Debarring a representative under FAIS section 14: the order of events, and the file
A representative leaves under a cloud. Section 14 of the FAIS Act tells a brokerage what to do, in what order, and inside which deadlines to notify the FSCA.
What a NAICOM-licensed broker in Nigeria may send on WhatsApp under the NDPA 2023: servicing versus marketing, consent and opt-outs, third-party motor and payments.
Nigerian brokers have been selling on WhatsApp for years: third-party motor certificates photographed and forwarded, group life schedules negotiated in a chat, microinsurance sold by agents who never meet the client. What changed is the rulebook around that chat. The Nigeria Data Protection Act 2023 created the Nigeria Data Protection Commission, the Commission has since signed a memorandum of understanding with NAICOM and met the Nigerian Council of Registered Insurance Brokers about compliance in the sector, and the Nigerian Insurance Industry Reform Act 2025 has rewritten the insurance framework itself. This article sets out what a broker may send, what needs consent, and how to run the channel so that it survives an inspection by either regulator.
A WhatsApp message from a brokerage to a client sits under two authorities at once. NAICOM licenses and supervises brokers, sets conduct and market-practice rules and now administers the NIIRA 2025, which among other things sets maximum periods for claims settlement and strengthens compulsory third-party motor cover. The NDPC enforces the NDPA 2023 and its General Application and Implementation Directive (GAID) 2025, which apply to any organisation processing personal data in Nigeria, and it has publicly identified insurance brokers as a sector processing large volumes of data with real risk if safeguards are weak. The NCRIB, the brokers' statutory body, is the channel through which much of that guidance reaches firms.
In practice, the brokerage principal should assume that a complaint about a WhatsApp message can go to either body, and that the record of what was sent, to whom and on what basis is the only defence that works with both.
The NDPA recognises processing that is necessary for the performance of a contract with the data subject, or for steps taken at the data subject's request before entering into one. A client who bought a policy through the brokerage, or asked for a quotation, has given the brokerage a reason to process their number for that purpose. Messages that fall squarely in this category:
| Message | Basis | Template type on WhatsApp |
|---|---|---|
| Renewal notice for an existing policy with the premium and due date | Contract performance | Utility |
| Confirmation that a bank transfer or USSD payment was received | Contract performance | Utility |
| Delivery of a third-party motor certificate or the NIID verification details | Contract performance | Utility |
| Claim acknowledgement, document request, claim status | Contract performance | Utility, then free-form replies inside the 24-hour window |
| Quotation the client asked for | Pre-contractual steps at the client's request | Utility or free-form reply |
| Regulatory notices such as a change in policy terms | Legal obligation / contract | Utility |
Even here, the GAID's principles on minimisation and transparency apply: the message should carry the policy reference, the amount and the action expected, not the client's national identification number or their full claims history. And the privacy notice the brokerage gives clients should say that WhatsApp is a service channel, so that the use is not a surprise.
Offers are a different matter. An upsell of comprehensive motor to a third-party client, a campaign for a new health plan, a message to a lapsed client inviting them back: these are direct marketing. Under the NDPA the data subject has the right to object to processing for direct marketing, and Nigerian courts have already ordered a major bank to stop unsolicited marketing to people who were not its customers, treating it as a breach of both the Act and the constitutional right to privacy. The NDPC's guidance follows the same line: marketing needs a lawful basis, which for most brokers means consent, and a working way to say stop.
A compliant marketing message on WhatsApp in Nigeria therefore looks like this:
In ORIS, campaigns carry a compliance tag of either service or marketing; a marketing campaign excludes every client with a marketing opt-out, and the webhook processes STOP, UNSUBSCRIBE and similar keywords automatically by recording an opt-out on the client. The general mechanics of consent and direct marketing on WhatsApp are described for the South African regime in a separate guide; the Nigerian logic is close, with the NDPC and the courts in place of the Information Regulator.
Three areas generate most of the WhatsApp traffic in a Nigerian brokerage, and each has its own pitfalls.
The NIIRA's claims provisions also give clients a concrete expectation: a maximum settlement period, and a duty on the insurer to say what is missing from a claim file. A broker who runs claims on WhatsApp can make that visible by acknowledging the claim, listing the documents, and confirming the date the complete file reached the insurer.
The NDPC can audit a data controller, and NAICOM can inspect a broker. Both will ask the same questions about WhatsApp: which number, whose phone, where are the messages stored, how is consent recorded, who can access the records, and how long are they kept. A brokerage that answers "on Ahmed's phone" has a problem. A brokerage that uses a business number connected through the WhatsApp Business Platform, a shared inbox with named users, client records with consent flags and an audit log, has an answer. The earlier guide to setting up WhatsApp Business for a brokerage describes the technical steps, which are the same in Lagos as in Johannesburg.
Two Nigeria-specific additions: appoint a data protection officer if the brokerage meets the NDPA's criteria for a controller of major importance, and check the NDPC's registration and annual audit filing requirements, which apply to many financial-sector firms. The NCRIB has said it will work with the NDPC on sector guidance; the brokerage's compliance officer should follow that work rather than wait for an enforcement notice.
A reminder about an existing policy is processing necessary for the contract, which the NDPA recognises as a lawful basis. The client should have been told in the privacy notice that WhatsApp is used as a service channel, and the message should contain no more than the renewal needs.
No. Consent under the NDPA is personal. The employer can share contact details for administering the scheme, but offers to individual employees need their own opt-in and their own opt-out route.
It is common and it is risky. The brokerage remains accountable for the personal data the agent collects, and a personal phone cannot be audited, retained or wiped on departure. A business number with a shared inbox is the defensible setup.
The date, the channel, the exact wording the client agreed to and, for WhatsApp, the message in which the client opted in. Stored against the client record, not in a spreadsheet on a laptop.
Not directly. It changes the products and the claims timelines that those communications describe, and it raises the stakes on third-party motor. The communication rules come from the NDPA, the GAID and NAICOM's market conduct expectations.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
A representative leaves under a cloud. Section 14 of the FAIS Act tells a brokerage what to do, in what order, and inside which deadlines to notify the FSCA.
What the FAIS General Code of Conduct requires of an FSP advising clients on WhatsApp: the five-year rule, electronic records, FSCA inspections and the Ombud.
NIC licensing, the Data Protection Act 2012 and MTN MoMo: how Ghanaian insurance brokers run compliant WhatsApp conversations and collect premiums.