Goldsmiths Solicitors Nigeria https://www.goldsmithsllp.com Goldsmiths Solicitors Nigeria Fri, 04 Sep 2026 17:59:32 +0000 en-US hourly 1 https://www.goldsmithsllp.com/wp-content/uploads/2025/05/cropped-Untitled-design-32x32.png Goldsmiths Solicitors Nigeria https://www.goldsmithsllp.com 32 32 Investing in Nigeria 2026: A Strategic Legal Roadmap for Foreign Businesses https://www.goldsmithsllp.com/investing-in-nigeria-2026-a-strategic-legal-roadmap-for-foreign-businesses/?utm_source=rss&utm_medium=rss&utm_campaign=investing-in-nigeria-2026-a-strategic-legal-roadmap-for-foreign-businesses Fri, 04 Sep 2026 12:44:00 +0000 https://www.goldsmithsllp.com/?p=10418

Introduction

As of 2026, Nigeria’s regulatory landscape has undergone its most significant transformation in over two decades. With the enactment of the Nigeria Tax Act (“NTA”) 2025 and the Nigeria Tax Administration Act (“NTAA”) 2025 which took effect on 1 January 2026, companies can no longer easily exploit legal loopholes. For foreign investors, the message is clear: success in the Nigerian market now requires compliance-by-design rather than addressed only when regulatory issues arise. The new architecture, anchored by the NTA, NTAA and the Investments and Securities Act (“ISA”) 2025, moves Nigeria toward a unified and digitally integrated regulatory strategy. This article highlights six important legal considerations every foreign business should understand before establishing or expanding operations in Nigeria in 2026.

  1. Market Entry and Corporate Structuring

Foreign investors intending to establish business in Nigeria are required to determine the appropriate corporate structure through which their business activities will be undertaken. The appropriate structure will depend on the nature of the proposed business, the extent of the investor’s physical presence in Nigeria, applicable sector-specific requirements and the tax implications of the proposed activities. Under the Companies and Allied Matters Act 2020 (“CAMA”), a foreign company incorporated outside Nigeria that intends to carry on business in Nigeria is generally required to incorporate a separate Nigerian entity before commencing business activities in Nigeria, subject to applicable statutory exemptions. A foreign investor may therefore establish a Nigerian subsidiary through which its business activities will be conducted. Following incorporation, a company with foreign participation is required to register with the Nigerian Investment Promotion Commission (“NIPC”) before commencing operations.

Minimum Capital Requirements

CAMA provides a general minimum issued share capital of ₦100,000 (One Hundred Thousand Naira) for private companies and ₦2,000,000 (Two Million Naira) for public companies. However, companies with foreign participation are subject to a higher minimum paid-up capital of ₦100,000,000 (One Hundred Million Naira) as mandated by the  Federal Ministry of Interior’s Revised Handbook on Expatriate Quota Administration 2022, which has been actively enforced by the CAC since 2023. Notwithstanding the foregoing, the applicable minimum capital requirement may also depend on the nature of the proposed business. Companies operating in regulated sectors, including banking, insurance, aviation and capital markets, may be subject to significantly higher minimum capital requirements prescribed by the relevant sector regulator. Investors should therefore determine the applicable minimum capital requirements before incorporating the Nigerian entity, and ensure that the company’s capitalisation is consistent with the requirements applicable to its proposed business activities.

  1. Tax Compliance and Incentives

Nigeria operates a multi-layered tax system spanning federal, state and local obligations. The Nigeria Tax Act 2025, the Nigeria Tax Administration Act 2025, and the Nigeria Revenue Service (Establishment) Act 2025 centralised the federal tax collection to reduce fragmented administration.

Corporate taxes are within the remit of the Federal Government and administered by the Nigerian Revenue Service (NRS). It is therefore important for companies upon incorporation to register with NRS for corporate tax purposes and obtain their Tax Identification Number (TIN) and remit their taxes including value added tax (VAT), Companies Income Tax (CIT), etc. as at when due to avoid regulatory sanctions.

Non-resident companies planning to operate in Nigeria should begin by carefully assessing whether their proposed activities will create a permanent establishment or significant economic presence, as this determines Companies Income Tax liability and the need for registration with the Nigeria Revenue Service. They must also identify potential withholding tax obligations on payments, VAT requirements and transfer pricing considerations, while checking possible relief under applicable double tax treaties, so that the correct compliance framework is established from the outset.

To achieve proper tax compliance, intending companies should register promptly, maintain accurate records of all transactions, and meet statutory filings and payment deadlines. Engaging a qualified local tax adviser early in the process is the most effective way to navigate NRS requirements, stay updated on any legislative changes, and ensure smooth, penalty-free operations once business activities commence.

Nigeria continues to offer a range of incentives available for investments in specific sectors or businesses which are designed to encourage capital inflows and industrial development, including Economic Development Incentive, Free Trade Zone incentives, Export Expansion Grant schemes, sector-specific fiscal incentives, and investment protection under applicable bilateral investment treaties. Alongside these incentives, foreign investors and businesses should develop appropriate legal risk management strategies, effective dispute resolution mechanisms, and comprehensive due-diligence practices before committing capital or commencing operations in Nigeria.

  1. Foreign Exchange Compliance:

Foreign investors should give careful consideration to Nigeria’s foreign exchange requirements when bringing capital into the country. A foreign company investing in Nigeria must bring in its capital through an authorised dealer bank and ensure the bank issues a Certificate of Capital Importation (CCI) for every inflow. The CCI is the official document that confirms the capital was imported in accordance with Central Bank of Nigeria’s (CBN) foreign-exchange regulations. It is also particularly important for facilitating the repatriation of eligible capital, dividends, profits and other returns through the Nigerian banking system, subject to applicable foreign exchange rules and documentation requirements. The company must therefore open or maintain an account with a licensed bank, submit all required supporting documents, and insist that the bank processes and issues the CCI promptly (usually within 24 to 48 hours) after the funds or assets arrive.

 

]]>
What The Virtual Assets Coordination Order Means For Digital Assets Operators https://www.goldsmithsllp.com/what-the-virtual-assets-coordination-order-means-for-digital-assets-operators/?utm_source=rss&utm_medium=rss&utm_campaign=what-the-virtual-assets-coordination-order-means-for-digital-assets-operators Mon, 24 Aug 2026 08:34:42 +0000 https://www.goldsmithsllp.com/?p=10394

INTRODUCTION

The coming into force of the Investments and Securities Act 2025, which repealed the Investments and Securities Act 2007, marked significant changes to the regulatory framework applicable to virtual and digital assets in Nigeria. Virtual and digital assets are now recognized as securities, and the businesses involved in activities relating to such assets falls within the regulatory purview of the Securities and Exchange Commission (SEC). The implications of this reclassification for issuers, exchanges and the wider public have been discussed in previous articles. It has, however, become clear that this is only one aspect of the evolving regulatory framework applicable to digital-asset businesses in Nigeria. Three separate regulatory tracks, an executive coordination order, an increase in the capital requirements prescribed by the SEC, and a bill currently before the Senate have, over the past eighteen months, further shaped the regulatory framework applicable to digital asset businesses in Nigeria.

A SINGLE INSTRUCTION: WORKING FROM THE SAME PLAYBOOK

On 17 July 2026, the Nigerian president signed the Executive Order on Virtual Assets Coordination 2026, which took effect immediately. Rather than establishing a new regulator, the Order provides for greater coordination, among the Central Bank of Nigeria (CBN), the Securities and Exchange Commission (SEC) and the newly constituted Nigeria Revenue Service in relation to the licensing, supervision and enforcement of virtual asset activities through a Virtual Asset Council, chaired by the CBN, with a Virtual Asset Office established within the CBN to serve as its secretariat. The Order is intended to address regulatory gaps that may be exploited by fraudsters and unlicensed platforms and to strengthen measures relating to money laundering, terrorism financing and tax compliance, without imposing an additional licensing requirement on operators beyond the requirements under the Investments and Securities Act 2025 and the SEC’s applicable rules. For operators, the Order further emphasises the need for regulatory compliance across the various applicable regulatory frameworks, particularly as increased information sharing among the CBN, SEC and tax authorities may result in inconsistencies in regulatory filings, banking records and anti-money laundering monitoring being identified and acted upon.

Two further workstreams under the Council remain relevant to the evolving regulatory framework.

  1. The Central Bank of Nigeria has now opened applications for Cohort 2 of its Regulatory Sandbox Programme between (12–31 August 2026). The programme includes a dedicated Virtual Asset Service Provider (VASP) track that enables eligible operators to test virtual-asset, stablecoin, custody, wallet and related payment solutions under regulatory supervision before full deployment. Participation does not constitute a licence or authorisation to operate outside the approved testing parameters.
  2. In parallel, the Nigeria Revenue Service has issued detailed Guidelines on the Taxation of Virtual Assets 2026. The guidelines establish a clear administrative framework intended to facilitate voluntary compliance and provide greater visibility into revenue derived from digital asset activities.

Operators developing product roadmaps for the next financial year should take both developments into account. While the sandbox and tax guidelines provide greater clarity than previously available, further regulatory guidance and refinements are still expected.

THE REVISED MINIMUM CAPITAL REQUIREMENTS FOR DIGITAL-ASSET OPERATORS

The January 2026 Circular preceded the above Order. In January 2026, SEC issued Circular No. 26-1, which revised the minimum capital requirements applicable to participants in the capital market and significantly increased the capital requirements applicable to digital-asset operators. Digital Asset Exchanges and custodians are now required to maintain a minimum capital of ₦2 billion, representing an increase from the previous threshold of ₦500 million. Digital Asset Offering Platforms are required to maintain a minimum capital of ₦1 billion, while ancillary virtual asset service providers are required to maintain a minimum capital of ₦300 million. Affected operators have until 30 June 2027 to comply with the new capital requirements. The revised capital requirements are intended to strengthen the financial capacity of firms involved in activities relating to digital assets and enhance the protection of client assets.

BANKING ACCESS AND SEC LICENSING REQUIREMENTS

None of the above developments changes the regulatory position that has applied since December 2023, under which digital-asset businesses are required to obtain a SEC licence before accessing banking services in Nigeria. The CBN’s Guidelines on the Operation of Bank Accounts for Virtual Assets Service Providers, which reversed the CBN’s earlier prohibition on banks servicing crypto businesses, permit banks to open designated accounts only for SEC-licensed operators and subject to conditions including dedicated settlement accounts, transaction limits and enhanced customer due diligence. Such operators also remain subject to the applicable anti-money laundering requirements. The coordination mandate of the Virtual Asset Council further strengthens this regulatory framework, particularly as banks may be required to ensure that the SEC licensing and capital requirements of digital-asset operators remain valid and up to date.

]]>
After The Extension: A Data Protection Playbook For Banks & Fintechs https://www.goldsmithsllp.com/after-the-extension-a-data-protection-playbook-for-banks-fintechs/?utm_source=rss&utm_medium=rss&utm_campaign=after-the-extension-a-data-protection-playbook-for-banks-fintechs Mon, 17 Aug 2026 06:30:54 +0000 https://www.goldsmithsllp.com/?p=10369

Data protection compliance in Nigeria has moved beyond simply having a privacy policy or obtaining consent from customers. The Nigeria Data Protection Act 2023 (NDPA) established the Nigeria Data Protection Commission (NDPC) and created a comprehensive statutory framework for the protection of personal data.  The General Application and Implementation Directive 2025 (“GAID” or “Directive”), which took effect on 19 September 2025, turned this Act into the documented, auditable programme that now governs every Data Controller and Processor of Major Importance in the country. For banks and FinTechs, data protection compliance is therefore not simply another legal or IT issue. It is a governance, operational and reputational issue that should be receiving attention across all leadership cadres.

The Compliance Deadline

The NDPC originally set 31 March 2026 as the deadline for filing the 2025 Compliance Audit Return (CAR), the annual filing through which Ultra-High and Extra-High Level registrants demonstrate to the Commission that their data protection framework is actually operating rather than merely documented. Following representations from stakeholders, the Commission extended that deadline to 30 May 2026[1]. That extended deadline has now also passed. The GAID requires the audit process to address matters including lawful bases for processing, legitimate-interest assessments, data-subject rights, data-security measures, cross-border transfers and breach notification.

For organisations that filed their CAR on time, the filing should not be treated as the end of the compliance exercise. Rather, the audit trail submitted in May is now the baseline the NDPC will measure future conduct against. For organisations that missed the deadline, the issue should not simply be left unresolved. The GAID provides for an administrative penalty for late filing, in addition to the applicable CAR filing fee.

The practical approach is therefore to assess the reason for the delay, determine the applicable consequences and take steps to regularise the organisation’s compliance position.

Rethinking Consent 

One of the most common data-protection mistakes financial institutions make, is treating consent as the default lawful basis for processing personal data. Consent is important, but it is not the only applicable or appropriate legal basis for every processing activity. The NDPA recognises several lawful bases for processing personal data. These include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest and legitimate interests. The GAID also provides guidance on legitimate-interest assessments and expects organisations relying on legitimate interests to properly assess and document that basis. Financial institutions are required to identify the lawful basis that genuinely supports each processing activity rather than merely asking for or relying on consent because it is familiar. This requires financial institutions to move beyond generic privacy notices and actually map their processing activities to the appropriate lawful bases.

The Role of the Data Protection Officer

The Directive mandates the appointment of a Data Protection Officer (DPO). The DPO is expected to have appropriate independence, access to relevant processing activities and sufficient resources to perform the role effectively. Banks and Fintechs are advised against folding this role into an existing legal or compliance title without giving it the independence or the resourcing the Directive actually requires. A DPO who is responsible for identifying data protection failures must have sufficient independence to raise those concerns and sufficient access to understand how personal data is actually being processed within the organisation. The GAID also provides for an annual credential assessment process for DPOs, including continuing professional development and inclusion in the Commission’s relevant database.

Cross-Border Data Transfers

Modern banking and FinTech operations rarely operate entirely within one country. As a result, Nigerian customers’ personal data may be transferred to, accessed from or processed in another jurisdiction. . The NDPA and GAID regulate cross-border transfers of personal data and provide recognised mechanisms and lawful grounds for such transfers. The practical problem for many institutions is not necessarily that there is no legal basis for a particular transfer. The problem is that the organisation may be unable to clearly explain what that basis is and where the supporting documentation is. An institution using offshore cloud hosting for its core banking platform, or routing customer data through an international payment processor, should therefore not wait for a regulatory enquiry before being able to clearly explain what the legal basis for a particular data transfer is and where the supporting documentation is.

 

]]>
Tinubu Signs Executive Order Coordinating Nigeria’s Virtual Asset Regulation https://www.goldsmithsllp.com/tinubu-signs-executive-order-coordinating-nigerias-virtual-asset-regulation/?utm_source=rss&utm_medium=rss&utm_campaign=tinubu-signs-executive-order-coordinating-nigerias-virtual-asset-regulation Wed, 22 Jul 2026 08:36:24 +0000 https://www.goldsmithsllp.com/?p=10318

President Bola Tinubu has signed the Presidential Executive Order on Virtual Assets Coordination, 2026, to establish a coordinated oversight framework for Nigeria’s virtual assets industry. The Order which was made pursuant to section 5 of the Nigerian Constitution, 1999 (as amended) and which takes effect immediately, is a response to a regulatory landscape that had become fragmented across multiple agencies with overlaps and enforcement gaps that exposed Nigerians to fraud, money laundering and unchecked losses from unregulated operators.

At the heart of the framework is a new Virtual Asset Council, chaired by the Central Bank of Nigeria (CBN), with the Nigeria Revenue Service (NRS) and the Securities and Exchange Commission (SEC) as vice-chairs, and the Nigerian Financial Intelligence Unit (NFIU) and the Office of National Security Adviser (ONSA). The Council will provide strategic policy direction and work with the Attorney-General of the Federation to develop a harmonised legal and institutional framework for the sector. It will have a Virtual Asset Office domiciled in the CBN which will be its operational arm to coordinate information sharing and regulatory applications across agencies using an integrated supervisory platform.

The Order does not establish a new regulator or strip any powers from any agency and this is critically important. It is a coordination mechanism on top of the existing regime with  SEC maintaining jurisdiction over virtual assets that qualify as securities under the ISA 2025, while the CBN undertakes supervision of payment, settlement and custody services involving non-security virtual assets.  If it is not clear which regulator has regulatory jurisdiction and power over a virtual asset offering, the Council will make the decision.

The Order defines the sector’s immediate agenda. First, the CBN will introduce a regulatory sandbox to pilot virtual asset products and blockchain use cases under supervision. Second, the NRS will create a dedicated tax policy for the sector. Third, the Federal Government is currently working on finalising a Virtual Assets White Paper that will define the country’s long-term approach to the virtual assets sector. Finally, the Council has 30 days to produce a Harmonised Implementation Framework to give guidance on how agencies will apply the Order in practice.

The Executive Order, combined with the ISA 2025, represents a pivot in Nigeria’s approach to virtual assets from defining who regulates what, to ensuring that those regulators now move as one system, closing the gaps that made the sector attractive to bad actors in the first place.

Disclaimer: The information shared in this post is to provide general guidance on the subject matter and does not constitute legal advice. For guidance tailored to your organisation’s specific circumstances, contact info@goldsmithsllp.com

]]>
Data Localisation: What the New Payments Circular Means for Banks & Fintechs https://www.goldsmithsllp.com/data-localisation-what-the-new-payments-circular-means-for-banks-fintechs/?utm_source=rss&utm_medium=rss&utm_campaign=data-localisation-what-the-new-payments-circular-means-for-banks-fintechs Mon, 20 Jul 2026 07:45:49 +0000 https://www.goldsmithsllp.com/?p=10303

Nigeria’s digital payments sector grew faster than the regulatory architecture that has been built around it. Electronic transaction volumes have increased, mobile money adoption has grown and a few switching, processing and payment solutions providers are at the center of how money moves around the country. The Central Bank of Nigeria concluded that this growth created risks that its rules were not designed to deal with and in June 2026, issued a new circular focusing on data localisation, market concentration & ownership transparency in the payments sector titled “Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System” (the “Circular”). The Circular is issued by the CBN Payments Systems Supervision Department and was sent out to deposit money banks, microfinance banks, mobile money operators, switching and processing companies, and other licensed participants in the digital payments sector. It imposes three different sets of obligations with their own compliance timelines and real implications for how banks & fintechs structure technology, ownership and market activity in Nigeria going forward.

  1. Data localisation – payment transaction data must be stored in Nigeria from 1 January 2027

All entities that process payments within Nigeria are required from 1st January 2027 to store and manage payment transaction data generated in Nigeria within Nigeria in accordance with Nigerian data protection laws. The requirement hits hardest institutions that already use offshore cloud infrastructure or cross-border data processing arrangements. For many of them, full compliance will mean new local data centre relationships/renegotiated cloud contracts and a planned data migration/migration plan. The requirement has been framed by the CBN as regulatory visibility, consumer protection and lowering operational risk of offshore data storage. It supplements, not replaces, obligations imposed by the Nigeria Data Protection Act 2023.

  1. Market structure limits – concentration caps on card issuing and merchant acquiring

The Circular introduces concentration limits intended to prevent a small number of dominant operators from controlling multiple critical functions within the payments value chain. An institution with more than 25% of the card-issuing market cannot also own more than 15% of the merchant-acquiring market – and this is in reverse. Affected institutions are required to submit a monthly market share report to the CBN, which must be in full compliance by 31st December 2026 (this is earlier than the data localisation deadline & should be treated as an earlier priority for institutions assessing exposure under the circular).

  1. Ultimate beneficial ownership disclosure

The Circular requires that payment system participants identify the ultimate beneficial owners of large shareholders in a way that aligns the payments supervisory framework with existing anti-money laundering and counter-terrorism financing obligations. This sits alongside and reinforces beneficial ownership register requirements for Nigerian companies in general under CAMA 2020, but it applies that requirement to the CBN in its direct supervisory relationship with the payment institutions.

Enforcement

The CBN said it will monitor compliance with this Circular closely and may levy supervisory sanctions against institutions that do not meet its requirements under applicable laws, regulations and guidance. For an industry that has so far exercised relatively light-touch oversight of things like data residency and ownership transparency in particular, this is one of those more consequential infrastructure and governance initiatives the CBN has made over the last few years in the payments space.

]]>
What the Investment & Securities Act 2025 Will Mean for Your Business https://www.goldsmithsllp.com/what-the-investment-securities-act-2025-will-mean-for-your-business/?utm_source=rss&utm_medium=rss&utm_campaign=what-the-investment-securities-act-2025-will-mean-for-your-business Wed, 15 Jul 2026 08:45:58 +0000 https://www.goldsmithsllp.com/?p=10292

The Investment and Securities Act 2025 (ISA 2025), signed into law by President Bola Ahmed Tinubu in March 2025 is the most comprehensive reform of Nigeria’s capital market legislation in nearly two decades. It repealed the Investment and Securities Act 2007 and provides for a new restructured framework to accommodate new asset classes and to significantly expand the enforcement powers of the Securities and Exchange Commission (SEC) so as to align Nigeria’s capital markets with world standards.

This article highlights six changes that are important to public companies, issuers, capital market operators including virtual/digital assets businesses in Nigeria.

  1. The SEC is now the primary authority for approving M&A involving public companies

The SEC now has the primary authority to approve mergers and acquisition of public companies. The Investments and Securities Act (ISA) 2025 in Nigeria reasserts the Securities and Exchange Commission’s (SEC) primary jurisdiction over public company mergers and acquisitions, following the disruption of its previous monopoly by the 2018 FCCPA. This legislation establishes a complex, dual-regulatory environment requiring simultaneous compliance for both SEC and FCCPC approvals. Advisors must recalibrate transaction strategies to navigate parallel filings and heightened regulatory coordination.

  1. Digital and virtual assets are now formally regulated securities

The new ISA 2025 classifies virtual and digital assets including cryptocurrencies, tokenised securities and digital investment contracts, as securities regulated by the SEC. For FinTechs, operators of digital assets and Virtual asset Service Providers (VASPs), who have been mired in the grey area between CBN and SEC regulatory authority now have clear regulatory certainty as to their classification and the regulatory authority to be subject to in respect of licensing and their business activities. Operators must register and satisfy capital requirements and adhere to disclosure and investor protection obligations as all registered capital market operators are obligated to do.

  1. Crowdfunding intermediaries are now formally recognised

The Securities and Exchange Commission (SEC) set the framework for crowdfunding in Nigeria by way of its 2021 Rule on Crowdfunding. This is now complemented by the Investments and Securities Act (ISA) 2025 which consolidates Nigeria’s crowdfunding landscape. The new law converts former regulatory guidelines into statutory law, creating a more robust legal framework for intermediaries and the protections for micro-investors. Platforms enabling raising equity or debt for retail investors should consider their registration status, operating terms and investor agreements in the light of the new legislative framework.

  1. The SEC can now appoint directors to public companies

In an unprecedented expansion of its regulatory powers under the ISA 2025, the SEC can nominate independent non-executive directors to the boards of directors of public companies where it has intervened or taken regulatory action. This is material enforcement capability that the ISA 2007 did not provide for. It suggests the legislature intends to give the SEC real corporate governance intervention powers, not just ability to issue financial sanctions.

]]>
What the CBN’s Financial Holding Company Rules Mean for Banking Groups Banking and Finance Practice https://www.goldsmithsllp.com/what-the-cbns-financial-holding-company-rules-mean-for-banking-groups-banking-and-finance-practice/?utm_source=rss&utm_medium=rss&utm_campaign=what-the-cbns-financial-holding-company-rules-mean-for-banking-groups-banking-and-finance-practice Mon, 06 Jul 2026 08:30:18 +0000 https://www.goldsmithsllp.com/?p=10281

Introduction

On 10 June 2026, the CBN published an Exposure Draft of Revised Guidelines for the Licensing and Regulation of Financial Holding Companies in Nigeria. The Exposure Draft’s public consultation window ends on 9 July 2026. Among the most significant changes to the holding company framework in the draft is the move from three-pillar structures to four-pillar structures. If approved, the proposed framework would be the most significant revamp of the holding company framework since the guidelines were issued for Nigerian banking groups during restructuring away from universal banking into holding companies structures in 2014.

The proposed changes must be understood by financial holding companies, their banking and non-banking subsidiaries, shareholders, and their advisers. The comment window is brief, the required structural changes under the final guidelines have long implementation deadlines and several of the proposals including capital requirements and foreign subsidiary ownership, for example, have material implications that require modelling even before the issuance of final rules.

We outline five of the biggest proposals in the CBN exposure draft and what banking groups need to do by the time the consultation deadline passes.

  1. Holding companies should not make lending decisions.

The draft guidelines limit holding companies to credit functions, restricting the company from playing any role in credit administration and approval of any subsidiary. This responds to a corporate governance issue that the CBN sees consistently across all banking groups: that the break between the holding company and operating bank, and hence between holding company management and the subsidiary bank’s lending, is functionally illusory, as holding company management does or can influence lending at the subsidiary. For those banking groups where historically holding company’s top management have been part of credit committees, or have been involved in investment decisions of the banking subsidiary, this prohibition will require that new corporate arrangements are made for the allocation of governance rights and corporate reporting lines.

  1. 51% of each subsidiary is to be a minimum equity stake

Every financial holding company must have not less than 51% equity interest in all of its subsidiaries. Re-structure is required where current structures do not meet this test. The draft introduces a requirement to register holding companies as a person with significant control in the appropriate corporate authority which is a practical requirement for disclosure obligations where corporate groups have used complex sub-group structures.

  1. Capital must be at least 20% in excess of the sum of minimum capital of the subsidiaries

There is a new holding company capital adequacy standard included in the draft: regulatory capital must be at least 20% greater than the sum of the minimum regulatory capital requirements of all subsidiaries. The capital implications of the requirement for a group, when that group has, or has significant plans to, have multiple regulated subsidiaries (e.g. a commercial bank, an insurance company, a fund manager, and a payment subsidiary) are potentially material and will need to be modelled against the current group capital position prior to final guidelines being published.

  1. Foreign subsidiaries have to be located at the parent holding company and not the bank level.

Under the extant 2014 framework, there is an equivalence between what a Nigerian banking subsidiary may be equity-hold in a foreign-owned subsidiary. The draft reverses that: equity-hold in the foreign-owned subsidiary must flow through a holding company itself (or at most, a single-interposition holding company). For banking groups with African subsidiaries (the ownership structure of which will now flow through the Nigerian Bank), this requires that corporate restructure, regulatory approval, and the tax treatment of the transfer of the equity be conducted with immediacy. Also,any shared services have to be at arm’s length. It plugs what the CBN refers to as holes in arrangements for shared services between bank groups. Group owners have historically provided technology, compliance and operation back-up to subsidiaries in ways the CBN now considers as giving subsidiaries unfair advantages over rivals elsewhere within the group. The draft wants any shared services to operate through formal, arm’s length agreements.

  1. Group customers cannot be shared without consent.

As with other regulatory frameworks, the Draft includes a clear data governance rule in the banking group framework- sharing of customer data across group entities that are closely linked without the express consent of the customer (except as permitted in NDPA 2023) is not allowed. This takes the Banking group framework in line with the NDPA and creates a compliance obligation that some will have to consider for their existing data management and technology architectures.

]]>
How to Commercialise Your Intellectual Property While Maintaining Control https://www.goldsmithsllp.com/how-to-commercialise-your-intellectual-property-while-maintaining-control/?utm_source=rss&utm_medium=rss&utm_campaign=how-to-commercialise-your-intellectual-property-while-maintaining-control Wed, 24 Jun 2026 09:00:26 +0000 https://www.goldsmithsllp.com/?p=10245

Introduction

IP licensing is the grant of a right to use the intellectual property, usually for a fee, royalty or other consideration. It is one of the most commercially underutilised tools available to Nigerian businesses. A trademark, established through years of investment, can generate a continuous stream of licensing revenues from franchisees, distributors or commercial partners. Software developed for internal use can be licensed to third parties in related markets. A unique proprietary method or approach distinguishing a professional services firm can be packaged and licensed into other geographies. Content developed once could generate a continuous revenue stream over its entire commercial lifespan. The primary reason Nigerian companies do not harness this value is not because the opportunity does not exist but because IP licensing is technically challenging and poorly structured licensing arrangements often create more commercial and legal problems than they solve. Nigerian IP law in this area requires strict compliance with applicable legal and regulatory requirements, and drafting errors tends to manifest themselves where their impact is most detrimental-in a commercial dispute or upon the expiry or termination of a license relationship.

In this article, we are discussing five aspects that must be addressed in any Nigerian IP licensing agreement, the most commonly encountered errors in Nigerian IP licenses, and what every company that owns valuable IP needs to know before it can licence to a third party. 

 

  1. Scope

The license scope establishes precisely what a licensee is entitled to do with licensed intellectual property, and importantly what it may not do. There are two classes of risks created by under-scoping a license. Under-scoping creates an insufficient business opportunity for the licensee such that it is unable to extract the commercial value it expected. Over-scoping confers unintended rights on the licensee which could lead to exploitation of the licensed IP, adversely affecting the licensor’s interests or infringing on the licensor’s business operations and contracts. The questions every Nigerian IP license must precisely answer include: the intellectual property rights to be licensed; whether any permitted use of the IP is limited to specific uses only, or to all uses; the geographical area or territory within which a license operates; and whether any derivatives can be produced from the licensed IP, and who will be deemed to own the same. In terms of tax implications under the NTA 2025, revenue generated from Nigerian licensors’ licensing arrangements is subject to income tax rates applicable depending on company size (30% for large companies; nil for small companies with turnover below 100 million). Gains on disposal of IP assets now fall into the category of a disposal and shall be taxed as a gain to the full market value of the asset at the time of disposal rather than at a flat 10% previously applied for capital gains tax rate.

 

  1. Exclusivity

The decision whether a license shall be exclusive, non-exclusive or sole is perhaps the most critical decision and commercial consideration in IP licensing, and is very often wrongly understood. An exclusive license affords the licensee exclusive rights in respect of the licensed IP to the exclusion of everyone, including the licensor, unless stated to the contrary. In the case of a non-exclusive license, the licensee is afforded a right to use the IP but may not prevent the licensor from granting equivalent or overlapping rights to third parties. A sole license sits in the middle: the licensor agrees not to license its IP to third parties, but is entitled to use the IP in its own business. The term ‘exclusive’ is frequently used incorrectly in Nigerian IP licenses where the scope of what it relates to, the territory and duration over which it subsists, are undefined. As such, the term has no precise meaning and will be interpreted more favourably to the licensee than the licensor.

Parties should also note the competition law dimension of exclusive licensing arrangements. Under the Federal Competition and Consumer Protection Act (FCCPA), agreements that have the effect of substantially lessening competition in a relevant market may be subject to scrutiny by the Federal Competition and Consumer Protection Commission (FCCPC). Exclusive licence agreements particularly those with broad territorial scope or long durations may be characterised as anti-competitive restraints, especially in sectors where the licensor holds significant market power.

Exclusivity is also crucial in determining what sublicensing rights a licensee is entitled to under Nigerian law as a licensee does not have the right to sub-license any licensed IP without the licensor’s written consent. Should the licensor permit this, the terms and conditions of sublicensing must be outlined in the agreement, including the right for the licensor to pre-approve all sublicenses before commitment and the consequences for the main license of a failed or breach sublicensing arrangement.

 

                                                                                                                                                                                                                                                                                                                                                                                                                                                

]]>
The NITDA Digital Economy Policy Review 2026: What Every Nigerian Technology Business Should Know https://www.goldsmithsllp.com/the-nitda-digital-economy-policy-review-2026-what-every-nigerian-technology-business-should-know/?utm_source=rss&utm_medium=rss&utm_campaign=the-nitda-digital-economy-policy-review-2026-what-every-nigerian-technology-business-should-know Tue, 16 Jun 2026 07:43:15 +0000 https://www.goldsmithsllp.com/?p=10222

Introduction

The regulatory environment for Nigeria’s digital economy is on the cusp of its most significant shift in more than ten years. This article outlines the implications of the National Information Technology Development Agency (NITDA) 2026 policy review on businesses and the immediate steps required to achieve compliance. It is updated to incorporate recent legal and regulatory developments as of May 2026.

The NITDA Digital Economy Policy Review 2026 is an ongoing regulatory process establishing the ground rules for Nigerian technology businesses, FinTechs, software providers, digital platforms, e-commerce companies, AI developers and all other organisations leveraging digital infrastructure for the period beginning 2027. With Nigeria’s digital economy set to balloon to $18.3 billion in 2026, from $9.97 billion in 2021, the regulatory stakes for technology firms have never been higher. Under the National Information Technology Development Agency Act and the National Digital Economy Policy and Strategy, 2020 – 2030, NITDA is the principal regulator for Nigeria’s digital economy. The 2026 policy review will build upon recent advances in AI governance, data localisation and protection, the amendment of the digital tax regime, the Nigeria Startup Act 2022, the Nigeria Data Protection Act 2023 and NITDA’s expanding licensing regime. In particular, the expected passage of the National Digital Economy and E-Governance Bill which will position NITDA as a ‘super-regulator’ for Nigeria’s digital economy raises a warning flag, signalling an immediate need for all Nigerian tech businesses to achieve compliance.

In this article, we have discussed the five (5) top priority areas within the NITDA 2026 policy review and how organisations should proceed immediately.

  1. AI Governance

The current regulation of AI in Nigeria has primarily drawn on general principles of the law, such as contract, data protection and product liability, rather than on AI-specific legislation. The NITDA 2026 policy review marks the end of this era. Nigeria has already launched its National AI Strategy (2024) and will likely transpose this into law via the National Digital Economy and E-Governance Bill. Subject to expected enactment in 2026, following a public hearing in November 2025, the Bill will render NITDA as Nigeria’s ‘super-regulator’ for digital technology. It will also position Nigeria as the first in Africa to establish a holistic, enforceable regulatory framework for AI. Key implications for companies deploying AI are:

  • Risk-based approach and structured classification for AI systems where AI deployed in public administration, finance, automated decision-making or surveillance is subject to mandatory annual audits and stricter scrutiny or regulation;
  • Mandatory licensing/registration of AI developers before AI system deployment within the Nigerian digital market;
  • Organisations must explain how automated systems make decisions and disclose same to the people affected by those decisions.
  • Requirement for human oversight of high-risk AI systems defined as AI systems with the potential to impact individual rights, financial standing or access to services;
  • Monetary fines up to NGN10,000,000 or 2% of the AI provider’s total annual Nigerian turnover;
  • A parallel framework will operate alongside the Nigeria Data Protection Commission (NDPC), which has previously announced its intent to establish AI regulatory sandboxes under the NDPA 2023.

Nigerian technology businesses using AI to automate services, for credit scoring or for fraud detection will need to assess how they implement and govern the relevant systems. Documentation will be crucial. An inventory of AI systems, their training data sources, testing procedures and human oversight mechanisms will be required by NITDA and will position companies in a stronger compliance stance.

  1. Data Protection and Localisation

The Nigeria Data Protection Act (NDPA) 2023 has superseded the previous NDPR 2019 and is now directly implemented by the March 2025 General Application and Implementation Directive (GAID). The GAID, which became operative from 19 September 2025, expressly supersedes the NDPR and its Implementation Framework as the authoritative regulatory instruments.

The NDPA establishes a stand-alone enforcement authority in the shape of the Nigeria Data Protection Commission (NDPC), an enforcement agency with broad powers of investigation and penalisation. Evidence of this enforcement is already mounting; the NDPC imposed a NGN766.2M penalty against Multichoice Nigeria and a $220M fine against Meta Platforms in Q2 2025 and has also already launched 1,368 broad sector investigations into companies in the insurance, pension, banking and gaming sectors as of August 2025. The GAID sets out tiered data controller and data processor classifications based on the nature of the personal data being processed:

  • Data Controller/Processors of Major Importance (DCMI/DPMI) and their sub-classifications based on an ultra-high, extra-high and ordinary high-level classifications are required to:
  • Have a local Data Protection Officer registered with the NDPC.
  • Undergo annual data protection audits within 15 months of operation.
  • File Compliance Audit Returns (CARs) with the NDPC. The deadline for submitting CARs for 2025 was extended to 30 May 2026 and this should be viewed as an immediate priority.
  • Revisit and update cross-border data transfer mechanisms to ensure compliance with formal transfer impact assessments and contractual safeguards required by the GAID.

The NITDA 2026 policy review looks set to expand existing data localisation obligations even further than mandated by the NDPA. A likely extension of what would be classified as personally identifiable information and data falling under localisation rules, will include data that touches on finances, health and government data. NITDA will likely also strengthen its audit powers of the relevant tech businesses. For any Nigerian FinTechs or tech companies utilising international cloud platforms (such as AWS, Microsoft, Google) without leveraging Nigerian-based infrastructure, the need to consider data localisation will become critical. NITDA is expected to develop an updated data classification framework which will clarify the residency requirements associated with categories of data-businesses should begin assessing likely classification categories immediately.

  1. Digital Taxation

Since the Finance Act 2021 established the basis for Significant Economic Presence (SEP), a landmark piece of legislation, the Nigeria Tax Act 2025 (NTA 2025) has revised and further enhanced the rules governing digital taxes in Nigeria.  Key digital tax obligations applicable to Nigerian technology businesses and international entities with a digital presence in Nigeria include:

  • Value Added Tax on digital services: Nigeria Revenue Service (NRS) may levy VAT on services provided to persons in Nigeria, even where rendered by a non-resident supplier. Where the recipient of the digital service is in Nigeria and not registered for VAT, the recipient is obliged to withhold and remit the VAT amount to the NRS under the NTA 2025.
  • Withholding Tax on digital services: Software, Cloud services, technical support and similar services purchased from non-resident tech companies will attract WHT at prescribed rates, which are specified in the updated Deduction of Tax at Source (Withholding) Regulations (effective 1 January 2025). NRS has provided implementation guidelines for these regulations.
  • Companies Income Tax on a significant economic presence (SEP): The NTA 2025 solidifies the existence of an SEP where a non-resident company is deriving income attributable to activities conducted within Nigeria through a digital platform, above a threshold of NGN25 million and is presumed to be deriving 6% deemed profit tax based on attributed turnover.
]]>
Nigerian Open Banking: The Legal Framework All Banks and FinTechs Need to Know https://www.goldsmithsllp.com/nigerian-open-banking-the-legal-framework-all-banks-and-fintechs-need-to-know/?utm_source=rss&utm_medium=rss&utm_campaign=nigerian-open-banking-the-legal-framework-all-banks-and-fintechs-need-to-know Wed, 10 Jun 2026 09:30:12 +0000 https://www.goldsmithsllp.com/?p=10208

The Central Bank of Nigeria (CBN) framework on open banking has now transitioned from a policy document to a phased implementation. Nigeria has a comprehensive history of open banking; with the Central Bank issuing Africa’s first Open Banking Regulatory framework in February 2021, followed by the Operational Guidelines in March 2023. In April 2025, the CBN provided August 2025 as the launch date for an operation that would have seen Nigeria emerge as the first African country to launch national open banking. However, the initial launch date was deferred as the CBN stressed that a wholly automated system that offers robust data protection and stringent consumer protection mechanisms should first be in place.

By May 2026, Nigeria’s phased rollout, the implementation dates are now spread across mid-2026, confirmed in CBN’s FinTech Report which was released in February 2026. The implementation workstreams comprise 5 key areas, namely:

  1. Governance & Regulation;
  2. Legal & Compliance;
  3. Technical & Infrastructure;
  4. Data Security; and
  5. Stakeholder Engagement.

Stakeholders have finalized and submitted their various deliverables in September 2025 and are currently pending review by the CBN. The Nigeria Inter-Bank Settlement System (NIBSS) has been nominated as the Open Banking Registry and will hold the public repository for all registered participants in the framework. All institutions that intend to participate will need to obtain a CBN license.

 

Legal and Regulatory Considerations for Intending Open Banking Participants

Here, we consider 5 legal questions that all banks and FinTech’s in Nigeria should now be seeking answers to, and which compliance gaps organisations in general have not addressed.

  1. Do Application Programming Interface (API) Agreements meet CBN Data sharing obligations?

The legal and technical standards that apply to the application programming interfaces  that allow for the sharing of financial information under Nigeria’s Open Banking framework are not guidelines; they are mandatory requirements and should not be treated as optional. The API agreements in place between banks and technology suppliers that existed prior to the extant open banking regime were not designed with this framework in mind and most of these will not satisfy the CBN framework.

All organisations with existing API agreements should re-examine them and ensure they meet all extant requirements. The relevant questions to ask regarding every API agreement include: whether it adequately defines the categories of data allowed to be accessed and if those are consistent with the tiers prescribed by CBN data access framework; whether the security levels required of the third party supplier meet the CBN’s minimum technical specifications; what the third party supplier’s obligations would be should data breach occur, including details on notification timelines and remedies, and whether the agreement’s terms for termination effectively allow the data supplier to cease data access if the third party supplier does not comply with their obligations under the framework.

  1. Are Customer Consent Frameworks Updated for Open Banking?

All data sharing arrangements under the CBN Open Banking framework will be contingent on customer consent which must be informed, specific, granular, and withdrawable. CBN has clearly stated that the open banking initiative should operate with customer ownership and control of personal data; which means that  customer should dictate who gets access to it, for how long, and must be able to revoke access at any time. Customer ownership and control over data was one of the key reasons given for the August 2025 delay.

A compliant open banking consent framework should outline; the specific data categories accessible to the third-party supplier; the purpose for which the third-party supplier would be utilizing the data; duration and frequency of third-party supplier’s access to data; customer’s right to revoke consent at any time, how that is done; and ramifications to the customer’s relationship with both bank and third-party supplier if the customer withdraws consent or withholds it.

A consent framework review should involve examining all customer-facing terms and digital interfaces where the company currently captures customer data and assesses its suitability for open banking. Where consent is not suitable for this purpose, new consent needs to be collected from existing customers before the institution’s data is shared under the open banking regime.

]]>