Data protection basics for small Nigerian businesses
If you hold customer names, phone numbers or employee records, data protection obligations generally apply to you.
Read articlePractice area
Digital lending in Nigeria is now closely supervised. Building it properly is far cheaper than retrofitting.
Overview
Digital lending has moved from an unregulated frontier to an area of active supervision, driven largely by concerns about recovery practices and the handling of borrowers' personal data.
Operators now face approval requirements, consumer protection expectations and data protection obligations that touch nearly every part of the product. We advise lenders, platforms and their suppliers on how those apply to their model, and on building products that withstand scrutiny.
What we help clients with
Which approvals and registrations apply to your lending activity, and support with the applications.
Agreements, terms and disclosures written to be understood by the borrower as well as enforceable.
Lawful bases, consent practices, device permissions, retention and third-party data sharing.
Reviewing collections processes against regulatory expectations and consumer protection standards.
Pricing transparency, complaint handling and fair treatment obligations.
Arrangements between lenders, technology providers and funding partners.
Typical matters
These illustrate the kind of work this practice area covers. They are not descriptions of specific client matters.
Frequently asked questions
It depends on the model: who holds the credit risk, whose balance sheet funds the loan, and how the product is presented. Expectations in this area have developed considerably and continue to. Do not assume a structure used by another operator fits yours. The analysis has to be done on your own facts.
Requesting broad device permissions and using contact data for recovery has attracted significant regulatory and public scrutiny, and raises clear issues around necessity, consent and proportionality. We advise clients to be conservative and design around what can actually be justified.
Broadly, practices that harass, shame, mislead, or involve contacting third parties who never agreed to anything. Beyond regulatory exposure, they create reputational damage that is hard to undo. We review scripts, timelines, escalation and third-party agency arrangements.
Before you build. The requirements shape the product: what data you collect, what permissions you request, how pricing is disclosed, how recovery works. Retrofitting compliance into a launched product costs materially more.
Related insights
If you hold customer names, phone numbers or employee records, data protection obligations generally apply to you.
Read articleRegulatory attention has increased sharply, driven by recovery practices and the handling of borrower data.
Read articleMost compliance failures are not decisions. They are dates that passed while everyone was busy.
Read articleOther practice areas
Company formation, shareholder arrangements and the commercial contracts a business runs on.
ExploreStrategic representation in court, and in negotiation, arbitration and mediation.
ExploreWorking out which regulators apply to you, and building a system that keeps up with them.
ExploreSpeak to a lawyer
Tell us what you are dealing with. We will explain your options in plain English and what it would take to move forward.