Connect with us

E-Business

SERAP to Sue NASS over Bill Empowering NDPC to Regulate Social Media

Published

on

Kindly share this post

Socio-Economic Rights and Accountability Project (SERAP) has threatened to drag the National Assembly to court over a proposed amendment to the Nigeria Data Protection Act, which it alleges could indirectly empower the government to shut down social media platforms in Nigeria.

SERAP to Sue NASS over Bill Empowering NDPC to Regulate Social Media

SERAP, which made the threat in an open letter to Godswill Akpabio, Senate President, and Tajudeen Abbas, speaker of the House of Representatives, urged them to immediately reject and withdraw the Nigeria Data Protection (Amendment) Bill, 2026, sponsored by Senator Ned Nwoko (APC, Delta North).

The civil organisation described the proposed legislation as a “backdoor attempt” to regulate social media and expand government control over online expression.

It further warned that if the bill is enacted in its current form or a substantially similar one, it would “promptly take all appropriate legal actions” to challenge its legality in the public interest and protect the fundamental rights of Nigerians.

The bill seeks to compel social media platforms, data controllers, and data processors operating in Nigeria to establish physical offices in the country.

Advertisement

It further empowers the Nigeria Data Protection Commission (NDPC) to shut down or prohibit the operations of any entity that fails to comply within 30 days.

SERAP, in the letter dated July 18, 2026 and signed by Kolawole Oluwadare, deputy director, SERAP, argued that the proposed powers could enable an administrative agency to impose what would effectively amount to a nationwide restriction on digital communication without adequate judicial or procedural safeguards.

“The Bill constitutes a backdoor attempt to regulate social media and increase governmental control over online expression through corporate localisation requirements rather than through transparent and constitutionally permissible regulation,” the organisation said.

It also maintained that the proposed localisation requirement could increase government leverage over technology companies, facilitate political pressure, and make censorship demands easier to enforce.

SERAP further warned that requiring companies to establish local offices could expose their employees in Nigeria to retaliation.

Advertisement

The organisation said the proposed amendment could affect millions of Nigerians who rely on digital platforms to exercise their rights to freedom of expression, access information, associate with others, participate in political life, conduct business, pursue education, and engage in civic advocacy.

SERAP particularly criticised the proposed power of the NDPC to prohibit entities from operating in Nigeria after a 30-day period of non-compliance.

It said the bill contains no requirement for prior judicial authorisation, no obligation to consider less restrictive alternatives, and no meaningful safeguards to assess the impact of a prohibition on the fundamental rights of millions of Nigerians.

“In effect, the Bill empowers an administrative agency to impose sanctions comparable to a nationwide restriction on digital communication without the procedural guarantees ordinarily required whenever fundamental rights are at stake,” it said.

SERAP argued that the proposed provision could not withstand scrutiny under Section 45 of the Nigerian Constitution, which permits restrictions on fundamental rights only when prescribed by law, pursued in the pursuit of a legitimate aim, and reasonably justifiable in a democratic society.

Advertisement

While recognising the government’s legitimate interest in ensuring that digital platforms comply with Nigerian law, the organisation contended that such regulation must meet the constitutional criteria of necessity and proportionality.

“There is no evidence that existing powers under the Nigeria Data Protection Act are inadequate, that current enforcement mechanisms have failed, or that less restrictive alternatives would be insufficient,” it stated.

SERAP further cautioned that the proposed legislation could recreate the repercussions of the Federal Government’s suspension of Twitter, which the ECOWAS Court of Justice previously criticised

In SERAP and Others v. Federal Republic of Nigeria, the regional court ruled that the Twitter suspension infringed rights to freedom of expression, access to information, and media freedom protected under the African Charter on Human and Peoples’ Rights.

Although the proposed amendment differs from the Twitter suspension, SERAP argued that it might produce a similar outcome indirectly by empowering regulators to bar digital platforms from operating in Nigeria.

Advertisement

“The National Assembly should not enact legislation capable of producing, through indirect regulatory means, the very restrictions on fundamental rights that regional human rights law prohibits,” the organisation emphasised.

It also cited Section 39 of the Nigerian Constitution, Article 19 of the International Covenant on Civil and Political Rights, and Article 9 of the African Charter, as securing freedom of expression and access to information.

SERAP maintained that international human rights standards mandate restrictions on freedom of expression to be lawful, necessary, proportionate, and the least intrusive means available to achieve a legitimate public goal.

The organisation additionally warned that mandatory localisation requirements could undermine Nigeria’s digital economy and innovation ecosystem by raising compliance costs for technology firms, start-ups, open-source projects, educational institutions, research organisations, and artificial intelligence developers.

It argued that the proposed amendment might make Nigeria less attractive to technology investors and conflict with the objectives of the Nigeria Startup Act 2022 and the National Digital Economy Policy and Strategy.

Advertisement

“The National Assembly should not achieve indirectly through regulatory localisation requirements what it cannot constitutionally achieve directly through restrictions on social media. The practical consequences for millions of Nigerians would be indistinguishable from a platform ban,” SERAP stated.

It urged Akpabio and Abbas to reject and withdraw the bill, warning that its enactment would breach the Nigerian Constitution and Nigeria’s commitments under international and regional human rights instruments.

“The National Assembly should seize this opportunity to demonstrate its commitment to constitutional democracy, the rule of law, and Nigeria’s digital future by immediately withdrawing the Bill,” SERAP added.

 

Advertisement

Kindly share this post

E-Business

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

Published

on

Kindly share this post

National Information Technology Development Agency (NITDA) has introduced so-called Nigeria’s Certified Cloud Register, regulatory framework developed under the agency’s National Sovereign Cloud Initiative to determine which cloud providers are authorized to handle sensitive data, such as banking records.

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

In effect, from October, NITDA requires banks, fintech companies and other regulated organisations to source cloud infrastructure providers from a national register of certified firms approved to host sensitive financial and government data.

The Certified Cloud Register, is expected to strengthen data sovereignty, improve regulatory oversight and support the implementation of the Central Bank of Nigeria’s (CBN) data localisation policy, which takes effect on January 1, 2027.

Under the framework, banks, fintechs, government institutions and other regulated entities will be able to verify whether cloud service providers, data centre operators, managed service providers and Artificial Intelligence (AI) infrastructure companies have met NITDA’s certification requirements before entrusting them with critical digital workloads.

The initiative is expected to provide regulated institutions with a standardised process for selecting cloud infrastructure providers that satisfy Nigeria’s technical, security and regulatory requirements.

Advertisement

According to NITDA, the framework establishes “a common national standard, an independent assessment process and a public register of approved providers that banks, fintechs and government institutions can rely on when selecting cloud infrastructure partners.”

The register is expected to become a key compliance tool ahead of the CBN’s directive, which requires all payment transaction data generated within Nigeria to be stored and processed locally, effective from January 1, 2027.

The policy applies to deposit money banks, microfinance banks, mobile money operators, payment service providers, switching companies and other financial institutions.

The certification regime is also expected to reshape Nigeria’s cloud computing ecosystem, making regulatory approval a major requirement for cloud providers seeking to handle sensitive data for regulated industries.

Figures cited by NITDA showed that Nigeria’s 10 largest banks spent about N177.91 billion on information technology in the first quarter of 2026, representing a 31 per cent increase over the corresponding period last year.

Advertisement

A sizeable portion of the investment currently supports cloud infrastructure hosted outside Nigeria, a trend the new certification framework is expected to address by encouraging greater utilisation of compliant local infrastructure.

NITDA said the certification programme will apply the same technical and regulatory standards to indigenous cloud providers and international hyperscale operators, creating a level playing field for all companies seeking to provide cloud services to regulated sectors.

The agency also disclosed that more than 85 per cent of Nigerian businesses currently rely on cloud services, with the majority using infrastructure hosted outside the country.

It said the new framework is aimed at improving confidence in Nigeria’s digital infrastructure while promoting local capacity and enhancing oversight of critical national data.

Speaking on the objective of the initiative, Kashifu Inuwa Abdullahi, director-general of NITDA, said the programme is designed to strengthen Nigeria’s position in the global digital economy rather than exclude foreign technology companies.

Advertisement

According to him, the initiative is intended “to redefine the terms under which Nigeria participates in the global digital economy rather than isolate the country from international technology providers.”

The Certified Cloud Register forms part of broader efforts by the Federal Government to deepen digital trust, strengthen cybersecurity and ensure that critical financial and public sector data are managed in line with Nigeria’s evolving data governance and sovereignty objectives.

Kindly share this post
Continue Reading

E-Business

Firm Advocates Healthy IT Habits to Strengthen Cyber Resilience

Published

on

Kindly share this post

At the recent Cyber Security Weekend 2026 conference, Kaspersky shared the findings from its survey titled “Cybersecurity in the workplace: Employee knowledge and behaviour” which was conducted among employees from the Middle East, Turkiye and Africa (META) region.

The study highlights that everyday IT habits, including decluttering computers and reducing digital fatigue, can have a direct and often underestimated impact on an organisation’s cyber resilience.

The Kaspersky survey points to a growing challenge of digital fatigue in the workplace. 13.5% of employees surveyed in the META region confirmed that they made IT-related mistakes due to a lack of cybersecurity knowledge – a figure that shows the critical importance of continuous cybersecurity training and awareness programmes.

Among other reasons behind IT mistakes, respondents cited being in a hurry (30%), oversight (14%), being tired or stressed (12.9%) and having too many notifications (10%). The constant barrage of alerts, messages, and on-screen clutter is becoming an acute problem that can lead to costly IT errors, overlooked social engineering attacks, and even to cyber breaches.

The survey also examined employees’ digital workspace habits. An overwhelming 44.5% of respondents in the META region reported having between 10 and 20 icons on their desktop, while 30% admitted to having even more – with half to a full screen covered in them.

Advertisement

Meanwhile, 33% of respondents also keep more than 10 tabs open in their browser at any given time. Excessive icons and open tabs do more than distract attention and fuel procrastination – they can slow device performance and, in the case of unused applications, quietly collect data.

Interestingly, most employees regularly disinfect their keyboards and phone surfaces (21.5% have adopted this habit since the COVID pandemic). However, digital cleanliness has not kept pace: 55% of respondents remove needless files once a month or more often; the rest perform digital clean-ups far less frequently – once a quarter, or even once a year.

Managing digital noise is key to staying alert: only essential notifications should remain active, especially during periods of deep focus on critical project deliverables. Regular breaks are just as vital for maintaining both well-being and cyber vigilance.

According to the survey, 78% of respondents spend their work breaks eating or drinking, while 58% chat with friends and colleagues. However, stretching and physical exercise is a more effective way to relieve stress and recharge focus – a habit adopted by only 14% of employees.

“It is important to recognise that digital fatigue is a real and growing stress factor: the constant stream of notifications, cluttered screens, and information overload gradually erode focus and make employees far more susceptible to mistakes and social engineering attacks. Simplifying your digital environment is not just a productivity tip, it is a cybersecurity measure”, says Brandon Muller, senior security consultant for the META region at Kaspersky.

Advertisement

Kindly share this post
Continue Reading

E-Business

Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

Published

on

Kindly share this post

Pan-African digital rights organisation Paradigm Initiative (PIN) has warned that violent extremist groups are increasingly exploiting digital platforms to recruit, radicalise and manipulate young people across the Sahel region.

Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

The organisation raised the concern in a new policy brief titled “Digital Frontlines: Countering Online Radicalisation and Violent Extremist Narratives in the Sahel.”

According to the publication, extremist groups are shifting from traditional recruitment methods to digital platforms, including social media, encrypted messaging applications, short-form video platforms and online financial incentives, to target vulnerable populations.

PIN noted that unemployed youths and people facing insecurity and limited economic opportunities are particularly susceptible to online recruitment campaigns.

The organisation said that although governments have intensified efforts to combat violent extremism, responses to the digital dimension of the threat have failed to keep pace with rapidly evolving online tactics.

Advertisement

It argued that addressing online radicalisation requires more than surveillance and restrictive measures, recommending investments in digital literacy, stronger community resilience, improved early-warning systems and credible counter-narratives.

PIN also urged governments to work closely with technology companies and civil society organisations to disrupt extremist recruitment while protecting citizens’ digital rights.

The report further highlighted the growing convergence between organised crime and violent extremist groups, noting that online propaganda increasingly promises financial rewards, belonging and purpose to vulnerable young people.

According to the organisation, this trend underscores the need for policymakers to prioritise prevention alongside conventional security responses.

Speaking on the findings, Moussa Waly SENE, Programmes Officer for Francophone Africa at Paradigm Initiative, described the digital space as a new frontline in the fight against violent extremism.

Advertisement

“As more young Africans come online, stakeholders must ensure that digital platforms remain spaces for opportunity, innovation and civic participation, not recruitment grounds for violent extremist groups. Protecting digital rights and protecting vulnerable communities should be mutually reinforcing objectives,” he said.

Among its recommendations, the policy brief called for stronger regional cooperation to tackle cross-border online extremist networks, rights-respecting content moderation and greater accountability by digital platforms.

It also advocated expanded digital literacy programmes to strengthen resilience against online manipulation and community-led initiatives that empower young people to identify and reject extremist narratives.

The organisation further urged policymakers to develop security measures that balance national security objectives with the protection of privacy, freedom of expression and access to information.

Advertisement

Kindly share this post
Continue Reading

Trending