IOC Law / Insight
Nigeria Digital Lending Regulation After the July 2026 Federal High Court Decision
Legal and commercial analysis for businesses operating across African markets
Nigeria’s regulation of digital consumer lending moved through three distinct stages in 2025 and 2026: the FCCPC issued the Digital, Electronic, Online or Non-Traditional Consumer Lending Regulations 2025; the Federal High Court temporarily restrained implementation in April 2026; and on 20 July 2026 the court vacated the restraint, after which FCCPC announced that implementation had resumed.
For lenders, investors, app providers, payment partners and telecom businesses, the practical conclusion is that the regulatory framework cannot be treated as suspended. The business model, registration, disclosures, data use, collections and third-party relationships should be tested against the current regime.
What activities are within the DEON framework
FCCPC describes the regulations as applying to unsecured consumer credit delivered through digital, electronic, online, mobile or other non-traditional means. Its public FAQs identify non-bank lenders, fintech businesses, mobile loan applications and microfinance institutions among affected operators.
Scope should be tested by function, not branding. Salary advance, buy-now-pay-later, airtime or data advance, embedded credit, merchant-funded lending and platform arrangements may require analysis even if the provider does not call the product a loan app.
The wider operating structure matters. A platform may originate customers, a licensed lender may fund, a technology company may score, a payment company may collect and a recovery firm may pursue arrears. Each participant should identify its own obligations and ensure the full chain is compliant.
Registration and market access
FCCPC’s digital lender registration page publishes the DEON Regulations, guidelines, application materials and lists of digital lenders and apps. The Commission initially set 5 January 2026 as the full-compliance deadline and later commenced phased enforcement against operators that had not regularised their status.
Registration with FCCPC does not replace another licence. Depending on the model, a CBN banking, microfinance, finance-company, payments or other authorisation may be relevant. State moneylender requirements and corporate objects may also need review. The entity named in the consumer contract, the entity funding the loan and the app publisher should be mapped accurately.
Investors should not accept “licensed” as a complete answer. They should request the actual approval, conditions, regulated entity name, public register entry and confirmation that operations match the permission.
The April to July 2026 court chronology
In Suit No. FHC/L/CS/760/2026, Wireless Application Service Providers Association of Nigeria Ltd/Gte v FCCPC, the Federal High Court in Lagos made an ex parte order on 15 April 2026 restraining implementation. On 22 May, FCCPC publicly confirmed that it had suspended implementation and enforcement while challenging the order.
On 20 July 2026, Justice A.L. Allagoa vacated the restraining order. FCCPC then announced that it had resumed implementation of the DEON Regulations. This chronology matters: commentary written during the restraint is no longer an accurate statement of the regulator’s published position.
The decision to vacate an interim restraint should not be overstated as a final judicial ruling on every substantive legal issue. What is clear for operational purposes is that the regulator says implementation has resumed.
Product terms must be transparent
FCCPC’s public guidance emphasises clear contract language and disclosure of interest, fees and repayment schedules. A compliant customer journey should allow the consumer to understand the amount advanced, total cost, due dates, default consequences and complaint route before accepting.
Disclosures should be visible in the interface, not hidden behind multiple links. The final agreement should be retrievable after acceptance. Promotional claims should not highlight a low periodic rate while obscuring fees or the total repayment.
Product governance should test affordability, renewals, rollovers, automatic deductions and the treatment of partial payments. Algorithms do not remove the need for fair outcomes and explainable rules.
Data access and credit scoring need a lawful design
Digital lending frequently uses device data, contacts, location, transaction history, behavioural signals and credit-bureau information. Each data field should have a defined purpose and lawful basis under the Nigeria Data Protection Act 2023 and GAID 2025.
Permission from an app store or device operating system is not, by itself, legal consent. Access should be necessary and proportionate. Contact-list scraping, public shaming, messages to unrelated third parties and coercive use of personal data create serious privacy and consumer-protection risk.
Where automated scoring significantly affects a person, the lender should document the model, data sources, validation, bias and human-review process. Vendor-provided models require diligence and contractual audit rights.
The business should determine DCPMI status, maintain privacy notices, processor agreements, security controls, retention rules, incident response and international-transfer documentation. A digital lender’s data programme is part of its licence-to-operate, not a secondary IT policy.
Debt collection must be controlled end to end
Collection scripts, timing, channels, escalation and third-party agents should be governed centrally. Harassment, threats, defamation and disclosure of a debt to unrelated contacts can engage the FCCPA, NDPA and other law.
Outsourcing does not outsource accountability. Recovery firms should be diligenced for ownership, staff training, security, complaint history and methods. Contracts should prohibit abusive practices, control data access, require incident reporting and permit audit and termination.
Customers need an accessible route to dispute balances, report fraud, correct data and obtain redress. The lender should preserve call, message and payment records sufficient to investigate a complaint fairly.
App stores, platforms and commercial partners are part of regulatory risk
The FCCPC framework contemplates action involving technology and service partners. App stores may remove non-compliant applications. Payment providers, banks, telecom businesses, credit bureaus, marketers and cloud vendors may be asked to support enforcement or may face their own obligations.
Commercial agreements should address regulatory status, consumer complaints, data roles, security, prohibited collection practices, audit, suspension, regulator requests and exit. A platform should be able to identify the legal lender clearly to the consumer.
M And A and investment due diligence for a Nigerian digital lender
A buyer or investor should examine:
corporate and beneficial ownership;
FCCPC registration and public register status;
CBN, state or other relevant licences;
app ownership and app-store accounts;
loan book composition, pricing and arrears;
customer terms and version history;
disclosure screens and evidence of acceptance;
complaints, refunds and regulator correspondence;
collection scripts, agents and incidents;
NDPC registration, CARs, DPIAs and privacy notices;
data sources, permissions and international transfers;
scoring models, validation and discrimination risk;
credit-bureau reporting and correction process;
fraud controls, AML and suspicious-activity processes;
related-party funding and service arrangements; and
litigation and the effect of regulatory change on valuation.
Sampling is essential. Policies should be tested against actual customer journeys, call recordings, screenshots, data permissions and complaints.
A practical compliance plan
1 Map the product and entities
Identify the contracting lender, funder, app owner, technology provider, payment collector, credit bureau, recovery firm and customer-support provider. Confirm the legal basis for each role.
2 Verify approvals
Match each activity to FCCPC, CBN, state and corporate requirements. Confirm public register entries and conditions. Close any gap between the approved entity and the customer-facing brand.
3 Rebuild disclosures
Use plain language for principal, interest, fees, total repayment, due dates, late consequences, auto-debit and complaints. Preserve evidence of the exact terms accepted.
4 Audit data and scoring
Remove unnecessary permissions, document lawful bases, assess DCPMI and CAR obligations, review transfers, complete DPIAs and validate automated models.
5 Control collections
Approve scripts and channels, train internal and outsourced teams, monitor calls and messages, and create rapid escalation for harassment or privacy complaints.
6 Test partners and incidents
Review app stores, payment providers, marketers, recovery agents and cloud services. Exercise suspension, breach and business-continuity procedures.
7 Report to the board
Track approval status, complaint volumes, disputed balances, collection conduct, privacy incidents, model changes and regulator correspondence. High-growth credit should be governed as a regulated product, not only as a sales metric.
Nigeria’s digital-credit market remains commercially significant. The sustainable businesses will be those that can show a clear permission chain, transparent product economics, disciplined data use and humane collection practices in the operation itself.
Discuss the practical implications
Speak with IOC Law about how these issues affect your proposed market entry, transaction or operations.
Start a Conversation →