Posts

NIGERIA’S NATIONAL DIGITAL CLOUD POLICY: WHAT BUSINESSES NEED TO KNOW

BY ADERONKE ALEX-ADEDIPE & ENIOLA SOGBESAN

Introduction

On 17 August 2026, the Federal Government of Nigeria introduced the National Digital Cloud Policy (the “Policy”), replacing the Nigeria Cloud Computing Policy 2019. The Policy is effective immediately, save for the sovereignty provisions contained in Part III, which remain subject to Presidential approval.

The Policy represents a significant evolution in Nigeria’s approach to cloud computing. While the 2019 policy primarily focused on encouraging the adoption and use of cloud technology, the Policy supports the deliberate development of a domestic cloud and data infrastructure ecosystem in Nigeria.

Among other objectives, the Policy seeks to –

  1. attract investment in cloud and data infrastructure;
  2. develop Nigeria as a regional digital services exporter;
  3. expand and diversify domestic capacity;
  4. modernize government service delivery and
  5. secure government and regulated data proportionately.

In this newsletter, we examine the key provisions of the Policy and consider their practical implications for cloud service providers, data centre operators, regulated entities and businesses that use cloud services in Nigeria.

Scope and Application

The Policy establishes a tiered framework which can be broadly understood across three distinct categories:

  1. General Market Framework: Parts I and IV of the Policy establish the overarching framework applicable to participants in Nigeria’s cloud market. These provisions address matters such as investment, trade, market development and the implementation of the Policy.
  2. Public Sector: Part II of the Policy is applicable to Federal Ministries, Departments, Agencies and entities exercising public functions on their behalf. State Governments, the Federal Capital Territory, and Local Governments may participate voluntarily under the Policy.
  3. Sovereign Data: Part III of the Policy is specifically applicable to sovereign data. Sovereign Data in the Policy refers to-
    i. data generated by the Federal Government, its MDAs, or by entities performing public functions on their behalf; and
    ii. data generated pursuant to a Federal regulation, license, or directives issued by the Federal Government and such data must be expressly designated as sovereign.

Key Policy Incentives

  1. Investment Incentives
    Qualifying Investment may benefit from a range of incentives such as –

    • import duty exemptions, waivers, or concessions on data centre equipment and
    • access to priority status and equivalent tax incentives for qualifying strategic digital infrastructure projects.
  2. Regulatory Facilitation and Investment Certainty
    The Policy recognizes regulatory friction as a material deterrent to infrastructure investment. Accordingly, the Federal Government will among others–

    • coordinate investment promotion to eliminate duplicative approval requirements and reduce administrative delay;
    • establish a single coordinated facilitation point for qualifying cloud and data centre investments; and
    • publish the licensing, compliance, and operational requirements applicable to cloud and data infrastructure investments.
  3. Capital Mobility and Foreign Exchange Incentives
    To ensure the effective realization and repatriation of investments, the Policy ensures the following:

    • lawful repatriation of capital, profits, and dividends in accordance with applicable investment and foreign exchange regulations;
    • prompt issuance of certificates for qualifying investments to secure repatriation rights; and
    • all earnings from cloud and data services provided to customers outside Nigeria will be treated as export earnings eligible for foreign exchange and export incentives.
  4. Energy Access
    The Policy provides a framework to support cloud and data centers in accessing reliable electricity, including opportunities to utilize renewable and alternative energy solutions.Importantly, the beneficiaries of these incentives are required to commit to capability development programmes, including knowledge transfer and skills development to Nigerians.

Eligibility and Qualification

To be eligible to benefit from incentives under the Policy, cloud and data centers must among other considerations demonstrate –

  • deployment, or committed planned deployment, of qualifying infrastructure in Nigeria;
  • registration under the Digital Infrastructure Assurance Registration scheme;
  • participation in the National Digital Marketplace framework, where seeking government business;
  • alignment with national interoperability requirements; and
  • compliance with applicable data protection, cybersecurity, and consumer protection obligations.

Sovereign Data Classification

As noted above, Part III of the Policy is applicable to sovereign data which is categorized into four–

Level Category Data Type Hosting Requirement
4

 

Classified National security, defence and critical infrastructure Hosted exclusively on infrastructure physically located in Nigeria under sovereign control, with processing within Nigeria.
3

 

Highly Sensitive Sensitive personal data, regulated data including financial, biometric, identity and health data. Stored in Nigeria, with continuous sovereign recovery capability; processing in approved environments subject to safeguards.
2 Sensitive Internal government operational data, administrative records, and data that could cause moderate risk if disclosed May be deployed in hybrid environments, including approved international infrastructure, subject to prior authorization.
1 Open Public access data or low risk information with minimal data if disclosed.

 

May be hosted on any compliant infrastructure without residency restriction.

 

Implementation Timeline

The Policy will be implemented in phases with an overall timeline of 24 months from the issuance date.

Next Steps

  1. Cloud providers and data centre operators – Assess eligibility for incentives and the process for registration under the Digital Infrastructure Assurance Registration scheme.
  2. Regulated entities – While the Policy does not impose general data localization requirements, however given that the category of what constitutes “regulated data” is not exhaustive and includes financial, biometric, identity and health data, this data category should be closely monitored where there is the expansion of the data types.
  3. Businesses using cloud services: All commercial data remain unaffected by the sovereignty provisions as the Policy provides regulatory certainty for continued use of international cloud services.

Conclusion

The introduction of the National Digital Cloud Policy is an important shift in Nigeria’s digital infrastructure and data governance landscape. By combining investment incentives, regulatory facilitation, domestic infrastructure development and a risk-based approach to sovereign data, the Policy seeks to strengthen Nigeria’s cloud ecosystem while promoting secure and resilient digital services.

The practical impact of the Policy will depend largely on the development of clear implementation guidelines, the achievement of the key performance indicators set out in the Policy, and the Presidential approval of the sovereignty provisions in Part III.

The Policy presents significant opportunities for investment, innovation and digital transformation. Its success, however, will require sustained collaboration among government and other stakeholders to ensure that Nigeria’s cloud infrastructure develops in a secure and commercially viable manner.

AI REGULATION IN THE EU AND NIGERIA: AI WATERMARKING

BY SEUN TIMI-KOLEOLU & OLUWAYEMI IBIRINDE

INTRODUCTION

On 2 August 2026, the transparency obligations under the European Union Artificial Intelligence Act (the “EU AI Act”) became applicable. These include requirements under Article 50 for certain AI-generated or manipulated content to be identifiable through machine-readable markings and, in specified circumstances, disclosed to users.

The effect of these developments’ cuts across global AI use and will also have implications for Nigerian businesses, particularly those using AI services provided by global technology companies or operating across borders. This is underscored by the participation of about 190 organisations, including major AI providers such as Anthropic, Google, Meta, Microsoft, Mistral and OpenAI, in the European Commission’s Code of Practice on Transparency of AI-Generated Content.

We therefore consider it important to highlight this development and its implication for Nigerian businesses, while examining Nigeria’s existing regulatory framework for AI use and the need for a more comprehensive AI governance framework.

WHAT ARE THE EFFECTS OF THE EU AI WATERMARKING REQUIREMENT?

The introduction of AI-generated content marking and disclosure requirements has several implications for businesses as follows:

  1. Cross-border Application: The EU AI Act applies to any AI tool or output used in the European Union, even for companies operating from outside the EU. Accordingly, Nigerian companies providing AI services or outputs for use in the EU may be subject to applicable transparency requirements, including the requirement to watermark AI-generated content.
  2. Dilution of Original Ownership: Users both inside and outside the EU using AI tools need to be aware that once original human ideas are fed into an AI system, the resulting output gets watermarked and may make it difficult for the creator to prove ownership of their underlying intellectual property or demonstrate that the core work was human authored
  3. Consumer protection and fraud prevention: It is expected that, with the use of AI watermarks, AI-generated content will be more readily identifiable, and therefore support the identification of deepfakes, impersonation, fraudulent content, and other forms of deception.

HOW IS AI REGULATED IN NIGERIA

Nigeria has no single comprehensive AI statute like the EU AI Act. AI-related obligations instead sit within existing laws and other AI governance structures as follows:

  1. Nigeria Data Protection Act (NDPA) Data protection:
    The key regulation in Nigeria governing the use of AI is the Nigeria Data Protection Act, 2023 (NDPA). While Nigeria has no comprehensive AI-specific law comparable to the EU AI Act, the NDPA regulates AI use where personal data is involved. This is particularly important where businesses use foreign AI providers, as these services may involve the processing or transfer of personal data outside Nigeria. Businesses should therefore assess their AI tools for compliance with the NDPA and applicable cross-border data protection requirements.It also clearly restricts and places safeguards around decisions made solely through automated processing where such decisions may have legal or similarly significant effects on individuals, reinforcing the need for appropriate human oversight and transparency.
  2. Federal Competition and Consumer Protection Act (FCCPA)
    Another regulation relevant to the use of AI in Nigeria is the Federal Competition and Consumer Protection Act, 2018 (FCCPA). The FCCPA sets clear consumer protection requirements that apply to AI-driven marketing, pricing, and other consumer-facing activities. It prohibits false, misleading, or deceptive representations and unfair contract terms. AI-generated content, recommendations and decisions must comply with these consumer protection standards.
  3. SEC Rules on Robo-Advisory Services
    Similarly, the SEC Rules on Robo-Advisory Services regulate the use of automated, algorithm-based tools to provide investment advice. The Rules require robo-advisers to identify and mitigate algorithmic bias and clearly disclose to clients how the technology works, including its assumptions, limitations and associated risks. Therefore, where AI is used to provide investment advice, compliance with these requirements is mandatory.
  4. Copyright Act, 2022
    The Copyright Act, 2022 protects original works created by human authors but does not expressly address AI-generated works or determine authorship where content is created by AI. Businesses using AI-generated content should therefore consider copyright ownership and infringement risks, particularly where AI tools generate or reproduce existing protected works.
  5. The National Artificial Intelligence Strategy
    The National Artificial Intelligence Strategy (NAIS) provides the policy foundation for responsible, ethical and inclusive AI adoption in Nigeria. While it does not create binding AI-specific obligations in the same manner as the EU AI Act, it provides a framework for the development of Nigeria’s AI governance and regulatory approach.
  6. The National Digital Economy and E-Governance Bill, 2025
    The National Digital Economy and E-Governance Bill, 2025, which is not yet law, proposes a more comprehensive framework for AI governance in Nigeria. It includes provisions on AI risk classification, monitoring of AI-related risks, accreditation of independent AI system auditors, inspections, audits and enforcement. If enacted, the Bill could significantly strengthen Nigeria’s regulatory framework for AI and move the country closer to a dedicated AI governance regime.Taken together, these instruments demonstrate that Nigeria currently regulates aspects of AI use through existing laws and emerging policy frameworks but does not yet have specific requirements for AI watermarking comparable to those under the EU AI Act.

CONCLUSION

The transparency requirements under the EU AI Act marks a significant shift towards more accountable and traceable AI use, with implications extending beyond the EU as global AI providers adapt their products and compliance practices to emerging regulatory standards. While Nigeria already has several laws and policy instruments that regulate aspects of AI use, it would benefit from a comprehensive AI governance framework that brings these obligations together, provides greater regulatory certainty and addresses AI-specific risks.

As the regulatory landscape evolves, it is important for businesses to take a proactive approach to AI compliance by applying appropriate human oversight and seeking professional advice when adopting or deploying AI technologies.

DECODING THE NCC’S DRAFT BUSINESS RULES FOR MOBILE VIRTUAL NETWORK OPERATORS IN NIGERIA

BY SEUN TIMI-KOLEOLU AND HILLARY OKOROTIE

Introduction

The Nigerian Communications Commission (“NCC”) recently published the Draft Business Rules for Mobile Virtual Network Operators in Nigeria (the “Draft Rules”), aimed at establishing a comprehensive regulatory framework for the operation of Mobile Virtual Network Operators (“MVNOs”) in Nigeria. The Draft Rules aim to promote transparency in the relationships between MVNOs, Host Network Operators (“HNOs”), and service delivery. The Draft Rules outline key operational obligations, compliance requirements and standards intended to guide the conduct of MVNOs within the Nigerian telecommunications sector.

In this newsletter, we share insights into the impact of the Draft Rules on the operations of MVNOs.

Onboarding and Integration of MVNOs

The Draft Rules establish a structured onboarding and integration framework aimed at minimizing delays in the negotiation, onboarding, and integration processes between MVNOs and HNOs. Under the Draft Rules, every HNO is required to maintain an approved Reference Onboarding Information Pack containing key information and requirements relevant to prospective MVNO partnerships. Upon receiving a request from a licensed MVNO, the HNO is required to acknowledge receipt within ten days and, within twenty days of receiving the required documentation from the MVNO, confirm its readiness to proceed together with an indicative implementation timeline. Where an HNO declines a hosting request, it is required to provide the MVNO and the NCC with a rationale for the refusal within the same twenty days period.

Furthermore, upon confirmation of readiness to proceed, the parties are required to commence negotiations and establish a joint onboarding working group within ten days to oversee implementation. The Draft Rules also prohibit HNOs from unjustifiably and indefinitely delaying the onboarding process. The Rules further provide that commercial and technical agreements relating to onboarding and integration must be concluded within one hundred and twenty days from the date of the formal hosting request.

Commercial Agreements between MVNOs and HNOs

Under the Draft Rules, parties are required to submit any executed commercial agreement relating to MVNO services to the NCC within fourteen days of execution, or within such timeline as may be prescribed by the NCC. In addition, the Draft Rules also impose ongoing obligation to notify the NCC in respect of amendments to existing agreements. Specifically, where parties make changes relating to pricing, onboarding models, numbering arrangements, interconnection architecture, SIM ownership, eSIM enablement, customer migration or termination rights, the NCC must be notified within thirty days of executing such amendments and prior to the implementation of the changes.

The Draft Rules further require that commercial agreements clearly identify the party responsible for key operational obligations, including Know Your Customer (“KYC”) verification, activation approvals, subscriber complaint management, and other compliance responsibilities relating to eSIM services.

Furthermore, existing commercial agreements between MVNOs and HNOs are required to be reviewed in line with the provisions of the Draft Rules within thirty days from the commencement date of the Draft Rules. This transitional period is intended to ensure that existing MVNO operations and contractual arrangements are aligned with the regulatory requirements introduced by the NCC.

The Dispute Resolution Framework Under the Draft Rules

The Draft Rules also introduce a structured dispute resolution mechanism aimed at preventing prolonged commercial and technical disagreements between MVNOs and HNOs. Under the Draft Rules, every commercial agreement must contain a clearly defined escalation ladder, for example technical disputes affecting onboarding of users or service continuity must first be escalated between designated technical leads within five days, while unresolved commercial disputes are to be escalated to executive representatives within ten days.

Where parties are unable to resolve the dispute, either party may refer the matter to the NCC. Importantly, the Rules prohibit retaliatory measures pending the duration of any dispute such as disruption of the service.

Consumer Protection and Quality of Service Obligations

The Draft Rules prohibit HNOs from unfairly limiting or restricting MVNO network traffic, this is aimed at ensuring fair treatment and quality service delivery for MVNO subscribers operating on host networks.

In addition, MVNOs are required to maintain transparent tariff structures, accessible customer complaint channels and effective dispute resolution mechanisms. The Draft Rules also place primary responsibility for subscriber relationships and customer care obligations on MVNOs, notwithstanding their reliance on HNO infrastructure. In delivering their services, MVNOs are further required to comply with the consumer protection standards and regulatory requirements prescribed by the NCC.

Conclusion

The Draft Rules seek to address some of the challenges that affect MVNO operations, particularly onboarding delays, infrastructure access, commercial uncertainty, disputes over operational responsibilities and other operational aspects of MVNOs. When finalized, these Rules will represent a significant step towards establishing a more structured and transparent framework for MVNO operations in Nigeria.

An aspect of the Draft Rules that can be improved upon is with respect to the regulation of quality of service and traffic management. We recommend that the NCC includes detailed guidelines to monitor the quality of service provided by HNOs and traffic management practices with a view to promoting fair treatment of all MVNOs.

For further details on MVNO licensing framework and the various tiers of MVNO licences, please refer to our previous newsletter.

PROTECTING INNOVATION IN NIGERIAN TECH CONTRACTS: COMMON PITFALLS AND SOLUTIONS

BY ADERONKE ALEX-ADEDIPE AND ENIOLA SOGBESAN

Introduction

In the current global digital economy, businesses enjoy significant competitive advantage from intangible assets such as intellectual property, confidential data and proprietary processes. In Nigeria, given that many businesses rely heavily on innovation and technology services, effective intellectual property is critical to long-term enterprise value and commercial sustainability.

In Nigeria, the intellectual property terrain is regulated by the provisions of the Copyright Act, Trademarks Act & Patents and Designs Act. However, while the provisions of these laws are robust, they do not sufficiently prevent disputes between parties. In practice, the allocation, licensing, transfer and enforcement of intellectual property rights are determined by the terms of contract. Notwithstanding, most intellectual property disputes usually arise because IP clauses are wrongly drafted, silent on risk allocation and misaligned with commercial objectives.

In this article, we examine the importance of IP clauses in technology agreements, identify loopholes that may give rise to disputes and proffer strategies for mitigating risks with regard to Nigerian and cross-border transactions.

The Role of IP Clauses in Tech Agreements

IP clauses are essential features of a modern technology agreement. They help determine who owns these intangible assets, the terms on which they may be used and any applicable restrictions. IP clauses are critical in agreements such as licensing and distribution agreements, joint ventures & mergers and acquisitions. In granting any IP rights under any of these agreements, parties should ensure that the IP clauses are detailed enough to protect the interest of the grantor while specifying whether the rights are granted on an exclusive or non-exclusive basis.

Common IP Clause Dispute Triggers

  1. Unclear ownership provisions – Uncertainty and lack of clarity on IP ownership in technology contracts is the basis of most IP clause disputes. This ambiguity becomes visible when there is a breakdown in the business relationship between the parties or there is an increase in the value of the asset. Where IP ownership provisions are not clearly drafted, it gives room for statutory and judicial interpretation.

    For example, under the Nigerian Copyright Act 2022, copyright is vested in the author of a work subject to certain exceptions including employment relationships and commissioned works. This therefore suggests that in the absence of clear assignment of the IP in such works, the author may retain ownership of the software or creative materials produced for a client.

  2. Inadequate licensing terms – Similarly, poorly drafted licensing terms can also give rise to IP-related disputes, particularly because IP licensing determines the extent of the economic value that can be derived from an intellectual property asset. Where there is ambiguity regarding the scope, duration, territory, or exclusivity of a license, such uncertainty may lead to overreach, misuse, or infringement disputes.

    At a minimum, licensing terms should highlight the scope, territorial limits, sublicensing rights (if applicable) and post-termination rights and obligations. Any failure to clearly define these terms, may enable a licensee to assume broader commercial rights than was intended, while the licensor may restrict its ability to explore the IP in other jurisdictions.

  3. Confidentiality Breaches– Trade secrets which constitute an IP asset class protects commercially valuable information. These are not registered but merely derive their value from its confidential nature, therefore confidentiality clauses are an essential protective mechanism in technology agreements. Important elements that should be included in a confidentiality clause include; definition of what constitutes confidential information, duration of the confidentiality obligations, exceptions and remedies in case of a breach.
  4. Inadequate Enforcement Provisions – While parties do not intend to engage in IP disputes at the onset of the business relationship, a well drafted IP clause should anticipate this possibility. In many technology agreements, the failure to specify the obligations of each party in relation to the ownership and use of the IP results in inconsistent enforcement strategies and disputes between the contracting parties themselves.

    This inadequacy extends to creating uncertainty as to who bears responsibility for monitoring infringement and initiating legal action. Without this clarity, enforcement actions against infringers may be protracted and weaken the commercial value of the IP.

  5. Post Termination Obligations – While IP disputes arise at the end of contractual relationships, the termination of a contract does not automatically extinguish all IP rights unless otherwise provided. In the absence of clearly defined post termination obligations, former licensees may continue using such IP assets thereby exposing both parties to legal and commercial risks. A well drafted post termination clause should address reversion rights, return or destruction of materials and any other ongoing license restrictions.

Practical Fixes & Risk Mitigation Strategies.

  1. Precise definitions and clear ownership of IP assets should be set out in the agreement.
  1. Legal due diligence and contract audits should be undertaken prior to executing the contract as it will help identify and mitigate potential risk factors associated with the IP asset.
  1. There should be a periodic review of the contract and update of IP clauses as the underlying technology evolves.
  1. To provide an additional layer of security, all IP assignments should be executed and properly registered with the relevant government agencies.

Conclusion

IP clauses are designed to protect the value of the underlying IP asset and provide commercial value to the holder. However, where they are ambiguous or misaligned with operational and commercial objectives, they become sources of disputes. Moreover, in a global economy which is increasingly driven by innovation and creativity, effective IP drafting, especially in technology agreements, is a core requirement that should consider the applicable legal framework, transaction structure and the commercial objectives of the parties.

Therefore, businesses and practitioners should engage IP contractual frameworks with the perspective of risk management and value protection which will further strengthen the value and commercial returns on the underlying IP asset.

REGULATORY UPDATE: NDPC EXTENDS DATA AUDIT FILING DEADLINE

By Seun Timi-Koleolu and Omodele Fatodu

The Nigeria Data Protection Commission (“NDPC”) has announced an extension of the deadline for the filing of the 2025 Data Protection Compliance Audit Returns (“CAR”) from March 31 to May 30, 2026. Data Processors and Controllers of Major Importance (“DPCMIs”) are therefore encouraged to utilise this period to ensure that their data protection frameworks are aligned with regulatory expectations and to file their Compliance Audit Returns within the extended timeline.

DPCMIs should note that failure to file within the prescribed timeline will attract regulatory sanctions. In particular, late filing of the CAR is subject to a penalty of 50% of the applicable filing fee, in addition to the risk of further regulatory scrutiny or enforcement action by the NDPC.

  1.  Practical Steps During the Extension Period

To make effective use of the extended timeline, DPCMIs should consider the following:

  1. Data Mapping: Ensure that all personal data processing activities are clearly identified and documented, including the nature of data collected, purposes of processing, storage locations, and third-party disclosures.
  2. Policy Review: Review privacy policies and internal data protection procedures to confirm that they are up to date and aligned with regulatory requirements and actual data processing practices.
  3. Remediation of Prior Findings: Ensure that any identified gaps or recommendations from prior audits have been appropriately addressed and implemented.
  4. Engage a licensed Data Protection Compliance Organisation (DPCO): A licensed DPCO can conduct the data protection compliance audit and file the CAR on behalf of the organisation, helping to ensure that the audit meets NDPC expectations.
  1. Update on Filing Fees

DPCMIs are also reminded that the filing fees applicable to the CARs were revised under the General Application and        Implementation Directive, 2025 (“GAID”). The fees depend on the DPCMI category, as well as the number of data subjects processed by the organisation, as outlined below:

  1. Ultra-High Level DPCMI
    Tier A – 50,000 data subjects and above: N1,000,000
    Tier B – 25,000 – 49,999 data subjects: N750,000
    Tier C – below 25,000 data subjects: N500,000
  2. Extra-High Level DPCMI
    Tier A – 10,000 data subjects and above: N250,000
    Tier B – 2,500 – 9,999 data subjects: N200,000
    Tier C – below 2,500 data subjects: N100,000
  1. Further Guidance

For a more detailed overview of compliance obligations under Nigerian data protection laws, and the role of DPCOs, please refer to our previous publications:

Conclusion

The extension of the 2025 data audit filing deadline provides organisations with an extended opportunity to review their data protection practices and file their Compliance Audit Returns on time.

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a DPCO. We provide support to organisations across diverse industries in conducting data protection compliance audits, preparing and filing Compliance Audit Returns, and ensuring alignment with the GAID and Nigeria Data Protection Act, 2023.