Posts

NIGERIA’S NATIONAL DIGITAL CLOUD POLICY: WHAT BUSINESSES NEED TO KNOW

BY ADERONKE ALEX-ADEDIPE & ENIOLA SOGBESAN

Introduction

On 17 August 2026, the Federal Government of Nigeria introduced the National Digital Cloud Policy (the “Policy”), replacing the Nigeria Cloud Computing Policy 2019. The Policy is effective immediately, save for the sovereignty provisions contained in Part III, which remain subject to Presidential approval.

The Policy represents a significant evolution in Nigeria’s approach to cloud computing. While the 2019 policy primarily focused on encouraging the adoption and use of cloud technology, the Policy supports the deliberate development of a domestic cloud and data infrastructure ecosystem in Nigeria.

Among other objectives, the Policy seeks to –

  1. attract investment in cloud and data infrastructure;
  2. develop Nigeria as a regional digital services exporter;
  3. expand and diversify domestic capacity;
  4. modernize government service delivery and
  5. secure government and regulated data proportionately.

In this newsletter, we examine the key provisions of the Policy and consider their practical implications for cloud service providers, data centre operators, regulated entities and businesses that use cloud services in Nigeria.

Scope and Application

The Policy establishes a tiered framework which can be broadly understood across three distinct categories:

  1. General Market Framework: Parts I and IV of the Policy establish the overarching framework applicable to participants in Nigeria’s cloud market. These provisions address matters such as investment, trade, market development and the implementation of the Policy.
  2. Public Sector: Part II of the Policy is applicable to Federal Ministries, Departments, Agencies and entities exercising public functions on their behalf. State Governments, the Federal Capital Territory, and Local Governments may participate voluntarily under the Policy.
  3. Sovereign Data: Part III of the Policy is specifically applicable to sovereign data. Sovereign Data in the Policy refers to-
    i. data generated by the Federal Government, its MDAs, or by entities performing public functions on their behalf; and
    ii. data generated pursuant to a Federal regulation, license, or directives issued by the Federal Government and such data must be expressly designated as sovereign.

Key Policy Incentives

  1. Investment Incentives
    Qualifying Investment may benefit from a range of incentives such as –

    • import duty exemptions, waivers, or concessions on data centre equipment and
    • access to priority status and equivalent tax incentives for qualifying strategic digital infrastructure projects.
  2. Regulatory Facilitation and Investment Certainty
    The Policy recognizes regulatory friction as a material deterrent to infrastructure investment. Accordingly, the Federal Government will among others–

    • coordinate investment promotion to eliminate duplicative approval requirements and reduce administrative delay;
    • establish a single coordinated facilitation point for qualifying cloud and data centre investments; and
    • publish the licensing, compliance, and operational requirements applicable to cloud and data infrastructure investments.
  3. Capital Mobility and Foreign Exchange Incentives
    To ensure the effective realization and repatriation of investments, the Policy ensures the following:

    • lawful repatriation of capital, profits, and dividends in accordance with applicable investment and foreign exchange regulations;
    • prompt issuance of certificates for qualifying investments to secure repatriation rights; and
    • all earnings from cloud and data services provided to customers outside Nigeria will be treated as export earnings eligible for foreign exchange and export incentives.
  4. Energy Access
    The Policy provides a framework to support cloud and data centers in accessing reliable electricity, including opportunities to utilize renewable and alternative energy solutions.Importantly, the beneficiaries of these incentives are required to commit to capability development programmes, including knowledge transfer and skills development to Nigerians.

Eligibility and Qualification

To be eligible to benefit from incentives under the Policy, cloud and data centers must among other considerations demonstrate –

  • deployment, or committed planned deployment, of qualifying infrastructure in Nigeria;
  • registration under the Digital Infrastructure Assurance Registration scheme;
  • participation in the National Digital Marketplace framework, where seeking government business;
  • alignment with national interoperability requirements; and
  • compliance with applicable data protection, cybersecurity, and consumer protection obligations.

Sovereign Data Classification

As noted above, Part III of the Policy is applicable to sovereign data which is categorized into four–

Level Category Data Type Hosting Requirement
4

 

Classified National security, defence and critical infrastructure Hosted exclusively on infrastructure physically located in Nigeria under sovereign control, with processing within Nigeria.
3

 

Highly Sensitive Sensitive personal data, regulated data including financial, biometric, identity and health data. Stored in Nigeria, with continuous sovereign recovery capability; processing in approved environments subject to safeguards.
2 Sensitive Internal government operational data, administrative records, and data that could cause moderate risk if disclosed May be deployed in hybrid environments, including approved international infrastructure, subject to prior authorization.
1 Open Public access data or low risk information with minimal data if disclosed.

 

May be hosted on any compliant infrastructure without residency restriction.

 

Implementation Timeline

The Policy will be implemented in phases with an overall timeline of 24 months from the issuance date.

Next Steps

  1. Cloud providers and data centre operators – Assess eligibility for incentives and the process for registration under the Digital Infrastructure Assurance Registration scheme.
  2. Regulated entities – While the Policy does not impose general data localization requirements, however given that the category of what constitutes “regulated data” is not exhaustive and includes financial, biometric, identity and health data, this data category should be closely monitored where there is the expansion of the data types.
  3. Businesses using cloud services: All commercial data remain unaffected by the sovereignty provisions as the Policy provides regulatory certainty for continued use of international cloud services.

Conclusion

The introduction of the National Digital Cloud Policy is an important shift in Nigeria’s digital infrastructure and data governance landscape. By combining investment incentives, regulatory facilitation, domestic infrastructure development and a risk-based approach to sovereign data, the Policy seeks to strengthen Nigeria’s cloud ecosystem while promoting secure and resilient digital services.

The practical impact of the Policy will depend largely on the development of clear implementation guidelines, the achievement of the key performance indicators set out in the Policy, and the Presidential approval of the sovereignty provisions in Part III.

The Policy presents significant opportunities for investment, innovation and digital transformation. Its success, however, will require sustained collaboration among government and other stakeholders to ensure that Nigeria’s cloud infrastructure develops in a secure and commercially viable manner.

DECODING THE NCC’S DRAFT BUSINESS RULES FOR MOBILE VIRTUAL NETWORK OPERATORS IN NIGERIA

BY SEUN TIMI-KOLEOLU AND HILLARY OKOROTIE

Introduction

The Nigerian Communications Commission (“NCC”) recently published the Draft Business Rules for Mobile Virtual Network Operators in Nigeria (the “Draft Rules”), aimed at establishing a comprehensive regulatory framework for the operation of Mobile Virtual Network Operators (“MVNOs”) in Nigeria. The Draft Rules aim to promote transparency in the relationships between MVNOs, Host Network Operators (“HNOs”), and service delivery. The Draft Rules outline key operational obligations, compliance requirements and standards intended to guide the conduct of MVNOs within the Nigerian telecommunications sector.

In this newsletter, we share insights into the impact of the Draft Rules on the operations of MVNOs.

Onboarding and Integration of MVNOs

The Draft Rules establish a structured onboarding and integration framework aimed at minimizing delays in the negotiation, onboarding, and integration processes between MVNOs and HNOs. Under the Draft Rules, every HNO is required to maintain an approved Reference Onboarding Information Pack containing key information and requirements relevant to prospective MVNO partnerships. Upon receiving a request from a licensed MVNO, the HNO is required to acknowledge receipt within ten days and, within twenty days of receiving the required documentation from the MVNO, confirm its readiness to proceed together with an indicative implementation timeline. Where an HNO declines a hosting request, it is required to provide the MVNO and the NCC with a rationale for the refusal within the same twenty days period.

Furthermore, upon confirmation of readiness to proceed, the parties are required to commence negotiations and establish a joint onboarding working group within ten days to oversee implementation. The Draft Rules also prohibit HNOs from unjustifiably and indefinitely delaying the onboarding process. The Rules further provide that commercial and technical agreements relating to onboarding and integration must be concluded within one hundred and twenty days from the date of the formal hosting request.

Commercial Agreements between MVNOs and HNOs

Under the Draft Rules, parties are required to submit any executed commercial agreement relating to MVNO services to the NCC within fourteen days of execution, or within such timeline as may be prescribed by the NCC. In addition, the Draft Rules also impose ongoing obligation to notify the NCC in respect of amendments to existing agreements. Specifically, where parties make changes relating to pricing, onboarding models, numbering arrangements, interconnection architecture, SIM ownership, eSIM enablement, customer migration or termination rights, the NCC must be notified within thirty days of executing such amendments and prior to the implementation of the changes.

The Draft Rules further require that commercial agreements clearly identify the party responsible for key operational obligations, including Know Your Customer (“KYC”) verification, activation approvals, subscriber complaint management, and other compliance responsibilities relating to eSIM services.

Furthermore, existing commercial agreements between MVNOs and HNOs are required to be reviewed in line with the provisions of the Draft Rules within thirty days from the commencement date of the Draft Rules. This transitional period is intended to ensure that existing MVNO operations and contractual arrangements are aligned with the regulatory requirements introduced by the NCC.

The Dispute Resolution Framework Under the Draft Rules

The Draft Rules also introduce a structured dispute resolution mechanism aimed at preventing prolonged commercial and technical disagreements between MVNOs and HNOs. Under the Draft Rules, every commercial agreement must contain a clearly defined escalation ladder, for example technical disputes affecting onboarding of users or service continuity must first be escalated between designated technical leads within five days, while unresolved commercial disputes are to be escalated to executive representatives within ten days.

Where parties are unable to resolve the dispute, either party may refer the matter to the NCC. Importantly, the Rules prohibit retaliatory measures pending the duration of any dispute such as disruption of the service.

Consumer Protection and Quality of Service Obligations

The Draft Rules prohibit HNOs from unfairly limiting or restricting MVNO network traffic, this is aimed at ensuring fair treatment and quality service delivery for MVNO subscribers operating on host networks.

In addition, MVNOs are required to maintain transparent tariff structures, accessible customer complaint channels and effective dispute resolution mechanisms. The Draft Rules also place primary responsibility for subscriber relationships and customer care obligations on MVNOs, notwithstanding their reliance on HNO infrastructure. In delivering their services, MVNOs are further required to comply with the consumer protection standards and regulatory requirements prescribed by the NCC.

Conclusion

The Draft Rules seek to address some of the challenges that affect MVNO operations, particularly onboarding delays, infrastructure access, commercial uncertainty, disputes over operational responsibilities and other operational aspects of MVNOs. When finalized, these Rules will represent a significant step towards establishing a more structured and transparent framework for MVNO operations in Nigeria.

An aspect of the Draft Rules that can be improved upon is with respect to the regulation of quality of service and traffic management. We recommend that the NCC includes detailed guidelines to monitor the quality of service provided by HNOs and traffic management practices with a view to promoting fair treatment of all MVNOs.

For further details on MVNO licensing framework and the various tiers of MVNO licences, please refer to our previous newsletter.