Nigeria Reps Move to Rewrite Cyberstalking Rules, Strengthen Protections for Journalists and Whistleblowers
Meat of the Story… Nigeria’s House of Representatives has advanced a bill seeking to amend the Cybercrimes (Prohibition, Prevention, Etc.) Act, with lawmakers proposing significant changes to...
- House advances HB 2740 to narrow the scope of Section 24, introduce court oversight over disputed online communications and protect public-interest journalism from criminal prosecution.
Meat of the Story…
Nigeria’s House of Representatives has advanced a bill seeking to amend the Cybercrimes (Prohibition, Prevention, Etc.) Act, with lawmakers proposing significant changes to the controversial cyberstalking provisions that have historically raised concerns over freedom of expression and investigative journalism.
The proposed legislation, Cybercrimes (Prohibition, Prevention, Etc.) (Amendment) Bill, 2026, HB 2740, was introduced by House spokesperson Akin Rotimi and passed first reading in April. It focuses principally on Sections 24, 27 and 38 of the existing law.
The proposed changes would create clearer boundaries around criminal cyberstalking, strengthen protections for journalists and whistleblowers handling confidential information in the public interest, and introduce greater judicial oversight over access to journalists’ and whistleblowers’ digital data.
Analysis
Section 24 has remained one of the most contested provisions of Nigeria’s cybercrime framework. The original 2015 law contained broad language that critics argued could allow criminal proceedings over online communications perceived as annoying, insulting or anxiety-inducing.
The 2024 amendment narrowed the provision, limiting the offence to certain messages that are pornographic or knowingly false and associated with a breakdown of law and order or threats to life.
HB 2740 proposes to go further by establishing clearer safeguards for public-interest publications. Where a dispute concerns reputation, defamation, alleged falsehood or cyberstalking arising from public-interest reporting, the proposed framework would direct the matter towards civil remedies rather than criminal prosecution.
The bill would also prevent law enforcement agencies or private complainants from having the final say on whether a communication constitutes false information, causes harm or is against the public interest. Those determinations would instead be reserved for a court of competent jurisdiction.
The proposed amendment to Section 27 is equally significant for compliance and media organisations. Journalists and whistleblowers who receive or handle confidential information while investigating matters of public interest would receive an explicit exemption from prosecution, provided the information is handled lawfully and in accordance with professional standards.
Section 38 would also be amended to strengthen safeguards around retained data and communications. Under the proposal, access to or interception of data involving journalists and whistleblowers would require judicial oversight, with the principles of legality, necessity and proportionality applying to such access.
Compliance Implications
For businesses, media organisations, technology companies and regulated entities, the proposed amendments could materially change how cybercrime investigations involving public-interest reporting are handled.
The proposed judicial gatekeeping mechanism would increase the importance of formal authorisation processes when investigators seek access to protected communications or retained data. Service providers may consequently face greater obligations to verify the legal basis for disclosure requests involving journalists and whistleblowers.
The proposed protections do not amount to an unrestricted exemption from cybercrime liability. The bill links protection to lawful handling of information and adherence to professional standards. Organisations should therefore maintain clear internal policies covering confidential sources, data acquisition, information security and the handling of leaked or sensitive material.
For compliance officers, the development also highlights the importance of distinguishing legitimate investigative activity from conduct that could constitute cybercrime. Internal investigations, whistleblowing mechanisms and information security controls should be structured so that employees can report wrongdoing without unnecessarily exposing either the organisation or the reporting individual to legal risk
The proposed changes would also make legal review more important where a complaint involves allegedly false online content, defamation or public-interest reporting. Organisations should avoid assuming that a contentious publication automatically constitutes a criminal cyber offence.
Why the Update Matters
The proposed amendment represents another stage in Nigeria’s attempt to balance cybercrime enforcement with constitutional protections for freedom of expression and press freedom.
Civil society and media organisations have long criticised the use of Section 24 against journalists, activists and critics. The proposed bill responds by attempting to replace broad discretionary powers with clearer statutory thresholds and judicial oversight.
The development is particularly relevant because Nigeria’s cybercrime framework is also being used to address increasingly sophisticated digital threats, including online fraud, data-related offences and other forms of cyber-enabled crime. The challenge for lawmakers is therefore to preserve effective enforcement without creating provisions that can be used to criminalise legitimate reporting or criticism.
HB 2740 has only begun the legislative process. Having passed first reading, it still has to proceed through subsequent readings, committee scrutiny and consideration by the National Assembly before it can become law. The proposed provisions therefore remain subject to change.
For businesses and compliance teams, the appropriate approach is to monitor the legislative process rather than treat the proposed amendments as current law.
Compliance Takeaway
The proposed changes to Nigeria’s Cybercrimes Act could significantly reshape the compliance environment around online communications, confidential information and investigative reporting.
Organisations should continue applying the existing law while monitoring HB 2740 closely. Media companies, technology providers and businesses with whistleblowing or investigative functions should also review their data-access procedures, information-handling policies and legal escalation mechanisms.
The central compliance lesson is that cybercrime controls must protect digital systems without turning legitimate public-interest reporting into a criminal offence. HB 2740 seeks to establish that distinction more clearly through narrower offences, explicit protections and stronger judicial oversight.



No Comment! Be the first one.