Posts

FOREX TRADING IN NIGERIA: THE IMPLICATIONS OF SEC PROPOSED RULES ON ONLINE FOREX TRADING FOR TECHNOLOGY AND PLATFORM PROVIDERS

BY SEUN TIMI-KOLEOLU & PROMISE ITAH

Introduction

The Securities and Exchange Commission (“SEC”) has proposed rules on Online Forex Trading and Contracts for Difference (“CFDs”) (the “Proposed Rules”), introducing a regulatory framework for businesses involved in the provision of online Forex and CFD trading services in Nigeria.

The Proposed Rules will affect not only Forex brokers and CFD providers, but also the companies that provide the technology they use. This includes companies that provide the websites and apps where users open trading accounts; check currency and asset prices; place trades; and manage their investments. It may also include companies that host these platforms or provide the technology and systems that allow them to operate.

In this newsletter, we highlight key provisions of the Proposed Rules relevant to businesses that provide technology or platforms for online Forex and CFD trading.

What are Online Forex Trading and CFDS?

Under the Proposed Rules, Forex/FX/Foreign Exchange means the exchange of one national currency for another. Online forex trading involves trading foreign currencies through an online platform.

A Contract for Difference (CFD) is a derivative that allows a person to trade based on changes in the price of an underlying asset without owning the asset.

Key Highlights of the Proposed Rules

  1. Technology and Platform Providers Within the Regulatory Framework

Under the Proposed Rules, technology and platform providers are recognised as a distinct category of regulated persons. This category appears broad enough to cover businesses that provide trading infrastructure, software, platforms, systems or other technology used in connection with online Forex and CFD trading.

The Proposed Rules also apply to offshore businesses that target or provide services to Nigerian residents. This may arise where a platform permits Nigerian residents to open accounts, advertises its services to Nigerians, uses Nigerian currency or references, engages Nigerian influencers or affiliates, or otherwise demonstrates an intention to serve the Nigerian market.

Accordingly, a technology provider may need to assess its activities carefully where its platform is used by a Forex broker or CFD operator serving Nigerian residents. The fact that the provider does not deal directly with clients or execute trades may not, by itself, take it outside the scope of the Proposed Rules.

  1. Registration and Capital Requirements

A person may not carry on, or hold itself out as carrying on, the business of a technology or platform provider within the scope of the Proposed Rules without registration with the SEC.

For technology and platform providers, the Proposed Rules contemplate a minimum paid-up capital of ₦5 billion. The provider must also be incorporated in Nigeria or be a foreign company with an appropriate local presence in Nigeria.

The proposed registration fees comprise:

  • Application fee – ₦100,000;
  • Processing fee – ₦300,000; and
  • Registration fee for a Category C technology or platform provider – ₦30 million.

In addition, a registered provider would be required to maintain professional indemnity insurance of not less than 20% of the applicable minimum capital per claim, or provide an equivalent security acceptable to the SEC.

  1. Operational and Technology Standards

The Proposed Rules place significant emphasis on the reliability, security and resilience of trading platforms. Technology providers would be expected to maintain systems that support the continuous and orderly operation of trading activities. The key requirements include:

  • Platform availability: Platforms must maintain a minimum uptime of 99.5% during trading hours.
  • Cybersecurity: Providers must have appropriate security measures in place, including end-to-end encryption of client and trade data, multi-factor authentication, regular penetration testing, and systems for monitoring and responding to security threats.
  • Business continuity and disaster recovery: Providers must maintain business continuity and disaster recovery arrangements, test these arrangements annually and submit the relevant certification to the SEC.
  • Record-keeping: Providers must retain audit trails of transactions and other relevant activities for at least seven years. Records must be readily retrievable within 24 hours and may include client information, orders, transactions, confirmations, electronic communications, financial records, AML records and risk disclosures.

These requirements may have implications for the design and operation of trading platforms and should be considered in the contractual arrangements between technology providers and the brokers or other regulated entities using their systems.

  1. Data Protection and Data Localisation

The Proposed Rules also set requirements for the storage and protection of client and trading data. Client order data must be stored in Nigeria or another jurisdiction approved by the SEC, in line with applicable data protection requirements. Technology providers may therefore need to review their data hosting arrangements, third-party access and cross-border data transfers.

  1. White-Label Platforms and Outsourced Technology

The Proposed Rules are also relevant to businesses that provide white-label platforms or outsourced technology solutions. Where a provider supplies the infrastructure used by a broker or trading operator, the parties will need to consider how responsibility for regulatory compliance is allocated. This should include responsibility for:

  • platform availability and performance;
  • cybersecurity and access controls;
  • data storage and processing;
  • incident reporting;
  • recordkeeping and audit trails;
  • business continuity and disaster recovery;
  • regulatory inspections and information requests;
  • use of subcontractors and external technology providers; and
  • suspension, termination or migration of the platform.

The Proposed Rules require prior SEC approval for certain material changes, including changes to a trading platform or technology provider. This means that brokers and other regulated entities may need to obtain SEC approval before changing their technology providers or making significant changes to their trading platform.

Technology agreements should therefore be reviewed to ensure that they contain appropriate provisions dealing with regulatory cooperation, audit rights, service levels, incident escalation, data access, business continuity and orderly transition.

  1. Incident Reporting and Regulatory Cooperation

A technology provider would be required to notify the SEC within 24 hours of a material system breach, outage or cybersecurity incident.

This requirement creates a need for clear internal escalation procedures and contractual reporting arrangements. A broker may not become aware of a system incident immediately, while a technology provider may not have sufficient information to determine whether an incident is material from a regulatory perspective.

Technology providers and their regulated clients should therefore agree in advance on:

  • What constitutes a reportable incident;
  • How quickly incidents must be escalated;
  • Who is responsible for notifying the SEC;
  • The information to be included in an incident report;
  • How affected clients will be notified; and
  • The steps required to contain, investigate and remedy the incident.

The Proposed Rules also contemplate independent systems audits and penetration testing reports for proprietary and white-labelled platforms. Providers should expect increased scrutiny of their technology architecture, security controls, access management, development processes and third-party dependencies.

  1. What Technology Providers Should Consider

Businesses providing technology or platform services to online Forex and CFD operators should begin reviewing their current operations against the proposed framework. In particular, they should:

  • assess their regulatory classification and determine whether their services fall within the proposed definition of a technology or platform provider;
  • review their Nigerian market exposure, including whether their platforms are accessible to Nigerian residents or marketed through Nigerian brokers, affiliates, influencers or other intermediaries;
  • evaluate their capital and local presence requirements, particularly where they operate through a foreign company or provide services on a white-label basis;
  • review their technology infrastructure, including uptime, encryption, authentication, monitoring, penetration testing and incident response arrangements;
  • assess their data arrangements, including data hosting locations, backups, cross-border transfers, subcontractors and compliance with applicable data protection laws;
  • update their contractual arrangements with brokers and other regulated entities to address service levels, audit rights, incident reporting, regulatory access, business continuity and liability;
  • prepare for enhanced recordkeeping and audit requirements, including the retention and retrieval of client, transaction and system records for at least seven years.

Conclusion

The SEC’s Proposed Rules signal closer regulation of online Forex and CFD trading in Nigeria, including the technology infrastructure supporting such activities. While the provisions highlighted in this newsletter are not exhaustive, the proposed requirements may have significant implications for both local and foreign businesses operating in this space.

Businesses should therefore review their regulatory position and relevant operations ahead of the final rules. As the proposals remain subject to change, businesses should continue to monitor developments and assess any implications based on the nature of their services and Nigerian market exposure.

NIGERIA’S NATIONAL DIGITAL CLOUD POLICY: WHAT BUSINESSES NEED TO KNOW

BY ADERONKE ALEX-ADEDIPE & ENIOLA SOGBESAN

Introduction

On 17 August 2026, the Federal Government of Nigeria introduced the National Digital Cloud Policy (the “Policy”), replacing the Nigeria Cloud Computing Policy 2019. The Policy is effective immediately, save for the sovereignty provisions contained in Part III, which remain subject to Presidential approval.

The Policy represents a significant evolution in Nigeria’s approach to cloud computing. While the 2019 policy primarily focused on encouraging the adoption and use of cloud technology, the Policy supports the deliberate development of a domestic cloud and data infrastructure ecosystem in Nigeria.

Among other objectives, the Policy seeks to –

  1. attract investment in cloud and data infrastructure;
  2. develop Nigeria as a regional digital services exporter;
  3. expand and diversify domestic capacity;
  4. modernize government service delivery and
  5. secure government and regulated data proportionately.

In this newsletter, we examine the key provisions of the Policy and consider their practical implications for cloud service providers, data centre operators, regulated entities and businesses that use cloud services in Nigeria.

Scope and Application

The Policy establishes a tiered framework which can be broadly understood across three distinct categories:

  1. General Market Framework: Parts I and IV of the Policy establish the overarching framework applicable to participants in Nigeria’s cloud market. These provisions address matters such as investment, trade, market development and the implementation of the Policy.
  2. Public Sector: Part II of the Policy is applicable to Federal Ministries, Departments, Agencies and entities exercising public functions on their behalf. State Governments, the Federal Capital Territory, and Local Governments may participate voluntarily under the Policy.
  3. Sovereign Data: Part III of the Policy is specifically applicable to sovereign data. Sovereign Data in the Policy refers to-
    i. data generated by the Federal Government, its MDAs, or by entities performing public functions on their behalf; and
    ii. data generated pursuant to a Federal regulation, license, or directives issued by the Federal Government and such data must be expressly designated as sovereign.

Key Policy Incentives

  1. Investment Incentives
    Qualifying Investment may benefit from a range of incentives such as –

    • import duty exemptions, waivers, or concessions on data centre equipment and
    • access to priority status and equivalent tax incentives for qualifying strategic digital infrastructure projects.
  2. Regulatory Facilitation and Investment Certainty
    The Policy recognizes regulatory friction as a material deterrent to infrastructure investment. Accordingly, the Federal Government will among others–

    • coordinate investment promotion to eliminate duplicative approval requirements and reduce administrative delay;
    • establish a single coordinated facilitation point for qualifying cloud and data centre investments; and
    • publish the licensing, compliance, and operational requirements applicable to cloud and data infrastructure investments.
  3. Capital Mobility and Foreign Exchange Incentives
    To ensure the effective realization and repatriation of investments, the Policy ensures the following:

    • lawful repatriation of capital, profits, and dividends in accordance with applicable investment and foreign exchange regulations;
    • prompt issuance of certificates for qualifying investments to secure repatriation rights; and
    • all earnings from cloud and data services provided to customers outside Nigeria will be treated as export earnings eligible for foreign exchange and export incentives.
  4. Energy Access
    The Policy provides a framework to support cloud and data centers in accessing reliable electricity, including opportunities to utilize renewable and alternative energy solutions.Importantly, the beneficiaries of these incentives are required to commit to capability development programmes, including knowledge transfer and skills development to Nigerians.

Eligibility and Qualification

To be eligible to benefit from incentives under the Policy, cloud and data centers must among other considerations demonstrate –

  • deployment, or committed planned deployment, of qualifying infrastructure in Nigeria;
  • registration under the Digital Infrastructure Assurance Registration scheme;
  • participation in the National Digital Marketplace framework, where seeking government business;
  • alignment with national interoperability requirements; and
  • compliance with applicable data protection, cybersecurity, and consumer protection obligations.

Sovereign Data Classification

As noted above, Part III of the Policy is applicable to sovereign data which is categorized into four–

Level Category Data Type Hosting Requirement
4

 

Classified National security, defence and critical infrastructure Hosted exclusively on infrastructure physically located in Nigeria under sovereign control, with processing within Nigeria.
3

 

Highly Sensitive Sensitive personal data, regulated data including financial, biometric, identity and health data. Stored in Nigeria, with continuous sovereign recovery capability; processing in approved environments subject to safeguards.
2 Sensitive Internal government operational data, administrative records, and data that could cause moderate risk if disclosed May be deployed in hybrid environments, including approved international infrastructure, subject to prior authorization.
1 Open Public access data or low risk information with minimal data if disclosed.

 

May be hosted on any compliant infrastructure without residency restriction.

 

Implementation Timeline

The Policy will be implemented in phases with an overall timeline of 24 months from the issuance date.

Next Steps

  1. Cloud providers and data centre operators – Assess eligibility for incentives and the process for registration under the Digital Infrastructure Assurance Registration scheme.
  2. Regulated entities – While the Policy does not impose general data localization requirements, however given that the category of what constitutes “regulated data” is not exhaustive and includes financial, biometric, identity and health data, this data category should be closely monitored where there is the expansion of the data types.
  3. Businesses using cloud services: All commercial data remain unaffected by the sovereignty provisions as the Policy provides regulatory certainty for continued use of international cloud services.

Conclusion

The introduction of the National Digital Cloud Policy is an important shift in Nigeria’s digital infrastructure and data governance landscape. By combining investment incentives, regulatory facilitation, domestic infrastructure development and a risk-based approach to sovereign data, the Policy seeks to strengthen Nigeria’s cloud ecosystem while promoting secure and resilient digital services.

The practical impact of the Policy will depend largely on the development of clear implementation guidelines, the achievement of the key performance indicators set out in the Policy, and the Presidential approval of the sovereignty provisions in Part III.

The Policy presents significant opportunities for investment, innovation and digital transformation. Its success, however, will require sustained collaboration among government and other stakeholders to ensure that Nigeria’s cloud infrastructure develops in a secure and commercially viable manner.

AI REGULATION IN THE EU AND NIGERIA: AI WATERMARKING

BY SEUN TIMI-KOLEOLU & OLUWAYEMI IBIRINDE

INTRODUCTION

On 2 August 2026, the transparency obligations under the European Union Artificial Intelligence Act (the “EU AI Act”) became applicable. These include requirements under Article 50 for certain AI-generated or manipulated content to be identifiable through machine-readable markings and, in specified circumstances, disclosed to users.

The effect of these developments’ cuts across global AI use and will also have implications for Nigerian businesses, particularly those using AI services provided by global technology companies or operating across borders. This is underscored by the participation of about 190 organisations, including major AI providers such as Anthropic, Google, Meta, Microsoft, Mistral and OpenAI, in the European Commission’s Code of Practice on Transparency of AI-Generated Content.

We therefore consider it important to highlight this development and its implication for Nigerian businesses, while examining Nigeria’s existing regulatory framework for AI use and the need for a more comprehensive AI governance framework.

WHAT ARE THE EFFECTS OF THE EU AI WATERMARKING REQUIREMENT?

The introduction of AI-generated content marking and disclosure requirements has several implications for businesses as follows:

  1. Cross-border Application: The EU AI Act applies to any AI tool or output used in the European Union, even for companies operating from outside the EU. Accordingly, Nigerian companies providing AI services or outputs for use in the EU may be subject to applicable transparency requirements, including the requirement to watermark AI-generated content.
  2. Dilution of Original Ownership: Users both inside and outside the EU using AI tools need to be aware that once original human ideas are fed into an AI system, the resulting output gets watermarked and may make it difficult for the creator to prove ownership of their underlying intellectual property or demonstrate that the core work was human authored
  3. Consumer protection and fraud prevention: It is expected that, with the use of AI watermarks, AI-generated content will be more readily identifiable, and therefore support the identification of deepfakes, impersonation, fraudulent content, and other forms of deception.

HOW IS AI REGULATED IN NIGERIA

Nigeria has no single comprehensive AI statute like the EU AI Act. AI-related obligations instead sit within existing laws and other AI governance structures as follows:

  1. Nigeria Data Protection Act (NDPA) Data protection:
    The key regulation in Nigeria governing the use of AI is the Nigeria Data Protection Act, 2023 (NDPA). While Nigeria has no comprehensive AI-specific law comparable to the EU AI Act, the NDPA regulates AI use where personal data is involved. This is particularly important where businesses use foreign AI providers, as these services may involve the processing or transfer of personal data outside Nigeria. Businesses should therefore assess their AI tools for compliance with the NDPA and applicable cross-border data protection requirements.It also clearly restricts and places safeguards around decisions made solely through automated processing where such decisions may have legal or similarly significant effects on individuals, reinforcing the need for appropriate human oversight and transparency.
  2. Federal Competition and Consumer Protection Act (FCCPA)
    Another regulation relevant to the use of AI in Nigeria is the Federal Competition and Consumer Protection Act, 2018 (FCCPA). The FCCPA sets clear consumer protection requirements that apply to AI-driven marketing, pricing, and other consumer-facing activities. It prohibits false, misleading, or deceptive representations and unfair contract terms. AI-generated content, recommendations and decisions must comply with these consumer protection standards.
  3. SEC Rules on Robo-Advisory Services
    Similarly, the SEC Rules on Robo-Advisory Services regulate the use of automated, algorithm-based tools to provide investment advice. The Rules require robo-advisers to identify and mitigate algorithmic bias and clearly disclose to clients how the technology works, including its assumptions, limitations and associated risks. Therefore, where AI is used to provide investment advice, compliance with these requirements is mandatory.
  4. Copyright Act, 2022
    The Copyright Act, 2022 protects original works created by human authors but does not expressly address AI-generated works or determine authorship where content is created by AI. Businesses using AI-generated content should therefore consider copyright ownership and infringement risks, particularly where AI tools generate or reproduce existing protected works.
  5. The National Artificial Intelligence Strategy
    The National Artificial Intelligence Strategy (NAIS) provides the policy foundation for responsible, ethical and inclusive AI adoption in Nigeria. While it does not create binding AI-specific obligations in the same manner as the EU AI Act, it provides a framework for the development of Nigeria’s AI governance and regulatory approach.
  6. The National Digital Economy and E-Governance Bill, 2025
    The National Digital Economy and E-Governance Bill, 2025, which is not yet law, proposes a more comprehensive framework for AI governance in Nigeria. It includes provisions on AI risk classification, monitoring of AI-related risks, accreditation of independent AI system auditors, inspections, audits and enforcement. If enacted, the Bill could significantly strengthen Nigeria’s regulatory framework for AI and move the country closer to a dedicated AI governance regime.Taken together, these instruments demonstrate that Nigeria currently regulates aspects of AI use through existing laws and emerging policy frameworks but does not yet have specific requirements for AI watermarking comparable to those under the EU AI Act.

CONCLUSION

The transparency requirements under the EU AI Act marks a significant shift towards more accountable and traceable AI use, with implications extending beyond the EU as global AI providers adapt their products and compliance practices to emerging regulatory standards. While Nigeria already has several laws and policy instruments that regulate aspects of AI use, it would benefit from a comprehensive AI governance framework that brings these obligations together, provides greater regulatory certainty and addresses AI-specific risks.

As the regulatory landscape evolves, it is important for businesses to take a proactive approach to AI compliance by applying appropriate human oversight and seeking professional advice when adopting or deploying AI technologies.

CBN’S DATA LOCALISATION DIRECTIVE – COMPLIANCE CONSIDERATIONS FOR PAYMENT SYSTEM PARTICIPANTS

BY ADERONKE ALEX-ADEDIPE & PROMISE ITAH

Introduction

On June 15, 2026, the Central Bank of Nigeria (“CBN“) issued a Circular on Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System (the “Circular“). Among other regulatory reforms, the Circular introduces a significant data localisation requirement directing all financial institutions and participants facilitating payments within Nigeria—including banks, payment service providers, mobile money operators and other payment participants— (collectively “Payment System Participants”) to ensure that data generated in relation to payment transactions in Nigeria is stored and managed in Nigeria by January 1, 2027.

In this newsletter, we examine the scope of the CBN’s data localisation requirements, their interaction with existing data protection obligations, and some of the key legal, contractual and operational considerations which Payment System Participants should consider in preparation for compliance.

  1. Who does the Circular Apply to?
    The Circular applies to payment transaction data generated through Nigeria’s payments system. Although the Circular does not define the term “payment transaction data”, it intuitively includes information generated in connection with a payment transaction, including the payer’s and beneficiary’s payment details, transaction amounts, payment references, authentication records, settlement and routing information, transaction logs and other related technical data required to process, verify or record a payment.

    The Circular also appears to frame the localisation requirement by reference to payment transaction data generated within Nigeria, rather than the location in which the business is principally domiciled. On this basis, therefore any Payment System Participant processing payment transaction data generated within Nigeria may be expected to comply with this requirement, regardless of their country of domicile.

  1. What are the Key Compliance Requirements?

    a. Local Processing and Storage
    Payment System Participants must ensure that payment transaction data is both stored and managed within Nigeria. This extends beyond maintaining a local copy of data and requires that the primary processing environment, databases, backups and operational control remain on infrastructure located within Nigeria.

    The requirement for payment transaction data to be “managed” in Nigeria may also have implications for administrative activities such as access management, database administration, encryption key management and audit logging, particularly where these functions are performed through offshore infrastructure or personnel.

    b. Technology and Infrastructure
    The Circular is likely to require many Payment System Participants to review their technology infrastructure, particularly where payment services rely on foreign cloud service providers or systems hosted outside Nigeria. Given the requirement for payment transaction data generated within Nigeria to be stored and managed locally, organisations should assess whether their existing technology architecture involves the storage, processing or replication of payment transaction data outside Nigeria. Areas that may require review include:

    • cloud hosting arrangements and the location of servers;
    • disaster recovery and backup systems;
    • analytics and monitoring platforms that process payment data;
    • testing and development environments that use live or production payment data; and
    • third-party APIs and other technology integrations that may transfer payment data outside Nigeria.

Payment System Participants operating hybrid or multiple cloud environments should assess whether payment data is stored, replicated or processed outside Nigeria and, where necessary, implement appropriate technical or operational changes before the compliance deadline.

c. Vendor and Outsourcing Arrangements

Whilst it is commonplace for Payments System Participants to assign data processing and storage activities to third parties, the Circular does not appear to transfer the obligations from Payment System Participants to service providers in such instance. Accordingly, organisations should review their contractual arrangements with cloud service providers, payment processors, application programming interface (API) providers and other technology vendors to assess whether those arrangements support compliance with the localisation requirement. In particular, organisations should consider whether their contracts adequately address:

    • the requirements for payment data to be stored and managed within Nigeria;
    • restrictions on processing payment data outside Nigeria;
    • rights to conduct audits and facilitate regulatory inspections;
    • controls over the use of subcontractors that may have access to payment data;
    • obligations to promptly notify the Payment System Participant of any data breaches or incidents; and
    • termination rights where a vendor is unable to comply with the localisation requirements.
  1. How does the Circular Interact with the Nigeria Data Protection Act (NDPA)?

The Circular complements rather than replaces the NDPA. While the NDPA regulates the processing and international transfer of personal data through recognised transfer mechanisms and safeguards, the CBN Circular imposes an additional regulatory obligation applicable specifically to payment transaction data. Accordingly, compliance with the NDPA alone will not satisfy the CBN’s localisation requirements.

  1. Practical Compliance Steps

Pending any further guidance from the CBN, Payment System Participants should consider taking the following steps to prepare for implementation:

    1. conducting a comprehensive data mapping exercise to identify where payment data is stored, processed and transmitted;
    2. assessing existing cloud and infrastructure arrangements for localisation risks;
    3. reviewing third-party vendor relationships and contractual provisions;
    4. updating internal data governance, outsourcing and information security policies;
    5. establishing board and management oversight of the implementation programme; and
    6. maintaining adequate documentation to demonstrate compliance during regulatory inspections.

Conclusion

The CBN’s payment data localisation requirements represent a significant development in the regulation of Nigeria’s payments ecosystem. By requiring payment transaction data generated within Nigeria to be stored and managed in Nigeria, the Circular appears intended to strengthen regulatory oversight, enhance operational resilience and support the security of Nigeria’s payments infrastructure. For Payment System Participants, the immediate priority will be to assess whether existing technology infrastructure, data governance frameworks and third-party vendor arrangements are consistent with the new localisation requirement. Given the breadth of the obligation and the absence of detailed implementation guidance, organisations that begin assessing their compliance position ahead of the January 2027 implementation date will be better positioned to address any legal, operational or contractual gaps as further guidance emerges.

PROTECTING INNOVATION IN NIGERIAN TECH CONTRACTS: COMMON PITFALLS AND SOLUTIONS

BY ADERONKE ALEX-ADEDIPE AND ENIOLA SOGBESAN

Introduction

In the current global digital economy, businesses enjoy significant competitive advantage from intangible assets such as intellectual property, confidential data and proprietary processes. In Nigeria, given that many businesses rely heavily on innovation and technology services, effective intellectual property is critical to long-term enterprise value and commercial sustainability.

In Nigeria, the intellectual property terrain is regulated by the provisions of the Copyright Act, Trademarks Act & Patents and Designs Act. However, while the provisions of these laws are robust, they do not sufficiently prevent disputes between parties. In practice, the allocation, licensing, transfer and enforcement of intellectual property rights are determined by the terms of contract. Notwithstanding, most intellectual property disputes usually arise because IP clauses are wrongly drafted, silent on risk allocation and misaligned with commercial objectives.

In this article, we examine the importance of IP clauses in technology agreements, identify loopholes that may give rise to disputes and proffer strategies for mitigating risks with regard to Nigerian and cross-border transactions.

The Role of IP Clauses in Tech Agreements

IP clauses are essential features of a modern technology agreement. They help determine who owns these intangible assets, the terms on which they may be used and any applicable restrictions. IP clauses are critical in agreements such as licensing and distribution agreements, joint ventures & mergers and acquisitions. In granting any IP rights under any of these agreements, parties should ensure that the IP clauses are detailed enough to protect the interest of the grantor while specifying whether the rights are granted on an exclusive or non-exclusive basis.

Common IP Clause Dispute Triggers

  1. Unclear ownership provisions – Uncertainty and lack of clarity on IP ownership in technology contracts is the basis of most IP clause disputes. This ambiguity becomes visible when there is a breakdown in the business relationship between the parties or there is an increase in the value of the asset. Where IP ownership provisions are not clearly drafted, it gives room for statutory and judicial interpretation.

    For example, under the Nigerian Copyright Act 2022, copyright is vested in the author of a work subject to certain exceptions including employment relationships and commissioned works. This therefore suggests that in the absence of clear assignment of the IP in such works, the author may retain ownership of the software or creative materials produced for a client.

  2. Inadequate licensing terms – Similarly, poorly drafted licensing terms can also give rise to IP-related disputes, particularly because IP licensing determines the extent of the economic value that can be derived from an intellectual property asset. Where there is ambiguity regarding the scope, duration, territory, or exclusivity of a license, such uncertainty may lead to overreach, misuse, or infringement disputes.

    At a minimum, licensing terms should highlight the scope, territorial limits, sublicensing rights (if applicable) and post-termination rights and obligations. Any failure to clearly define these terms, may enable a licensee to assume broader commercial rights than was intended, while the licensor may restrict its ability to explore the IP in other jurisdictions.

  3. Confidentiality Breaches– Trade secrets which constitute an IP asset class protects commercially valuable information. These are not registered but merely derive their value from its confidential nature, therefore confidentiality clauses are an essential protective mechanism in technology agreements. Important elements that should be included in a confidentiality clause include; definition of what constitutes confidential information, duration of the confidentiality obligations, exceptions and remedies in case of a breach.
  4. Inadequate Enforcement Provisions – While parties do not intend to engage in IP disputes at the onset of the business relationship, a well drafted IP clause should anticipate this possibility. In many technology agreements, the failure to specify the obligations of each party in relation to the ownership and use of the IP results in inconsistent enforcement strategies and disputes between the contracting parties themselves.

    This inadequacy extends to creating uncertainty as to who bears responsibility for monitoring infringement and initiating legal action. Without this clarity, enforcement actions against infringers may be protracted and weaken the commercial value of the IP.

  5. Post Termination Obligations – While IP disputes arise at the end of contractual relationships, the termination of a contract does not automatically extinguish all IP rights unless otherwise provided. In the absence of clearly defined post termination obligations, former licensees may continue using such IP assets thereby exposing both parties to legal and commercial risks. A well drafted post termination clause should address reversion rights, return or destruction of materials and any other ongoing license restrictions.

Practical Fixes & Risk Mitigation Strategies.

  1. Precise definitions and clear ownership of IP assets should be set out in the agreement.
  1. Legal due diligence and contract audits should be undertaken prior to executing the contract as it will help identify and mitigate potential risk factors associated with the IP asset.
  1. There should be a periodic review of the contract and update of IP clauses as the underlying technology evolves.
  1. To provide an additional layer of security, all IP assignments should be executed and properly registered with the relevant government agencies.

Conclusion

IP clauses are designed to protect the value of the underlying IP asset and provide commercial value to the holder. However, where they are ambiguous or misaligned with operational and commercial objectives, they become sources of disputes. Moreover, in a global economy which is increasingly driven by innovation and creativity, effective IP drafting, especially in technology agreements, is a core requirement that should consider the applicable legal framework, transaction structure and the commercial objectives of the parties.

Therefore, businesses and practitioners should engage IP contractual frameworks with the perspective of risk management and value protection which will further strengthen the value and commercial returns on the underlying IP asset.

KEY REGULATORY UPDATE: CBN GUIDELINES ON INSTANT PAYMENT FUNCTIONALITIES AND MOBILE BANKING SECURITY

By: Aderonke Alex-Adedipe and Mark Imonitie

Introduction

On 12 March 2026, the Central Bank of Nigeria (CBN) issued a circular (the “Circular”) to all financial institutions (FIs) offering Instant Payment (IP) services in Nigeria.

The Circular provides the CBN’s Guidelines on instant payments and introduces sweeping measures to strengthen IP operations, enhance security protocols, improve consumer protection, and align with global best practices. This newsletter highlights the key provisions introduced by the Guidelines.

  1. VOLUNTARY OPT-IN AND OPT-OUT FUNCTION

Under the existing framework, FIs are not mandated to provide a feature on their mobile banking application, enabling customers to voluntarily opt in or out of IP services.

The new Guidelines however require FIs to allow customers to opt in or out at any time, subject to Multi-Factor Authentication (MFA).

New customers will be onboarded in opt-in mode by default. While opted out, customers cannot perform instant online fund transfers from their account; however, such transfers remain available via a physical branch visit.

  1. FLEXIBILITY IN SETTING TRANSACTION LIMITS

Prior to establishing the Guidelines, the maximum transaction limits of N25,000,000.00 for individuals and ₦250,000,000.00 for corporate entities, were fixed, with no option for customers to set personalized limits within those thresholds.

The Guidelines will subsequently allow both individuals and corporate entities to adjust these limits as needed, subject to enhanced due diligence and appropriate risk management by the FI.

To ensure security, the new transaction limit takes effect only after the customer completes the Multi-Factor Authentication (MFA) process.

  1. LIVELINESS CHECKS AND ENHANCED SECURITY FOR ONLINE TRANSACTIONS
    The Guidelines provide that where a customer seeks to open an account online or reactivate an online account, the following enhanced security measures shall apply:

    • liveliness check of the online account;
    • real-time validation of BVN/NIN database for online account openings/reactivations;
    • enhanced authentication mechanisms such as biometric authentication, soft token, hard token, for online account reactivations.

    A liveliness check is a biometric security measure which confirms that a user is a live, physically present human rather than a photo, video, or deepfake—by analyzing facial traits like skin texture, eye movement, and depth during remote onboarding or transactions, thereby preventing spoofing attacks.

  2. FRAUD MONITORING FUNCTIONALITY

The Guidelines mandate that all FIs implement and activate enterprise-wide fraud monitoring functionality covering both in-flows and out-flows. This measure restricts suspicious transactions in real-time while enabling prompt fraud detection and response.

  1. MANDATORY DEVICE BINDING

Under the existing framework, customers can operate their mobile banking application concurrently on multiple devices. The new Guidelines restrict mobile banking applications to one active device at a time, prohibiting concurrent use across devices. Switching to a new device triggers automatic deactivation of the previous one, followed by re-activation and authentication.

  1. ADDITIONAL REQUIREMENTS

The Guidelines introduce the following measures for mobile financial services applications and internet banking:

  • New account owners: Upon activation of a mobile banking application, inflow and outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira).
  • Existing account owners: Upon activation of a mobile banking application, outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira)
  • First-time login on a new device for internet banking requires enhanced Multi-Factor Authentication (MFA).

Conclusion

The Central Bank of Nigeria’s (CBN) new Guidelines on Instant Payment Functionalities for Financial Institutions mark a significant advancement in safeguarding digital transactions nationwide.

Effective 1 July 2026, financial institutions (FIs) must implement these measures. Among other requirements, the Guidelines necessitates comprehensive security and Data Protection Impact Assessments (DPIAs) to ensure compliance with the Nigeria Data Protection Act 2023 particularly resulting from mandatory features like multi-factor authentication (MFA), facial recognition, and continuous transaction monitoring.

About us:

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a Data Protection Compliance Organization. We provide quality and innovative legal and data protection  support across diverse industries, helping clients operate in compliance with applicable laws and regulations to drive sustainable business growth.

REGULATORY UPDATE: NDPC EXTENDS DATA AUDIT FILING DEADLINE

By Seun Timi-Koleolu and Omodele Fatodu

The Nigeria Data Protection Commission (“NDPC”) has announced an extension of the deadline for the filing of the 2025 Data Protection Compliance Audit Returns (“CAR”) from March 31 to May 30, 2026. Data Processors and Controllers of Major Importance (“DPCMIs”) are therefore encouraged to utilise this period to ensure that their data protection frameworks are aligned with regulatory expectations and to file their Compliance Audit Returns within the extended timeline.

DPCMIs should note that failure to file within the prescribed timeline will attract regulatory sanctions. In particular, late filing of the CAR is subject to a penalty of 50% of the applicable filing fee, in addition to the risk of further regulatory scrutiny or enforcement action by the NDPC.

  1.  Practical Steps During the Extension Period

To make effective use of the extended timeline, DPCMIs should consider the following:

  1. Data Mapping: Ensure that all personal data processing activities are clearly identified and documented, including the nature of data collected, purposes of processing, storage locations, and third-party disclosures.
  2. Policy Review: Review privacy policies and internal data protection procedures to confirm that they are up to date and aligned with regulatory requirements and actual data processing practices.
  3. Remediation of Prior Findings: Ensure that any identified gaps or recommendations from prior audits have been appropriately addressed and implemented.
  4. Engage a licensed Data Protection Compliance Organisation (DPCO): A licensed DPCO can conduct the data protection compliance audit and file the CAR on behalf of the organisation, helping to ensure that the audit meets NDPC expectations.
  1. Update on Filing Fees

DPCMIs are also reminded that the filing fees applicable to the CARs were revised under the General Application and        Implementation Directive, 2025 (“GAID”). The fees depend on the DPCMI category, as well as the number of data subjects processed by the organisation, as outlined below:

  1. Ultra-High Level DPCMI
    Tier A – 50,000 data subjects and above: N1,000,000
    Tier B – 25,000 – 49,999 data subjects: N750,000
    Tier C – below 25,000 data subjects: N500,000
  2. Extra-High Level DPCMI
    Tier A – 10,000 data subjects and above: N250,000
    Tier B – 2,500 – 9,999 data subjects: N200,000
    Tier C – below 2,500 data subjects: N100,000
  1. Further Guidance

For a more detailed overview of compliance obligations under Nigerian data protection laws, and the role of DPCOs, please refer to our previous publications:

Conclusion

The extension of the 2025 data audit filing deadline provides organisations with an extended opportunity to review their data protection practices and file their Compliance Audit Returns on time.

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a DPCO. We provide support to organisations across diverse industries in conducting data protection compliance audits, preparing and filing Compliance Audit Returns, and ensuring alignment with the GAID and Nigeria Data Protection Act, 2023.