Introduction
The Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act, 2024 was enacted to amend the Cybercrimes (Prohibition, Prevention, etc.) Act, No. 17, 2015. According to the Explanatory Memorandum, the Amendment Act inserts “some consequential words that were inadvertently omitted in the Act.” While described as consequential, the amendments introduce significant compliance obligations, expand the scope of existing provisions, and clarify critical definitions. This article highlights the key changes introduced by the 2024 Amendment Act.
Expanded Scope for Financial and Non-Financial Institutions
Section 22(1) of the Principal Act previously applied to “any Financial Institution.” The 2024 Amendment expands this to “any Financial Institution, public or private organisation.” This means that the offence of identity theft using special knowledge now extends beyond financial institutions to all public and private organisations. Similarly, Section 27(2), which deals with aiding and abetting cyber fraud, now applies to “any public or private organisation” rather than just “a financial institution.” This significantly broadens the class of entities that can be held liable.
New Grounds for Cyberstalking
Section 24(1) of the Principal Act, which defines the offence of cyberstalking, has been amended. The Amendment introduces new grounds: a message is now considered an offence if it “is pornographic; or he knows to be false, for the purpose of causing a breakdown of law and order, posing a threat to life, or causing such message to be sent.” This broadens the scope of cyberstalking to include pornographic content and false messages that threaten life or public order.
Clarification on ATM and Payment Technology
Section 30 of the Principal Act, which deals with ATM and Point of Sales (POS) fraud, has been amended. The 2024 Amendment inserts “or any other payment technology means” after “terminals” in subsection (1) and substitutes “or point of sales device” with “or any other payment technology means” in subsection (2). This ensures that the provision is technology-neutral and covers emerging payment technologies beyond traditional ATMs and POS devices.
Enhanced Customer Identification Requirements
Section 37(1)(a) of the Principal Act, which requires financial institutions to verify customer identity for electronic transactions, has been amended. The Amendment inserts “National Identification Number issued by the National Identity Management Commission and other valid” after the word “present.” This makes the National Identification Number (NIN) a primary means of customer identification for electronic financial transactions, strengthening the Know Your Customer (KYC) framework.
Data Protection Compliance for Service Providers
Section 38(1) of the Principal Act, which requires service providers to keep traffic data and subscriber information for two years, has been amended. The Amendment substitutes the subsection with a new provision that requires service providers to keep and protect traffic data and subscriber information “in accordance with the provision of the Nigeria Data Protection Act.” This aligns the retention and protection of subscriber data with the Nigeria Data Protection Act, 2023, creating consistency in the data protection regime.
Cybersecurity Architecture: Sectoral CERTs and SOCs
Section 41(1) of the Principal Act, which outlines the functions of the Office of the National Security Adviser, has been significantly amended. The Amendment introduces new paragraphs requiring the establishment of “sectoral Computer Emergency Response Teams (CERT) and sectoral Security Operation Centres (SOC) that shall feed into the national CERT.” It further requires “all public and private organisations to integrate and route their internet and data traffic to the sectoral SOCs thereby protecting the national cyberspace.” This represents a major shift in Nigeria’s cybersecurity architecture, mandating sectoral coordination and traffic routing.
Cybercrime Levy and Penalties
Section 44 of the Principal Act, which establishes the National Cyber Security Fund, has been amended. The Amendment clarifies that the levy is “0.5% (0.005) equivalent to a half percent of all electronic transactions value by the business specified in the Second Schedule.” It also introduces new subsections providing that the Office of the National Security Adviser shall administer the Fund and ensure compliance monitoring. Critically, a new subsection (8) provides that a business that fails to remit the levy “commits an offence and is liable on conviction to a fine of not less than 2% of the annual turnover of the defaulting business and failure to comply shall lead to closure or withdrawal of the business operational licence.” This introduces a stringent enforcement mechanism for non-compliance.
Deletion of Certain Provisions
Section 48(4) of the Principal Act, which required the cancellation of international passports of convicted persons, has been deleted by the 2024 Amendment Act.
Conclusion
The Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act, 2024 introduces significant changes to Nigeria’s cybercrime framework. The expanded scope for public and private organisations, enhanced identification requirements, alignment with the Nigeria Data Protection Act, new cybersecurity architecture, and stringent levy enforcement mechanisms all have practical compliance implications. Organisations should review their internal policies and systems to ensure compliance with the amended provisions. Legal practitioners and compliance officers must familiarise themselves with these changes to advise their clients effectively.