BlackTree Security · Infrastructure · Automation · AI

Nigeria’s 2024 Cybercrime Amendment Is More Than a Cybersecurity Levy

Nigeria’s Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act 2024 is usually remembered for the disputed cybersecurity levy. That focus misses changes to traffic-data retention, sectoral monitoring and the country’s cyber enforcement architecture.

The Act was assented to on 28 February 2024 and amended the 2015 cybercrime statute. It revised offences, expanded implementation functions, tied retention to the Nigeria Data Protection Act and clarified the National Cybersecurity Fund mechanism.

The practical reading should separate three things: what Parliament enacted, what regulators later instructed, and what remains politically or legally contested. Treating one circular as the whole law creates a misleading compliance picture.

The levy exists, but the first banking instruction did not survive

Section 44 provides for a levy of 0.5 percent of electronic transaction value by businesses listed in the Act’s Second Schedule, with proceeds directed to the National Cybersecurity Fund. It also adds recordkeeping, audit and compliance-monitoring provisions and serious consequences for failure to remit.

In May 2024, the Central Bank issued implementation guidance to banks and then withdrew that circular. The withdrawal matters operationally, but it did not itself erase the statutory amendment. Finance and compliance teams should track the current implementing position rather than assume either that collection is active or that the underlying provision disappeared.

Traffic-data retention now points to privacy law

The amended section 38 requires service providers to keep and protect specified traffic data and subscriber information for two years, in accordance with the Nigeria Data Protection Act and prescriptions from the communications regulator.

This connects cybercrime evidence preservation to privacy governance. Retention does not remove the need for access control, purpose limitation, auditability, secure deletion and a documented response to lawful requests.

Sectoral SOCs become part of the national model

The amendments assign functions supporting sectoral computer emergency response teams and security operations centres that feed into the national CERT. They also contemplate routing internet and data traffic into sectoral monitoring structures.

That raises immediate architecture and governance questions. Organisations need clarity about scope, data minimisation, access, retention, confidentiality, incident ownership and the boundary between regulatory monitoring and their own security operations.

The speech provisions changed, but the debate did not end

Section 24 was narrowed compared with the earlier language, removing several broad terms that had attracted sustained criticism. The amended wording still covers specified false messages connected to breakdown of law and order or threats to life, and it remains the subject of rights-based scrutiny.

Security legislation should be evaluated on both defensive capability and safeguards. Clear offence definitions and judicial oversight affect trust, reporting behaviour and the risk that cybercrime powers are used for unrelated speech enforcement.

What organisations should do now

  1. Identify whether the organisation falls within any levy or sectoral implementation category.
  2. Track current regulator instructions separately from the statute.
  3. Map two-year traffic and subscriber-data retention to privacy controls.
  4. Define governance for any sectoral CERT or SOC integration.
  5. Review lawful-request, evidence preservation and disclosure procedures.
  6. Monitor litigation and implementation guidance for material changes.

The law is an operating model, not one fee

The amendment is better understood as a redesign of how Nigeria funds, coordinates and gathers information for national cybersecurity. The levy is significant, but the deeper compliance work sits in retention, monitoring, institutional coordination and safeguards.

Official sources

This article provides general information and is not legal advice.

Continue the series: Africa Cyber & Digital Law Series index

Leave a Reply

Your email address will not be published. Required fields are marked *