Compliance in Nigeria: Data Protection Directives for Businesses

BY SEUN TIMI-KOLEOLU AND EBIKENIYE BEST

Introduction

As businesses in Nigeria increasingly leverage technology including social media platforms such as LinkedIn, Instagram, and Medium; and Emerging Technologies including Artificial Intelligence to expand their customer reach both locally and internationally, such businesses must adhere to Data Protection provisions in Nigeria.

In view of the foregoing, it is important to note recent updates to the protection of Personal Data in Nigeria. The most recent update is the Nigeria Data Protection Act – General Application and Implementation Directive (the “GAID”) issued on March 20, 2025, by the Nigeria Data Protection Commission (the “Commission”).

In this newsletter, we have set out useful information on the GAID to guide businesses.

1.     What is the effect of the GAID on the Nigeria Data Protection Regulation (NDPR), 2019?

With the adoption of the GAID, the NDPR shall no longer regulate data in Nigeria. Data Protection in Nigeria is now regulated by the existing Nigeria Data Protection Act and the GAID.

Please note, however, n that any act done under the NDPR prior to the issuance of the GAID remains valid.

2.    What are the obligations under the GAID for data controllers and processors?

Under the GAID, data controllers and processors of major importance are required to adhere to certain obligations including:

a.    engaging a licensed Data Protection Compliance Organisation (DPCO) to carry out an audit of their business within 15 (fifteen) months of commencing business and subsequently annually before March 31 of each year;

b.    filing a compliance audit report not later than March 31 of each year through a DPCO;

c.     appointing associate/assistant Data Protection Officers (DPOs) and privacy champions to support the DPO where the data controller or processor interfaces with data subjects on multiple platforms;

d.    storing personal data for not more than 6 (six) months after the purpose of processing the data has been achieved. Please note that this would only apply where no existing law has specified a retention period.

3.   In what circumstances is explicit consent required under the GAID?

The GAID acknowledges that consent as a lawful basis for processing personal data could be constructive or implied. It, however, states that explicit consent is required for certain activities like – direct marketing, processing children’s data and sensitive personal data, automated decision making and cross-border data transfer.

4.    Are there provisions for Emerging Technologies?

Yes, the GAID now provides explicit provisions on Emerging Technologies such as Artificial Intelligence, Blockchain, and the Internet of Things. It requires that any data controller or processor deploying or planning to deploy Emerging Technologies for personal data processing must adhere to the provisions of the NDPA, public policies, the GAID, and any other regulations issued by the Commission.

In addition, a data controller or processor must do the following:

a.    develop and implement technical and organizational frameworks for the design of Emerging Technologies tools, ensuring that these frameworks are properly documented and submitted to the Commission; and

b.    conduct a Data Privacy Impact Assessment, considering factors such as how data processing might unfairly affect different groups and the level of risk faced by vulnerable individuals, to access and reduce privacy risks effectively.

5.    Are there provisions on Data Ethics under the GAID?

Yes. In auditing data controllers and processors, DPCOs are required to confirm if data controllers and processors apply global best practices on Data Ethics when handling personal data. The DPCO must ensure that data controllers and processors possess: (i) organizational policy on ownership of data; (ii) demonstrable transparency and accountability; (iii) fairness of intention; and (iv) respect for data subjects’ rights to control the use of their personal data.

6.    What are the requirements for Cross-Border Data Transfer?

Under the GAID, a data controller or processor must obtain approval from the Commission before transferring personal data outside Nigeria. The Commission will grant approval based on an adequacy decision, which considers whether the receiving country has enforceable data subject rights; a robust data protection law; and a competent supervisory authority with sufficient enforcement powers.

In the absence of an adequacy decision, the data controller or processor will be required to prepare and submit a Cross-Border Data Transfer Instrument (the “Instrument”) for approval by the Commission. This Instrument may be in the form of (i) code of conduct; (ii) certification, (iii) binding corporate rules; or (iv) standard contractual clauses.

7.    Are data subject’s rights provided for under the GAID?

The GAID reinforces data subjects’ rights, including the right to access, right to rectification, right to data portability, right to be forgotten, right to lodge a complaint, and right to objection. Businesses are required to create transparent and easy to use processes to respond to these rights promptly.

8.    What is the procedure for lodging complaints under the GAID?

The GAID now allows data subjects who believe that their right to privacy has been violated to seek redress directly from data controllers by sending a document titled “Standard Notice to Address Grievance” to the relevant data controller or processor. A format of this document has been provided in the GAID. This action is to be taken without prior notification to the Commission.

9.    When will the GAID come into effect?

The Commission noted that for ease of doing business, the GAID shall take effect 6 (six) months from the date of publication, that is, September 2025.

Conclusion

To ensure compliance with Nigeria’s evolving data protection landscape, organizations should carefully review the key updates introduced by the GAID. To align with applicable data protection laws, organisations should engage the services of licensed DPCOs.

 

For more information on data protection compliance, please see our previous newsletter.

INFLUENCER AND DIGITAL MARKETING REGULATION IN NIGERIA

BY ADERONKE ALEX-ADEDIPE AND PROMISE ITAH

INFLUENCER AND DIGITAL MARKETING REGULATION IN NIGERIA

Introduction
As businesses continue to explore innovative ways to engage their target audience, influencer marketing and digital advertising (ads) have become increasingly popular. This marketing strategy presents significant opportunities for businesses and influencers alike. It is however essential for all parties involved to understand the legal implication of their activities to avoid potential legal pitfalls.

In this newsletter we highlight key legal aspects of influencer marketing and digital advertising which businesses, influencers, and digital marketers need to consider.

What is Influencer Marketing?

This occurs when businesses collaborate with individuals (influencers) who have a substantial following or influence on social media platforms, blogs, or other digital channels to promote products, services, or brands to their audience, leveraging their credibility and trust.

What is Digital Advertising?

This involves using online platforms, websites, and digital channels to promote products, services, or brands. This includes various strategies such as display ads, search engine marketing (e.g., Google ads), social media ads, email marketing, and video ads, all targeted toward specific demographics or user behavior.

What You Need to Know

1.Advertising and Marketing Content
As the primary regulatory body for advertising in Nigeria, the Advertising Regulatory Council of Nigeria (ARCON) sets the rules governing advertising activities, including those in the digital space, such as influencer marketing campaigns and online ads. The Advertising Regulatory Council of Nigeria Act (ARCON Act), the Code of Advertising Practice, and the Vetting Guidelines establish specific principles and requirements for advertising and marketing content and materials. Some key considerations  include:

  • Advertising and Marketing Principles: Marketing and advertising materials must be truthful, decent, and non-deceptive, ensuring they are appropriate for minors if the target audience includes them. Content should never exploit sexual behavior, promote superstition, or discriminate based on sex. It should also avoid misleading or exaggerating claims. Influencers who endorse brands and products must ensure that endorsements  they give are accurate and transparent, providing genuine recommendations. It is essential that brands and influencers constantly review their materials to ensure they comply.
  • Vetting of Advertisements and Marketing Materials: All marketing and advertising materials, including flyers and jingles intended for digital platforms, must undergo vetting by ARCON before publication. The only exceptions are vacancies, notices, financial statements, goodwill messages, obituaries, and immemorial ads. The Vetting Guidelines issued by ARCON provide the procedure to follow to obtain vetting approval for advertising and marketing materials before exposure to the public.
  • Failure to obtain vetting approval prior to exposure of the advertising or marketing materials attracts a fine of up to N1,000,000.00 (One Million Naira) per infraction from ARCON. The ARCON Act also makes failure to obtain vetting approval prior to exposure a crime punishable by both fine and imprisonment upon conviction.
  • Disclosure of Paid Partnerships: Influencers must clearly disclose any paid partnerships to maintain transparency and prevent misleading their audience by presenting paid promotions as organic content.

2.Consumer Protection
The Federal Competition and Consumer Protection Commission Act (FCCPCA) empowers the Federal Competition and Consumer Protection Commission (FCCPC) to maintain and protect consumer rights in Nigeria. Brands and influencers must avoid engaging in unfair or deceptive marketing practices that could harm consumers. Key things to look out for here include:

  • False Advertising & Consumer Rights: Both influencers and advertisers must avoid practices that mislead or deceive consumers. False or exaggerated claims about products or services can lead to consumer complaints and regulatory sanctions from the Federal Competition and Consumer Protection Commission (FCCPC).
  • Transparency in Pricing and Products: The FCCPC mandates clear and honest communication about product pricing and quality. Influencers must avoid making misleading claims, such as promising unrealistic results or misrepresenting product effectiveness.
  • Brands and influencers who engage in activities that violate these provisions and other consumer rights may be required to pay damages to consumers or face fines imposed by the FCCPC. Additionally, engaging in unfair and deceptive practices that infringe upon consumer rights is considered a criminal offense under the FCCPCA, which may result in fines and potential imprisonment for the brands and influencers involved.

3.Data Privacy and Protection
Personal data is sometimes often processed during the creation and publication of digital ads. Brands and influencers must therefore comply with the Nigeria Data Protection Act (NDPA) and other data protection laws and regulations when collecting, processing, and using consumer data. Key points include:

  • Data Collection and Consent: Businesses and influencers must obtain explicit consent before collecting or processing personal data of individuals, including using cookies or tracking data to target ads. Non-compliance with the NDPA may result in severe penalties.
  • Data Sharing and Security: Influencers and brands must ensure consumer data is securely stored and not shared without consent. If data is shared, there must be adequate protection provided for such data.

4.Intellectual Property
Influencers and businesses must be cautious about intellectual property laws when creating or sharing content. The Copyright Act in Nigeria governs the protection of original works, including photographs, videos, written content, and logos.

  • Use of Copyrighted Content: Influencers often share content provided by brands. Both brands and influencers must ensure that the content shared does not violate copyright laws. Proper licenses or permissions should be obtained for any third-party content used in marketing campaigns.
  • Trademarks and Branding: Brands must protect their logos, trademarks, and other intellectual property from unauthorized use through contractual arrangements. Influencers should avoid infringing on trademarks when promoting products.

5.Contractual Agreements and Legal Liabilities
Contracts between brands and influencers are essential for defining the scope of work, compensation, content requirements, timelines, and other terms. Clear written contracts help avoid misunderstandings and protect all parties involved. These contracts should include the following key provisions:

  • Terms and Conditions: Contracts should specify deliverables, payment schedules, content rights, and usage restrictions.
  • Breach of Contract: Both influencers and brands should be aware of their contractual obligations. Breaches may lead to legal disputes and claims for damages. Brands should include clauses that protect them against potential non-performance by influencers.

6.Social Media Platforms and Terms of Service
Influencers and advertisers must adhere to the terms of service of platforms like Instagram, Facebook, X (formerly Twitter), and TikTok. These platforms have specific rules regarding advertising, promotions, and sponsored content.

  • Platform Rules on Sponsored Content: Most platforms require influencers to disclose when content is sponsored or when they are paid to promote a product. Influencers must comply with these rules to avoid sanctions such as account suspension or banning.
  • Platform Liability: Brands and influencers must understand the platform’s role in digital advertising. While platforms provide the medium, they may not always enforce advertising laws. However, they can remove content that violates policies or legal standards.

Conclusion
As influencer marketing and digital advertising continue to grow in Nigeria, understanding the legal landscape is crucial for businesses, influencers, and marketers. Adhering to advertising, consumer protection, data privacy, and intellectual property laws can mitigate legal risks and ensure that marketing campaigns are conducted ethically and transparently. The foregoing is, however, not exhaustive, and we advise seeking legal counsel to effectively navigate legal aspects of influencer marketing and digital advertising.

Intellectual Property Protection in Nigeria’s Agricultural Sector

BY SEUN TIMI-KOLEOLU AND HILLAY OKOROTIE

INTRODUCTION

The agricultural sector is an important sector in Nigeria, with great potential to drive significant growth to the economy. There are various opportunities in the sector to create value which are largely untapped. One of these opportunities is with respect to the value that can be derived from the protection of Intellectual Property( “IP”) arising from innovative works- such as improved plant varieties, and new food processing technology amongst other novel works- developed by players in the agricultural sector.

In view of the foregoing, we have set out in this newsletter some IP protections available for innovative works in the agricultural sector to enable players in this space explore protecting their creative works and derive investment value amongst other values from such protection.

Plant Variety Protection (PVP)

One of the most significant developments in Nigeria’s agricultural IP landscape is the Plant Variety Protection Act (the “Act”) 2021. This legislation grants breeders the right to protect their IP in new plant varieties they develop. With protection under this Act, a breeder has the exclusive and sole  right to reproduce, export, or license their  proprietary right in the protected varieties. The Act also grants the breeder exclusive proprietary rights to the plant variety developed for a duration of 20 years. With this protection, the breeder will for a period of 20years from the date of registration, have the sole right to grant licenses to third parties to use the plant variety and obtain payment for granting such right. The breeder may also attract investments for his or her unique IP in the plant variety.

Patenting of Novel Agricultural Technology

Another form of protection available to stakeholders in the agricultural sector is a Patent. The sector can benefit from protecting novel technologies, such as novel food processing machines, mechanized farming tools and techniques by obtaining a Patent for such technologies.

An inventor who obtains a Patent for his or her agricultural technology invention will have exclusive proprietary right to the invention for up to 20 years. This means that where third parties wish to use the technology, they will have to obtain a license or similar rights from the inventor to use or reproduce that technology and make payments to the inventor for the grant of such rights.

It should be noted that a duly registered Patent has the potential to increase the investment value of the inventors business and drive investment to the business.

Protecting Trade Secrets and Trademarks

Another IP which can drive value to players in the agricultural sector is the Trade secret of the business such as formulas, business process, techniques and other confidential information that have played a key role in the success of the business. Such Trade secrets are valuable and can increase the investment value of businesses. Accordingly, Trade secrets should be guarded carefully to ensure they are not freely available in the public domain. To safeguard Trade secrets, businesses must implement confidentiality measures, this may include  non-disclosure and confidentiality clauses in agreements with potential investors, employees or consultants.

The Trademark of the agriculture business and products is also valuable IP which should be carefully guarded by registering the trademark at the Trademark registry. Please see our newsletter for more information with respect to trademarks.

Geographical Indication (GI)

Although Nigeria is yet to enact legislation protecting Geographical Indications (GIs), it is useful to note its potential to drive value to Nigeria.

GI are products originating from specific locations which can be registered by representatives of a country in relevant registries as IP of that country. For instance, “Champagne” is registered as a GI for France, “Argan” Oil for Morocco and “Darjeeling” tea for India.

Certain Nigerian products, like “Ijebu Garri” or “Amala,” could benefit from GI registration as they have gained international recognition and should be protected as IP belonging to Nigeria.

It is important that our policymakers establish a framework for the registration of Nigeria GIs at international trademark offices and within Nigeria.

GI registration would also help distinguish Nigerian agricultural products in the global food supply chain and create economic opportunities for the country’s agricultural sector. It would also prevent foreign competitors from marketing products as Nigerian-origin, thereby securing an exclusive market for Nigeria’s agricultural sector.

Conclusion

By effectively protecting IP, the Nigeria’s agricultural sector can drive innovative research, increase productivity, and create opportunities for employment. There is also the need for policy makers to provide the framework that would encourage registration of GI in various international trademark offices thereby providing distinction and marketability for Nigerian specific product in the global food supply chain.

For more information on Trademarks and Patents, please see our newsletters at

  1. https://pavestoneslegal.com/requirements-and-procedure-for-registration-of-trademarks-in-nigeria/
  2. https://pavestoneslegal.com/registering-patents-in-nigeria/

 

 

Compliance with Nigerian Data Protection Laws – The Role of Data Protection Compliance Organizations

BY ADERONKE ALEX-ADEDIPE AND OLAWALE ATANDA


Introduction

In an era where data breaches and privacy concerns are on the rise, organizations processing Personal Data must prioritize compliance. In Nigeria, data protection laws have evolved to ensure businesses and public institutions uphold data privacy standards.

The Nigeria Data Protection Act, 2023 (NDPA) and the Nigeria Data Protection Regulation, 2019 (NDPR) set out the legal obligations for entities that collect, process, and store personal data. To assist organizations in meeting these obligations, the Nigeria Data Protection Commission (NDPC) issues licenses to qualified Data Protection Compliance Organisations (DPCOs). These specialized firms provide guidance, conduct statutory data audits, and help businesses implement robust compliance frameworks.

This newsletter addresses the key responsibilities of DPCOs vis-à-vis the regulatory framework governing data protection in Nigeria.

Regulatory Framework for Data Protection Compliance Organizations

Section 33 of the NDPA empowers the NDPC to license DPCOs to monitor, audit, and report on data protection compliance. According to the NDPC, DPCOs may be Law Firms, Professional Service Consultants, IT Service Providers, or Audit Firms.

Only licensed DPCOs are authorized to conduct data protection audits.. Furthermore, Part 4.1(4) of the NDPR mandates DPCOs to provide training and compliance consulting to Data Controllers (and Processors).*

The NDPR mandates all organizations that process Personal Data to conduct audits of their privacy and data protection practices. These audits must detail the nature of Personal Data collected, purpose of collection, notice provided to Data Subjects*, policies and procedures for data protection, security measures, and other key compliance factors.

In addition, organizations that process up to 2,000 Data Subjects’ data within 12 months or up to 1,000 within 6 months must submit a Compliance Audit Report (CAR) to the NDPC by March 15 each year. Failure to meet this deadline will attract a penalty of 50% of the filing fee.

Core Functions of DPCOs

DPCOs provide a swathe of services in relation to data privacy and protection. For the purpose of this newsletter, we shall put these services into three main buckets – Data Audit Services, Data Compliance Implementation Services, and Data Protection Officer (DPO) Services.

1.Data Audit Services

A core function of a DPCO is conducting data audits to assess an organization’s compliance with the NDPA and NDPR. This process involves reviewing an organization’s data protection policies, assessing how personal data is collected, processed, stored, and shared, and identifying potential risks. The audit typically begins with an evaluation of the organization’s data protection framework, including privacy policies, data retention practices, security measures, and contracts with third-party processors. A DPCO will also interview key personnel who process data as part of their functions—such as compliance officers, IT teams, and HR representatives—to gauge awareness and ascertain if policies are effectively implemented in daily operations.

Beyond policy review, a data mapping exercise is done to trace the flow of personal data within the organization. Security measures, including encryption, access controls, and breach response plans, are also examined to identify vulnerabilities.

At the end of the audit, the DPCO issues a detailed report, highlighting compliance gaps, risks, and recommended corrective actions.

2. Data Compliance Implementation Services

Beyond audits, DPCOs also support organizations in implementing corrective actions to address compliance gaps. These include:

  • Developing internal policies that align with data protection laws, including privacy policies, terms of use, cookie policies, data protection policies, subject access request procedures, amongst others.
  • Providing data protection and privacy advisory services to help organizations understand and comply with their legal obligations to Data Subjects* and other third parties.
  • Conducting training and awareness programs to ensure employees are aware of data privacy risks and best practices.
  • Drafting and reviewing data protection contracts, including Data Processing Agreements (DPAs), Data Sharing Agreements (DSAs), and Binding Corporate Rules (BCRs) to establish legally compliant relationships with related and third parties.
  • Assisting in breach remediation by helping organizations develop response strategies for handling data breaches effectively.
  • Conducting due diligence investigations in cases of mergers, acquisitions, or partnerships to assess the data privacy risks associated with third-party engagements.
  • Representing organisations as a liaison with the NDPC for regulatory filings and compliance matters.

3. Outsourced Data Protection Officer Services

Part 4.1. (3) of the NDPR requires every Data Controller and Processor to have a Data Protection Officer (DPO). However, some organizations may not have the resources to appoint an internal DPO. DPCOs fill this gap by offering outsourced DPO services to ensure that organizations meet this requirement without needing to hire a full-time in-house expert.

An outsourced DPO performs various functions, including:

  • Overseeing data protection impact assessments (DPIAs) for high-risk processing activities.
  • Ensuring that the organization maintains records of data processing activities as required by law.
  • Providing ongoing advisory support to senior management on data protection risks and obligations.
  • Conducting data protection awareness training to equip staff with the necessary knowledge to handle personal data responsibly.
  • Acting as the primary liaison between the organization and the DPCO as it delivers data protection services to the organization.

Outsourced DPO services are especially valuable to startups, SMEs, and multinational companies operating in Nigeria, as they provide expert compliance oversight without the burden of a full-time hire.

Conclusion

DPCOs play a vital role in helping businesses navigate regulatory requirements through data audits, compliance implementation, and outsourced DPO services. Engaging a DPCO strengthens data governance, mitigates risks, and fosters trust. This ensures organizations stay compliant while maintaining a secure posture in an evolving data landscape.

 

Endnotes

  • Data Controller – An organization that decides why and how personal data is collected and used. For example: A bank collecting customer details for account creation.
  • Data Processor – A third party that processes personal data on behalf of the Data Controller based on their instructions. For example: A cloud storage provider storing customer data for a bank.
  • Data Subject – The individual whose personal data is being collected or processed. For example: A customer whose name, email, and phone number are stored by the bank.

For more reading on data protection in Nigeria, we invite you to explore our collection of articles here – https://pavestoneslegal.com/newsletters/

Renewable Energy: Requirements to Operate a Solar Business in Nigeria

BY SEUN TIMI-KOLEOLU AND PROMISE ITAH

Introduction

Renewable energy is rapidly transforming the global power landscape, with solar energy emerging as a key solution to electricity challenges. In Nigeria, where millions of homes and businesses face unreliable power supply, the demand for alternative energy sources has surged. Among other renewable energy sources — such as hydropower, wind energy, and geothermal energy—there is a rapid and growing reliance on solar energy, which presents immense opportunities for businesses looking to provide sustainable power solutions. It is therefore essential, in order to navigate this expanding market in Nigeria, for businesses to understand the legal and regulatory framework governing operations in the solar energy sector.

In this newsletter, we highlight key regulatory considerations to operate a solar energy business in Nigerian.

Key Regulatory Considerations

For businesses looking to set up operations in Nigeria, the following key requirements must be met:

1. Business Registration

All businesses must first register with the Corporate Affairs Commission (CAC) to legally operate in Nigeria. This process includes choosing a name, submitting necessary documentation, and paying registration fees. The CAC issues a certificate evidencing registration, which is required to open a business bank account and for various other regulatory processes. For other considerations on business registration and available business structures, please see our newsletter on Frequently Asked Questions (FAQ) here. For foreigners intending to set up business in Nigeria, please see our newsletter providing guidance here.

2. Importer/Exporter Number from Nigerian Customs Service

To import or export solar products, businesses must register with the Nigerian Customs Service (NCS) and obtain an Importer/Exporter Number (IEN). This number is essential for proper documentation and clearance of goods through Nigerian ports.

Required documents to accompany application for registration with the NCS include: Certificate of Incorporation, Tax Identification Number (TIN) from the Federal Inland Revenue Service (FIRS), Bank Reference Letter, Identification of business owners or directors, and Company contact information.

The process typically takes 1-2 weeks, and the applicable fees may vary.

3. Standards Organisation of Nigeria Certification for Solar Products

Solar products must undergo certification by the Standards Organisation of Nigeria (SON) through the SON Conformity Assessment Programmes. This ensures the products meet local quality and safety standards.

Certifications:

· Mandatory Conformity Assessment Programme (MANCAP): This is a quality assurance initiative established by SON to ensure that locally manufactured products meet the required quality and safety standards before introducing the product to the market. A MANCAP certificate and MANCAP logo is issued to a manufacturer by SON upon application, after formal inspection and product testing have been conducted by SON. A MANCAP certificate is valid for three years, after which the product will have to undergo recertification.

Required Documents for SON Registration include CAC certificate, picture of the product, power of attorney (if you are an importer), manufacturer’s agreement (if you are an importer), trademark certificate (if you have a brand name).

Fees and timelines vary based on product type and completeness of documentation.

· Product Certificate: For products to be imported into Nigeria, the first step to certification with SON in Nigeria is obtaining the product certificate from the manufacturing country. The product certificate confirms that the product meets the required quality standards. It contains information relating to the product, the testing and details of the product manufacturer.

· SON Conformity Assessment Programme (SONCAP): Upon arrival in Nigeria, imported products must be registered with SON. When the registration of the product is completed and successful, a SONCAP Certificate will be issued to confirm compliance with the required quality and safety standards.

Required Documents for SON Registration include: duly completed application form, valid product certificate, company certificate of incorporation, photographs of the product, manufacturer’s agreement, trademark certificate (if applicable), list of items to be imported and sample proforma invoice.

The SONCAP certificate is issued after product inspection and payment of fees. Fees and timelines vary based on product type and completeness of documentation.

4. Generating Set Import Clearance from the Nigerian Electricity Regulatory Commission

To be able to import solar-powered generators, clearance certificate must be obtained from Nigerian Electricity Regulatory Commission (NERC). The clearance certificate is valid for six months and can be renewed upon payment of renewal fees.

Required information and documents for obtaining the clearance certificate include: name of applicant and quantity of generators to be imported; noise level (not more than 35Db) and pollution control; make of generators as well as the technical and environmental rating, purpose of importation; country of origin and capacity of the generator; copy of the Certificate of Incorporation; three years Tax Clearance Certificate; Value Added Tax registration certificate, commercial invoice/proforma invoice; SONCAP Certificate; and proof of conformity with extant environmental regulations (emissions, noise etc).

The associated fees are dependent on the size (kVA) of the generating set. The timeline for the issuance of the clearance certificate is dependent on the availability of the required documents and NERC’s satisfaction with the application.

Other Regulatory Considerations

In addition to the key regulatory considerations outlined above, other regulatory factors to be considered include:

· Import Duty and Tariffs: While solar panels are exempt from import duties, other solar energy products may be subject to duties unless exempted.

· Customs Clearance: Imported solar products must undergo clearance at Nigerian ports. Documents required for customs clearance include Bill of Lading, Commercial Invoice, Certificate of Origin, and Packing List.

· Environmental Impact Assessment (EIA): For large-scale solar projects, an EIA must be obtained from the National Environmental Standards and Regulations Enforcement Agency (NESREA).

· Electrical Safety and Installation Standards: Businesses engaging in the installation and maintenance of solar energy products must have a qualified engineer who will oversee solar installations to ensure compliance with safety regulations.

· Electricity Licensing: NERC license must be obtained before businesses can generate solar power exceeding 1 MW.

Conclusion

As solar energy becomes a key solution to Nigeria’s power challenges, businesses in the sector must navigate essential regulatory requirements. By understanding and adhering to these legal frameworks, businesses can effectively tap into the potential of the solar energy sector and contribute to a sustainable energy future. The foregoing is, however, not exhaustive, and it is advised that businesses stay up to date on regulatory and compliance requirements for their operations.

Tax Reforms: Guidelines on Advance Pricing Agreements in Nigeria

BY ADERONKE ALEX-ADEDIPE AND EBIKENIYE BEST

Tax Reforms – Guidelines on Advance Pricing Agreements in Nigeria

Introduction

On November 27, 2024, the Federal Inland Revenue Service (FIRS) issued the Guidelines on Advance Pricing Agreements (“the Guidelines”) pursuant to Section 8(1)(u) of the FIRS (Establishment) Act, 2007 and Regulation 9(12) of the Income Tax (Transfer Pricing) Regulations, 2018 to clarify the procedures and conditions for obtaining APAs, thereby enhancing tax compliance and reduce transfer pricing disputes.

In this newsletter, we have highlighted some of the key provisions of the Guidelines.

What is an Advance Pricing Agreement (APA)?

An APA is a formal agreement between a taxpayer and the tax authority that establishes the transfer pricing methodology, defines relevant comparables, and specifies any necessary adjustments for future transactions between the taxpayer and related parties. The purpose of the APA is to determine the transfer prices for future transactions in compliance with the Arm’s Length Principle, for a fixed period[1], based on the fulfillment of the agreed terms and conditions.

What are the types of APA?

As indicated in the Guidelines, an APA may be unilateral, bilateral or multilateral.

Unilateral APA – this is an agreement between the FIRS and a taxpayer concerning the transfer pricing of related -party transactions.

Bilateral APA – this involves the FIRS, a taxpayer, its connected person(s) resident in a foreign country and the competent tax authority in that country.

Multilateral APA – this involves the FIRS, a taxpayer, its connected persons resident in two or more countries and the competent tax authorities in those countries.

What are the eligibility criteria and threshold for an APA application?

To be eligible to apply for an APA, a taxpayer must be a resident or a non-resident company that has a taxable presence in Nigeria and the commercial transactions that have occurred or contemplated must meet the following minimum thresholds:

  1. Single Transaction – the equivalent of $10 million for each commercial transaction in each year; or
  2. Group Transactions: the equivalent of $50 million in the case of a group of commercial transactions (group of transactions) in each year.

What is the application process and costs?

Taxpayers who meet the eligibility criteria are required to begin the application process by submitting a proposal for an APA to the FIRS. Once the proposal is submitted, the application proceeds through the following stages:

Stage 1: Pre-filing Meeting

A mandatory pre-filing meeting must be held at least 30 days after the submission of the APA proposal, between FIRS and the applicant. The purpose of this meeting is to discuss the feasibility of a successful APA and to address key issues such as the nature and scope of the proposed APA, the transfer pricing method to be used, and any other relevant matters. This meeting must take place before the formal APA application is submitted.

Stage 2: Formal Application

Where the FIRS agrees that the APA is feasible, the taxpayer can proceed with the formal application within the agreed timeline. This application must be comprehensive, outlining the type of APA sought, the entities involved in the commercial transactions, any relevant treaty partners (if applicable), a general description of the market conditions, the proposed transfer pricing method, and any other relevant terms and conditions including key assumptions.

At this stage, the taxpayer is required to pay a non-refundable application fee of $20,000 and the evidence of payment is to be included in the APA application.

Stage 3: Analysis and Evaluation

Following the submission of the formal application, the FIRS will analyze the documentation, assess the data provided, and request additional information or documents if necessary to make an informed decision on the APA.

Stage 4: Negotiation and Agreement

At this stage, the FIRS will enter into discussions with the taxpayer to align and finalize the terms of the APA. If the APA is bilateral or multilateral, discussions will also involve the tax authorities of the relevant treaty partners.

Stage 5: Drafting, Execution, and Monitoring

Once the terms are agreed upon, the APA will be executed. Upon execution, the APA will be subject to ongoing monitoring to ensure compliance with its terms. Additionally, the FIRS will verify that the facts, assumptions, and circumstances remain consistent.

The taxpayer is responsible for all costs related to the processing of the APA by FIRS, including but not limited to travel expenses for field visits and consultancy fees (where the FIRS engages an expert). If the costs incurred by the FIRS exceed this amount, the taxpayer must reimburse the additional costs directly related to the processing of the APA.

What is the timeframe for applying for an APA?

The Guidelines specify that the APA application process in the case of a unilateral APA may be completed within 24 months from the acceptance of a taxpayer’s formal application, and within 36 months for bilateral or multilateral APAs. However, the actual timeframe may vary depending on factors such as the prompt submission of required information, the complexity of the issues involved, and the pace of negotiations with treaty partners.

What is the term of an APA?

An APA becomes effective from the date specified in the agreement and remains valid for up to three (3) years, with a possible rollback of up to three (3) prior years if conditions are met.

In what instances can an APA be terminated?

In line with the provisions of Regulation 9(9) of the Income Tax (Transfer Pricing) Regulations, 2018, an APA may be terminated by either the taxpayer or the FIRS through the issuance of a notice of termination, in the event of a change in the nature of the covered transaction(s), any alteration to the critical assumptions supporting the APA, or a change in tax laws that significantly impacts the terms of the APA.

What other regulatory requirements must be fulfilled by a taxpayer under the Guidelines?

Once a taxpayer has successfully negotiated an APA with the FIRS, it is required to prepare and submit an Annual Compliance Report (ACR) for each year covered by the APA. The ACR must be submitted by the deadline for filing the taxpayer’s annual Companies Income Tax returns. This report should provide comprehensive details of the taxpayer’s actual financial outcomes for the year and demonstrate full compliance with the terms outlined in the APA.

Conclusion

Given the increasing concerns among taxpayers regarding the uncertainties around transfer pricing, driven by the complexities and subjectivity in transactions, as well as the potential tax liabilities arising from transfer pricing disputes, the Guidelines, which took effect on January 1, 2025, represent a welcome development for eligible taxpayers. It is hoped that the implementation of these Guidelines will significantly reduce the occurrence of tax disputes.Bottom of Form

[1] For more information on transfer pricing, please see our newsletter at https://pavestoneslegal.com/the-arms-length-principle-and-its-implication-on-taxation-in-nigeria/

SETTING UP A NON-INTEREST BANK IN NIGERIA

BY SEUN TIMI-KOLEOLU AND OLAWALE ATANDA

Setting Up a Non-Interest Bank in Nigeria

Introduction

Non-interest banking is gaining traction in Nigeria as an alternative to conventional banking. This model operates on the principles of ethical finance, risk-sharing, and asset-backed transactions. It prohibits interest-based lending while promoting profit-sharing mechanisms.

In this newsletter, we explore the regulatory and compliance considerations for setting up a Non-Interest Financial Institutions (NIFI) in Nigeria and highlight the licensing process and governance requirements.

Non-Interest Banking and Regulatory Framework

Non-interest banking services in Nigeria are carried out by NIFIs licensed by the Central Bank of Nigeria (CBN). The CBN classifies these banks as specialized institutions. Under its Guidelines for the Regulation and Supervision of Institutions Offering Non-Interest Financial Services in Nigeria, the categorizes them into two types:

  1. Institutions offering Islamic Financial Services (Islamic Banking) – Based on Islamic commercial jurisprudence.
  2. Other Non-Interest Financial Institutions (Other Non-Interest Banks) – Operating under any other established non-interest principle.

Licensing Categories

Non-interest banking licenses fall into two main categories: National and Regional. In March 2024, the CBN increased the minimum share capital for a National non-interest banking license from ₦10 billion to ₦20 billion while a Regional license went from ₦5 billion to ₦10 billion. These changes take effect in April 2025 for new applicants, while existing NIFIs must comply by March 2026. The share capital must be fully paid up to meet the CBN requirement.

In addition to these, NIFIs providing Islamic Banking services can register as Microfinance Banks (MFBs) under the CBN’s Guidelines for the Regulation and Supervision of Non-Interest (Islamic) MFBs. The registration requirements align with those of conventional MFBs.*

Licensing Stages

There are three licensing stages for obtaining a NIFI license.

1. Pre-Approval Stage (Application for a Banking License)

Applicants must submit a formal application to the CBN which will include:

  • a cover letter signed by the promoters;
  • non-refundable application fee (determined by CBN);
  • evidence of meeting the minimum capital requirement (including the source of funds);
  • a detailed business plan/feasibility report covering the objectives and nature of the proposed bank, ownership structure, shareholding, and governance framework, financial projections for at least five years, Shariah governance framework, including the Advisory Committee of Experts (ACE) [for Islamic Banking]
  • board composition, detailing qualifications and experience of proposed directors and key officers;
  • draft copies of incorporation documents, including Memorandum and Articles of Association (indicating non-interest banking operations);
  • evidence of deposit with CBN (minimum capital requirement must be deposited in an escrow account with CBN).

2. Approval-in-Principle (AIP) Stage

If the application meets CBN’s requirements, the bank will be granted an Approval-in-Principle (AIP) which will be valid for six months. During this period, the promoters must:

  • register the bank as a limited liability company with the Corporate Affairs Commission (CAC);
  • secure office premises and operational infrastructure;
  • appoint a Board of Directors and Management Team, subject to CBN approval;
  • implement an IT and banking system for operations; and
  • recruit and train staff on non-interest banking principles.

3. Final License Approval

After fulfilling AIP conditions, the promoters must apply for the final banking license by submitting the following:

  • a final inspection report from CBN confirming the operational readiness of the NIFI;
  • certified copies of CAC incorporation documents;
  • evidence of capital deposit confirmation by CBN;
  • internal policies on risk management, anti-money laundering (AML), cybersecurity, and corporate governance;
  • list of management staff and board members, with CBN’s approval.

Upon successful review, CBN will issue the final license which permits the bank to commence operations.

Corporate Governance

The CBN Corporate Governance Guidelines for Commercial, Merchant, Non-Interest, and Payment Service Banks** set out governance requirements for NIFIs, based on the Nigerian Code of Corporate Governance. Key provisions of the code include:

  • Board Composition: The board of a NIFI must have between 7 and 15 members, with at least three independent non-executive directors for National NIFIs and two for Regional NIFIs.
  • Diversity Requirements: The board must reflect gender diversity.
  • Executive Roles: The Managing Director (MD) is subject to a maximum tenure of 10 years. The Company Secretary’s role must be distinct from that of the Head of Legal/Legal Adviser.

For Islamic Banking, additional governance requirements such as these will apply:

  • Shariah Review and Compliance (SRC) Function: NIFIs carrying out Islamic Banking must establish an SRC unit responsible for regular assessments to ensure operations align with Shariah principles.
  • Internal Shariah Auditor (ISA): NIFIs providing Islamic Banking must appoint an ISA as the head of the internal Shariah audit function, holding a position not lower than Assistant General Manager.

Difference Between Islamic Banking and Other Non-Interest Banks

There are certain differences between Islamic Banking and Other Non-Interest Banks. Some are explained below.

1.Underlying Principles

  • Islamic Banking: Operate based on Islamic commercial jurisprudence (Shari’ah law), which prohibits interest (riba) and ensures financial transactions align with Islamic ethical standards.
  • Other Non-Interest Banks: Operate on alternative non-interest principles that do not necessarily align with Islamic jurisprudence but still avoid interest-based transactions.

2. Shari’ah Compliance

  • Islamic Banking: Must have a Shari’ah Advisory Board to ensure compliance with Islamic financial principles.
  • Other Non-Interest Banks: Not required to adhere to Shari’ah principles and do not require a Shari’ah Advisory Board.

3. Permissible Transactions

  • Islamic Banking: Engage in profit-sharing models (e.g., Mudarabah, Musharakah), asset-backed financing (e.g., Ijarah), and trade-based contracts (e.g., Murabaha).
  • Other Non-Interest Banks: May adopt models such as ethical banking or other non-interest structures that do not necessarily follow Islamic finance contracts.

4. Regulatory Considerations

  • Islamic Banking: Subject to both CBN regulations and Shari’ah governance frameworks, ensuring all transactions comply with Islamic finance principles.
  • Other Non-Interest Banks: Only subject to CBN regulations without an Islamic governance framework.

5. Target Market

  • Islamic Banking: Primarily cater to individuals and businesses seeking Islamic-compliant financial services.
  • Other Non-Interest Banks: Serve a broader audience, including individuals and institutions looking for non-interest financial solutions without a religious requirement.

Conclusion

The growing adoption of non-interest banking in Nigeria underscores the need for a clear understanding of its regulatory framework. From licensing requirements to corporate governance, NIFIs must comply with CBN guidelines to ensure operational efficiency and sustainability. As the sector evolves, adherence to these regulations will be important in fostering trust, financial inclusion, and long-term stability in Nigeria’s banking sector.

Footnotes

* Please see our article on the categorization and license requirements for MFBs here https://pavestoneslegal.com/pavestones-regulatory-update-the-draft-revised-guidelines-for-the-regulation-and-supervision-of-microfinance-banks/

** Please see our article on the CBN Corporate Governance Guidelines for Commercial, Merchant, Non-Interest, and Payment Service Banks here – https://pavestoneslegal.com/regulatory-update-cbns-new-corporate-governance-guidelines-for-banks-commercial-merchant-non-interest-and-payment-services-banks/

CORPORATE GOVERNANCE: THE DUTIES AND RESPONSIBILITIES OF DIRECTORS UNDER NIGERIAN LAW

BY ADERONKE ALEX-ADEDIPE AND HILLARY OKOROTIE

Introduction

Corporate Governance plays a fundamental role in impacting the success and sustainability of any company and at the heart of a company’s governance structure is its Directors.  The Directors are the decision-makers with fiduciary responsibilities to the company, its shareholders and other stakeholders including, employees, creditors, and regulators. Understanding the duties and responsibilities of directors is therefore crucial. In this newsletter we examine some of these responsibilities and their importance.

Who is a Director?

A director is an individual appointed to oversee and manage the affairs and operations of a company. The Board of a company may comprise executive directors who are responsible for the day-to-day operations, non-executive and independent directors who provide external oversight. Under the Companies and Allied Matters Act (CAMA) 2020, directors owe fiduciary duties to the company, requiring them to act in good faith, and in the best interests of the company and its shareholders. These fiduciary duties include:

1. Duty to Promote the Business of the Company

Under the CAMA and the Nigerian Code of Corporate Governance, directors must act in a way that promotes the business of the company. In fulfilling this duty, directors must consider the impact of the company’s operations on the environment and society and the impact of their decisions on the company’s stakeholders, shareholders and employees. To fulfill this obligation, directors must ensure that the company operates in a manner that maximizes its profitability. This includes making strategic decisions, managing risks effectively, and ensuring compliance with legal and regulatory requirements

2. Duty to exercise Care and Diligence

A director is obligated to exercise reasonable care, skill, and diligence in performing his duties. This duty requires directors to act in good faith and in the best interest of the company, its members and stakeholders in the course of operations. A director’s obligation to exercise care implies that his actions must be conducted in a manner in which a reasonable man would conduct themselves in dealing with the company’s affairs.

3. Duty to Avoid Conflicts of Interest

Directors have a fiduciary duty to ensure that their personal interests do not conflict with those of the company. They are obligated to disclose any actual or potential conflicts and, where necessary, recuse themselves from related decision-making processes. Additionally, directors are prohibited from using their position for personal gain or deriving undisclosed financial benefits from the company, while discharging their duties.

4. Duty to Exercise Independent Judgment

Directors are required to exercise independent judgment when making decisions on behalf of the company. In essence, a director must make decisions based on his personal opinion and skills, without any bias or undue influence by a third party. A director must not fetter his discretion by committing in advance to vote in a particular way, as doing so may compromise their ability to act in the best interests of the company.

5. Duty to Act Within Authorized Powers

A director’s powers are defined by the company’s articles of association and the board charter. Directors must act within the scope of these powers and cannot make decisions that exceed their authority or contradict the provisions of the articles or board charter.

What Happens When Directors Breach Their Duty?

When directors fail to exercise the duties stated above, the consequences may range from regulatory sanctions and civil liability to criminal prosecution. Some of these consequences include:

Loss of Investment: While the directors are responsible for the day to day operation of the company, they are also responsible to the shareholders and investors of the company. Where the directors are in breach of their duties, it may affect investor confidence, and such an occurrence may lead to withdrawal of investment.

Civil Liability: Legal action may be filed against the director for breaching his fiduciary duty. Directors may also face removal from the board of the company or other personal liability for financial mismanagement, fraud etc.

Criminal Liability: A director can also be held criminally liable for offences such as insider trading or fraud committed during the course of operation of the company. Under the Investments and Securities Act, for example, a person convicted of insider trading may be fined ₦500,000 or an amount equivalent to twice the profit gained, or face imprisonment of up to seven years. In the event that a director is convicted, the director will be disqualified from holding office as a director in any company for a period of 10 years.

Regulatory Sanction: The impact of breach of directors’ duties often extends beyond the personal liability of the director. Failure to manage the affairs of a company in accordance with regulatory requirements may lead to sanctions against the company by regulators. A notable example is the recent withdrawal of the banking license of a Nigerian commercial bank by the Central Bank of Nigeria (CBN), demonstrating that regulatory bodies can take decisive actions in response to corporate governance failure.

Conclusion

The obligations and duties of directors are crucial in ensuring adherence to corporate governance framework. Therefore, directors must continue to discharge their fiduciary duties to the company while balancing multiple responsibilities, from strategic decision-making to financial management and compliance and risk management.

Regulatory Compliance Requirements for Companies Operating in Nigeria

SEUN TIMI-KOLEOLU AND EBIKENIYE BEST

Regulatory Compliance Requirements for Companies Operating in Nigeria

Introduction

Regulatory compliance is important for any company and forms the foundation that enables businesses operate smoothly and sustainably. For companies operating in Nigeria, the first step in the regulatory compliance process is incorporating the business with the Corporate Affairs Commission followed by registration with relevant industry regulators, where applicable. Once the company is successfully incorporated, there are various regulatory requirements that must be met to ensure that the company can continue to operate legally in Nigeria.

In this newsletter, we have highlighted some of these key compliance requirements.

  1. Corporate Affairs Commission (CAC)

All companies registered in Nigeria are mandated to file annual returns with the CAC. The annual returns are to be filed within 18 months of incorporation and subsequently on an annual basis. These returns must be accompanied by the company’s audited financial statements or audited accounts for the relevant financial year.

The deadline for filing returns with the CAC is 14 days after a company’s general meeting for the year, but no later than June of that year. Late filings attract penalties for each year of non-compliance.

  1. Nigeria Data Protection Commission (NDPC)

Companies that collect or process personal data of over 1,000 Nigerians within a 6-month period or handle the personal data of more than 2,000 Nigerians within a year, are mandated to submit an annual Compliance Audit Report (CAR) to the Nigeria Data Protection Commission (NDPC) through a certified Data Protection Compliance Organisation (DPCO). The DPCO will review the company’s data protection policies, evaluate its systems and practices, and assess staff knowledge before making recommendations.

A summary of the CAR for the previous year must be submitted to the NDPC no later than March 15 of the current year. Failure to meet this deadline will result in a penalty of 50% of the filing fee.

  1. Tax Compliance

Companies are required to file the taxes as set out below to the Federal Inland Revenue Service (FIRS) and Inland Revenue Service of States respectively either monthly or yearly.

  • Companies Income Tax (CIT): Companies are obligated to file their annual returns within 18 months of incorporation. Subsequent filings are to be made within 6 months following the end of the financial year, which is typically by June 30 of every year. The penalty for failure to file CIT returns is ₦25,000 for the first month and ₦5,000 for each subsequent month of default. While late payment of CIT attracts a10% penalty and interest at the prevailing bank rate.
  • Withholding Tax (WHT): This serves as an advanced method for the collection of CIT. It is deducted at rates which vary between 2% and 10%, depending on the nature of the transaction and the parties involved. The deadline for filing WHT returns falls on the 21st day of each subsequent month after the deduction. The failure to meet this deadline will result in a late filing penalty of 10% of the tax not withheld or remitted.
  • Value Added Tax (VAT): This is a consumption tax levied on the value of goods and services provided in or imported into Nigeria. It is charged at a rate of 7.5% which is applicable to all goods and services provided to individuals and companies. The deadline for filing VAT returns is the 21st day of the month following the month of transaction. Failure to meet this deadline will result in a late filing penalty of ₦50,000 in the first month and ₦25,000 for each subsequent month of default. It is important to note however that VAT is not paid on all goods and services. Some of the exempt goods and services are medical and pharmaceutical products, basic food items, books and educational materials, all exported goods and services, equipment and infrastructure related to the expansion of compressed natural gas and liquefied petroleum gas amongst others.
  • Personal Income Tax: Companies are required to withhold and file the personal income tax of their employees to the internal revenue service of the state where the employees reside. This income tax is also known as Pay As You Earn (PAYE). In Lagos State, for example, employers must begin deducting tax from employee salaries six months after the company commences operations. The deducted are to be remitted to the Lagos Internal Revenue Service (LIRS). The deadline for remitting PAYE is before the 10th of the month following the deductions. Also, returns must be filed with the LIRS by January 31st for the preceding year.
  1. Labour and Employment Compliance

Companies are required to meet the requirements set out below in respect to labour and employment.

  • Industrial Training Fund (ITF): Companies are required to contribute 1% of the total sum of their annual payroll to the ITF. The fund is used to develop human capital and provide individuals with technical and entrepreneurial managerial skills in both the public and private sectors. However, companies with less than five employees and with a turnover of less than ₦50 million are exempted from this remittance requirement. Payments are required to be made on or before the 1st of April each year. Where eligible companies do not make the required contribution to the fund, they are liable to pay a monthly penalty of 5% on the unpaid contribution for each month they are in default.
  • Nigeria Social Investment Trust Fund (NSITF): The NSITF was established by the Employee’s Compensation Act and is designed to provide insurance for employees against incidents that occur in the course of their employment such as workplace injuries, mental stress, occupational hazards, and death. Employers are required to contribute 1% of their total monthly payroll to the NSITF by the last day of each month in which payroll payments are made. Where companies do not make the required contribution to the fund, they are liable to pay a monthly penalty of 5% on the unpaid contribution for each month they are in default.
  • National Pension Commission (PENCOM): The Pension Reform Act which establishes the PENCOM as the pensions regulatory body in Nigeria requires employers with at least 15 employees to participate in a contributory pension scheme. Under the scheme, the employer contributes a minimum of 10% of the employee’s monthly emolument and the employee contributes 8%. However, the employer may opt to bear all the contribution to the pension scheme. In that case, the minimum contribution will be 20% of monthly emolument.

Contributions are required to be remitted within 7 days after the payment of salaries and are to be made monthly for the duration of the employee’s employment in the company. The penalty for non-contribution is at least 2% of the total outstanding pension contributions that remain unpaid, in addition to the already outstanding contributions.

Conclusion

Please note that this list is not exhaustive, as companies may be subject to additional compliance requirements based on their industry or sector. Meeting all compliance obligations is important as it enables companies to remain legally compliant, avoid regulatory sanctions, and foster trust in their brand among customers. It is advisable that companies doing business in Nigeria liaise with legal advisers to help create a tailored compliance checklist for ease of operations.

 

For further reading on sector specific licenses, please see our newsletters below.

SEC Licenses – https://pavestoneslegal.com/insights-into-the-sec-accelerated-regulatory-incubation-program-framework/

Fintech – https://pavestoneslegal.com/regulatory-requirement-for-fintech-in-nigeria-cbn-licenses/

Banking – https://pavestoneslegal.com/licensing-requirements-for-banks-and-other-financial-institutions-in-nigeria/

Lending – https://pavestoneslegal.com/regulation-of-lending-in-nigeria/

Cryptocurrency – https://pavestoneslegal.com/setting-up-a-cryptocurrency-business-in-nigeria/

 

 

STAYING AHEAD OF THE CURVE: NAVIGATING NIGERIA’S DATA PROTECTION COMPLIANCE LANDSCAPE

ADERONKE ALEX-ADEDIPE AND PROMISE ITAH

STAYING AHEAD OF THE CURVE: NAVIGATING NIGERIA’S DATA PROTECTION COMPLIANCE LANDSCAPE

Introduction

The Nigeria Data Protection Act 2023 (NDPA) is the primary legislation that governs the privacy and protection of Personal Data of natural persons in Nigeria. Modelled in many respects after the General Data Privacy Regulation (GDPR) of the European Union, the NDPA and the subsidiary legislations such as the Nigeria Data protection Regulations (2019) establish substantial compliance requirements for organisations or persons that control and process Personal Data.

In this Newsletter we summarise some of these regulatory compliance requirements.

What are the Key Concepts in Data Privacy?  

A Data Controller is a person or entity that determines the purposes and means of processing Personal Data. A Data Controller usually has a direct relationship with the Data Subject and is accountable for the protection and privacy of the Personal Data of a Data Subject. Examples of Data Controllers may include Government agencies; e-commerce businesses typically in custody of customer data; healthcare providers with patient data; educational institutions with student data etc.

A Data Processor is a person that processes Personal Data on the instruction of a Data Controller. Processing activities include a range of activities like collection, storage, use, disclosure, arrangement and structuring, modification etc. Example of Data processors may include marketing agencies, financial service companies, e-learning platforms, telecommunication service providers, and courier service providers who process Personal Data on the instruction of a Data Controller. A Data Controller may also be a Data Processor.

Personal Data refers to any information that relates to an identified or identifiable natural person (human being) and may include name, address, contact information, identification numbers, biometric data. The natural person who the information relates to is known as the Data Subject.

 

Key Regulatory Compliance Requirements for Data Controllers and Processors

1. Annual Data Protection Compliance Audits:

The NDPA mandates Data Controllers and Processors that process the Personal Data of more than 2,000 Data Subjects within a 12-month period (or more than 1000 Data Subjects within a 6-month period), to conduct annual data protection audits not later than the 15th of March of the following year. Such audits must be conducted by a Data Protection Compliance Organisation (DPCO) licensed by the Nigeria Data Protection Commission (NDPC) and must be completed and filed by the deadline stated by the NDPC. Upon the filing of an audit and after a satisfactory review by the NDPC, Trustmarks are issued to the compliant organizations to entities that have complied with this provision.

2. Registration as Data Controller/Processor of Major Importance

A Data Controller/Processor qualifies as Data Controller/Processor of Major Importance (DCPMI) and is required to register with the NDPC within six (6) months, if it meets any of the following criteria:

  • has access to a filing system and processes Personal Data of more than 200 Data Subjects in a six (6) month period; or
  • provides commercial Information Communication Technology (ICT) services on any digital storage device with a storage capacity owned by another; or
  • processes Personal Data in the financial, communication, aviation, tourism, oil and gas, import and export, education, health, insurance and electric power industries; or
  • is in a fiduciary relationship with a Data Subject, pursuant to which it is expected to keep confidential information on the Data Subject’s behalf.

The categories of DCPMI are:

  • Major Data Processing-Ultra High Level
  • Major Data Processing-Extra High Level
  • Major Data Processing-Ordinary High Level

3.Data Protection Impact Assessment

Data Controllers must conduct Data Protection Impact Assessment (DPIA) to assess and identify any security risk associated with their data processing activities. This assessment should be conducted regularly on their processes, services and technology to ensure that they remain compliant with data protection laws.

DPIA is typically required where there is a change in processing activities involving automated decision-making with legal or significant effects on the Data Subject rights; evaluation or profiling; sensitive Personal Data; systematic monitoring; application of new technological solutions of deployment of innovative processes; and processing of Personal Data in relation to vulnerable Data Subjects.

4.Designation of a Data Protection Officer

A DCPMI must appoint a Data Protection Officer (DPO) with knowledge of data protection and privacy laws who will carry out the tasks prescribed under the NDPA. The DPO may be an employee of the organization or engaged by a service contract.

5. Data Breach Notification

Data Controllers must notify the NDPC within 72 hours of becoming aware of a breach of Personal Data which is likely to impact the privacy rights of individuals. Data Subjects should also be notified of such breach.

6. Management of Data Subject Rights

Data Controllers and Processors must implement mechanisms to adequately respond to Data Subjects’ requests and ensure that such mechanisms are effective.  The NDPA outlines specific rights of Data Subjects, which include the right to access, rectification, erasure, and portability of their Personal Data.

7. Implementation of Data Security Measures

Data Controllers and Data Processors must implement adequate technical and organizational measures to protect the Personal Data of Data Subjects from unauthorized access, loss, or alteration. These measures may include encryption, regular security assessments, and training of employees to safeguard data breaches and other vulnerabilities.

8. Keeping Record of Processing Activities

Data Controllers and Processors must maintain detailed records of their processing activities. This includes documenting the purposes of data processing, categories of Personal Data, and third parties with whom Personal Data is shared. This record should be available for inspection by the NDPC upon request.

9. Conduct of Regular Staff Training and Awareness Programmes

Data Controllers and Processors must provide regular data protection training for employees, particularly those involved in data processing activities. This will help to foster a culture of privacy and ensure all staff are aware of their obligations under the NDPA.

Penalties for Non-Compliance

Non-compliance with the NDPA can result in significant penalties:

  • For DCPMIs: Fines up to 2% of annual gross revenue or NGN 10,000,000, whichever is greater.
  • For Data Controllers and Processors that are not DCPMIs: Fines up to NGN 2,000,000 or 1% of their annual gross revenue, whichever is greater.

Additionally, violations may result in imprisonment for up to one year. Both fines and imprisonment may be applied either alternatively or together upon conviction.

Conclusion

As businesses and organisations engage in data processing activities, compliance with data privacy and protection regulations is crucial. Adherence to the NDPA ensures that entities protect the Personal Data of individuals and avoid potential sanctions from the Nigeria Data Protection Commission (NDPC), the regulatory authority for data privacy and protection in Nigeria. It is essential for businesses to assess their compliance status regularly and take proactive measures to meet the requirements of the NDPA.