Open banking, closed courts? Liability and dispute dynamics in Nigeria’s API ecosystem

Open Banking refers to a framework that allows for the secure sharing of financial information through an Application Programming Interface (API), among authorised third-party developers.

Nigeria can be credited as one of the earliest African countries to formally regulate open banking through a central bank-driven framework and API standards as opposed to relying solely on industry-led initiatives. The regulatory journey formally commenced with the issuance of the Central Bank of Nigeria (CBN) Regulatory Framework for Open Banking in Nigeria in February 2021, which established the foundational principles, participant categorizations and API risk tiers. This was subsequently operationalised through the CBN’s Operational Guidelines for Open Banking in Nigeria 2023 (CBN Guidelines) which provide a firm foundation for participation, data governance and technical interoperability within an emerging ecosystem.

This article examines emerging liability hotspots within Nigeria’s open banking ecosystem, focusing on contractual privity in multi-party API relationships, responsibility for data breaches, and the adequacy of the existing dispute resolution mechanisms. It argues that while Nigeria has established a functional regulatory architecture for open banking, the liability and dispute resolution architecture remains underdeveloped, which leaves significant uncertainty and risks for banks, FinTech firms and end-users alike.

In a multi-party API system in Open Banking, privity of contract works as a tripartite relationship between the bank (financial institution or API Provider), the third-party service provider (the API Consumer) and the user (the Customer).

The user must consent before any third-party data sharing can be done by the bank, and any third party data processing or control can be done by the third-party service provider. The bank and third-party service provider are limited to the extent of the consent given by the user and have a duty to process the user’s data in accordance with the Nigeria Data Protection Act.

For the bank and the third-party service provider, the contract is grounded in the ordinary principles of contract and contractual privity. The CBN Guidelines require both parties to be registered on the open banking Registry. They must also comply with defined responsibilities, including access rules, security standards, data ethics obligations, and consent management -requirements. The contract must clearly define each party’s obligations, permitted data uses, liability for breach, and termination rights, ensuring enforceable accountability while upholding customer permissioned data -sharing.

Data breach incidents: Responsibilities of the parties and possible defences

Under the CBN Guidelines, the bank and third-party service provider have a duty to implement measures to prevent a data breach. They are also mandated to develop a data breach policy. Where a breach occurs, the responsible parties (which can be either the bank or the third party service provider or both) must rely on their established data breach- policy to deal with the breach. The CBN Guidelines provide that such policy must be one that emphasises prevention, preparedness, structured assessment, and procedure to contain the breach. A data breach incident must also be promptly communicated to all relevant parties including the CBN, with a subsequent review to ascertain the underlying cause of the incident. The responsible party(ies) must promptly contain the incident, communicate with relevant parties, analyse root causes, and implement corrective measures. The bank and third-party provider must also ensure that there is strict adherence to the policy in the event of a data breach.

A data breach lawsuit would most likely be an action in tort based on the failure of the responsible party to protect the customer’s data. In the event of a data breach suit, the bank and third party may rely on the following possible defences depending on the nature of the suit:

i. Compliance with regulatory standards: The Responsible party may raise the defence and tender evidence that it complied with the relevant legislations such as the Central Bank of Nigeria Open Banking Guidelines, 2023, and the Nigeria Data Protection Act, 2023.

ii. Third-Party Liability: The bank can raise the defence that the data breach was caused by the third-party service provider.

iii. Customer negligence: The responsible party may raise the defence that customer negligence or carelessness with their data led to the data breach. The bank may also raise the defence of contributory negligence.

iv. Force majeure: An example of a force majeure is a sophisticated cybersecurity attack that bypassed industry-standard security measures.

Dispute resolution mechanisms: Arbitration clauses vs. CBN’S complaint channels

Under the CBN Operational Guidelines for Open Banking 2023, participants are mandated to incorporate formal dispute resolution procedures within their bilateral Service Level Agreemnents (SLAs), alongside providing clear complaint channels for end-users. In practice, banks and FinTechs routinely insert private arbitration clauses into these commercial SLAs, favouring arbitration for its confidentiality, speed and technical expertise. While arbitration provides an efficient bilateral forum, its utility across the broader Open Banking ecosystem is constrained by fundamental legal limitations.

First, end-users are not parties to inter-institutional SLAs and are therefore not bound by, nor can they benefit from arbitration clauses contained within bank-FinTech agreements under the doctrine of contractual privity. Secondly, API chains involve multiple distinct actors – banks, API aggregators, middleware providers and consumer facing FinTechs – operating under separate contractual frameworks. Despite the procedural mechanisms for joinder and consolidation introduced under Sections 39 and 40 of the Arbitration and Mediation Act 2023, arbitrating multi-party API failures across disconnected agreements remains procedurally complex. This is because joinder and consolidation generally still require consent or proof that all entities are bound by the same underlying arbitration agreement.

Importantly, the CBN Guidelines do not prescribe litigation, nor could any regulatory guidelines override the constitutional jurisdiction of Nigerian courts to adjudicate civil rights and commercial obligations. Litigation remains fully available to aggrieved institutional participants and consumers. However, traditional court litigation presents significant practical drawbacks in API disputes. Public court records risk exposing sensitive software architecture or operational vulnerabilities, while formal judicial proceedings are often ill-equipped for the rapid technical remediation required in automated financial rails.

As an alternative to private arbitration and court litigation, the CBN framework mandates internal grievance procedures and permits unresolved customer disputes to be escalated to the CBN Consumer Protection Department. However, while the Consumer Protection Department provides essential administrative oversight and consumer redress, its supervisory role is not designed to function as an adjudicatory court or arbitral tribunal capable of determining complex contractual damages, allocating multi-party tortious liability or enforcing cross-indemnities between institutional actors.

Indemnity clauses and risk redistribution

Open Banking transactions involve multiple parties – banks, FinTechs, API providers, infrastructure partners, and customers – often operating under separate but interconnected contracts.

Indemnity clauses therefore serve as a redistributor, allowing a party that is externally liable – whether to a customer or regulator – to shift financial responsibility internally to the actor whose conduct caused the loss. For example, where a bank reimburses a customer for an unauthorised debit traceable to a FinTech’s compromised API integration, the bank may rely on contractual indemnification to recover that loss.

Under Nigerian contract law, indemnity clauses are generally enforceable where clearly drafted and not contrary to public policy. However, courts interpret such provisions strictly. At the same time, overly expansive indemnities bear the risk of creating imbalance within the open banking ecosystem. Smaller FinTech participants may face disproportionate exposure, especially where losses stem from systemic or shared infrastructure failures beyond their exclusive control. The drafting challenge therefore lies in balancing effective risk allocation with commercial sustainability.

Limitation of liability and exposure management

While indemnities redistribute loss, limitation clauses define its outer boundary; typically limit aggregate liability, exclude indirect or consequential losses, and carve out exceptions for fraud, willful misconduct, or gross negligence. Such clauses cannot ordinarily exclude liability for fraud or deliberate wrongdoing, and their enforceability depends on clarity and proper incorporation.

However, tension arises where liability stems from statutory breach. The Nigeria Data Protection Act 2023 imposes mandatory obligations on data controllers and processors, and regulatory fines imposed for statutory non-compliance may not be easily neutralized through contractual limitation. Thus, while parties may allocate financial responsibility amongst one another, they cannot avoid regulatory accountability through their contracts. This distinction becomes particularly significant in disputes involving data breaches or systemic API failures.

Conclusion

Nigeria’s pioneer adoption of Open Banking under the regulatory stewardship of the CBN has established a commendable framework for financial solid regulatory and technical foundation for data sharing and FinTech innovation. However, as this article has demonstrated, a significant divergence remains between Nigeria’s advanced technical architecture and its legal and dispute resolution framework, the core vulnerabilities identified across this article include – the doctrine of contractual privity in multi-party API chains, the complex allocation of tortious liability during data breaches and the procedural limitations of existing dispute channels – reveal an ecosystem where systemic risks are easily shifted rather than effectively managed.

Left unaddressed, these structural gaps threaten to undermine institutional trust and slow the commercial adoption of open banking. Bridging this divide requires aligning private commercial arrangements with broader public regulatory objectives through a multi-pronged legal approach. Firstly, the CBN should issue supplemental regulatory guidance that explicitly defines statutory default rules for liability allocation and indemnification in common multi-party scenarios. Secondly, industry stakeholders must move away from fragmented bilateral dispute mechanisms toward a dedicated, institionalised Open Banking Dispute Resolution Panel capable of adjudicating complex, multi-party API claims. Finally, enhancing judicial familiarity with financial technology and data protection law through specialized judicial training will ensure that when open banking disputes reach court, judicial outcomes are technically sound and commercially sustainable.

Okechukwu Ekweanya, Partner; Nnaedozie Ajogwu and Victory Uhunmwangho, Associates – KENNA LP’s Technology, Media, and Telecommunications Practice Unit

The Legal Insights column by KENNA provides thought leadership on the legal and business issues shaping today’s commercial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *