Regulatory Compliance Requirements for Companies Operating in Nigeria

SEUN TIMI-KOLEOLU AND EBIKENIYE BEST

Regulatory Compliance Requirements for Companies Operating in Nigeria

Introduction

Regulatory compliance is important for any company and forms the foundation that enables businesses operate smoothly and sustainably. For companies operating in Nigeria, the first step in the regulatory compliance process is incorporating the business with the Corporate Affairs Commission followed by registration with relevant industry regulators, where applicable. Once the company is successfully incorporated, there are various regulatory requirements that must be met to ensure that the company can continue to operate legally in Nigeria.

In this newsletter, we have highlighted some of these key compliance requirements.

  1. Corporate Affairs Commission (CAC)

All companies registered in Nigeria are mandated to file annual returns with the CAC. The annual returns are to be filed within 18 months of incorporation and subsequently on an annual basis. These returns must be accompanied by the company’s audited financial statements or audited accounts for the relevant financial year.

The deadline for filing returns with the CAC is 14 days after a company’s general meeting for the year, but no later than June of that year. Late filings attract penalties for each year of non-compliance.

  1. Nigeria Data Protection Commission (NDPC)

Companies that collect or process personal data of over 1,000 Nigerians within a 6-month period or handle the personal data of more than 2,000 Nigerians within a year, are mandated to submit an annual Compliance Audit Report (CAR) to the Nigeria Data Protection Commission (NDPC) through a certified Data Protection Compliance Organisation (DPCO). The DPCO will review the company’s data protection policies, evaluate its systems and practices, and assess staff knowledge before making recommendations.

A summary of the CAR for the previous year must be submitted to the NDPC no later than March 15 of the current year. Failure to meet this deadline will result in a penalty of 50% of the filing fee.

  1. Tax Compliance

Companies are required to file the taxes as set out below to the Federal Inland Revenue Service (FIRS) and Inland Revenue Service of States respectively either monthly or yearly.

  • Companies Income Tax (CIT): Companies are obligated to file their annual returns within 18 months of incorporation. Subsequent filings are to be made within 6 months following the end of the financial year, which is typically by June 30 of every year. The penalty for failure to file CIT returns is ₦25,000 for the first month and ₦5,000 for each subsequent month of default. While late payment of CIT attracts a10% penalty and interest at the prevailing bank rate.
  • Withholding Tax (WHT): This serves as an advanced method for the collection of CIT. It is deducted at rates which vary between 2% and 10%, depending on the nature of the transaction and the parties involved. The deadline for filing WHT returns falls on the 21st day of each subsequent month after the deduction. The failure to meet this deadline will result in a late filing penalty of 10% of the tax not withheld or remitted.
  • Value Added Tax (VAT): This is a consumption tax levied on the value of goods and services provided in or imported into Nigeria. It is charged at a rate of 7.5% which is applicable to all goods and services provided to individuals and companies. The deadline for filing VAT returns is the 21st day of the month following the month of transaction. Failure to meet this deadline will result in a late filing penalty of ₦50,000 in the first month and ₦25,000 for each subsequent month of default. It is important to note however that VAT is not paid on all goods and services. Some of the exempt goods and services are medical and pharmaceutical products, basic food items, books and educational materials, all exported goods and services, equipment and infrastructure related to the expansion of compressed natural gas and liquefied petroleum gas amongst others.
  • Personal Income Tax: Companies are required to withhold and file the personal income tax of their employees to the internal revenue service of the state where the employees reside. This income tax is also known as Pay As You Earn (PAYE). In Lagos State, for example, employers must begin deducting tax from employee salaries six months after the company commences operations. The deducted are to be remitted to the Lagos Internal Revenue Service (LIRS). The deadline for remitting PAYE is before the 10th of the month following the deductions. Also, returns must be filed with the LIRS by January 31st for the preceding year.
  1. Labour and Employment Compliance

Companies are required to meet the requirements set out below in respect to labour and employment.

  • Industrial Training Fund (ITF): Companies are required to contribute 1% of the total sum of their annual payroll to the ITF. The fund is used to develop human capital and provide individuals with technical and entrepreneurial managerial skills in both the public and private sectors. However, companies with less than five employees and with a turnover of less than ₦50 million are exempted from this remittance requirement. Payments are required to be made on or before the 1st of April each year. Where eligible companies do not make the required contribution to the fund, they are liable to pay a monthly penalty of 5% on the unpaid contribution for each month they are in default.
  • Nigeria Social Investment Trust Fund (NSITF): The NSITF was established by the Employee’s Compensation Act and is designed to provide insurance for employees against incidents that occur in the course of their employment such as workplace injuries, mental stress, occupational hazards, and death. Employers are required to contribute 1% of their total monthly payroll to the NSITF by the last day of each month in which payroll payments are made. Where companies do not make the required contribution to the fund, they are liable to pay a monthly penalty of 5% on the unpaid contribution for each month they are in default.
  • National Pension Commission (PENCOM): The Pension Reform Act which establishes the PENCOM as the pensions regulatory body in Nigeria requires employers with at least 15 employees to participate in a contributory pension scheme. Under the scheme, the employer contributes a minimum of 10% of the employee’s monthly emolument and the employee contributes 8%. However, the employer may opt to bear all the contribution to the pension scheme. In that case, the minimum contribution will be 20% of monthly emolument.

Contributions are required to be remitted within 7 days after the payment of salaries and are to be made monthly for the duration of the employee’s employment in the company. The penalty for non-contribution is at least 2% of the total outstanding pension contributions that remain unpaid, in addition to the already outstanding contributions.

Conclusion

Please note that this list is not exhaustive, as companies may be subject to additional compliance requirements based on their industry or sector. Meeting all compliance obligations is important as it enables companies to remain legally compliant, avoid regulatory sanctions, and foster trust in their brand among customers. It is advisable that companies doing business in Nigeria liaise with legal advisers to help create a tailored compliance checklist for ease of operations.

 

For further reading on sector specific licenses, please see our newsletters below.

SEC Licenses – https://pavestoneslegal.com/insights-into-the-sec-accelerated-regulatory-incubation-program-framework/

Fintech – https://pavestoneslegal.com/regulatory-requirement-for-fintech-in-nigeria-cbn-licenses/

Banking – https://pavestoneslegal.com/licensing-requirements-for-banks-and-other-financial-institutions-in-nigeria/

Lending – https://pavestoneslegal.com/regulation-of-lending-in-nigeria/

Cryptocurrency – https://pavestoneslegal.com/setting-up-a-cryptocurrency-business-in-nigeria/

 

 

STAYING AHEAD OF THE CURVE: NAVIGATING NIGERIA’S DATA PROTECTION COMPLIANCE LANDSCAPE

ADERONKE ALEX-ADEDIPE AND PROMISE ITAH

STAYING AHEAD OF THE CURVE: NAVIGATING NIGERIA’S DATA PROTECTION COMPLIANCE LANDSCAPE

Introduction

The Nigeria Data Protection Act 2023 (NDPA) is the primary legislation that governs the privacy and protection of Personal Data of natural persons in Nigeria. Modelled in many respects after the General Data Privacy Regulation (GDPR) of the European Union, the NDPA and the subsidiary legislations such as the Nigeria Data protection Regulations (2019) establish substantial compliance requirements for organisations or persons that control and process Personal Data.

In this Newsletter we summarise some of these regulatory compliance requirements.

What are the Key Concepts in Data Privacy?  

A Data Controller is a person or entity that determines the purposes and means of processing Personal Data. A Data Controller usually has a direct relationship with the Data Subject and is accountable for the protection and privacy of the Personal Data of a Data Subject. Examples of Data Controllers may include Government agencies; e-commerce businesses typically in custody of customer data; healthcare providers with patient data; educational institutions with student data etc.

A Data Processor is a person that processes Personal Data on the instruction of a Data Controller. Processing activities include a range of activities like collection, storage, use, disclosure, arrangement and structuring, modification etc. Example of Data processors may include marketing agencies, financial service companies, e-learning platforms, telecommunication service providers, and courier service providers who process Personal Data on the instruction of a Data Controller. A Data Controller may also be a Data Processor.

Personal Data refers to any information that relates to an identified or identifiable natural person (human being) and may include name, address, contact information, identification numbers, biometric data. The natural person who the information relates to is known as the Data Subject.

 

Key Regulatory Compliance Requirements for Data Controllers and Processors

1. Annual Data Protection Compliance Audits:

The NDPA mandates Data Controllers and Processors that process the Personal Data of more than 2,000 Data Subjects within a 12-month period (or more than 1000 Data Subjects within a 6-month period), to conduct annual data protection audits not later than the 15th of March of the following year. Such audits must be conducted by a Data Protection Compliance Organisation (DPCO) licensed by the Nigeria Data Protection Commission (NDPC) and must be completed and filed by the deadline stated by the NDPC. Upon the filing of an audit and after a satisfactory review by the NDPC, Trustmarks are issued to the compliant organizations to entities that have complied with this provision.

2. Registration as Data Controller/Processor of Major Importance

A Data Controller/Processor qualifies as Data Controller/Processor of Major Importance (DCPMI) and is required to register with the NDPC within six (6) months, if it meets any of the following criteria:

  • has access to a filing system and processes Personal Data of more than 200 Data Subjects in a six (6) month period; or
  • provides commercial Information Communication Technology (ICT) services on any digital storage device with a storage capacity owned by another; or
  • processes Personal Data in the financial, communication, aviation, tourism, oil and gas, import and export, education, health, insurance and electric power industries; or
  • is in a fiduciary relationship with a Data Subject, pursuant to which it is expected to keep confidential information on the Data Subject’s behalf.

The categories of DCPMI are:

  • Major Data Processing-Ultra High Level
  • Major Data Processing-Extra High Level
  • Major Data Processing-Ordinary High Level

3.Data Protection Impact Assessment

Data Controllers must conduct Data Protection Impact Assessment (DPIA) to assess and identify any security risk associated with their data processing activities. This assessment should be conducted regularly on their processes, services and technology to ensure that they remain compliant with data protection laws.

DPIA is typically required where there is a change in processing activities involving automated decision-making with legal or significant effects on the Data Subject rights; evaluation or profiling; sensitive Personal Data; systematic monitoring; application of new technological solutions of deployment of innovative processes; and processing of Personal Data in relation to vulnerable Data Subjects.

4.Designation of a Data Protection Officer

A DCPMI must appoint a Data Protection Officer (DPO) with knowledge of data protection and privacy laws who will carry out the tasks prescribed under the NDPA. The DPO may be an employee of the organization or engaged by a service contract.

5. Data Breach Notification

Data Controllers must notify the NDPC within 72 hours of becoming aware of a breach of Personal Data which is likely to impact the privacy rights of individuals. Data Subjects should also be notified of such breach.

6. Management of Data Subject Rights

Data Controllers and Processors must implement mechanisms to adequately respond to Data Subjects’ requests and ensure that such mechanisms are effective.  The NDPA outlines specific rights of Data Subjects, which include the right to access, rectification, erasure, and portability of their Personal Data.

7. Implementation of Data Security Measures

Data Controllers and Data Processors must implement adequate technical and organizational measures to protect the Personal Data of Data Subjects from unauthorized access, loss, or alteration. These measures may include encryption, regular security assessments, and training of employees to safeguard data breaches and other vulnerabilities.

8. Keeping Record of Processing Activities

Data Controllers and Processors must maintain detailed records of their processing activities. This includes documenting the purposes of data processing, categories of Personal Data, and third parties with whom Personal Data is shared. This record should be available for inspection by the NDPC upon request.

9. Conduct of Regular Staff Training and Awareness Programmes

Data Controllers and Processors must provide regular data protection training for employees, particularly those involved in data processing activities. This will help to foster a culture of privacy and ensure all staff are aware of their obligations under the NDPA.

Penalties for Non-Compliance

Non-compliance with the NDPA can result in significant penalties:

  • For DCPMIs: Fines up to 2% of annual gross revenue or NGN 10,000,000, whichever is greater.
  • For Data Controllers and Processors that are not DCPMIs: Fines up to NGN 2,000,000 or 1% of their annual gross revenue, whichever is greater.

Additionally, violations may result in imprisonment for up to one year. Both fines and imprisonment may be applied either alternatively or together upon conviction.

Conclusion

As businesses and organisations engage in data processing activities, compliance with data privacy and protection regulations is crucial. Adherence to the NDPA ensures that entities protect the Personal Data of individuals and avoid potential sanctions from the Nigeria Data Protection Commission (NDPC), the regulatory authority for data privacy and protection in Nigeria. It is essential for businesses to assess their compliance status regularly and take proactive measures to meet the requirements of the NDPA.

ENFORCING YOUR INTELLECTUAL PROPERTY RIGHTS IN NIGERIA AND GLOBALLY

BY SEUN TIMI-KOLEOLU AND HILLARY OKOROTIE

Enforcing Your Intellectual Property Rights in Nigeria and Globally

Introduction

In our previous newsletters, we explored the fundamentals of protecting your intellectual property (IP) rights, such as identifying protectable assets to navigating registration procedures. Protecting your IP right however does not end with registration. Once your IP rights are legally recognized, understanding how to enforce your rights, preventing unauthorized use of your IP, and safeguarding your brand value are equally important. Global brands such as Louis Vuitton and Dior, demonstrate the importance of this by constantly enforcing and protecting their trademark and designs from counterfeiting and misuse across multiple jurisdiction.

As African businesses and creatives continue to expand their reach globally, it is important that businesses pay attention to protecting the goodwill in their brands and maximize the investment value of their IP . In this newsletter, we will provide you with some guidance on how IP rights can be enforced in Nigeria and the importance of protecting IP globally.

Addressing Infringement: Opposing Similar Names and Passing Off

One of the most common challenges faced by IP owners is the unauthorized use of similar brand names, trademarks, taglines or other identifiers that may confuse and misdirect consumers. Hence addressing infringement involves taking action against unauthorized use of your IP that could harm your brand. This includes opposing the registration or use of similar names, trademarks, or designs that may confuse customers or damage your brand credibility. For example, in cases where a third party applies to register a similar name or symbol, swift action, such as filing an opposition with the appropriate registry, is vital to prevent approval.

To achieve this, you should ensure that you continuously monitor publication of trademarks that are undergoing registration or filings, this will allow you raise oppositions if any.  For instance, in Nigeria, the Trademark Registry publishes journals listing newly registered trademarks,  and permits opposition by the public. Engaging a lawyer to monitor these publications will ensure timely action against similar marks. Similarly, in the United States, regular checks of the United States Patent and Trademark Office (USPTO) filings can help identify and challenge conflicting applications promptly.

Where infringement occurs in the form of “passing off” which involves another business using your brand’s goodwill to deceive customers, actions such as issuing a cease and desist letter or a civil action to assert your rights may be necessary.

Utilizing Non-Disclosure Agreements (NDAs)

While external threats to IP are common, internal risks should not be overlooked. Employees, contractors, or partners often have access to proprietary data, trade secrets, or innovative concepts. To address this risk, it is important to integrate NDAs into your business processes as a standard practice before sharing sensitive information with consultants or employees. An NDA would provide the duration of confidentiality obligations, jurisdiction of enforcement, and penalties in the event of an infringement. In the event of a breach, it is important to take immediate action by investigating the violation, assessing the impact on your business or brand, and enforcing the terms of the NDA through formal dispute resolution or litigation if necessary. By taking these steps, you can mitigate internal risks and ensure the IP rights remain protected.

Enforcing Your IP Internationally: Scaling Your Protection with Your Brand

As businesses expand into global markets, protecting IP rights becomes a critical task. Without adequate protection, your IP may become vulnerable to unauthorised use in other jurisdictions. It is important to register your IP in each country where you plan to functionally operate your business. This is essential because IP protections are territorial, for instance, IP rights granted in Nigeria do not automatically extend to other countries. When your IP is protected in various jurisdictions, you not only gain the right to restrict third parties from using it, you are also able to monetize it.

Conclusion

While registration is a critical first step in protecting IP, enforcing your rights ensures that your creativity, and business investments are shielded from exploitation both locally and internationally.

Whether tackling infringement, safeguarding sensitive information, or scaling your organisation  to new markets, understanding these principles are vital to staying ahead in today’s competitive landscape.

For more information on intellectual property, you can refer to our previous newsletters below.

  1. https://pavestoneslegal.com/requirements-and-procedure-for-registration-of-trademarks-in-nigeria/
  2. https://pavestoneslegal.com/intellectual-property-licensing-in-nigeria/
  3. https://pavestoneslegal.com/registering-patents-in-nigeria/

SETTING UP A CRYPTOCURRENCY BUSINESS IN NIGERIA

ADERONKE ALEX-ADEDIPE AND OLAWALE ATANDA

Setting Up a Cryptocurrency Company in Nigeria

Introduction

The adoption of Cryptocurrency has gained significant traction in Nigeria over the years, serving as a store of value to hedge against inflation and as an investment tool for increasing wealth. It has also become a medium for international transfers, where individuals send cryptocurrency to family members in Nigeria who in turn convert it to local currency.

Despite its popularity, cryptocurrency usage has not been without challenges. In this newsletter, we examine the regulation of cryptocurrency in Nigeria and outline the steps businesses must take to operate within the country in compliance with existing regulations.

Crypto Regulation in Nigeria

In 2021, the Central Bank of Nigeria (CBN) issued a directive instructing banks to cease facilitating payments for cryptocurrency exchanges and to close the accounts of individuals and entities transacting in or operating crypto exchanges. According to the CBN, this directive aimed to mitigate the risks of money laundering and terrorism financing associated with cryptocurrency transactions.

In December 2023, the CBN partially reversed its stance by issuing the Guidelines on Operations of Bank Accounts for Virtual Assets Service Providers (the “Guidelines”).*
These Guidelines permitted cryptocurrency trading companies—such as crypto exchanges, crypto wallets, and digital currency creators—to open bank accounts, provided they met specific conditions, including obtaining a license from the Securities and Exchange Commission (SEC).’

At present, the SEC is the primary regulatory body overseeing cryptocurrency and othe  digital assets in Nigeria. The Guidelines followed the SEC’s release of Rules on the issuance and custody of Digital Assets in May 2022. These Rules established the framework for the registration and operation of Virtual Asset Service Providers (VASPs) which include crypto companies.**

In June 2024, the SEC introduced the framework on the Accelerated Regulatory Incubation Program (ARIP), which expedited the registration process for VASPs.*** Following the release of the framework, the SEC announced in August 2024 that it had granted licenses to two crypto exchanges.

These developments demonstrate that cryptocurrency companies can operate in Nigeria, provided they comply with the applicable regulatory requirements.

Steps to Consider when Setting Up a Crypto Company

1. CAC Registration
Crypto companies must be registered with the Corporate Affairs Commission (CAC) as a preliminary requirement to operate in Nigeria. Companies must be incorporated with a minimum paid-up share capital of NGN 500 million.

2. SEC Registration
To operate a crypto company in Nigeria, such a company must be registered by the SEC. As of the time of this publication, registration is conducted through the ARIP program. Interested parties must submit an expression of interest to the SEC, followed by a detailed application comprising documents such as an operational plan, business model, company documents, and other requirements specified in the SEC Rules.

Upon approval, the SEC will issue an Approval in Principle, allowing the entity to operate as a regulated crypto entity. It is important to note certain requirements, including the need for crypto companies to be incorporated and have a physical office in Nigeria. Also, the Chief Executive Officer or Managing Director must be resident in Nigeria.

3. Capital Importation and Bank Accounts
Where funding for the crypto company is sourced from outside Nigeria, it must be brought in through authorized dealers (i.e., commercial banks). A Certificate of Capital Importation (CCI) is important, as it enables investors to repatriate capital, dividends, and profits earned from the company at the official foreign exchange market rates in a freely convertible currency, subject to applicable taxes.

Crypto companies can also open accounts in commercial banks for settlement purposes. It should be noted that such accounts will not bear interest, and companies are not permitted to withdraw funds in cash. Withdrawals are limited to transfers to other bank accounts or the use of a manager’s cheque.

4. Immigration Considerations

If a crypto company employs foreign staff, it must obtain an Expatriate Quota from the Ministry of Interior. This quota permits the employment of foreigners within the company. Also, the company must secure a Combined Expatriate Residence Permit and Aliens Card (CERPAC) from the Immigration Service. This allows expatriate staff to live and work in Nigeria. A CERPAC is mandatory if the MD/CEO is a foreigner, as the SEC requires this
individual to reside in Nigeria.

5. Intellectual Property (IP) Registration
It is crucial for crypto companies to protect their intellectual property (IP) by registering it in Nigeria. This may include registering their brand name with Nigeria’s trademarks registry or patenting blockchain technology that powers their crypto assets or inventions that complement the use of crypto. It is important that IP is protected as it not only forms part of a company’s assets but also enhances its valuation and goodwill.

6. Registration with the National Office for Technology Acquisition and
Promotion (NOTAP)
NOTAP is the government agency responsible for regulating technology transfer agreements between Nigerian companies and foreign entities. If a crypto company engages with a foreign entity (including a foreign parent company, if applicable) to transfer technology—such as licenses to patents, trademarks, inventions, or technical,
management, or consulting services—the agreement must be registered with NOTAP. NOTAP ensures that technology transfer agreements are fair and contribute to local content development. Crypto companies must register these agreements within 30 days of their effective date. Registration enables the company to make payments to foreign entities through the official foreign exchange market under a technology contract.

Conclusion
Setting up a cryptocurrency business in Nigeria requires navigating a complex regulatory framework. By complying with SEC rules and meeting other regulatory requirements, crypto companies can establish a solid foundation for operating in Nigeria. Adhering to guidelines relevant to their operations not only ensures legal compliance but also builds trust with stakeholders and will help foster long-term growth in Nigeria’s evolving crypto
market.

Footnotes

1. Please see our article on the CBN’s Guidelines for the operation of bank accounts for
VASPs here – https://pavestoneslegal.com/regulatory-update-central-bank-of-nigeriaguidelines-
on-operation-of-bank-accounts-for-virtual-assets-service-providers/

2. Please see our article on the regulation of VASPs in Nigeria –
https://pavestoneslegal.com/regulatory-update-regulation-of-virtual-assets-serviceproviders-
in-nigeria/

3. Please see our article on the ARIP Program here – https://pavestoneslegal.com/insightsinto-
the-sec-accelerated-regulatory-incubation-program-framework/