Posts

ANALYSIS OF NIGERIA’s NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY

By Seun Timi-Koleolu and Olawale Atanda

Download Publication

 

Introduction

In August 2024, the Federal Ministry of Communications, Innovation and Digital Economy released the draft of Nigeria’s first National Artificial Intelligence Strategy (NAIS). The NAIS was co-created by the National Centre for Artificial Intelligence and Robotics (NCAIR) and the National Information Technology Development Agency (NITDA) with support from private bodies.

The unveiling of the NAIS is to position the country to harness AI’s potential responsibly and inclusively. The NAIS vision is clear: to establish Nigeria as a global leader in AI and to foster sustainable development through ethical innovation and collaborative efforts.

In a previous article, we explored the foundational aspects of AI and its legal and regulatory implications in Nigeria. The NAIS takes this a step further by outlining strategic pillars that will drive Nigeria’s AI development and ensure that these technologies are leveraged responsibly and effectively.

In this newsletter, we analyze the main aspects of the NAIS and its importance to the growth of the Nigerian technology ecosystem.

 

  1. Guiding Principles of the NAIS

The NAIS is guided by principles that emphasize responsible and ethical AI development to ensure that AI technologies are designed with societal impact in mind. These principles include, amongst others, a commitment to transparency, accountability, human-centric approaches, inclusivity and shared prosperity.

Another key principle is data ethics and agency. This involves strict adherence to principles of privacy, consent, fairness, and transparency in the collection, use, and sharing of data for AI applications. From a regulatory standpoint, this means enforcing robust privacy* protections and ensuring that individuals have the knowledge and tools to make informed decisions about their data. For businesses, it will mean integrating these ethical standards into their operations to build trust and compliance.

 

  1. Key Strategic Pillars of the NAIS

There are 5 key strategic pillars of the NAIS. These are addressed below.

i. Building Foundational AI Infrastructure

Nigeria’s ambition to lead in AI hinges on developing a solid infrastructure foundation and enhanced computing capacity. This pillar emphasizes investing in AI-specific hardware and software, particularly through domestic solutions to reduce reliance on foreign technology.

Additionally, the NAIS highlights the establishment of clean energy-powered AI clusters and offers tax breaks and incentives to encourage private sector investment in critical AI infrastructure, such as high-performance computing centers. These efforts aim to accelerate innovation, create jobs, and position Nigeria as a competitive player in the global AI arena.

ii. Building and Sustaining a World-Class AI Ecosystem

To achieve global leadership in AI, Nigeria aims to develop a robust and dynamic ecosystem of partners, academia, and a highly skilled workforce. This pillar focuses on fostering sustainable AI partnerships, championing international collaborations, and nurturing a culture of innovation.

Initiatives include the creation of platforms such as the Sustainable Applied AI Partnership Platform (SAAPP) to bring together diverse stakeholders for AI development, and the AI Synergy Alliance to facilitate global partnerships. Similarly, the NAIS aims to establish Deep Tech AI Accelerators and AI Centers of Excellence to drive innovation and commercialize AI solutions.

 iii. Accelerating AI Adoption and Sector Transformation

This pillar seeks to harness AI for real-world impact by driving widespread adoption across various sectors, transforming industries, and promoting economic growth in Nigeria. This pillar emphasizes locally-led AI innovation, data-driven decision-making, and the development of an AI-ready workforce. Key strategies here include launching sector-specific AI adoption roadmaps, implementing global data quality standards, and creating a National AI Research and Development Fund to support cutting-edge research. The pillar also focuses on ensuring AI contributes to environmental well-being through green and sustainable AI initiatives, such as establishing a Green AI Challenge and Grant Programme to foster AI solutions for climate change, resource management, and smart city development.

The 3 Million Technical Talent (3MTT) Programme by the Federal Ministry of Communications, Innovation & Digital Economy aligns with these efforts by focusing on building Nigeria’s future digital workforce. This program, which aims to train millions of Nigerians in tech and AI skills, complements the NAIS goal of building a skilled AI workforce and accelerating AI adoption across sectors.

iv. Ensuring Responsible and Ethical AI Development

Pillar 4 focuses on the need for Nigeria to develop and adopt AI within a responsible and ethical framework while recognizing the transformative power of AI and the inherent risks it poses. A key objective under this pillar is the establishment of a robust AI ethics framework. This involves creating a diverse AI Ethics Expert Group (AIEEG) to guide the development and implementation of ethical AI principles that align with Nigerian values. The framework will focus on fairness, transparency, accountability, privacy, and human well-being, supported by a comprehensive AI ethics assessment tool that evaluates the ethical implications of AI projects throughout their lifecycle.

Another critical objective is shaping a human-centered AI transition, which aims to anticipate and mitigate the societal disruptions AI might cause, such as job displacement and increased inequality. This will involve conducting foresight studies to map out potential challenges and opportunities, as well as implementing legislative reforms to adapt legal frameworks to the evolving nature of AI. These reforms will focus on protecting human rights, privacy, and ensuring equitable access to technology through initiatives like digital literacy programs and community technology hubs.

v. Developing a Robust AI Governance Framework

Pillar 5 emphasizes the need for clear and consistent governance principles to ensure the responsible and successful development of AI in Nigeria. A primary objective is to create well-defined National AI Principles that will guide aspects of AI development, deployment, and usage. Also, it will state Nigeria’s core values and for AI development, including the achievement of the Sustainable Development Goals (SDGs) through AI.

The pillar aims to establish an independent AI Governance Regulatory Body responsible for enforcing ethical standards, providing clear guidance, and mediating disputes related to AI. The pillar also includes the development of a National AI Policy Framework to outline governance guidelines and a National AI Risk Management Framework to identify, assess, and mitigate potential safety and security risks associated with AI systems.

 

Conclusion

This ambitious roadmap outlines a comprehensive vision for AI development across five key pillars –  each addressing critical areas essential for building a robust AI ecosystem. However, while the NAIS is thorough in its scope, it currently lacks an implementation framework detailing key timelines, milestones, and monitoring mechanisms. Also, the NAIS does not yet clarify the funding sources for the various projects it proposes. As this is still a draft, it is anticipated that these gaps will be addressed in the final version of the NAIS to ensure a more complete and actionable plan for Nigeria’s AI future.

 

Download the NAIS document here – https://ncair.nitda.gov.ng/wp-content/uploads/2024/08/National-AI-Strategy_01082024-copy.pdf

 

*For more on privacy and data protection, please see our articles on these here:

1.https://pavestoneslegal.com/tag/data-protection/

2.https://pavestoneslegal.com/tag/data-privacy/

 

 

 

THE REGULATION OF TECHNOLOGY COMPANIES IN NIGERIA – THE PROPOSED NITDA ACT 2021

DOWNLOAD PUBLICATION

By Seun Timi-Koleolu and Eustace Aroh

The National Information Technology Development Agency (NITDA) was created under the NITDA Act 2007 (the “Act”) to implement the Nigerian Information Technology Policy and coordinate general Information Technology development in Nigeria. NITDA, however, recently shared a proposed law with stakeholders titled the National Information Technology Development Agency Act 2021 (the “Bill”) which if enacted would repeal and replace the Act.

In addition to repealing the Act, the bill seeks to establish a framework for mandatory licenses to be obtained by Technology companies from NITDA; expand the regulatory oversight of NITDA; and generally, foster the development of the Nigerian information technology sector and the digital economy. In this article, we have analysed the provisions of the Bill.

  1. Companies to be Regulated

The Bill grants power to NITDA to regulate and license companies involved in digital services, products and platforms. This includes companies that use any digitally enabled system in the provision of service or products; and companies that carry out a business within the information technology space in Nigeria.

  1. Licensing and Registration Requirement

One of the major changes proposed under the Bill is the introduction of mandatory licenses to be obtained by companies regulated by it.  More specifically, it states that operators within the information technology and digital economy sector are to apply and obtain licences and authorisation from NITDA to operate. Furthermore, it provides that companies that fail to obtain the requisite license may be guilty of an offence and subject to a fine of N30,000,000 or imprisonment of its principal officers.

The Bill seeks to create three categories of licenses namely: (i) Product Licence, (ii) Service Provider Licence; and (iii) Platform Provider Licence. The Bill, however, does not clearly state the factors that would be considered by NITDA in determining which of the licenses a company is to obtain.

In addition to issuing licences,  the Bill empowers NITDA to maintain a register of operators within the information technology and digital economy sector and publish the register for the general public’s information.

  1. Tech Companies to be Levied

Similar to the Act, the Bill establishes the National Information Technology Development Fund (NITDF) to be used for advancing the nation’s digital economy objectives and related purposes. The NITDF will be funded by a levy of 1% of the profit before tax of regulated companies, amongst other funding sources set out in the Bill.

It is pertinent to note, that the existing Act already requires certain companies to pay a similar levy to NITDA which was however limited. The Bill now seeks to extend the list of the companies required to pay levies as follows:

i.mobile and fixed telecommunications companies;

ii.information technology, e-commerce companies; (new)

iii.digital platform operators and providers; (new)

iv.foreign digital platforms targeting the Nigerian market; (new)

v.pensions managers and pension-related companies;

vi.banks, financial institutions and companies providing financial services using information technology tools;

vii.insurance companies; and

viii.such other companies and enterprises as determined by regulations from time to time by the Agency. (new)

  1. Other Notable Changes

The Bill seeks to empower the NITDA, with support from the Standard Organisation of Nigeria, to develop standard requirements for operators within the information technology space. The Bill also confers a duty on NITDA to regulate amongst other things, the use of digital signature and digital contracts; and the use of data for business analytics and intelligence.

Conclusion

An Act that seeks to uniformly and fairly regulate the technology sector and startup space in Nigeria would be a welcome development. The Bill appears to be an attempt at achieving this uniformity. This, however, cannot be achieved by NITDA in silos. The effect of a standalone regulation like the Bill is that companies in the tech space in Nigeria would be over-regulated and weighed down with excessive levies and licensing requirements.

To successfully regulate the Tech space, NITDA must work with other regulators such as the Central Bank of Nigeria, the Securities and Exchange Commission, the Nigerian Communications Commission, and the National Insurance Commission to streamline licences, levies and develop regulations that adequately govern the activities of Tech companies without stifling their growth.

In addition to the foregoing, there are certain ambiguous terms in the Bill that should be clarified which includes terms like “operators within the information technology and digital economy”, “foreign digital platforms targeting the Nigerian market” and “digital economy”. Furthermore, the licensing categories to be established by the Bill should be clarified to ensure companies are clear on the licence they are to obtain.

SETTING UP A FINTECH COMPANY IN NIGERIA

By Seun Timi-Koleolu and Eustace Aroh

DOWNLOAD PUBLICATION

Introduction

With the rapid growth of technology, Start-ups have continually found ways to improve financial services. This trend has been matched by the growing appetite of consumers globally, for faster and more convenient financial services. The financial sector in Nigeria has witnessed a growth in FinTechs with their revenue expected to reach $543m in 2022.

In this article, we have set out below the process of setting up a fintech company in Nigeria.

1. Licences
For promoters seeking to set up a FinTech, it is generally advised that they understand the existing regulatory space before proceeding to incorporate the business. This will help promoters to understand the acceptable organisational structure, share capital requirements and financial implications attached to any business they seek to engage in.

Fintechs in Nigeria are generally categorized and regulated as follows:

Fintech categories Regulators
i Payment service providers, mobile money operators, digital bank, switch companies Central Bank of Nigeria (CBN)
ii Lending CBN; State Ministry of Home Affairs
iii Savings, investment and funding CBN; Securities and Exchange Commission (SEC)
iv Cryptocurrency CBN; SEC
v Insurtech National Insurance Commission

Notwithstanding the above, some regulators cut across all sectors due to their general regulatory function such as the National Communications Commission (NCC) (for FinTechs providing value added services) and the National Information Technology Development Agency (NITDA) (for users of data, amongst other things).

2. Incorporation
Once there is a clear understanding of the regulatory terrain, the next step is to incorporate the company for the FinTech service. Although the minimum share capital for incorporating a private company in Nigeria is 100,000 naira, the share capital requirement for FinTechs usually exceeds this amount. Promoters must consult the regulators and relevant laws (via their legal advisers) to determine the adequate minimum share capital and shareholding requirement for their FinTech.

There are also capital deposits required by relevant regulators such as CBN for setting up FinTechs, to find out more, click here.

3. Documentation
Upon incorporation, it is pertinent for the founders to ensure that all relevant contracts are in place to properly protect the business. The founders are generally advised to execute the following: a Founders’ Agreement (to regulate the relationship of the founders of the business); a Shareholders’ Agreement (to regulate the relationship between all shareholders including present and future shareholders); Loan Agreements (to evidence and detail all capital injections including investments by founders and friends into the business); and Employee Stock Option (granting an option of share purchase to key employees).

4. Protecting the Intellectual Property

Founders of FinTechs are advised to ensure that intellectual property developed in the cause of the business are protected. It is important that the company’s logos are registered as trademarks at the Trademark Registry; and the software and codes are registered at the National Copyright Commission or Patent Registry (if it qualifies). Although software and codes are automatically copyrighted under Nigerian law, it is useful to carry out the registration of the software at the relevant registry.

It is pertinent to note that intellectual property rights automatically vests in the developer (which could be employees or contractors of the company) under Nigerian law. To ensure that the rights vest in the company/founder, it is advisable that the FinTech enters into an agreement with the developer assigning rights in the software to the company/FinTech either through an employment contract or a Copyright Agreement.

5. Financing

Founders may choose to first source for funds from family and friends, after which they may need to progress to venture capital and other institution.

The CBN and the SEC recently launched programs to aid FinTechs in test running their software under-regulated spaces. Click here to find out more about these programs.

Conclusion
With the population of unbanked Nigerians currently calculated at above 50% of the adult population, there are great growth opportunities in the FinTech ecosystem. It is, however, recommended that professional advice is obtained by emerging and existing FinTech founders from the inception of the FinTech, to properly guide the business.

 

 

DATA PROTECTION IN NIGERIA: DISTINGUISHING BETWEEN A DATA CONTROLLER AND A DATA PROCESSOR

By Seun Timi-Koleolu and Praise Adetunmibi

 

DOWNLOAD PUBLICATION

Introduction

In this digital age, data has become a vital asset for both individuals and corporate bodies. It has in fact been regarded as the world’s most valuable resource[1]. The question then is, what is data?

Data can simply be defined as information that has been translated into a form that is efficient for movement or processing[2]. It can be collected, used, shared, measured, analysed, stored and destroyed (data processing). The most common type of data is personal data, which refers to any information related to an identified or identifiable natural person. In Nigeria, the National Information Technology Development Agency (NITDA) through the Nigeria Data Protection Regulation (NDPR)[3], regulates the processing of personal data of Nigerian citizens. Persons who engage in data processing activities can either be Data Controllers or Data Processors.

Under the NDPR, startups, businesses and companies that engage in the processing of personal data of over 1000 Nigerians, are mandated to conduct a detailed annual audit of their data processing activities. This audit is to be conducted by a licensed Data Protection Compliance Organisation (DPCO). Failure to comply with the provisions of the NDPR will result in the payment of a fine of 10 million Naira or 2% of the annual turnover (whichever is greater).

In view of the foregoing, it is useful to understand when you will be considered as a data processor and when you will be considered to be a data controller; for the purpose of complying with the provisions of the NDPR. In this article, we have provided a guide on how to identify each category.

Who is a data controller?

A data controller simply means any person or company that determines “why” data is to be processed and “how” data is to be processed. Most businesses/companies collect the personal data of clients/customers in the course of providing services to them (e.g. by requiring the customers to complete an online or physical, registration form for the service or for the purpose of payment); in all such instances that company/business is a data controller.

Furthermore, where companies/businesses share personal details of their customers, such as names, email addresses, phone numbers to third-party service providers, for various business purposes such as to market their products  (e.g. sharing with a Digital Marketing Agency); or to enhance their service delivery (e.g. sharing with an Information Technology Partner), that company/business remains the data controller in those instances and primarily responsible for the use and protection of the data.

In addition, companies and business owners are data controllers of data they collect in respect of their employees and remain primarily responsible for the use of such data.

Who is a data processor?

Companies/businesses are regarded as data processors when they are involved in the processing of data, on the instruction and on behalf of another person (data controller). Effectively, a data processor cannot act on its own or undertake any data processing activity without the permission of the data controller.

In the scenarios given above, the Digital Marketing Agency and Information Technology Partner are data processors. Also, where a company outsources payroll payment to a third party or other human resource related services, that third party would be seen as the data processor.

Can a data processor be a data controller?

Yes. What distinguishes a data controller from a data processor is control. Where you have control over which data is to be collected and the purpose for which the data is to be collected, you are the data controller. Where all you have is the possession of the data and must act in accordance with the instructions of another person, then you are the data processor.

Where you, however, have both control and possession of data (i.e. the data was given to you by a third party), in such an instance, you act as both a data controller and a data processor.

Conclusion

Under Nigerian law, data controllers and data processors are required to undergo Data Protection Compliance audits and generally adhere to the provisions of the NDPR. Each business should be clear on whether they are handling data in the capacity of a data controller or a data processor as the obligations of a data controller vary from the obligations of a data processor.

If you require clarity as to whether your business would be categorised as a data controller or a data processor, please do not hesitate to contact the team at Pavestones Legal.

[1] The Economist, ‘The World’s Most Valuable Resource is no Longer Oil, but Data’   Economist (6 May 2017) <https://www.economist.com/leaders/2017/05/06/the-worlds-most-valuable-resource-is-no-longer-oil-but-data>

[2] https://searchdatamanagement.techtarget.com/definition/data

[3] To understand more about the NDPR, follow the link to our article https://pavestoneslegal.com/nigeria-data-protection-regulation-2019/