Posts

UPDATE ON REGULATION OF DIGITAL ASSETS IN NIGERIA: SOME LESSONS FROM SWITZERLAND

By Aderonke Alex-Adedipe and Baraebibai L. Ekpebu

 

DOWNLOAD PUBLICATION

Introduction

Generally, skepticism expressed about cryptocurrencies stems from their classification as high-risk assets’’ which are extremely volatile and speculative in terms of price.[1] The main reason for the existence of Blockchain Technologies is their independence from financial endorsement and their universal nature. This is why the regulation of cryptocurrencies remains an arduous task for financial authorities.

Following the recent announcement of the ban on the dealing or facilitation of cryptocurrency transactions by Nigerian financial institutions by the Central Bank of Nigeria (CBN)[2], the Securities and Exchange Commission (SEC) also announced on 11th February 2020, that its previous decision to regulate cryptocurrency investments in Nigeria has now been suspended. In light of these developments, this article aims to shed light on possible options to aid the crafting of a regulatory regime for blockchain technologies in Nigeria.

There are indeed some valid concerns about cryptocurrency transactions. For instance,  the fact that they create new opportunities for criminals and terrorists to launder their proceeds, or finance their illicit activities.[3] Notwithstanding, the Swiss have built a system that innovatively utilizes pre-existing Swiss law and novel legislation, to regulate the activities of blockchain service providers in Switzerland.

Nigeria is responsible for more cryptocurrency trading than most countries and is currently rated as the third highest globally for trading volumes in cryptocurrency. It is therefore desirable, that a robust regulatory regime exists to govern these transactions, address negative tendencies, and in effect, strengthen the financial services industry and the Nigerian economy in general. For these reasons, it is essential to examine some key aspects of Swiss Blockchain Laws to understand the methodology employed to provide a grounded basis for digital asset exchange and tokenization, while simultaneously addressing the issue of digital currency money laundering.

The Swiss Approach

The Swiss Financial Market Supervisory Authority or ‘FINMA’’ recognises the tendency for block-chain business models to sidestep existing regulations. To put a check on such tendencies, Swiss authorities have successfully placed blockchain service providers under the ambits of the Swiss Anti-Money Laundering Act.[4] Blockchain service providers in Switzerland are mandated to verify all their customers’ identities, monitor business relationships based on risk level, and report to the ‘Money Laundering Reporting Office Switzerland (MROS), where there are reasonable grounds to suspect money laundering. All Virtual Asset Service Providers who intend on doing business in Switzerland are required to apply for a license from FINMA.

The new Swiss laws define ‘exchange digital securities’ and stipulate the legal procedure for the seizure of digital currency assets in bankruptcy proceedings. The roles of digital currency trading platforms and their legal standing on digital securities are also well clarified.

FINMA has currently granted licenses to several financial institutions to carry out cryptocurrency trading activities. This has served to promote distributed ledger technology and incorporate crypto assets into portfolios and Exchange-Traded Funds.

Switzerland is noted to have a comprehensive regime for Initial Coin Offerings (ICOs) which are also regulated under money laundering laws, terrorist financing laws, securities trading laws, banking laws and, Swiss collective investment scheme legislation.

Residents of the Canton of Zug in Switzerland (referred to as the “Crypto Valley”) can now pay their taxes in bitcoin and cryptocurrencies up to 100,000 CHF, under the supervision of the Swiss Federal Tax Administration (SFTA).[5]

Interestingly, like the Nigerian position, cryptocurrencies are still not classed as a legal tender in Switzerland, neither are they considered to be “money” for reasons that their intangible nature stops them from being classified as a “thing” under Swiss civil law.[6]

Conclusion

From the foregoing, it is evident that a technology-neutral legislative approach is needed and can be developed in Nigeria. To achieve this, active steps need to be taken towards streamlining regulations on insolvency, financial market, banking, collective investment, and anti-money laundering into a legal framework for the regulation of cryptocurrency transactions and investments in Nigeria. This is likely to trigger an unprecedented boost in the Nigerian economy which has continuously suffered from currency devaluation over the years.

 

[1] Mario Draghi, President of the ECB, Introductory Statement and Closing Remarks at the European Parliament Plenary Debate on the ECB Annual Report for 2016 (Feb. 5, 2018), https://www.ecb.europa.eu/press/key/date/ 2018/html/ecb.sp180205.en.html, archived at http://perma.cc/M6WX-T3RR.

[2] Aderonke Alex-Adedipe and Eustace Aroh, (Pavestoneslegal September 23, 2020) Regulation of Cryptocurrencies and Other Digital Assets in Nigeria accessed 24 March 2021

[3] CGMF’s report, National Risk Assessment: Risk of money laundering and terrorist financing posed by crypto assets and crowdfunding, October 2018

[4] Federal Council report – Legal framework for distributed ledger technology and blockchain in Switzerland, December 2018

[5] Tanzeel Akhtar, (Nasdaq, February 18, 2021)  Switzerland’s ‘Crypto Valley’ Has Started Accepting Bitcoin, Ether for Tax Payments accessed 24 March 2021

[6] Mueller / Reutlinger / Kaiser, p. 86 et seq .; Maurenbrecher / Meier, protection of users of virtual currencies under insolvency law; Eggen, Chain of Contracts – A private law dispute with Distributed Ledgers, AJP 2017, p.14; Bärtschi / Meisser, Virtual Currencies from a Financial Market and Civil Law Perspective, in: Weber / Thouvenin (ed.), Legal challenges through web-based and mobile payment systems, Zurich 2015, p. 141

 

Data Protection In Nigeria; Impact On Open Banking Regulation

By Aderonke Alex-Adedipe and Eustace Aroh

Introduction

The rapid growth of finance and technology (fintech) companies in the last decade have been necessitated by consumers’ needs for faster and more convenient financial services. These needs continue to evolve over time and traditional financial institutions struggle to keep up. Open banking offers financial institutions who have access to information of customers (“Providers”) the opportunity to share such information with other financial institutions (“Consumers”) to keep them aware of those needs and enable them offer optimum services.

In our previous article, we highlighted the provisions of the recent Central Bank of Nigeria’s (CBN) Regulatory Framework for Open Banking in Nigeria (“Framework”). In today’s article, we consider specifically, the implication of data sharing under the Framework in light of the Nigeria Data Protection Regulation 2019 (NDPR).

NDPR
The NDPR was issued by the National Information Technology Development Agency (NITDA) in 2019 to regulate the collection, processing and storage of personal data. Personal data is information relating to an individual who can be identified, directly or indirectly, in particular by reference to an identifier. It includes a name, address, a photo, an email address, bank details, medical information, IP address, IMEI number, IMSI number, SIM, and others.

Due to the fact that the damage an individual may suffer in the course of breach of some personal data may be higher, data such as ethnic and racial information, religious beliefs, biometric and health information are categorized as sensitive data. These data must, therefore, be subject to a higher level of protection. Although the NDPR does not classify financial data as sensitive data, financial institutions have access to a number of sensitive data such as ethnicity and biometrics.

Applicable Personal Data
Under the Framework, four types of data qualify for the open exchange of data. These are Product Information and Service Touchpoints (PIST), Market Insight Transactions (MIT), Personal Information and Financial Transaction (PIFT), Profile, Analytics and Scoring Transaction (PAST). Only the PIFT and PAST, however, involve the sharing of personal data of consumers amongst participants.

The PIFT deals with the sharing of customer’s information provided during the Know Your Customer (KYC) process and information of the customer’s transactions such as account balance, payments, loans, recurring transactions etc. The PAST involves the sharing of information on the customer which analyses, provides scores and gives an opinion on customer behaviour (profiling).

Safeguards of the Framework
The Framework stipulates a number of security standards and protocols with respect to sharing of personal information over the Application Programming Interface (API) as it relates to authentication, authorisation, encryption, and secure hosting of data. The Framework also provides for a risk management system for each participant to, among others, track the risk of data sharing with other participants, comply with data privacy laws such as the NDPR, and report such associated risks to the CBN.

Consent
Irrespective of the data protection requirements under the Framework, the Framework specifically requires participants to comply with all extant laws on data privacy such as the NDPR and the NDPR Implementation Framework. Under the NDPR, before personal data of a customer can be used for a purpose different from that which it was initially given, the data controller, (in this case, the financial institution) is required to inform the customer of:

  1. the purpose for which the data was originally collected;
  2. if there is any connection between the original purpose and the proposed purpose;
  3. the possible impact of the new processing on the data subject; and
  4. the existence of security safeguards to protect the data.

The Framework further requires participants to list the specific rights which customers may grant to the participants and obtain the consent of the customer for each right separately.

Providers are also expected to ensure that customers revalidate their consent annually or after 180 days in cases where the services of the provider have not been used.

Conclusion
While the Framework seeks to support innovation in the Nigerian financial sector, participants of the open exchange of data are expected to reassess their data privacy practices to ensure they meet data compliance requirements of the NDPR and the Framework.

THE REGULATION OF OPEN BANKING IN NIGERIA

By Seun Timi-Koleolu and Praise Adetunmibi
Introduction

The Banking sector worldwide is undergoing major changes and the key drivers of these change are You and I. In today’s world (described as the Experience Economy by Pine and Gilmore, Harvard Business Review 1998), we all want easier, seamless and personalised digital banking experiences.

One way banks in the United Kingdom and other countries are meeting this need is with the use of Open Banking. Open Banking is the banking practice that grants third-party financial service providers access to consumer banking transactions and financial data through the use of Application Programming Interfaces (APIs). Such access must be only to the extent approved by customers.

It is expected that with Open Banking, customers would: (i) view and manage their various bank accounts from one centralized location; (ii) grant easy access of account information to creditors when applying for a loan rather than gathering reports from various banks; (iv) have easier accounting processes; and (v) enjoy competitive banking rates, amongst other benefits.

In view of the foregoing and with a view to enhance financial inclusion, improve competition in the financial services space and promote efficient services, the Central Bank of Nigeria (CBN) on the 17th day of February 2021, issued the Regulatory Framework for Open Banking in Nigeria (“Framework”).

In this article, we have highlighted some of the key provisions of the Framework.

1.Scope – The Framework applies to banking and other related services including: (i) payments and remittance services; (ii) collection and disbursement services; (iii) deposit-taking; (iv) credit; (v) personal finance advisory and management; (v) credit ratings/scoring; (vi) leasing/hire purchase; and (vii) mortgages.

2.The Participants – The Framework regulates the following 4 Participants in Open Banking: (i) The Providers (who use API to provide data or a service to another participant); (ii) The Consumers (who uses API released by the providers to access data or service); (iii) The Fintech companies (they may be Providers or API Users; in such instance, they assume the responsibilities of the role they play at any point in time); (iv) the Developer Community (individuals and entities that develop APIs for participants based on requirements). The responsibilities of each of the Participants are set out in the Framework.

3.The Regulator – Though not listed as a Participant, it is pertinent to note that the CBN is the primary regulator of Open Banking in Nigeria. The CBN is to be responsible for the maintenance of an Open Banking Registry and the development of the Common Banking Industry API Standards. These Standards are to be developed within 12 months of issuance of the Framework.

4.Categories of Financial Data that can be shared through APIs – The Framework divides data and services that can be shared through APIs into four broad categories and defines the risk level associated with each category.

S/N Data and Service Category Risk Rating Participants who can access this data
i. Product Information and Service Touch Points – includes data on products provided by Participants to their customers and the access points e.g. ATM/POS/Agents locations, website/app addresses, fees, rates etc. Low All Participants (including participants without licences and those in the CBN Sandbox).
ii. Market Insight Transactions (MIT) – this includes data exchanged for the purpose of gathering statistics of products, services and segments. Such information must not be associated to any individual, customer or account. Moderate All Participants (as above).
iii. Personal Information and Financial Transaction (PIFT) – this includes data at an individual customer level either on general information on the customer (e.g., KYC data, total number of accounts held, etc) or data on the customer’s transaction (e.g., balances, bill payments, loans, recurring transactions on customer’s accounts, etc). High These can be accessed by Participants in the CBN Sandbox; licenced Payment Service Providers and other financial institutions; and Deposit Money Banks.
iv. Profile, Analytics and Scoring Transaction (PAST) – this includes data of a customer that analyses, scores or gives an opinion on the customer e.g., credit score, incoming ratings etc. High and Sensitive These can only be accessed by licenced Payment Service Providers and other financial institutions; and Deposit Money Banks.

5. Customer Protection – The implementation of Open Banking is hinged on the explicit consent of the customers/end users of financial products. The Framework mandates Participants to obtain the consent of customers in the customer’s preferred language and to ensure the security of financial data of such customer.

6. Liability for Misuse of Data – Participants and their partners would be jointly liable for any loss occurring to the customer as a result of data sharing; save for where the Participant can prove wilful negligence or fraudulent act against the customer.

Conclusion

As earlier stated, there are various benefits attributable to Open Banking including more ease in banking transactions. There is, however, a major risk of data breach or the misuse of consumer data. It is imperative that data protection regulations are properly implemented in Nigeria to avoid grave financial losses to consumers.

Data Protection Compliance Organisations and Legal Advisers1 will be expected to play a major part in supporting Participants and regulators in protecting consumers, as Open Banking develops in Nigeria.

CONTACTLESS PAYMENT METHODS – THE REGULATION OF QUICK RESPONSE (QR) CODES IN NIGERIA

By Seun Timi-Koleolu and Eustace Aroh

Introduction

A cashless world was hard to imagine in the 80s and 90s (at least for most of us). It was unimaginable for you to successfully make payments, without cash, a debit or a credit card. What exactly were you to use then?! Right before our eyes, the world began to change, the mobile phone became more than a phone, it became your everything; your notepad, your office, your camera and your payment device (with the use of Quick Response [QR] Codes and Near Field Communication [NFC] tags).

The use of QR Codes as a payment method was introduced by Alipay in 2011 and became a widely used method of payment in China. NFC tags (which are chips built into smartphones) were used in countries like the United Kingdom first.

In Nigeria, QR Codes as a payment method is gradually gaining traction. Fintech companies such as Paystack and Flutterwave now offer sellers and service providers the ability to receive payment by generating and printing or sending a QR Code to their customers even over social media platforms such as Facebook. Many of the traditional financial institutions (such as First Bank and Guaranty Trust Bank) have updated their mobile applications to enable Customers utilize QR Codes as a payment method.

To properly regulate the use of QR Codes as a payment means in Nigeria, the Central Bank of Nigeria (CBN) on January 13, 2021, issued a Framework for QR Code Payments in Nigeria (“Framework”). We have highlighted some salient provisions of the Framework below.

Who are the Participants?

The major participants to a QR Code transaction as stated in the Framework are:

  1. The Merchant – this is the store owner, seller or service provider that has requested for payment through a QR Code.
  2. The Customer – this is the individual who is to pay the Merchant using the QR Code.
  3. The Issuer – this is the financial institution of the Customer.
  4. The Acquirer – this is the financial institution of the Merchant.
What are their Obligations?
  1. Where a Merchant elects to receive payment through QR Codes, he can only display QR Codes approved in Nigeria.
  2. The Merchant is also expected to comply with all extant CBN regulations and the rules of the Acquirer.
  3. The Customer is expected to use the QR Code application (provided by its financial institution i.e. the Issuer) without modifications and adhere to any security protocol of the Issuer.
  4. The Issuer is required to provide the Customer, upon request, with a QR Code Payment application that complies with the QR Code regulations; and ensure that all Customers update the application within 14 days of deployment of an update or patch.
  5. Issuers are also required to send a quarterly risk management assessment report to the Director, Payments System Management Department, CBN.
  6. The Acquirer is expected to ensure the proper use of the QR codes at the Merchant’s location or platform; and ensure the technology and protocol used for QR code conforms with the QR Code payment regulations.
  7. The value of each QR Code transaction must be delivered by the Acquirer to the Merchant within a day after the transaction.
  8. Both the Acquirer and the Issuer are to ensure the security of their system in such transactions.
  9. Where a switch or payment service provider is involved, they are required to facilitate interoperability between the Issuer and Acquirer and comply with the Framework and other CBN regulations on electronic payments.
Other Provisions of the Framework

The Framework adopts the Merchant-presented mode specification for Nigeria (as opposed to the customer-presented mode) which means the Merchant has to present the QR Code for buyers to scan in order to conclude the payment transaction.
Please also note that the Nigeria Inter-Bank Settlement System Plc (as the Payment Terminal Service Aggregator) is to certify QR Codes, the payment applications, updates and patches.

Conclusion

Payment with the use of QR Codes in Nigeria is gradually becoming the preferred choice for businesses in Nigeria as it is an affordable alternative to utilizing POS solutions. The issuance of the Framework is a positive step to encourage innovation in financial services and promote the secured use of QR Codes in Nigeria