual payroll to the Industrial Training Fund. The fund is used to develop human capital and provide individuals with technical and entrepreneurial managerial skills in both the public and private sectors.

However, companies with less than five employees and with a turnover of less than ₦50 million are exempted. Payments are required to be made on or before the 1st of April each year. Where companies do not make the required contribution to the fund, they are liable to pay a monthly penalty of 5% on the unpaid contribution for each month they are in default.

5. Nigeria Social Investment Trust Fund (NSITF)

The NSITF is established by the Employee’s Compensation Act and is designed to provide insurance for employees against incidents that occur in the course of their employment such as workplace injuries, mental stress, occupational hazards, and death. Employers are required to contribute 1% of their total monthly payroll to the NSITF by the last day of each month in which payroll payments are made.

Where companies do not make the required contribution to the fund, they are liable to pay a monthly penalty of 5% on the unpaid contribution for each month they are in default.

It is important to note that an employer cannot deduct from the remuneration of an employee towards its contribution to the NSITF. An employer cannot also require an employee to indemnify it against any liabilities which the employer may incur under the Employee’s Compensation Act.

6. National Pension Commission (PENCOM)

The Pension Reform Act which establishes the PENCOM as the pensions regulatory body in Nigeria requires employers with at least 15 employees to participate in a contributory pension scheme. Under the scheme, the employer contributes a minimum of 10% of the employee’s monthly emolument and the employee contributes 8%. However, the employer may opt to bear all the contribution to the pension scheme. In that case, the minimum contribution will be 20% of monthly emolument.

Contributions are required to be remitted within 7 days after the payment of salaries and are to be made monthly for the duration of the employee’s employment in the company. The penalty for non-contribution is not less than 2% of the total outstanding pension contributions that remain unpaid, in addition to the outstanding contributions.

7. Nigeria Data Protection Commission (NDPC)

All companies collecting or processing the personal information of over 1,000 individuals within a 6-month period and processing the personal data of more than 2,000 individuals within 12 months are required to submit a yearly Compliance Audit Report (CAR)1 to the NDPC though a Data Protection Compliance Organisation (DPCO). The DPCO will review the data protection documentation of the company, assess the systems and practices of the company and assess the knowledge of the staff before providing recommendations. The DPCO will thereafter submit a summary of the CAR to the NDPC not later than the 15th of March of the following year. A default fee of 50% of the filing fee will apply where companies fail to file their CAR by the 15th March deadline.

In February 2024, the NDPC issued a guidance notice2 requiring companies that process the data of Nigerians to register with the NDPC as “Data Controllers or Data Processors of Major Importance”. Companies are considered Data Controllers or Data Processors of Major Importance (DCMI/DPMI) if they:

i. process the personal data of more than 200 Nigerians within 6 months;

ii. provide ICT services directly to individuals;

iii. process personal data in the ordinary course of their business; or

iv. operate in sectors critical to Nigeria’s economy, society, or security, including financial, communication, health, education, insurance, and others listed in the guidance notice.

Companies regarded as DCMI/DPMI are to register under any of the three categories of data processors/controllers listed in the guidance notice between January 30, 2024, and June 30, 2024.

The failure to register within this timeframe or registering after the due date will be deemed a default under the Nigeria Data Protection Act (NDPA), subjecting the defaulting companies to penalties as stipulated in the NDPA.

Conclusion

It is important to note that the list above is not exhaustive. In addition to the compliance obligations above, certain sector-specific regulatory requirements may apply depending on a company’s sector of operations. Companies should seek legal counsel to understand the specific regulatory requirements applicable to their operations.

REGULATORY UPDATE: GUIDANCE NOTICE ON REGISTERING DATA CONTROLLERS AND PROCESSORS OF MAJOR IMPORTANCE

BY SEUN TIMI-KOLEOLU AND QASIM OGUNJIMI

DOWNLOAD PUBLICATION

INTRODUCTION

On the 14th of February, in accordance with its mandate to ensure the genuine processing of personal data by legitimate persons or organizations, the Nigeria Data Protection Commission (the “Commission”) issued a guidance notice on Registering Data Controllers and Processors of Major Importance (the “Notice”). The Nigeria Data Protection Act (the “Act”), specifically in section 5 (c), stipulates that one of the functions of the Commission shall be to register data controllers and data processors of major importance. To carry out this function, the Commission has issued this Notice to clearly define the scope of the organizations that may be classified as data controllers and data processors of major importance and communicate the registration requirements for the relevant controllers and processors.

In this newsletter, we provide an overview of the Notice and its implications for data controllers and processors of major importance.

Who are Data Controllers and Data Processors of Major Importance?

According to the interpretation section of the Act – Section 65, a data controller or data processor of major importance is defined as an entity that is domiciled, resident in, or operating in Nigeria and processes or intends to process personal data of more than such number of data subjects who are within Nigeria, as the Commission may prescribe.

Additionally, this definition includes any other class of data controller or data processor that is processing personal data of particular value or significance to the economy, society, or security of Nigeria as designated by the Commission. From the foregoing, it is safe to say that it is the volume and value of the data in question that determines the categorization of a data controllers and data processors as one of major importance.

Based on this definition, the Commission has now established criteria to identify organizations that qualify as data controllers or processors of major importance. In line with the notice, organizations that are designated as data controllers or processors of major importance include the ones that:

1.keep or have access to a filing system (analog or digital) for processing personal data;

2.process personal data of more than 200 data subjects within a six-month period; 3.carry out commercial Information Communication Technology (ICT) services on digital devices belonging to others; and

4.operate in sectors critical to Nigeria’s economy, society, or security, including financial, communication, health, education, insurance, and others listed in the Notice.

Moreover, entities under a fiduciary relationship with data subjects, obligated to keep confidential information on their behalf, are also regarded as data controllers or processors of major importance.

Classification of Data Controllers and Data Processors of Major Importance

The Commission has established a classification system to categorize data controllers and data processors of major importance based on the scale and significance of their data processing activities. This classification aims to provide clarity on the obligations and standards applicable to different organizations within this category.

The Commission’s classification system includes three levels or categories:

1.Major Data Processing-Ultra High Level (MDP-UHL): Organizations falling under this category are expected to adhere to global and highest attainable standards of data protection. Criteria for classification include factors such as: (i) the sensitivity

of personal data, reliance on third-party servers or cloud computing services; (ii) involvement in cross-border data flows; (iii) processing the personal data of over 5,000 data subjects through technology under its control or through a service contract; (iv) legal competence to generate revenue on a commercial scale; and (v) the need for international standard certifications.

Entities falling under this category, such as commercial banks, telecommunication companies, insurance companies, multinational corporations, and others listed in the Notice, are required to register as an MDP-UHL. Additionally, in any case, organizations that process personal data of over 5,000 data subjects within six months fall under this category.

2. Major Data Processing-Extra High Level (MDP-EHL): Organizations categorized under this level are required to abide by global best practices of data protection. Criteria for classification include factors such as: (i) the sensitivity of personal data; (ii) reliance on third-party servers or cloud computing services; (iii) involvement in cross-border data flows; (iv) processing the personal data of over 1,000 data subjects through technology under their control or through a service contract; (v) legal competence to generate revenue on a commercial scale; and (vi) the need for reputable and standardized certifications.

This category includes entities like ministries, departments, and agencies (MDAs) of government, microfinance banks, higher institutions, hospitals providing tertiary or secondary medical services, and mortgage banks. These organizations are required to register under the MDA-EHL category. Organizations processing personal data of over 1,000 data subjects within six months also fall under this category.

3.Major Data Processing-Ordinary High Level (MDP-OHL): Organizations falling under this category are also expected to adhere to global best practices of data protection. Criteria for classification include factors such as: (i) the sensitivity of data assets; (ii) inherent vulnerability of data subjects; (iii) high risk to the privacy of data subjects if personal data are processed in a systematic or automated manner; (iv) processing the personal data of over 200 data subjects through technology under their control or through a service contract; (v) the need for adequate technical and organizational measures for data protection; and (vi) the need for reputable and standardized certifications.

Entities classified under MDP-OHL, such as small and medium-scale enterprises, primary and secondary schools, primary health centers, agents, contractors, and vendors engaging with data subjects on behalf of other organizations, are required to register with the Commission as such. Similarly, organizations processing personal data of over 200 data subjects within six months are included in this category.

By classifying data controllers and processors of major importance into these levels, the Commission aims to ensure that appropriate regulatory requirements and standards are applied, taking into account the varying levels of risk and impact associated with different organizations’ data processing activities.

 

Conclusion

It is important to note that existing data controllers and data processors of major importance are mandated to register as such with the Commission between January 30, 2024, and June 30, 2024. Failure to register within this timeframe or registering after the due date will be deemed a default under the Act, subjecting the defaulting organization to penalties as stipulated in the Act.

FOREIGN CURRENCY REGULATORY UPDATE: CENTRAL BANK OF NIGERIA’S CIRCULAR ON THE HARMONISATION OF REPORTING REQUIREMENTS FOR BANKS

BY ADERONKE ALEX-ADEDIPE AND SHARON OKPO

DOWNLOAD PUBLICATION

INTRODUCTION

The Central Bank of Nigeria (CBN) on January 31, 2024, issued a circular for the harmonization of reporting requirements on foreign currency exposures of banks (the “Circular”). This circular was issued following concerns in the growth in foreign currency exposures of banks through their Net Open Position. The circular and its implementation is aimed at ensuring that foreign exchange risks are well managed and that losses which could pose material challenges are avoided.

In this newsletter, we highlight the various requirements which banks are expected to meet in compliance with the Circular.

  1. What is the Net Open Position (NOP) (or foreign currency position) of a Bank?

NOP is the metric used by banks to analyse the foreign exchange risk which they are exposed to. The foreign exchange risk of a bank in any currency is that bank’s net open position in that currency. This position could be long (i.e. when the bank’s total foreign assets are greater than its total foreign liabilities. In such case the bank is overbought on  foreign currency) or short (i.e. when the bank’s total foreign currency liabilities are greater than its total foreign assets. That means the bank is oversold on foreign currency).

The NOP is calculated by determining the difference between the total assets in foreign currency and total liabilities in foreign currency, divided by the bank’s total equity or net worth.

The CBN had in a similar circular issued in October 2014 prescribed that a bank’s NOP shall not exceed 20% of its shareholders’ funds unimpaired by losses, and by a letter dated January 28, 2015, further prescribes that the NOP be calculated daily, and the result forwarded to the CBN at the end of each day. The Circular however recognizes that because of the growing foreign currency exposures, banks have more incentive to hold long foreign currency positions. On this basis, the Circular sets forth some prudential requirements to manage and avoid losses which could cause serious challenges in the financial sector.

  1. What are the prudential requirements provided by the Circular?
  1. A bank’s NOP must not exceed 20% short or 0% long of shareholders’ funds unimpaired by losses.
  2. Banks whose current NOP exceeds 20% short and 0% long are required to have brought them within prudential limit by February 1, 2024.
  3. The Circular provides a template which banks are required to use in the computation of their daily and monthly NOP and foreign currency trading position.
  4. Banks are required to have adequate reserve of high-quality liquid foreign assets to cover their maturing foreign currency obligations.
  5. Banks are also required to have a foreign exchange contingency funding arrangement with other financial institutions.
  1. What other requirements are banks expected to comply with?

In addition to the prudential requirements, banks are also expected to comply with the following:

  1. Banks are advised and required to borrow and lend in the same currency to avoid any currency mismatch.
  2. Banks are required to ensure that the basis of interest rates are the same for floating and fixed interests to avoid risks associated with foreign borrowing interest rate risk.
  3. As regarding Eurobonds, it is required that any clause for early redemption of the investment/indebtedness should be at the instance of the issuer. The approval of the CBN is required in this instance.
  4. All banks are required to adopt adequate treasury and risk management systems to provide oversight on all foreign exchange exposures and ensure accurate and timely reporting.
  5. Banks are expected to ensure that all returns filed with the CBN accurately reflect their balance sheets.

CONCLUSION

It is important to note that failure to comply with the NOP limit will result in an immediate sanction being issued against the bank and/or suspension from participation in the foreign exchange market. Therefore, Banks are encouraged to ensure compliance with the Circular.

REVISED CBN GUIDELINES ON INTERNATIONAL MONEY TRANSFER SERVICES IN NIGERIA

BY SEUN TIMI-KOLEOLU AND OLAWALE ATANDA

DOWNLOAD PUBLICATION

Introduction

The Central Bank of Nigeria (CBN) on 31 January 2024 released its revised guidelines for international money transfer services in Nigeria. The revised guidelines (the “New Guidelines”) provides an updated framework for the licensing and operations of International Money Transfer Organizations (IMTOs) in Nigeria. According to the CBN, the New Guidelines were issued in view of recent reforms to liberalize the foreign exchange market, boost diaspora remittances, and enhance the ease of doing business for IMTOs.
In this newsletter, we examine the changes introduced in the Guidelines and how they differ from the previous guidelines issued in September 2014 (the “Previous Guidelines”).

1. Licensing Procedure and Fees
The New Guidelines outline a two-step application process for IMTOs – the Approval in Principle and the Final Approval. Each stage requires the submission of specific documentation to the CBN. IMTOs can only commence operations upon the issuance of a final license. Unlike the New Guidelines, the Previous Guidelines did not explicitly provide for a two-stage application process. Applications for an IMTO license are to be made alongside the payment of a NGN10million application fee. An IMTO license is required to be renewed annually at the rate of NGN10million and payable by the 31st of January.
The New Guidelines also state that it is unlawful for any organization or individual to offer financial products that include services for international transfers or remittances unless they have obtained a license from the CBN.

2. Minimum Share Capital

The New Guidelines now state a minimum share capital of $1million for foreign companies and the equivalent in Naira for indigenous companies. The Previous Guidelines on the other hand, required a minimum paid up capital of NGN2billion for indigenous companies seeking an IMTO license and NGN50million for foreign companies. However, unlike the Previous Guidelines, the New Guidelines do not state whether the share capital of an IMTO needs to be fully paid up.
Considering the volatility of the Naira to Dollar exchange rate, the $1million share capital raises the question about whether indigenous companies will be required to increase their share capital every time the exchange rate increases. It is expected that the CBN will clarify this point in due course.

3. Permissible Activities

Under the New Guidelines, IMTO services are now limited to inbound money transfer services alone. This means that IMTOs are only able to provide money transfer or remittance services from a foreign country into Nigeria. This is a departure from the Previous Guidelines which provided for limited outbound money transfer services.
The New Guidelines also expands the scope of the target demographic for money transfer services. While individual customers remain the primary focus, the scope now includes transfers on a “person to person”, “business to person”, and “business to business” basis as opposed to the Previous Guidelines which only provided for transactions on a “person to person” basis.
In line with the Previous Guidelines, the New Guidelines continue to prohibit IMTOs from purchasing foreign exchange from the domestic foreign exchange market for settlement purposes.

4. Prohibition of Fintechs From Obtaining IMTO Licence

The New Guidelines explicitly bar “Financial Technology Companies” from procuring an IMTO license. Although the New Guidelines do not define what a fintech is, it can be inferred from the CBN’s National Fintech Strategy document that fintech companies refers to institutions carrying out payment services under the various Payment Service Provider(PSP) licenses issued by the CBN. However, it will be helpful for the CBN to clarify what it means by Financial Technology Companies.

5. Other Provisions

IMTOs can partner with deposit money banks to act as their agents. IMTOs are required to domicile customer funds for remittance with their agents.
• All money transfers by IMTOs to beneficiaries must be made in Naira via bank deposit or cash. Cash payments are limited to transfers below the equivalent of $200.
• The exchange rate used in converting the foreign currency to Naira shall be at the prevailing rate in the Nigerian Foreign Exchange Market on the day the transfer was received.
• IMTOs are required to state the exchange rate and all applicable charges for each money transfer transaction prior to the conclusion of the transaction.

Conclusion

The CBN consistently demonstrates its role as a proactive regulator with its frequent updates of regulations and guidelines to meet its perception of current needs. It will however be helpful for the CBN to provide clarity and address certain concerns that have arisen from the New Guidelines. Some of these concerns are:
• the prohibition of fintech companies from acquiring IMTO licenses; and
• the pegging of the minimum share capital for indigenous IMTO companies to the US
Dollar considering the fluctuation of the Naira. It will be preferable for the share capital of indigenous companies to be a fixed amount in Naira.