Digital lending in Nigeria: what operators need to think about
Regulatory attention has increased sharply, driven by recovery practices and the handling of borrower data.
Sample article 5 min read

Digital lending in Nigeria grew quickly, and for a period it grew ahead of the framework governing it. That gap has narrowed considerably. Operators now face approval requirements, consumer protection expectations and data protection obligations that touch nearly every design decision in the product.
Because this area continues to develop, the points below are orientation rather than a definitive statement of current requirements.
Approvals depend on your model
What applies turns on what you are actually doing: who bears the credit risk, whose balance sheet funds the loans, whether you are lending or arranging, and how the product is presented. Two apps that look similar to a user can sit in quite different regulatory positions.
A common and costly assumption is that a structure used by another operator must be appropriate for you. It may not be.
Data practices are central
Much of the attention on this sector has concerned the personal data borrowers hand over, particularly device permissions such as contacts, media and location.
The questions to ask of each permission are straightforward and uncomfortable: is this necessary for the service, would the borrower reasonably expect it, and could we justify it to a regulator? If the honest answer to the first is no, requesting it is difficult to defend, and consent buried in a terms screen does not resolve it.
Recovery practices carry the sharpest risk
Collections that involve contacting a borrower's phone contacts, disclosing the debt to third parties, or using shaming or harassment have attracted significant regulatory attention and reputational damage. Third parties in an address book never entered a relationship with the lender.
Review the actual process: scripts, timelines, escalation, and importantly the practices of any agency acting for you. Outsourcing recovery does not outsource responsibility.
Disclosure has to be genuine
Borrowers should understand what they will pay, when, and what happens if they are late, before they commit. Interest, fees and total repayment should be clear and prominent. Pricing that is technically disclosed but practically invisible is a recurring source of complaints.
Build a complaints route
A documented complaints process is both a regulatory expectation and a practical early warning system. Complaints tell you where a product is failing before a regulator does.
The design point
Compliance in digital lending is a product question, not a documentation question. What data you collect, what permissions you request, how pricing appears, how recovery works: these are decisions made by product and engineering teams. Involving legal input at that stage costs a fraction of retrofitting it later.
Found this useful? Share it.