Nigeria – Goldsmiths Solicitors Nigeria https://www.goldsmithsllp.com Goldsmiths Solicitors Nigeria Sun, 07 Dec 2025 20:35:26 +0000 en-US hourly 1 https://www.goldsmithsllp.com/wp-content/uploads/2025/05/cropped-Untitled-design-32x32.png Nigeria – Goldsmiths Solicitors Nigeria https://www.goldsmithsllp.com 32 32 Better Late than Never: Nigeria Finally Passes the Data Protection Act https://www.goldsmithsllp.com/better-late-than-never-nigeria-finally-passes-the-data-protection-act/?utm_source=rss&utm_medium=rss&utm_campaign=better-late-than-never-nigeria-finally-passes-the-data-protection-act Tue, 27 Jun 2023 12:02:55 +0000 https://goldsmithsllp.com/?p=8579 On 12 June 2023, the Nigeria Data Protection Act, 2023 (“the Act”) was signed into law by President Bola Ahmed Tinubu. The Act provides a legal framework for the protection of personal information, processing and transfer of personal information and regulatory obligations of data controllers and data processors among others in Nigeria. Prior to this, Nigeria did not have a single unified data protection law despite there being calls for one.

This article provides an overview of the new law, it considers the objectives, application, principles guiding the processing of personal data, cross-border transfer of personal data and other key provisions.

Application of the Nigeria Data Protection Act

The Act applies to data controllers or data processors domiciled, resident or operating in Nigeria and the processing of personal data that occurs within Nigeria. It also applies to situations where the data controllers or data processors are not domiciled, resident or operating in Nigeria but are processing the personal data of data subjects in Nigeria.

The Act does not apply to the processing of personal data which is done solely for personal or household purposes by one or two more persons. The Act also does not apply to the processing of personal data necessary for the investigation, detection or prosecution of crimes or the prevention or control of a public health emergency, etc.

Objectives of the Act

The Act seeks to achieve the following objectives:

  1. Safeguard the fundamental rights, freedoms and interest of data subjects as guaranteed under the Constitution.
  2. Regulate the processing of personal data and ensures that personal data is processed in a fair, lawful and accountable manner.
  3. Protect data subjects’ rights and provide means of recourse and remedies in the event of breach.
  4. Ensure that data controllers and data processors fulfill their obligations to data subjects.
  5. Establish an impartial, independent and effective regulatory Commission to superintend over data protection and privacy issues and supervise data controllers and data processors.

Establishment and Functions of the Nigeria Data Protection Commission

The Act established the Nigeria Data Protection Commission (“the Commission”) for the purposes of achieving the objectives of the Act. Thus, the Commission has the core functions of regulating the deployment of technological and organizational measures to enhance personal data protection, accredit, licence, and register suitable persons to provide data protection compliance services, register data controllers and data processors, receiving complaints relating to violations of the Act or any subsidiary legislations.

Principles of Processing Personal Data

Data controllers and data processors process personal data on the basis of care and accountability to data subjects. Accordingly, data controllers and data processors must act in a fair, lawful and transparent manner, collect data only for specified and legitimate purpose, hold and retain the data accurately, not longer than necessary, and generally ensure appropriate security measures are taken to secure the personal data.

Consent and Lawful Basis for the Processing of Personal Data

Consent of a data subject is very important for processing personal data. A data subject is a person whose information or data is being processed or sought to be processed. A data controller or data processor must obtain the consent of a data subject before processing his/her data, and it lies on the data controller or processor to prove that the data subject has given consent. The request for consent must be in a clear simple language and format with information that the data subject reserves the right to withdraw the consent at any time.  The consent must be freely and intentionally given either in writing, orally or through electronic means. Silence or inactivity does not amount to consent. In the case of a child, or person lacking legal capacity), the consent of a parent or guardian will suffice. The need to obtain consent of parent or guardian, may however not apply where the processing of personal data is necessary to protect the vital interests, or for the purpose of the education, medical or social care of such child or person lacking legal capacity, or where it is necessary for proceedings before a court.

The consent must be given for the specific purpose(s) for which personal data is processed, or where the processing is necessary for the following purposes:

  1. For the performance of a contract to which the data subject is a party
  2. For compliance with a legal obligation to which the data controller or data processor is subject
  3. To protect the vital interest of the data subject or another person
  4. For the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller or data processor
  5. For the purposes of the legitimate interest pursued by the data controller or data processor, or by a third party to whom the data is disclosed.

Obligations of a Data Controller

  • Obligation to Provide Information: A data controller has the obligation to provide certain necessary information to a data subject before collecting his personal data. The information which the data controller must provide to the data subject include the following:
  1. Identity, residence or place of business and means of communication with the data controller and its representative.
  2. Recipients or categories of recipients of the personal data
  3. Existence of the rights of the data subject
  4. Retention period for the personal data, etc.

The data controller shall make this information available by means of a privacy policy which should be expressed in a clear, concise, transparent, intelligible and easily accessible format.

  • Data Privacy Impact Assessment Obligation: The assessment is a process designed to identify the risks and impact of processing personal data. A data controller is required to conduct a data privacy impact assessment where the processing of personal data may result in high risk to the rights and freedom of a data subject. This is to be conducted before the processing of personal data.
  • Obligation to Erase Personal Data: A data controller has the obligation to erase the personal data of a data subject without undue delay where it is no longer necessary or where the data controller has no other lawful basis to retain the personal data.

Obligations of a Data Processor

Data controllers are engaged by data processors to process personal data. These data processors are also mandated to comply with the principles for the processing of personal data, assist the data controller to fulfill its obligation, implement appropriate technical and organizational measures to ensure the security, integrity, and confidentiality of personal data. Where a data processor engaged by a data controller further engages another data processor, the data processor directly engaged by the data controller is obliged to notify the data controller of its engagement with another data processor.

Data Protection Officers

Data controllers that process significant personal data are required to designate a person as a Data Protection Officer (DPO). The DPO may be an employee of the data controller or a person engaged by a service contract and must possess expert knowledge on data protection laws and practices. A DPO advises data controller, monitors compliance with the Act and related data protection policies of the data controller. The DPO also act as the contact point for the Commission on data processing issues.

Rights of Data Subjects

A data subject has the following rights with respect to the processing of his personal data by a data controller.

  1. Right to Confirmation from a Data Controller. A data subject has the right to obtain from a data controller without constraint or unreasonable delay, confirmation as to whether the data controller or a data processor operating on its behalf is storing or otherwise processing personal data relating to the data subject and if so, the purpose of the processing, the recipients or categories of recipients to whom the personal data have been disclosed or will be disclosed, etc.
  2. Right to receive a copy of his personal data in a commonly used electronic format.
  3. Right to correction or deletion of the data subject’s personal data where correction is not possible where the personal data is inaccurate, out of date, incomplete or misleading.
  4. Erasure of personal data of the data subject without undue delay
  5. Right to restrict the processing of personal data
  6. Right to withdraw consent to the processing of personal data at any time.
  7. Right to object to the processing of personal data relating to the data subject.
  8. The right to reject being subject to a decision based solely on automated processing of personal data.
  9. The right to receive personal data in a structured, commonly used and machine-readable format and be able to transmit it to another data controller without any hindrance.

Data Security

Data controllers and data processors are required to implement appropriate technical and organisational measures to ensure the security, integrity and confidentiality of personal data in the possession. They must ensure that personal data are protected against accidental or unlawful destruction, loss, misuse, alteration, unauthorized disclosure or access.

The security measures that may be implemented to ensure personal data security include encryption, periodic assessments of risks to processing systems and services, regular testing, assessing and evaluation of the effectiveness of the measures, regular updating of the measures and introducing new measures to address shortcomings, etc.

Personal Data Breaches

Personal data breach is the breach of the security of a data controller or data processor which leads to or may lead to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or processed.

Data processors are required to notify data controllers or engaging data processors of personal data breaches which the data processors store or process upon becoming aware of it by describing the nature of the personal data breach and the number of data subjects and personal data records concerned and also respond to all information requests from the data controllers or the engaging data processors.

Data controllers should also notify the Commission of personal data breaches which are likely to result in a risk to the rights and freedoms of individuals within 72 hours of becoming aware of such breach. Data controllers are also to communicate the personal data breach to the data subjects in a plain and clear language including measures that could be taken by the data subjects to mitigate any possible adverse effects.

Data controllers and data processors are also required to keep a record of all personal data breaches, facts relating to the breaches, its effects and remedial actions taken.

Cross-border Transfers of Personal Data

Data controllers and data processors are not allowed to transfer or permit the transfer of personal data from Nigeria to another country unless:

  1. The recipient is subject to a law, binding corporate rules, contractual clauses, code of conduct or certification mechanism that affords an adequate level of protection.
  2. meets one of the lawful basis for transfer of personal data outside Nigeria.

The level of protection considered adequate must uphold the principles that are substantially similar to the conditions for processing personal data provided by the Act. An adequate level of protection is assessed by taking into account the existence of an effective data protection law, access of public authority to personal data, existence of an independent supervisory authority, etc.

Registration of Data Controllers and Data Processors

Data controllers and data processors of major importance are mandated to register with the Commission within six months after the commencement of the Act or upon becoming a data controller or data processor of major importance. Data controllers or data processors of major importance are data controllers or data processors that process personal data of particular value or significance to the economy, society or security and are resident or operating in Nigeria.

The Commission is required to maintain and publish a register of duly registered data controllers and data processors of major importance on its website. A data controller or data processor of major importance shall be removed from the register where it ceases operation.

Enforcement and Penalties

A data subject who is aggrieved by the action, inaction or decision of a data controller or processor may lodge a complaint with the Commission and it may investigate the complaint where it is not vexatious or frivolous.

The Commission may also issue a compliance order once it is satisfied that any requirement of the Act or subsidiary legislation has been violated or likely to be violated by a data controller or data processor. The order may be a warning, order to comply with the request of a data subject or a cease-and-desist order. The Commission may also issue an enforcement order or impose a sanction for violation of the Act or a subsidiary legislation.

The penalty or remedial fee for violation of the Act or subsidiary legislation is:

  1. Higher maximum amount, which is the greater of N10,000,000 and 2% of its annual gross revenue in the preceding financial year, in the case of a data controller or data processor of major importance.
  2. Standard maximum amount, which is the greater of N2,000,000 and 2% of its annual gross revenue in the preceding financial year, in the case of a data controller or data processor not of major importance.

Conclusion and Remarks

The Nigeria Data Protection Act, 2023 is an important piece of legislation and has been long in coming. It provides for the basic principles and the lawful bases for the processing and transfer of personal data in Nigeria and applies to both resident and non-resident data processors. It provides for the responsibilities of data controllers and data processors while also providing for the rights of data subjects. The processing of sensitive personal data and the personal data of children and persons lacking legal capacity to consent must follow the applicable principles as provided by the Act. Data security measures which are robust are expected to be put in place by data controllers and data processors to protect against the risk of personal data breaches. The Act creates the Nigerian Data Protection Commission which has the overall responsibility to ensure compliance and impose penalties where necessary. Both resident and non-resident data processors are advised to pay particular attention to this new legislation as they are now required to take specific steps to ensure compliance with the Act.

 

Please note that the contents of this article are for general guidance on the Subject Matter. It is NOT legal advice.

For further information or to see our other service offerings, please visit www.goldsmithsllp.com  or contact:

]]>
An Overview of the Central Bank of Nigeria Exposure Draft Guidelines for the Regulation of Representative Offices of Foreign Banks in Nigeria https://www.goldsmithsllp.com/an-overview-of-the-central-bank-of-nigeria-exposure-draft-guidelines-for-the-regulation-of-representative-offices-of-foreign-banks-in-nigeria/?utm_source=rss&utm_medium=rss&utm_campaign=an-overview-of-the-central-bank-of-nigeria-exposure-draft-guidelines-for-the-regulation-of-representative-offices-of-foreign-banks-in-nigeria Mon, 24 Oct 2022 11:46:48 +0000 https://goldsmithsllp.com/?p=8506 On 12 October 2022, the Central Bank of Nigeria (CBN) released an exposure draft Guidelines for the Regulation of Representative Offices of Foreign Banks in Nigeria (the Guidelines). The Guidelines complement the CBN’s Regulations on the Scope of Banking Activities and Ancillary Matters, No. 3, 2010 and are issued by the CBN to specify the permissible and non-permissible activities, requirements for the licensing and operations of approved representative offices of foreign banks in Nigeria, and their reporting obligations to the CBN.

What is Representative Office of a Foreign Bank?

Representative office of a foreign bank is defined as an approved Representative Office of a Foreign Bank in Nigeria acting as liaison office of the foreign bank licensed by the Central Bank of Nigeria, whose sole object is to market the products and services of its foreign parent as well as serve as liaison between its foreign parent and local banks, other financial institutions, private companies and the general public.

Scope and Applicability of the Guidelines

The Guidelines shall apply to the following institutions:

  1. A bank licensed under any foreign law, whose registered office is outside Nigeria
  2. Any financial institution licensed under foreign law, whose primary business includes the receipt of deposits, granting of loans and/or provision of current and savings accounts.
  3. Any foreign-owned operating bank/financial holding company that is foreign-based, that owns controlling interest in one or more banks or institutions whose primary business includes the receipt of deposits, granting of loans and provision of current and savings accounts.

Permissible Activities of Approved Representative Offices

Representative offices of foreign banks in Nigeria can carry out the following activities in Nigeria:

  1. Marketing the products and services of its foreign parent or an affiliate of the foreign parent licensed and domiciled outside Nigeria.
  2. Carrying out research activities on behalf of the foreign parent.
  3. Serving as liaison between the foreign parent and local banks, private institutions within Nigeria and other customers of the foreign parent based in Nigeria.
  4. Connect banks and other financial institutions to its foreign parent.
  5. Connect exporters in Nigeria with potential customers in jurisdictions where the parent company operates and assisting Nigerian exporters with finding new markets through its international offices, etc.

Non-permissible Activities of Approved Representative Offices

Representative offices of foreign banks in Nigeria are not allowed to carry out the following activities:

  1. Provision of services designated in Nigeria as banking business.
  2. Provision of any commercial or trading activity that may lead to the issuance of invoices for services rendered.
  3. Acceptance of orders on behalf of the foreign parent.
  4. Engage directly in any financial transaction except for transactions that are related to those permitted.

Licensing

The licensing of representative offices of foreign banks in Nigeria is done in two stages which are:

  1. Approval-in-Principle (AIP); and
  2. Final license or approval

The Requirements for Approval-in-Principle (AIP) of a Representative Office

Foreign banks and other financial institutions seeking to establish an approved representative office in Nigeria and obtain the approval-in-principle of the CBN shall submit a formal application to the Governor of the CBN and shall meet the requirements for approval-in-principle which include:

  1. The home supervisory authority of the applicant bank or other financial institution must have a valid Memorandum of Understanding with the CBN.
  2. No objection letter (or approval) from the home supervisory authority.
  3. Evidence of payment of non-refundable application fee of N5,000,000 to the CBN.
  4. Board resolution in support of the foreign parent’s decision to invest in the equity shares of the proposed representative office.
  5. Evidence of name reservation with the Corporate Affairs Commission.
  6. Detailed business plan or feasibility report
  7. Schedule of services to be rendered
  8. Sources of funding for the representative office’s operations and five years financial projection
  9. Draft copy of the representative office’s Memorandum and Articles of Association
  10. Draft Shareholders Agreement unless it is 100% owned by the foreign parent bank.

 

The Requirements for Final License or Approval of a Representative Office

The promoters of a proposed representative office in Nigeria are expected to apply for the grant of the final license to the CBN not later than three months after obtaining the approval-in-principle of the CBN. The requirements include:

  1. Evidence of payment of non-refundable licensing fee of N10,000,000
  2. Certified true copy of certificate of Incorporation of the business
  3. Certified True Copy of Memorandum and Articles of Association
  4. Certified True Copy of Form CAC 1.1
  5. Evidence of location of the Office for the take-off of the business
  6. Names, addresses and curricular vitae of Management staff
  7. Schedule of changes, if any, in the Board and shareholding after the grant of the AIP.
  8. Copies of letters of offer and acceptance of employment in respect of the management team.

The CBN will also conduct an inspection of the premises and facilities of the proposed representative as a requirement for the grant of final license.

Reporting Requirements of a Representative Office

A representative office has the following reporting requirements or obligations:

  1. Informing the CBN forthwith of any incidents of fraud, theft or robbery.
  2. Submitting a written confirmation by the Chief Representative that the Representative Office has complied with all the requirements in its approval document to the CBN.
  3. Submitting a quarterly report which summarizes the activities undertaken by the representative office.
  4. A certificate from a recognized audit firm affirming that during the year no income was earned or accrued to the Nigeria office. Such certificate shall be submitted not later than 28 February of each year.

Operational Requirements of a Representative Office

The operational requirements which apply to a representative office include:

  1. A representative office shall use the parent’s name only in conjunction with the description “representative office” in its documents and correspondences, including office signage, letterheads and business cards.
  2. A representative office shall inform the CBN of its proposed hours of business
  3. No representative office shall be relocated or closed without the prior written approval of CBN
  4. Notify the CBN in writing immediately or within seven days if there is any variation to the shareholding structure that changes the control and/or majority ownership in its parent foreign institutions.

Disclosure and Examination of a Representative Office

A representative office is obliged to display the following information in a conspicuous place on its premises:

  1. The name, contact details and logo of the foreign bank it is representing
  2. Its authorization to operate a representative office as issued by the CBN
  3. An authenticated copy of the consent letter from the home country supervisory authority.
  4. An authenticated copy of the foreign bank’s valid license to conduct banking business
  5. A list of the services offered by the representative office.

The representative office is to be examined periodically and risk-based on issues which are not limited to the following:

  1. A review of the activities conducted
  2. A general assessment of its management and supervision
  3. A review of whether the office is complying with applicable laws and regulations.

A brief examination report shall be prepared highlighting any significant supervisory concerns.

Conclusion

The Guidelines provide a clear regulatory overview to what representative offices are, the requirements for the licensing of a representative office in Nigeria, the activities that can be undertaken by a representative office while also highlighting the obligations that are to be met by the representative office. The Guidelines, when issued, will streamline the activities of representative offices whilst giving the CBN more regulatory overview of their activities.

]]>