- Background
Nigeria does not have a single, comprehensive safe harbour regime for online intermediaries. Hosting, carrying, caching, indexing or organising third-party content does not, by itself, make an intermediary liable for that content. The legal position depends on the function the intermediary performs, the nature of the content or claim, the applicable framework, what the intermediary knew or controlled, and how it responded.
That fragmented position is the organising principle of this edition of TALP’s TechBrief. It first distinguishes the main intermediary functions, then explains how liability may arise and the separate statutory or regulatory protections that may apply. It concludes with practical steps for reducing exposure and preserving available protections.
- Who is an Internet Intermediary?
An internet intermediary transmits, stores, indexes or organises content created by others. The function matters more than the label, as one business often performs several functions, each attracting a separate legal analysis. We group intermediaries by function:
- Mere conduit and access providers, which transmit data or give users access to the internet, without selecting or changing the content. Examples include network operators such as MTN Nigeria, Airtel Nigeria, Glo and T2mobile (formerly 9mobile), internet access providers such as Spectranet, ipNX and Tizeti, and cybercafes and Wi-Fi hotspot providers.
- Caching services, which store automatic, temporary copies of content to speed up delivery. Examples include content delivery networks such as Cloudflare and Akamai, and the proxy caches some Internet Service Providers (ISPs) run.
- Hosting providers, which store content at a user’s request. Examples include web hosting, cloud and data storage providers such as GoDaddy, Amazon Web Services, Whogohost, Web4Africa and Rack Centre, and email providers such as Gmail and Outlook.
- Search and indexing services, which index content held elsewhere, such as Google, Bing, Yahoo, Yandex and Baidu.
- Online platforms, which host and organise content created and shared by users, such as Facebook, X (formerly Twitter), YouTube, Reddit, Medium, Quora, Substack, WordPress and Nairaland. This category also covers online marketplaces, which host listings and transactions between independent vendors and buyers, such as Jumia, Konga, Jiji, Amazon, Etsy and eBay.
Other businesses support online activity without fitting neatly into these groups. Payment service providers such as Paystack, Flutterwave, Interswitch, Moniepoint and OPay, and domain name registries such as the Nigeria Internet Registration Association (NiRA), face their own sector rules. This edition focuses on the five (5) groups above.
- How Intermediary Liability Arises in Nigeria
Intermediary liability is not a freestanding consequence of unlawful content appearing online. It must be anchored in an underlying cause of action, a statutory or regulatory duty, or the intermediary’s own conduct. Notice, knowledge, control and response often affect the analysis, but their significance depends on the particular legal regime. Three routes are especially relevant:
- Liability under the underlying cause of action:
The intermediary may be alleged to have participated in the wrong itself. In defamation, for example, the question includes whether the intermediary participated in publication and whether any statutory or common-law defence applies. In Nicholas Okoye v Ladun Liadi, Google Inc & Google Nigeria (Suit No. LD/170/2012, judgment delivered 22 November 2022), the High Court of Lagos State held the blogger liable for defamatory comments but found the Google defendants not liable, applying the statutory defence for website operators and principles of innocent dissemination. Copyright liability is addressed differently: Part VII of the Copyright Act 2022 creates specific notice-and-takedown duties and limitations on service-provider liability.
- Liability for breach of a statutory or regulatory duty:
Separate duties may be imposed directly on an intermediary or service provider, even where the intermediary is not liable under the underlying private claim. Examples include takedown, reporting and cooperation obligations under the NCC’s Internet Code of Practice 2026, the NITDA Code and, where applicable, the Cybercrimes (Prohibition, Prevention, etc.) Act 2015, as amended in 2024. The scope, trigger and consequence of non-compliance must be assessed under the particular instrument.
- Liability for the intermediary’s own conduct:
An intermediary may incur obligations independently of third-party content. A platform that processes personal data may be a data controller or processor under the Nigeria Data Protection Act 2023 (the “NDPA”). In copyright, active intervention or participation in making content available may take the provider outside the Part VII limitations on liability. More generally, editorial intervention, modification, selective promotion or other control over specific content may be relevant to whether the intermediary remains neutral or passive under the applicable regime.
- Safe Harbour Protections in Nigeria
Nigeria’s intermediary framework combines true limitations on liability with notice-and-takedown and compliance duties. The principal regimes include:
- The Copyright Act 2022:
Part VII of the Copyright Act 2022 creates both a notice-and-takedown procedure and limitations on service-provider liability. A copyright owner may send a written notice satisfying section 54. On receipt, the service provider must promptly notify the subscriber, expeditiously take down or disable access to the infringing content or link, and notify the copyright owner. It must also take effective steps, in accordance with high industry standards, to prevent removed content from being reloaded and must promptly remove it again if it reappears and the provider becomes aware of it.
The Act also provides a counter-notice and repeat-infringer process. A subscriber may submit a written counter-notice, which the service provider must forward immediately to the copyright owner. The provider may restore the content if, within seven days after forwarding the counter-notice, it receives no response from the copyright owner indicating that no authorisation has been granted. A dissatisfied party may refer the matter to the Nigerian Copyright Commission. For repeated notifications relating to an account, section 56 requires a warning after the first notification and, subject to a pending challenge, suspension for at least one month after a second notification. Knowingly false claims of infringement or mistaken removal can attract damages under section 57.
Non-compliance has direct consequences. Under section 55(6), a service provider that fails to comply with the takedown and counter-notice requirements is liable for breach of statutory duty and for the infringement to the same extent as the person who placed the content on the system or network. Separately, the law limits monetary liability for qualifying user-directed storage and information-location tools, subject to conditions including lack of actual or apparent knowledge, absence of disqualifying financial benefit where the provider has the right and ability to control the activity, and expeditious action on notice. It also limits these protections to neutral, automatic and passive activities and to providers that do not take an active role in making content available and that designate an agent or address to receive notices.
- NCC Internet Code of Practice 2026:
The NCC published the revised Code in February 2026. It is a distinct regulatory instrument and does not itself create a safe harbour. For Internet Access Service Providers, there is generally no obligation to monitor stored or transmitted content, except when acting under an NCC or law-enforcement instruction. Once the NCC determines reported content is unlawful and issues a takedown notice, an IASP is expected to deny or disable access within 24 hours. The Code separately requires covered online and digital communications platforms, digital service providers and application service providers to submit community rules or guidelines within six (6) months, make biannual renditions and maintain a channel for engagement with the NCC’s Designated Online Governance Officer. Non-compliance is addressed through remedial directions and the NCC’s enforcement framework.
- NCC Guidelines for the Provision of Internet Service:
The Guidelines apply to licenced providers of Internet access services and other Internet Protocol-based telecommunications services. The Guideline provides distinct mere-conduit, caching and hosting limitations on liability. For hosting, the ISP is protected where it satisfies the listed conditions, including lack of knowledge of illegal activity and action without delay on receipt of a takedown notice. It separately requires ISPs to maintain a procedure for receiving and promptly responding to content complaints and takedown notices issued by the NCC or another legal authority. For hosting, the relevant conditions include that the ISP does not:
- modify the information;
- interfere with any conditions of access applicable to the information;
- interfere with the lawful use of technology to obtain data on the use of the information;
- have knowledge of illegal activity related to the information; and
- delay in removing or disabling access to the information on receipt of any takedown notice.
- NITDA Code:
The Code of Practice for Interactive Computer Service Platforms/Internet Intermediaries was issued by NITDA in collaboration with the NCC and the National Broadcasting Commission in 2022. Its scope includes social media operators, websites, blogs, media-sharing websites, online discussion forums, streaming platforms and similar intermediaries. Its obligations must therefore be read together with other applicable Nigerian laws and sector-specific instruments where their scopes overlap.
Under the Code, a platform receiving a notice from an Authorised Government Agency of unlawful content must acknowledge it and take down the content within 48 hours; on a user notice, it must acknowledge the complaint and take down the content as soon as reasonably practicable. The Code also protects a platform from liability for taking down unlawful content on a substantiated notice and states that no liability is incurred where the platform can demonstrate due diligence and all reasonable steps to prevent unlawful content from being uploaded. All platforms must file an annual compliance report with NITDA, while a “Large Service Platform”, defined as having more than one million (1,000,000) Nigerian users, must satisfy additional obligations, including appointing a liaison officer. These requirements may apply concurrently with content-specific or sector-specific regimes, so compliance with the NITDA Code should not be treated as a substitute for separate obligations under the Copyright Act, NCC instruments or data protection law.
- Defamation Law (Lagos State):
Section 12 of the Defamation Law of Lagos State 2015 provides a defence to a website operator in an action concerning a statement posted on the website where the operator did not post the statement. The defence is defeated in specified circumstances, including where the claimant gave a notice of complaint and the operator failed to respond to the notice or take steps to remove the statement. This is a Lagos State statutory example, not a general Nigerian safe harbour.
Operators facing claims governed by the law of another state should not assume that an equivalent statutory defence applies. The analysis should begin with the relevant state law and any applicable common-law principles, including publication and innocent dissemination.
- Limits of Nigeria’s Safe Harbour Protections
The protections remain fragmented. Part VII of the Copyright Act is confined to copyright and to service-provider activities satisfying its statutory conditions. The NCC Guidelines apply to licenced ISPs. The Internet Code of Practice 2026 imposes obligations on IASPs and other impacted entities but does not create an equivalent limitation on liability. The Lagos State website-operator defence is jurisdiction-specific. The NITDA Code creates its own limited protections but does not displace other applicable duties.
The interaction between the legal regimes matters. A single business may simultaneously perform hosting, access, search or platform functions and may fall within more than one instrument. The practical task is therefore not to identify one universal safe harbour, but to map each function and category of content against every applicable legal regime, then identify and satisfy the notice, response, record-keeping and escalation requirements that apply under each.
- Practical Steps to Reduce Liability
Notice and knowledge matter across several frameworks, but there is no single trigger or deadline. The best defence is built before a complaint or regulatory notice arrives:
- map each function you perform (access, caching, hosting, search, platform or marketplace) against the regimes above, since your protection depends on the function, not the label;
- publish clear Terms of Use and Community Guidelines which ban unlawful content and explain how you handle complaints, and file them with the NCC where required;
- set up an always-open channel for notices from users, rights holders and government agencies, name a responsible officer, and offer an appeal route for users who believe their content was wrongly removed;
- set internal response deadlines shorter than the regulatory windows;
- keep a dated log of every notice, decision and action;
- verify user identity only where the law requires it or the nature of your service justifies it, and keep the data you hold accurate and secure, so you can respond to lawful disclosure orders without breaching privacy rules;
- avoid any form of interference, including editorial intervention, modification, selective promotion or other control over specific user content, which may weaken the argument your role is neutral, automatic and passive; and
- once a notice is received, assess the notice, remove or disable access to clearly unlawful content, inform the uploader, handle any counter-notice within the Copyright Act timelines, and preserve removed content and related data securely.
- Conclusion
Intermediary liability in Nigeria is not determined simply by the presence of unlawful content on a platform. The intermediary’s role, the applicable legal framework, and the quality and timeliness of the intermediary’s response all decide the outcome.
No single Nigerian rule gives an intermediary universal cover. Each instrument addresses a particular function, type of content or regulatory relationship and sets its own triggers, conditions and timelines. Strong internal systems do not themselves create immunity, but they are essential to satisfying the protections that are available. An intermediary that understands the role it is performing, identifies the governing framework and responds accurately and on time is best placed to reduce exposure while preserving lawful user content.