CBN REGULATORY OVERSIGHT; APPOINTMENT AND REMOVAL OF DIRECTORS OF FINANCIAL INSTITUTIONS UNDER NIGERIAN LAW

By Aderonke Alex-Adedipe and Eustace Aroh

DOWNLOAD PUBLICATION

Introduction

On April 29, 2021, the Central Bank of Nigeria (CBN), as the apex regulator of all banks and other financial institutions in Nigeria, announced the removal of all the directors of First Bank Limited, a licensed commercial bank and financial services company, and FBN Holdings PLC, its holding company. The CBN also went a step further to appoint a new board of directors for the two companies.

In this article, we analyse the regulatory powers of the CBN to make decisions in relation to the constitution of the board of directors of financial institutions in Nigeria.

 

Provisions of the Companies and Allied Matters Act 2020[i]

The affairs of companies, including financial institutions, are generally guided by the provisions of the Companies and Allied Matters Act 2020 (“CAMA 2020”) which also provides for the general procedure for the appointment and removal of directors of a company.

Appointment – The first directors of a company are appointed by the subscribers during incorporation[ii] and subsequent directors are appointed at the annual general meeting by the shareholders.[iii] Where a vacancy is created by death, removal, retirement or resignation, a replacement director may be appointed by the board of directors to fill the vacancy until the next annual general meeting.[iv]

Removal – For a director to be removed under the CAMA 2020, a meeting of the shareholders must be convened and a decision to remove the shareholder passed at the meeting.[v] Prior to the meeting, the shareholder proposing the removal of the director is required to send a special notice to the company. The company will, in turn, send the special notice to the director proposed to be removed who will, if he wishes, make his representation in writing. The Company shall send the representation of the director alongside the notice of the meeting to all shareholders.[vi]

 

Provisions of the Bank and Other Financial Institution Act 2020

In addition to the CAMA 2020, banks and other financial services companies are also regulated by the Central Bank of Nigeria Act 2007 (CBN Act), Bank and Other Financial Institution Act 2020 (“BOFIA”) and the CBN’s various codes of corporate governance.

Under the BOFIA, before a company can carry on the business of banking, it must be licensed by the CBN.[vii] The CBN which was created under the CBN Act with the task of promoting a sound financial system in Nigeria[viii] was also granted regulatory powers under the BOFIA over all Nigerian banks. Sequel to its regulatory powers, banks are not to enter into any arrangement that will change the control (which includes appointment and removal of directors) or significant shareholding of the bank without seeking the prior written consent of the CBN.[ix]

 

Powers of the CBN to appoint and remove Directors

The powers of the CBN to remove and appoint a director can be deduced from the combined reading of sections 33 and 34(1)(2) of the BOFIA. Essentially, the CBN, under section 33, has the power to investigate the affairs of a bank where:

  • a director, shareholder, creditor or depositor applies to the CBN;
  • the bank is carrying on business in a way that is detrimental to the interest of the depositors or creditors;
  • the bank does not have sufficient assets to cover its liabilities to the public;
  • the bank has contravened any provision of the BOFIA or a relevant law; or
  • where it is in the interest of the public to do so.

Based on the investigations conducted under section 33, if the CBN is satisfied that the bank is liable in respect of the issue it was investigated for[x], the CBN may exercise the powers conferred on it under section 34(2) which includes the power to (notwithstanding any law or the memorandum and articles of the bank) remove a director and appoint any person in his stead and stipulate the amount to be paid to that director as remuneration.[xi]

 

Other Financial Institutions

Under the BOFIA, “other financial institution” refer to individuals, groups or companies that engage in the business of discount houses, bureau de change, finance company, money brokerage, foreign exchange purchase, international money transfer services, mortgage refinance or guarantee company, finance holding company or payment service providers, factoring, project financing, debt administration, equipment leasing, fund and investment management, private ledger services, and local purchases order financing.[xii]

Under the BOFIA, where the CBN is satisfied that a company classified as an “other financial institution” is in “a grave situation”, the CBN may exercise the powers granted to it under section 34, including the power to remove and appoint a director.[xiii]

 

Conclusion

The powers of the CBN to appoint and remove directors in a financial services company have been tested at the Court of Appeal[xiv] where it was held that the power of the CBN to remove and appoint directors was legal in line with sections 33 and 34 of BOFIA.[xv] Financial institutions must note that, notwithstanding their powers to remove and appoint directors at their discretion, its decision is subject to the regulatory oversight of the CBN.

 

[i] See our article on “Nigerian Companies and Allied Matters Act 2020 – Does The Removal of a Director Result in His or Her Disqualification as a Director of Other Companies?” https://pavestoneslegal.com/nigerian-companies-and-allied-matters-act-2020-does-the-removal-of-a-director-result-in-his-or-her-disqualification-as-a-director-in-other-companies/

[ii] Section 272 CAMA 2020

[iii] Section 273 (1) CAMA 2020

[iv] Section 274(1) CAMA 2020

[v] Section 288(1) CAMA 2020

[vi] Sections 288(2)(3) CAMA 2020

[vii] Section 2(1) BOFIA

[viii] Sections 1 and 2 CBN Act.

[ix] Section 7 BOFIA. CBN’s Revised Assessment Criteria For Approved Persons’ Regime For Financial Institutions

[x] Section 34(1)(d) BOFIA

[xi] Section 34(2)(f) BOFIA

[xii] Section 131 BOFIA

[xiii] Section 62 (1) BOFIA

[xiv] Danson Izedonmwen & Anor v. Union Bank PLC & Anor (2011) LCN/4919 (CA); appeal no: CA/L/1205/10 delivered by John Inyang Okoro, J.C.A on the 21st day of November, 2011

[xv] Then 33 and 35 of the BOFIA 1990.

HOW TO SET UP A TECH ORGANISATION FOR SOCIAL IMPACT IN NIGERIA

By Seun Timi Koleolu and Praise Adetunmibi

DOWNLOAD PUBLICATION

INTRODUCTION

In Nigeria, technology plays a prominent role in driving the growth and development of the society. In recent times, several tech startups/tech hubs have been established to solve social, cultural, environmental, and even religious matters (“Social Impact Startups”). It is, however, important for these Social Impact Startups to understand what legal structures are most suitable for their operations under Nigerian law.

In this article, we have highlighted the legal structures provided under the Companies and Allied Matters Act 2020 (“CAMA”) and other legal issues to be considered by a Social Impact Startup.

LEGAL STRUCTURES UNDER CAMA

A Social Impact Startup can acquire legal status in Nigeria by registering either as a company limited by guarantee or an incorporated trustee. In determining the most suitable structure, it is important to consider the differences between both structures, as set out below.

 

S/N CRITERIA COMPANY LIMITED BY GUARANTEE INCORPORATED TRUSTEE
1. Profit-making A company limited by guarantee is permitted to make profit. Such profit must however be applied solely towards the objects of the company. An organisation registered as an incorporated trustee is not permitted to make profit in any way. It is to depend on grants and donations.
2. Tax Liability A company limited by guarantee would be required to pay tax on its profits. As organisation is not expected to make profit, it is exempted from paying tax.
3. Registration process The registration process takes at least 3 (three) months as a result of the requirement to obtain the consent of the Attorney General of the Federation (“AG”). CAMA has now provided an alternative which involves the publication of the application for registration in 3 (three) daily newspaper by the Corporate Affairs Commission (“CAC”), where the AG’s consent is not obtained after 30 days. This typically takes a shorter period as only the consent of the Registrar General of the CAC is required.
4. Liability of members in the event of winding up/dissolution In the event of winding up of a company limited by guarantee, the members are required to contribute to the outstanding liabilities of the company. The members of the organisation are not required to make any contributions in the event of its dissolution.

 

In addition, the type of structure to be adopted by the Social Impact Startup is largely dependent on its goals or objects. For instance, where the Social Impact Startup would be making profit through the sale of its products or offering services for a fee, a company limited by guarantee is the most suitable structure.

OTHER LEGAL CONSIDERATIONS

Upon incorporation, there are certain issues to be considered by the Social Impact Startup. Below are some of the issues.

1.Protection of Intellectual Property Rights

In Nigeria, where a software is developed, the copyright in a software automatically vests in the developer. If a Social Impact Startup would prefer that the copyright be vested in them, an agreement that assigns the copyright to the Social Impact Startup would have to be entered into with the developer. This assignment can be done through an employment agreement or a separate copyright assignment agreement. Additionally, it is important that the name and logo of a Social Impact Startup be registered at the trademarks registry.

2. Agreements with Employees, Software Developers etc.

A Social Impact Startup may choose to have both paid and voluntary staff. It is therefore advisable for them to enter into suitable agreements with each staff, such as employment agreements, software development/license agreements, independent contractor agreements etc. As earlier stated, where the Social Impact Startup requires ownership of intellectual property rights, the agreements must expressly provide for the assignment of these rights to the Social Impact Startup.

3. Data Protection Audit

Where the operations of the Social Impact Startup would involve the collection of personal information of members of the public either for training purposes or for grant of access to their technological products, an annual audit must be conducted on their data processing activities by a licensed Data Protection Compliance Organisation (DPCO). Such an organisation is also required to employ a Data Protection Officer (DPO) to ensure compliance with Nigerian data protection laws.

For more information on setting up businesses in Nigeria, please visit https://pavestoneslegal.com/news-publications/

CAMA 2020: SHARE CAPITAL REQUIREMENTS UNDER NIGERIAN LAW

By Aderonke Alex- Adedipe and Akinyanmi Feyijuwa

DOWNLOAD PUBLICATION

Introduction

After years of anticipating a review of the primary law on companies in Nigeria, the President, Muhammadu Buhari on the 7th day of August, 2020, signed into law the Companies and Allied Matters Act, 2020 (“CAMA 2020”). The CAMA 2020 is one of the most significant laws in the Nigerian commercial space due to the key changes introduced by it. In our previous article, we had provided an overview of some of these changes. Today’s article will briefly discuss the share capital requirement for limited liability companies under the CAMA 2020 and its implications.

What is a Share Capital?

A share capital may simply be defined as the amount of money invested in a company by its members in exchange for ownership of shares[1]. A share capital is fundamental to businesses as it determines the extent of liabilities and dividends or profits that the shareholders are entitled to with respect to the company. Also, many regulators, (for instance, the Central Bank of Nigeria), have set minimum thresholds for the share capital of companies which they regulate and companies whose share capital do not meet those thresholds will not be allowed to do business within the industry.

The Companies and Allied Matters Act, 1990 (the “CAMA 1990”) did not make any provision for the definition of the share capital of a company as it was deemed as the company’s authorized share capital. An authorized share capital refers to the maximum number of shares a company is allowed to issue to its shareholders based on its memorandum of association. The CAMA 2020 on the other hand, specifically defines a share capital as the issued share capital of a company at a given time. This provision implies that the share capital of a company includes only shares that have been issued to its members and that companies no longer have the discretion to leave some of their shares unissued as was provided for in the CAMA 1990.

Therefore, unissued shares will not be counted when determining a company’s share capital and companies can no longer reserve a percentage of their share capital for future investors, employee share options scheme or other purposes. The implication of the current position is that companies intending to allot new shares in the future will now be required to increase their share capital to create new shares at the relevant time(s).

What is the Minimum Share Capital of a Company under the CAMA 2020?

The CAMA 1990 set the minimum authorized share capital for private and public companies at N10,000 (Ten Thousand Naira) and N500,000 (Five Hundred Thousand Naira) respectively[2] and allowed companies to issue at least 25% of their share capital while reserving the remainder for future allotment.  The CAMA 2020[3] on the other hand, has set the minimum issued share capital of every private and public company at N100,000 (One Hundred Thousand Naira) and N2,000,000 (Two Million Naira) respectively.

CAC’s Public Notice

The Corporate Affairs Commission (“CAC”) in the Companies Regulations, 2021[4] (the “Regulations”) instructed all companies to fully issue all their unallotted shares on or before 30th day of June 2021. These companies will not be required to pay filing fees for the issuance of such shares. Upon requests made by various stakeholders, the CAC by a public notice dated 16th April 2021 has extended the deadline to the 31st day of December 2022. The Public notice also includes a warning stating that any company that files an application in compliance with section 124 of CAMA 2020, after the deadline on the 31st of December 2022, will be liable to a daily default fee ranging from N250 to N1000 depending on the type and size of the company. The officers of the company will also be liable to a daily default penalty.

How to Comply with the CAMA 2020 Share Capital Requirements

A company can comply with section 124 of the CAMA 2020 and Paragraph 13 of the Regulations by allotting the unissued part of its share capital to its existing shareholders or new shareholders, or by reducing its share capital to the amount already issued, provided they meet the minimum share capital requirement[5]. The process of allotment must be done in accordance with the provisions of the CAMA 2020, the Regulations and other regulations of other relevant regulatory bodies.

Conclusion

In view of the above, persons intending to incorporate a company must bear in mind that the shares of the company must be fully issued to all the subscribers to the company’s memorandum at incorporation. Also, existing companies that have unissued shares are to comply with the directives of the CAC before the 31st day of December, 2022.

[1] https://www.companybug.com/what-is-share-capital/

[2] Section 27(2) of the Companies and Allied Matters Act, 1990.

[3] Section 27(2) of the Companies and Allied Matters Act, 2020.

[4] Paragraph 13 of the Companies regulations, 2021

[5] Section 130 of the Companies and Allied Matters Act, 2020.

TRADING OF FOREIGN LISTED SECURITIES IN NIGERIA – REGULATORY UPDATE

By Seun Timi-Koleolu and Baraebibai L. Ekpebu

Introduction

Regulators of financial service sectors all over the world grapple with the overwhelming effect of disruptive technologies which have left policymakers and academics alike scratching their heads in search of a coherent set of regulatory remedies. This trend also applies to Nigeria, as evident by the recent directive of the Securities and Exchange Commission (SEC), that fintech companies facilitating trade in foreign listed securities, should desist from offering such securities to the Nigerian public through the fiat of registered Capital Market Operators.

From a neutral point of view, the above-mentioned platforms which include companies like Bamboo, Chaka, Risevest, etc. have so far offered Nigerians an opportunity that was hard to imagine not too long ago; the ability to invest in some of the juiciest foreign stocks, bonds, and other securities from US companies like Apple, Amazon, Tesla, Facebook, PayPal, etc. with a few swipes on a mobile phone, thereby expanding their investment reach beyond the borders of Nigeria.

As can be expected, this SEC directive on local trading of foreign securities is viewed from different perspectives by concerned Nigerians. This article aims to analyse the rationale/implications of SEC’s recent directive.

What was the legal basis for the directive?

The SEC directive of 8th April 2021[1] referred to existing provisions of the SEC Rules and Regulations 2013 (Rule 414 and Rule 415), and the Investment and Securities Act, 2007 (Section 67 – 70).

Some points to note from the above-mentioned legislation include the following:

  1. Rule 414 of the SEC Rules and Regulations 2013 permits the sale or offer for subscription of foreign securities to the Nigerian public, through the Nigerian Capital Market.
  2. Rule 415 provides that “Every foreign issuer of securities is required to file an application for registration of its securities with the Commission, accompanied by a draft prospectus and under such conditions as prescribed by the Commission.” (Form SEC 6F).
  3. Section 67 of the ISA 2007 permits only authorised public companies, statutory bodies, or banks (in Nigeria), to offer corporate securities to the public, or deposit money with any Nigerian company for such purposes.
  4. Section 67 also mandates compliance with obligations placed on Sub-Brokers, Market Makers, Underwriters, and Issuing Houses under sections 73 to 87 of ISA 2007. Penalties are prescribed for default, and the written consent of the SEC is compulsory for any such public offers of securities to the public.

Analysis

Notably, the SEC does not introduce any new laws, but simply refers affected companies to pre-existing laws. The SEC Rules do not place an absolute restriction on the sale or offer of foreign securities to local investors. Nonetheless, entities who intend to offer foreign securities for sale within Nigeria, are mandated to register such securities with the SEC. This requirement appears reasonable as it is understandable that economies often opt for protectionist policies geared at aiding domestic investment and curbing capital flight. However, regulators and policymakers need to conduct more research on the economic benefits which the exposure of Nigerian citizens to trading in foreign securities may offer to the economy at large. Though it may seem that Nigerian capital is being invested in foreign jurisdictions to the detriment of the local economy, consideration should also be given to the economic benefits which accrue from successful investments by the Nigerian middle class whose spending power is improved and who obtain a level of insulation from naira devaluation.

Furthermore, Section 67 of the ISA permits only Nigerian public companies, banks, or statutory bodies to offer corporate securities to the public or deposit money with any Nigerian company for trading in local or foreign securities. A capital market must be able to pool funds from both local and international financial markets through the formulation and implementation of policies that promote competition and foreign investment. Therefore, by restricting eligibility to public companies, Section 67 of the ISA may hinder foreign companies wishing to make their stock available to the Nigerian capital market and stifle the ease of doing business in this respect. Financial Authorities may need to explore additional options for the ‘onboarding’ of foreign securities to the Nigerian capital market through technological means.

Conclusion

Studies have shown that the efficiency in the way the Nigerian stock market (or any other stock market globally) dispenses with its functions, is a major determinant of economic growth in the country.[2] Although the development of the tech space in Nigeria (particularly Fintech) has created several investment opportunities within Nigeria and outside Nigeria; for evident economic growth, it is imperative that laws evolve to encourage, whilst regulating innovative technological developments.

The SEC in their efforts to ensure proper regulation of the capital market, may choose to ‘borrow a leaf’ from other jurisdictions such as India and the USA, where investments in foreign company stocks are permitted through several specialized, but regulated schemes.

DOWNLOAD PUBLICATION

[1] Securities and Exchange Commission Nigeria ‘Proliferation of Unregistered Online Investment and Trading Platforms Facilitating Access to Trading in Securities Listed in Foreign Markets’ <https://sec.gov.ng/proliferation-of-unregistered-online-investment-and-trading-platforms-facilitating-access-to-trading-in-securities-listed-in-foreign-markets/>  Accessed on the 10th of April, 2021

[2]Oladayo Timothy Popoola, ‘The Effects of Stock Market on Economic Growth and Development of Nigeria’ (2014) Journal of Economics and Sustainable Development Vol.5, No.15

NIGERIAN COMPANIES AND ALLIED MATTERS ACT 2020 -DOES THE REMOVAL OF A DIRECTOR RESULT IN HIS OR HER DISQUALIFICATION AS A DIRECTOR OF OTHER COMPANIES?

By Seun Timi-Koleolu and Eustace Aroh

DOWNLOAD PUBLICATION

The Nigerian Companies and Allied Matters Act, 2020 (“CAMA 2020”), introduced various changes to the law governing companies in Nigeria, most of which are positive changes.[i]

There is, however, a revision in CAMA 2020 to the grounds for the disqualification of directors (section 283), that has resulted in ambiguity with respect to the implication of the removal of a company director prior to the end of his or her term. In this article, we highlight this ambiguity.

What are the grounds for the disqualification of directors under CAMA 2020 vis-a-vis CAMA 1990?

Below we have compared the grounds for the disqualification of a person from being a director in the Companies and Allied Matters Act 1990 (“CAMA 1990”) vis-a-vis the grounds set out in CAMA 2020.

   

Grounds for disqualification

Contained in
Section 257 CAMA 1990 Section 283 CAMA 2020
The following persons shall be disqualified from being a director    
(a) an infant, that is, a person under the age of 18 years Yes Yes
(b) a lunatic or person of unsound mind; Yes Yes
(c) a person suspended or removed under section 288 of the Act No Yes
(d) a person disqualified under sections 279, 280, 284 of the Act (sections 253, 254 and 258 of CAMA 1990) Yes Yes
(e) A corporation other than its representative appointed to the board for a given term. Yes Yes

 

How does this affect the provisions on the removal of a director?

Under Section 262 of CAMA 1990, a company could by ordinary resolution remove a director prior to the expiration of his or her term as a director, provided a special notice is issued and the director is given the opportunity to make representations to the shareholders on the removal.

Although CAMA 2020 has a similar provision for removal in section 288, by the inclusion of section 283(c) detailed in the table above, there is now an impression that where a director has been removed under section 288 (i.e. prior to the end of his term or prior to a rotation), regardless of the reason for the removal, he will be disqualified from being a director in any other company.

This is because the prevalent view is that, a director who fits within any of the grounds in CAMA for disqualification is not permitted to be a director in other companies.

 

Analysis

In our view, the interpretation of section 283(c) to mean that a director removed before his term would be disqualified from being a director anywhere else is illogical, particularly as a director may be removed by the company for any reason and such reason might not be as a result of a fault or misdeed by that director.

It is likely that the intention of the lawmakers by introducing 283(c) was to limit the disqualification of the director to the particular company removing the director and not all companies. Consequently, if Mr. A is removed by the shareholders from being a director in company X, Mr. A is only disqualified from holding the position of a director in company X.

Conclusion

The foregoing ambiguity would need to be clarified to avoid differing interpretations of section 283(c). In the meantime, directors may wish to consider resigning instead of being removed under section 288 to avoid being deemed as a disqualified director under CAMA.

 

[i] See our article on The Nigerian Companies and Allied Matters Act https://pavestoneslegal.com/the-nigerian-companies-and-allied-matters-act-2020/

 

UPDATE ON REGULATION OF DIGITAL ASSETS IN NIGERIA: SOME LESSONS FROM SWITZERLAND

By Aderonke Alex-Adedipe and Baraebibai L. Ekpebu

 

DOWNLOAD PUBLICATION

Introduction

Generally, skepticism expressed about cryptocurrencies stems from their classification as high-risk assets’’ which are extremely volatile and speculative in terms of price.[1] The main reason for the existence of Blockchain Technologies is their independence from financial endorsement and their universal nature. This is why the regulation of cryptocurrencies remains an arduous task for financial authorities.

Following the recent announcement of the ban on the dealing or facilitation of cryptocurrency transactions by Nigerian financial institutions by the Central Bank of Nigeria (CBN)[2], the Securities and Exchange Commission (SEC) also announced on 11th February 2020, that its previous decision to regulate cryptocurrency investments in Nigeria has now been suspended. In light of these developments, this article aims to shed light on possible options to aid the crafting of a regulatory regime for blockchain technologies in Nigeria.

There are indeed some valid concerns about cryptocurrency transactions. For instance,  the fact that they create new opportunities for criminals and terrorists to launder their proceeds, or finance their illicit activities.[3] Notwithstanding, the Swiss have built a system that innovatively utilizes pre-existing Swiss law and novel legislation, to regulate the activities of blockchain service providers in Switzerland.

Nigeria is responsible for more cryptocurrency trading than most countries and is currently rated as the third highest globally for trading volumes in cryptocurrency. It is therefore desirable, that a robust regulatory regime exists to govern these transactions, address negative tendencies, and in effect, strengthen the financial services industry and the Nigerian economy in general. For these reasons, it is essential to examine some key aspects of Swiss Blockchain Laws to understand the methodology employed to provide a grounded basis for digital asset exchange and tokenization, while simultaneously addressing the issue of digital currency money laundering.

The Swiss Approach

The Swiss Financial Market Supervisory Authority or ‘FINMA’’ recognises the tendency for block-chain business models to sidestep existing regulations. To put a check on such tendencies, Swiss authorities have successfully placed blockchain service providers under the ambits of the Swiss Anti-Money Laundering Act.[4] Blockchain service providers in Switzerland are mandated to verify all their customers’ identities, monitor business relationships based on risk level, and report to the ‘Money Laundering Reporting Office Switzerland (MROS), where there are reasonable grounds to suspect money laundering. All Virtual Asset Service Providers who intend on doing business in Switzerland are required to apply for a license from FINMA.

The new Swiss laws define ‘exchange digital securities’ and stipulate the legal procedure for the seizure of digital currency assets in bankruptcy proceedings. The roles of digital currency trading platforms and their legal standing on digital securities are also well clarified.

FINMA has currently granted licenses to several financial institutions to carry out cryptocurrency trading activities. This has served to promote distributed ledger technology and incorporate crypto assets into portfolios and Exchange-Traded Funds.

Switzerland is noted to have a comprehensive regime for Initial Coin Offerings (ICOs) which are also regulated under money laundering laws, terrorist financing laws, securities trading laws, banking laws and, Swiss collective investment scheme legislation.

Residents of the Canton of Zug in Switzerland (referred to as the “Crypto Valley”) can now pay their taxes in bitcoin and cryptocurrencies up to 100,000 CHF, under the supervision of the Swiss Federal Tax Administration (SFTA).[5]

Interestingly, like the Nigerian position, cryptocurrencies are still not classed as a legal tender in Switzerland, neither are they considered to be “money” for reasons that their intangible nature stops them from being classified as a “thing” under Swiss civil law.[6]

Conclusion

From the foregoing, it is evident that a technology-neutral legislative approach is needed and can be developed in Nigeria. To achieve this, active steps need to be taken towards streamlining regulations on insolvency, financial market, banking, collective investment, and anti-money laundering into a legal framework for the regulation of cryptocurrency transactions and investments in Nigeria. This is likely to trigger an unprecedented boost in the Nigerian economy which has continuously suffered from currency devaluation over the years.

 

[1] Mario Draghi, President of the ECB, Introductory Statement and Closing Remarks at the European Parliament Plenary Debate on the ECB Annual Report for 2016 (Feb. 5, 2018), https://www.ecb.europa.eu/press/key/date/ 2018/html/ecb.sp180205.en.htmlarchived at http://perma.cc/M6WX-T3RR.

[2] Aderonke Alex-Adedipe and Eustace Aroh, (Pavestoneslegal September 23, 2020) Regulation of Cryptocurrencies and Other Digital Assets in Nigeria accessed 24 March 2021

[3] CGMF’s report, National Risk Assessment: Risk of money laundering and terrorist financing posed by crypto assets and crowdfunding, October 2018

[4] Federal Council report – Legal framework for distributed ledger technology and blockchain in Switzerland, December 2018

[5] Tanzeel Akhtar, (Nasdaq, February 18, 2021)  Switzerland’s ‘Crypto Valley’ Has Started Accepting Bitcoin, Ether for Tax Payments accessed 24 March 2021

[6] Mueller / Reutlinger / Kaiser, p. 86 et seq .; Maurenbrecher / Meier, protection of users of virtual currencies under insolvency law; Eggen, Chain of Contracts – A private law dispute with Distributed Ledgers, AJP 2017, p.14; Bärtschi / Meisser, Virtual Currencies from a Financial Market and Civil Law Perspective, in: Weber / Thouvenin (ed.), Legal challenges through web-based and mobile payment systems, Zurich 2015, p. 141

 

REGULATION OF USSD SERVICES IN NIGERIA – CHARGES ON FINANCIAL TRANSACTION

By Seun Timi-Koleolu and Feyijuwa Akinyanmi

DOWNLOAD PUBLICATION

Unstructured Supplementary Service Data (USSD) has evolved from being a channel employed predominantly by Mobile Network Operators (Telcos) to one deployed by a broad spectrum of service providers. Most financial institutions have sought the services of different Telcos to deploy unique USSD codes, allowing millions of Nigerians to enjoy basic banking services from the comfort of their homes and without the need for internet connection.

How do USSD codes work?
USSDs are sometimes referred to as “quick codes” or “feature codes”. They are communication protocols that allow customers to send queries or requests and receive solutions simply by dialling a short code that begins with an asterisk (*) and ends with a hash(#) symbol. Some examples of USSDs include GTBank’s *737#, Zenith Bank’s *996#, Ghana Commercial Bank’s *422#, Kenya National Bank’s *625# e.t.c. Practical uses of USSDs in the finance space include the transfer of funds, airtime top-ups, account balance checks, BVN checks etc.

 

Are there any regulations on the use of USSD services for financial transactions?
USSDs for financial transactions are majorly regulated by the Central Bank of Nigeria (CBN) Regulatory Framework for the Use of Unstructured Supplementary Service Data (USSD) for Financial Services in Nigeria, 2018; and the Nigerian Communications Commission (NCC) Guidelines on Short Code Operation in Nigeria, 2011.

Financial institutions who wish to provide USSD services to their customers are required to obtain a letter of no objection or introduction from CBN before being considered for the issuance of the USSD shortcodes by the NCC.

 

How have customers been billed for USSD services?
For over two years now, Telcos and Deposit Money Banks (DMBs) in Nigeria have had prolonged disagreements over the appropriate USSD pricing model for financial transactions. The crux of the issue has been whether the Telcos are to adopt the End User billing model i.e. charging customers directly; or the Corporate billing model i.e. charging the financial institution directly. NCC issued a publication on the 24th  day of July 2020[1], prohibiting Telcos from using the End User billing model and instructing that they employ the Corporate billing model. The basis for this was that granting access to USSD channels was a service delivered by Telcos to financial institutions and not customers.

 

What are the current directives by the CBN and NCC on USSD billing?

On the 12th  day of March 2021, the Association of Licensed Telecommunication Operators of Nigeria (ALTON) threatened to withdraw USSD services from DMBs until the ₦42 billion debt they owe for the services is settled[2]. In response to the above, the NCC and CBN on the 16th day of March 2021, issued a joint statement to the effect that DMBs and other financial institutions will be charged a flat fee of N6.98 per transaction; in accordance with the Corporate billing model. The new charge is to be deducted from customers’ accounts by the financial institutions on behalf of the Telcos. Financial institutions are now prohibited from charging customers any other fees for the service.

Conclusion

In response to the above, the joint statement finally brings clarity on how payment is to be made for USSD services and seems to be a win for the Telcos. Although the Corporate billing model appears to have been adopted, customers will ultimately bear the costs. This may adversely affect the popularity of USSD transactions within the general populace, particularly low-income earners.

[1] https://www.ncc.gov.ng/accessible/documents/910-determination-of-ussd-pricing-amended/file

[2]https://www.thisdaylive.com/index.php/2021/03/15/telcos-suspend-withdrawal-of-banks-ussd-services/

SONCAP CERTIFICATE; A REQUIREMENT FOR IMPORTATION OF GOODS INTO NIGERIA

By Aderonke Alex-Adedipe and Eustace Aroh

DOWNLOAD PUBLICATION

1. Introduction
The Standard Organisation of Nigeria (SON) was established by the Standard Organisation of Nigeria Act (No 56) of 1971 with the mandate to set the Standards for manufacturing and sale of products, materials, processes and services amongst others; to certify and provide assistance in the production of quality of goods and services; and improve measurement accuracies and circulation of information relating to standards.

The SON in 2005, introduced the Standards Organisation of Nigeria Conformity Assessment Program (the “Program”) to address the problem of substandard and unsafe products imported into the country. Under the Program, certain imported products[1], are required to be inspected to conform with essential requirements, technical regulations and approved industrial standards before importation into Nigeria.

For convenience and efficiency, the SON accredited some independent firms such as Cotecna, Intertek, SGS, CCIC etc (“Accredited Firms”) to process and issue SONCAP Certificate on behalf of the SON[2].

In this article, we summarise the procedure and steps to obtaining a SONCAP Certificate below.

2. What are the steps to obtaining a SONCAP Certificate?
A Product Certificate (“PC”) is a mandatory requirement for products regulated by the SON. The PC is also a pre-requisite for the issuance of a SONCAP Certificate for imported products. There are three (3) categories of PCs and an importer may make an application based on frequency as described in the table below.
PC type Preference Validity Period

PC type Preference Validity Period
1 Product Certificate one Preferred for one-time importers 6 months
2 Product Certificate two Preferred for occasional importers 1 year
3 Product Certificate three Preferred for frequent importers 1 year

 

3. How should an application for a PC be made?
An application for a PC should be accompanied by the following documents[3];

i. an application form;
ii. an ISO 9001 Certificate of the manufacturer;
iii. a test report of the product from an accredited ISO17025 laboratory[4];

iv. a quality declaration from the manufacturer;
v. a picture of the product or a sample of the product (where the Accredited Firm requests);
vi. all other quality documents available; and
vii. Factory Inspection/Audit (applicable only for PC 3).

4. How long does it take to process a PC?
Provided that all the required information and documentation are satisfactory, the PC will generally applicable issued between three to seven (3-7) days depending on the Accredited Firm.

5. What is the next step after obtaining the PC?
The next step is to obtain an e-Form M[5] required for the clearing of products at the Nigerian port. The PC is used to process the e-Form M on the Nigerian Single window for trade portal or through an authorised dealer (usually a commercial bank). Upon approval by an authorised dealer and registration by the Nigeria Customs Service (NCS), the importer may then proceed to apply for a SONCAP Certificate.
Upon successfully obtaining the e- Form M, the importer may apply for a SONCAP Certificate through one of the Accredited Firms. The SONCAP Certificate is linked to the PC obtained for the product and a particular shipment may or may not be subject to inspection based on the category of the PC obtained as described in the table below.

PC Type Inspection Rate
Product Certificate one 100% inspection rate
Product Certificate two 40% inspection rate
Product Certificate three 20% inspection rate

6. How should an application for SONCAP be made?
To process a SONCAP Certificate, a company will be required to provide the following:

i. SONCAP application/ request for certificate form
ii. A Valid PC for each product;
iii. Tax Identification Number;
iv. Pro forma Invoice; and
v. E-Form M.

7. Conclusion
A SONCAP Certificate is a condition precedent required for the clearance of products at the Nigerian port[1]. This has played a pivotal role in reducing the importation and sale of substandard products in the country. The Program has proven to be a step in the right direction in ensuring the availability of quality products in Nigeria.

 

[1] https://son.gov.ng/soncap_service

[2] These Accredited Firms have offices in several countries across the world.

[3] In some cases, Accredited Firms may request additional information/documentation in respect of certain products.

[4] Where the importer is unable to produce a satisfactory test report, the Accredited Firm shall test the product based on SON standards.

[5] This is used by the Central Bank of Nigeria (CBN) to track and collect import duties.

[6] It is pertinent to note that some products are exempt from the Program pursuant to a SON Circular with reference number SON/SONCAP/EX/Vol. 1/005. These products which include, food, medicine and medical products, chemical products etc, are nonetheless subject to other regulatory requirements.

DATA PROTECTION IN NIGERIA: DISTINGUISHING BETWEEN A DATA CONTROLLER AND A DATA PROCESSOR

By Seun Timi-Koleolu and Praise Adetunmibi

 

DOWNLOAD PUBLICATION

Introduction

In this digital age, data has become a vital asset for both individuals and corporate bodies. It has in fact been regarded as the world’s most valuable resource[1]. The question then is, what is data?

Data can simply be defined as information that has been translated into a form that is efficient for movement or processing[2]. It can be collected, used, shared, measured, analysed, stored and destroyed (data processing). The most common type of data is personal data, which refers to any information related to an identified or identifiable natural person. In Nigeria, the National Information Technology Development Agency (NITDA) through the Nigeria Data Protection Regulation (NDPR)[3], regulates the processing of personal data of Nigerian citizens. Persons who engage in data processing activities can either be Data Controllers or Data Processors.

Under the NDPR, startups, businesses and companies that engage in the processing of personal data of over 1000 Nigerians, are mandated to conduct a detailed annual audit of their data processing activities. This audit is to be conducted by a licensed Data Protection Compliance Organisation (DPCO). Failure to comply with the provisions of the NDPR will result in the payment of a fine of 10 million Naira or 2% of the annual turnover (whichever is greater).

In view of the foregoing, it is useful to understand when you will be considered as a data processor and when you will be considered to be a data controller; for the purpose of complying with the provisions of the NDPR. In this article, we have provided a guide on how to identify each category.

Who is a data controller?

A data controller simply means any person or company that determines “why” data is to be processed and “how” data is to be processed. Most businesses/companies collect the personal data of clients/customers in the course of providing services to them (e.g. by requiring the customers to complete an online or physical, registration form for the service or for the purpose of payment); in all such instances that company/business is a data controller.

Furthermore, where companies/businesses share personal details of their customers, such as names, email addresses, phone numbers to third-party service providers, for various business purposes such as to market their products  (e.g. sharing with a Digital Marketing Agency); or to enhance their service delivery (e.g. sharing with an Information Technology Partner), that company/business remains the data controller in those instances and primarily responsible for the use and protection of the data.

In addition, companies and business owners are data controllers of data they collect in respect of their employees and remain primarily responsible for the use of such data.

Who is a data processor?

Companies/businesses are regarded as data processors when they are involved in the processing of data, on the instruction and on behalf of another person (data controller). Effectively, a data processor cannot act on its own or undertake any data processing activity without the permission of the data controller.

In the scenarios given above, the Digital Marketing Agency and Information Technology Partner are data processors. Also, where a company outsources payroll payment to a third party or other human resource related services, that third party would be seen as the data processor.

Can a data processor be a data controller?

Yes. What distinguishes a data controller from a data processor is control. Where you have control over which data is to be collected and the purpose for which the data is to be collected, you are the data controller. Where all you have is the possession of the data and must act in accordance with the instructions of another person, then you are the data processor.

Where you, however, have both control and possession of data (i.e. the data was given to you by a third party), in such an instance, you act as both a data controller and a data processor.

Conclusion

Under Nigerian law, data controllers and data processors are required to undergo Data Protection Compliance audits and generally adhere to the provisions of the NDPR. Each business should be clear on whether they are handling data in the capacity of a data controller or a data processor as the obligations of a data controller vary from the obligations of a data processor.

If you require clarity as to whether your business would be categorised as a data controller or a data processor, please do not hesitate to contact the team at Pavestones Legal.

[1] The Economist, ‘The World’s Most Valuable Resource is no Longer Oil, but Data’   Economist (6 May 2017) <https://www.economist.com/leaders/2017/05/06/the-worlds-most-valuable-resource-is-no-longer-oil-but-data>

[2] https://searchdatamanagement.techtarget.com/definition/data

[3] To understand more about the NDPR, follow the link to our article https://pavestoneslegal.com/nigeria-data-protection-regulation-2019/

Data Protection In Nigeria; Impact On Open Banking Regulation

By Aderonke Alex-Adedipe and Eustace Aroh

Introduction

The rapid growth of finance and technology (fintech) companies in the last decade have been necessitated by consumers’ needs for faster and more convenient financial services. These needs continue to evolve over time and traditional financial institutions struggle to keep up. Open banking offers financial institutions who have access to information of customers (“Providers”) the opportunity to share such information with other financial institutions (“Consumers”) to keep them aware of those needs and enable them offer optimum services.

In our previous article, we highlighted the provisions of the recent Central Bank of Nigeria’s (CBN) Regulatory Framework for Open Banking in Nigeria (“Framework”). In today’s article, we consider specifically, the implication of data sharing under the Framework in light of the Nigeria Data Protection Regulation 2019 (NDPR).

NDPR
The NDPR was issued by the National Information Technology Development Agency (NITDA) in 2019 to regulate the collection, processing and storage of personal data. Personal data is information relating to an individual who can be identified, directly or indirectly, in particular by reference to an identifier. It includes a name, address, a photo, an email address, bank details, medical information, IP address, IMEI number, IMSI number, SIM, and others.

Due to the fact that the damage an individual may suffer in the course of breach of some personal data may be higher, data such as ethnic and racial information, religious beliefs, biometric and health information are categorized as sensitive data. These data must, therefore, be subject to a higher level of protection. Although the NDPR does not classify financial data as sensitive data, financial institutions have access to a number of sensitive data such as ethnicity and biometrics.

Applicable Personal Data
Under the Framework, four types of data qualify for the open exchange of data. These are Product Information and Service Touchpoints (PIST), Market Insight Transactions (MIT), Personal Information and Financial Transaction (PIFT), Profile, Analytics and Scoring Transaction (PAST). Only the PIFT and PAST, however, involve the sharing of personal data of consumers amongst participants.

The PIFT deals with the sharing of customer’s information provided during the Know Your Customer (KYC) process and information of the customer’s transactions such as account balance, payments, loans, recurring transactions etc. The PAST involves the sharing of information on the customer which analyses, provides scores and gives an opinion on customer behaviour (profiling).

Safeguards of the Framework
The Framework stipulates a number of security standards and protocols with respect to sharing of personal information over the Application Programming Interface (API) as it relates to authentication, authorisation, encryption, and secure hosting of data. The Framework also provides for a risk management system for each participant to, among others, track the risk of data sharing with other participants, comply with data privacy laws such as the NDPR, and report such associated risks to the CBN.

Consent
Irrespective of the data protection requirements under the Framework, the Framework specifically requires participants to comply with all extant laws on data privacy such as the NDPR and the NDPR Implementation Framework. Under the NDPR, before personal data of a customer can be used for a purpose different from that which it was initially given, the data controller, (in this case, the financial institution) is required to inform the customer of:

  1. the purpose for which the data was originally collected;
  2. if there is any connection between the original purpose and the proposed purpose;
  3. the possible impact of the new processing on the data subject; and
  4. the existence of security safeguards to protect the data.

The Framework further requires participants to list the specific rights which customers may grant to the participants and obtain the consent of the customer for each right separately.

Providers are also expected to ensure that customers revalidate their consent annually or after 180 days in cases where the services of the provider have not been used.

Conclusion
While the Framework seeks to support innovation in the Nigerian financial sector, participants of the open exchange of data are expected to reassess their data privacy practices to ensure they meet data compliance requirements of the NDPR and the Framework.