WHAT NIGERIA’S CYBERCRIMES (AMENDMENT) ACT 2024 ACTUALLY SAYS – A GUIDE FOR ONLINE USERS AND PLATFORM ADMINS

A message has been circulating online claiming that a brand-new “Cybercrimes Act 2025” was just signed into law by the National Assembly. That claim is false as fact-checkers, including Africa Check and The ICIR, have confirmed no such law exists. What Nigerians actually need to know about is the Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act 2024, which amended the original 2015 Cybercrimes Act and was signed into law by President Bola Tinubu on 28 February 2024.

Here is what is verifiably in the law and what content creators, group admins, and everyday internet users should understand about it.

THE BASICS

The 2015 Act remains Nigeria’s foundational cybercrime law, running to 59 sections and two schedules. The 2024 Amendment Act does not replace it; it updates 12 of those sections to close gaps, sharpen definitions, and respond to newer forms of online harm. Some changes took effect immediately, while others required follow-up regulations from agencies like the Central Bank of Nigeria and the National Cybercrime Centre before they could be enforced in practice.

KEY CHANGES UNDER THE 2024 AMENDMENT

  1. The amendment increased penalties for offences such as identity theft, cyberstalking, and data breaches, though for some offences including several cyberstalking-related provisions – the fines and prison terms were left largely unchanged from 2015, at up to three years’ imprisonment.
  2. Unauthorised access to computer systems. It remains an offence to intentionally access a computer system without authorisation for a fraudulent purpose in order to obtain data vital to national security. The maximum penalty is five years’ imprisonment, a fine of up to ₦5 million, or both. Where someone accesses a system with intent to obtain commercial or industrial secrets or classified information, the maximum penalty rises to seven years’ imprisonment and a fine of up to ₦7 million.
  3. Interfering with computer systems intentionally and unlawfully hindering the normal functioning of a computer system. For example, by damaging, deleting, or altering data carries a maximum penalty of two years’ imprisonment and a fine of up to ₦5 million.
  4. The amendment introduced a cybersecurity levy to help fund national cybersecurity initiatives, to be implemented through participating financial institutions and other designated bodies.
  5. Mandatory cybersecurity measures for organisations, businesses and public institutions now face specific obligations; including setting up sectoral computer emergency response teams (CERTs). Organisations classified as Critical National Information Infrastructure providers such as telecoms firms, electricity grid operators, and financial switching companies, among others must now conduct quarterly vulnerability assessments, submit compliance reports to the National Cybercrime Centre, and appoint a dedicated Cybersecurity Compliance Officer.
  6. Security agencies can now intercept communications without a court order in cases deemed “urgent,” and telecom companies are required to retain user data for longer periods. Civil society groups have raised concerns that this expands the state’s surveillance capacity with limited independent oversight.
  7. The amendment removed the widely criticised Section 48(4) of the 2015 Act, which had allowed courts to cancel the passports of convicted Nigerians and withhold the passports of convicted foreigners.
  8. The law strengthens Nigeria’s legal basis for cooperating with other countries on cross-border cybercrime investigations, in line with the Budapest Convention on Cybercrime framework.

WHAT REMAINS UNCLEAR OR DISPUTED

Some provisions of the law particularly those criminalising “false” or “misleading” online posts have drawn criticism from press freedom and human rights groups, who argue the wording is broad enough to be used against journalists and government critics. This concern predates the 2024 amendment and has continued into its enforcement.

There is, at this stage, no verified, specific legal provision establishing automatic liability for WhatsApp, Facebook, or Telegram group administrators simply for content posted by members. Claims to that effect have circulated widely online but should be treated with caution until confirmed against the Act’s actual text or an authoritative legal source. Group admins should still exercise reasonable moderation as good practice, but sweeping claims about automatic personal criminal liability are not something this piece can confirm.

WHY THIS MATTERS FOR CONTENT CREATORS AND ADMINS

Regardless of the confusion around a “2025” law, the 2024 Amendment Act is real, in force, and does carry meaningful penalties for unauthorised access, data interference, and related offences. Anyone running an online platform or community in Nigeria should be aware of it  but should be equally wary of exaggerated or fabricated versions of the law circulating on social media, which tend to inflate penalties and invent provisions to drive fear-based sharing.

Readers who need to rely on the exact wording for legal or compliance purposes should consult the official gazetted text of the Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act, 2024, or seek advice from a qualified Nigerian lawyer, rather than relying on summaries.

Sources: Africa Check; The ICIR (FactCheckHub); AllAfrica; Mondaq (Nigeria); ICLG Cybersecurity Laws and Regulations 2025 (Nigeria chapter); SabiLaw; AB Legal Practitioners; NALTF; Lex Initiative for Rights Advocacy and Development (LIRAD).

Leave a Reply

Your email address will not be published. Required fields are marked *