Nigeria
5 regulators · 6 laws & regulations · 6 obligations · 1 upcoming deadline
| Obligation | Timing | Regulator | Arises from | Source | Detail |
|---|---|---|---|---|---|
| Banking | |||||
| AML compliance programme and officer | Ongoing | NFIU | Money Laundering (Prevention and Prohibition) Act 2022 | official | |
An AML Compliance Program in Nigeria is an obligatory, board-approved internal system of controls that is mandated by the MLPPA 2022 and compels enterprises to identify and prevent any illegal money transactions through KYC procedures, automatic transaction monitoring, and keeping records of transactions for five years. Being the driving force of such a system, the Compliance Officer is a special staff member at the management level of the business who personally bears the responsibility of being the only point of contact between the company and regulatory authorities, such as NFIU or SCUML. The Compliance Officer must monitor customers for sanctions from all around the world on a continuous basis and notify the regulatory authority about suspicious transactions within 24 hours, along with transactions of cash in amounts higher than ₦5,000,000 for individuals and ₦10,000,000 for companies. Non-compliance with internal controls and statutory obligations leads to strict measures, such as a fine of not less than ₦25 million and imprisonment for up to 14 years. |
|||||
| AML record retention | Retention period 5 years | NFIU | Money Laundering (Prevention and Prohibition) Act 2022 | official | |
In Nigeria, there is a statutory requirement for AML record retention, which states that all financial institutions and regulated firms are legally mandated to ensure that they store all financial transaction records and KYC data for a minimum period of 5 years. The statutory record retention is enacted under Section 8 of the Money Laundering (Prevention and Prohibition) Act 2022 and runs from the day that a transaction takes place or when the customer relationship ends [MLPPA 2022]. All record and file-keeping requirements include the keeping of account files, transaction records, investigation processes undertaken by the company and copies of Suspicious Transaction Reports (STRs). The deletion, destruction, or failure to store these records within 5 years is a grave breach that attracts penalties ranging from administrative fines for the company, which start at ₦25 million, to up to 14 years' imprisonment. |
|||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | NFIU | Money Laundering (Prevention and Prohibition) Act 2022 | official | |
In Nigeria, the requirement to carry out Customer Due Diligence (CDD) and Know Your Customer (KYC) is a mandatory risk-based onboarding regime under Section 4 of the Money Laundering (Prevention and Prohibition) Act 2022, which requires the verification of customers' identities prior to conducting any business transaction. Regulated by the Central Bank of Nigeria (CBN) and the Special Control Unit Against Money Laundering (SCUML), this statutory regulation requires the cross-matching of personal details against the biometric pillars such as the National Identity Number (NIN) and Bank Verification Number (BVN), identification of beneficial owners of corporate clients at a control of 25%, as well as classification of individual clients into a Three-Tiered KYC structure. Under the current 2026 CBN AML Baseline Standards, companies have to conduct biometric authentication for remote onboarding and use automated AI technology solutions in connecting KYC profiles to real-time transaction monitoring by March 2028. In case these biometric checks are not done or Enhanced Due Diligence (EDD) is not done for Politically Exposed Persons (PEPs), stringent penalties include multi-million Naira corporate fines, withdrawal of license, and even personal criminal prosecution with imprisonment period of at least 4 years. |
|||||
| Suspicious transaction reporting | Deadline Event-based | NFIU | Money Laundering (Prevention and Prohibition) Act 2022 | official | |
The Suspicious Transaction Report requirement in Nigeria is a compulsory directive as per Section 7 of the Money Laundering (Prevention and Prohibition) Act 2022, which requires businesses to report their suspicions regarding the movement of funds in illegal ways to the Nigerian Financial Intelligence Unit (NFIU). The compliance team has a period of 72 hours to analyze the transactions internally. Upon suspicion based on the absence of a clear economic purpose of the transaction or inconsistency with the client's profile, a suspicious transaction report must be filed through the electronic goAML system within 24 hours. These reports are made irrespective of the amount and status of the transaction and involve very stringent 'tipping-off' prohibitions, which make it illegal to give information about the filing of STRs to the customers. Not filing an STR within 24 hours or tipping off the clients results in serious penalties, including fines of ₦25 million or imprisonment for up to 14 years. |
|||||
| Telecom & Tech | |||||
| Lawful basis, notice and data subject rights | Ongoing | NDPC | Nigeria Data Protection Act 2023 | source | |
Legally Binding Basis, Privacy Notice and Data Subject Rights in Nigeria is a mandatory requirement that requires organizations to collect and process personal information according to the Nigeria Data Protection Act 2023 in a legally binding framework. The Nigeria Data Protection Commission (NDPC), together with the GAID 2025 rules, enforces Section 25, which states that the organization will be prohibited from processing personal data unless it is established under one of the six statutory bases: consent, contract, legal obligation, vital interests, public task, and legitimate interest [NDPA 2023]. It is necessary for the data controller to provide a Privacy Notice of the data usage purpose and period of time of retention, along with details of third-party sharing at the moment of data collection. It is also obligatory for organizations to have dedicated channels for ensuring enforcement of enforceable Data Subject Rights and to allow access, rectification, restriction, and complete deletion (erasure) of their personal data. The violation of the legal basis, failure to publish a privacy notice, or ignoring the rights request will lead to administrative sanctions, including fines up to ₦10,000,000 or up to 2% of annual gross revenue. |
|||||
| Personal data breach notification | Deadline Event-based | NDPC | Nigeria Data Protection Act 2023 | source | |
The duty to notify of personal data breaches in Nigeria is a mandatory statutory requirement provided for under Section 40 of the Nigeria Data Protection Act 2023 that compels data controllers to inform the Nigeria Data Protection Commission (NDPC) within 72 hours of being aware of any security incidents [NDPA 2023]. Based on the operational guidelines set out by the GAID 2025, it states that whenever there is likelihood of risk of breach resulting into risk to individual rights and freedoms, the organization is obliged to formally notify NDPC about the nature of the hack, number of records compromised, and steps taken as remedy. Additionally, if there is a high risk to individuals as a consequence of the security incident, the data controller will be required to notify the affected individuals immediately and without unreasonable delays using clear and plain language. Data processors have a legal duty to immediately notify their respective data controllers in case of any unauthorized access. Any failure to comply with the 72 hours deadline, or cover-up of an active data breach leads to serious punitive actions by NDPC through mandatory audit checks and imposition of hefty administrative fines not exceeding ₦10,000,000 or 2% of annual |
|||||
| No obligations match these filters. | |||||