Research Sources and Review Notes
Version: v1 draft Research date: 2026-06-18 Status: Source notes for legal review, not legal advice
This file records sources used to draft the Nigeria v1 policy set. Exact statutory citations and final legal positions must be verified by Nigerian counsel before public launch.
Data Protection
- Nigeria Data Protection Commission context and NDPA overview:
https://ndpc.gov.ng/and NDPC-related guidance/material surfaced in research. - NDPC General Application and Implementation Directive 2025 surfaced at:
https://ndpc.gov.ng/wp-content/uploads/2025/03/NDP-ACT-GAID-2025-MARCH-20TH.pdf - Nigeria Data Protection Act, 2023 and General Application and Implementation Directive 2025 references were identified in reputable summaries and NDPC-related materials.
- GAID 2025 review notes: confirm Data Controller/Processor of Major Importance registration, audit returns, DPO duties, DPIA duties, cookie/tracking consent, breach notification, data-subject rights, cross-border transfer, and written retention policy obligations against final counsel advice.
- Placement notes: homepage privacy/cookie notices should be conspicuous, give clear accept/decline choices for non-essential cookies, and maintain accountable consent records where consent is relied on.
- Review notes: confirm current NDPC guidance, registration status for data controllers/processors of major importance, breach-notification obligations, cross-border transfer requirements, DPIA requirements, cookie consent recordkeeping, and whether NDPR references should be removed from public text.
Payments, Wallets, and Stored Value
- Central Bank of Nigeria mobile money guidance:
https://www.cbn.gov.ng/out/2015/bpsd/guidelines%20on%20mobile%20money%20services%20in%20nigeria.pdf - CBN payment/mobile money framework summaries and payment regulation guides were reviewed.
- Review notes: confirm current CBN licensing categories, provider-contract position, whether ZenWave activities are limited to technical facilitation, and that any wallet/stored-value/fund-holding activity is handled only through properly licensed providers.
Consumer Protection and Refunds
- Federal Competition and Consumer Protection Commission consumer rights page:
https://fccpc.gov.ng/consumers/consumer-rights-responsibilities/rights-responsibilities/ - FCCPC e-commerce operational principles release:
https://fccpc.gov.ng/fccpc-online-marketing-coys-streamline-operational-principles-for-enhanced-consumer-confidence/ - FCCPC public materials on refunds, complaints, and consumer redress were reviewed.
- Placement notes: marketplace/order/payment surfaces should keep terms, restrictions, cancellation, return, refund, dispute, delivery, and complaint paths visible before users commit or submit evidence.
- Review notes: confirm final refund/cancellation/return wording against FCCPA and sector-specific provider rules. Avoid blanket "no refund", "sold as seen", or hidden-fee messaging.
Events and Sellers
- FCCPC consumer rights and e-commerce principles were used for event and seller disclosures: plain-language terms, full price disclosure, timely delivery/service performance, fair return/refund handling, complaint resolution, privacy protection, and non-misleading descriptions.
- Review notes: confirm final seller obligations for used goods, defective goods, warranties, delivery, receipts, product safety, prohibited goods, tax/accounting, and marketplace intermediary responsibilities.
- Review notes: confirm final event obligations for cancellation windows, venue/organizer liability, safety notices, QR attendance records, age limits, paid attendance refunds, and emergency escalation.
Cybercrime, Fraud, and Incident Reporting
- ngCERT contact and incident-reporting page:
https://cert.gov.ng/contact - Nigeria Police Force National Cybercrime Centre e-reporting portal:
https://nccc.npf.gov.ng/ - Reputable summaries of the Cybercrimes Act 2015 as amended in 2024 were reviewed, including 72-hour cyber-incident reporting discussion.
- UNODC cybercrime assessment surfaced for agency context:
https://www.unodc.org/conig/uploads/documents/Cybercrime_Assessment_in_Nigeria_WEB.pdf - Placement notes: fraud, unsafe meetup, account compromise, report, support, payment dispute, and evidence upload flows should route users to Trust & Safety/support while preserving external cybercrime escalation paths in policy text.
- Review notes: verify exact Cybercrimes Act reporting triggers, sectoral CERT/SOC channel, penalties, agency escalation, and internal incident-response workflow before launch.
Copyright and User Content
- Nigerian Copyright Commission / Copyright Act 2022 PDF surfaced at:
https://www.copyright.gov.ng/CopyrightAct/CopyrightAct2023FinalPublication1.pdf - Reputable summaries of online-content takedown and counter-notice provisions were reviewed.
- Review notes: confirm final notice, counter-notice, repeat-infringer, stay-down, and Nigerian Copyright Commission dispute-escalation procedure before launch.
AML, KYC, and Financial Crime
- CBN AML/CFT/CPF Regulations 2022 source surfaced at:
https://www.cbn.gov.ng/Out/2022/FPRD/AML%20CIRCULAR%20AND%20REGULATIONS%20MERGED.pdf - CBN Customer Due Diligence Regulations 2023 source surfaced at:
https://www.cbn.gov.ng/Out/2023/CCD/CBN%20Customer%20Due%20diligence%20Reg.%202023-combined.pdf - Nigerian Financial Intelligence Unit overview:
https://nfiu.gov.ng/ - CBN automated AML solution baseline standards were identified in 2026 legal/industry summaries; counsel should confirm official CBN circular status and applicability before launch.
- Placement notes: verification, wallet, transfer, payment request, payment dispute, seller, checkout, and account-limit flows should disclose that KYC, fraud, limits, holds, MFA, and provider review may apply.
- Review notes: confirm whether ZenWave is a reporting entity for any enabled product flow or whether obligations are handled by licensed providers. Confirm suspicious-activity escalation, sanctions screening, and provider reporting responsibilities.
Product Assumptions
- ZenWave v1 is trust/community-first.
- Phone/email verification and Trust Passport are user-visible safety and eligibility features.
- Termii OTP must remain backend-only.
- Paystack is primary payment provider readiness target; Flutterwave is fallback/provider-readiness support.
- Marketplace checkout and broad escrow remain paused unless explicitly enabled through backend flags and readiness review.