In an appeal brought by Meta Platforms Inc. and WhatsApp, LLC, the Competition and Consumer Protection Tribunal confirmed that their conduct violated data protection and competition laws. The Tribunal affirmed the Federal Competition and Consumer Protection Commission’s (FCCPC) decision to impose an administrative fine of $220 million and a reimbursement fee of $35,000 to cover the cost of the investigation. The Tribunal also found that the FCCPC had acted within its powers while giving the companies a fair opportunity to be heard.
Overview of Nigeria’s fine on Meta
The case stems from a joint investigation launched in 2020 by the FCCPC and the Nigeria Data Protection Commission (NDPC). The investigation followed widespread concern about WhatsApp’s updated privacy terms and the implications for Nigerian consumers.
On 19 July 2024, the FCCPC issued a final order concluding that Meta and WhatsApp had:
- failed to give Nigerian users meaningful control over how their data is collected, used, and shared;
- published a privacy policy that did not comply with Nigerian data protection laws;
- shared WhatsApp user data with Facebook and third parties without active, informed consent;
- engaged in unlawful tying by linking WhatsApp data with other Meta services; and
- failed to implement effective opt-in consent mechanisms.
The companies were directed to revert to their 2016 data-sharing framework, submit written assurances, and implement a clear remedy package within 15 days. The FCCPC imposed an administrative fine of $220 million and ordered them to pay $35,000 in investigation costs. Meta and WhatsApp appealed the decision to the Tribunal in August 2024.
Tribunal’s findings and interpretation of a data breach
The Tribunal dismissed the appeal and confirmed that the FCCPC acted within its legal powers under the Federal Competition and Consumer Protection Act (FCCPA). It found that the Commission followed a fair process, carried out a proper investigation and gave Meta and WhatsApp enough time to respond to the findings. The Tribunal also affirmed the ruling that the 2021 privacy policy update contravened the rules set out in the Nigerian Data Protection Regulations (NDPR).
As a result, it upheld the penalty and award for costs. It set aside only one part of the order because the legal basis for it was unclear. The Tribunal also accepted the FCCPC’s interpretation of a data breach. It found that Meta and WhatsApp transferred personal information outside Nigeria without obtaining informed consent from users. Even though no cyberattack took place, the Tribunal ruled that this still counted as a data breach. This decision confirms that companies can face serious penalties for transferring data across borders without proper consent or technical and organisational safeguards.
What you can learn from Nigeria’s fine
This ruling confirms that businesses can no longer treat data protection, consumer rights and competition compliance as separate. In practice, the FCCPC has shown that it will take enforcement action when a company’s privacy terms or data practices harm users or limit fair competition, particularly in the digital economy.
If your organisation holds a strong market position, you must take extra care. Processing personal information in ways that tie users into broader services or reduce their ability to choose will attract regulatory attention. You can reduce your risk of violating the provisions of the NDPR and FCCPA by taking practical, proactive steps towards compliance.
- Review your privacy notices and consent options. They must be easy to understand and comply with the local data protection laws.
- Assess and confirm how personal data leaves the country. Make sure you have clear data sharing agreements in place and have obtained approval from the local data protection authority.
- Avoid forcing users to agree to unnecessary data-sharing as a condition for using your services.
- Keep records of decisions about how you handle user data and competition risks, especially if your business holds market power.
- Notify local data protection authorities early when updating policies or launching new services that have an impact on large groups of users.
Actions you can take
- Protect yourself by conducting a gap analysis. Review your current data practices against Nigerian laws.
- As part of the Lexing network, we have direct access to experienced attorneys in Nigeria who can provide on-the-ground insights.
- Ensure compliance by working with our team to tailor your privacy policies specifically for the Nigerian market and Nigerian legal standards.
- Ask us how to achieve cross-border transfers in compliance with local laws.
- Join our Data Protection Programme and work through our modules on transferring data across borders.