{"id":28774,"date":"2026-06-04T09:00:58","date_gmt":"2026-06-04T07:00:58","guid":{"rendered":"https:\/\/voelkerrechtsblog.org\/?p=28774"},"modified":"2026-06-05T10:13:25","modified_gmt":"2026-06-05T08:13:25","slug":"the-regulatory-command-asymmetry","status":"publish","type":"post","link":"https:\/\/voelkerrechtsblog.org\/de\/the-regulatory-command-asymmetry\/","title":{"rendered":"The Regulatory-Command Asymmetry"},"content":{"rendered":"<p>The urgency of reconciling the territorial limits of sovereign jurisdiction with the deterritorialised movement of data is a question of data sovereignty.\u00a0Within Africa, this question is ambitiously addressed by Nigeria\u2019s package of regulatory frameworks, which combines a comprehensive data protection statute, detailed implementation regulations, a draft Digital Sovereignty Bill, and a national AI policy\u2014\u00a0a combination without a clear analogue elsewhere on the continent. Yet, political will and robust regulatory drafting are not sufficient to guarantee data sovereignty. The case of Nigeria illustrates why. Nigeria\u2019s data-regulation architecture, however well-drafted, operates within what this post terms a regulatory-command asymmetry: a structural gap between lawful assertion of prescriptive jurisdiction and the capacity to enforce it, produced by the interaction of Nigerian regulatory instruments with the extraterritorial reach of another state\u2019s public law over the same corporate entity. The gap is not doctrinal. It is a function of the infrastructural, economic, and diplomatic leverage that conditions the exercise of effective jurisdiction\u2014 leverage which Nigeria, and the wider continent, presently lack in relation to the corporate parents that hold the data.<\/p>\n<p>The discussion in this blogpost\u00a0demonstrates how the operative instrument of extraterritorial jurisdiction asserted by the United States\u2014 the Clarifying Lawful Overseas Use of Data Act (<a href=\"https:\/\/www.justice.gov\/criminal\/media\/999391\/dl?inline\">CLOUD Act<\/a>) 2018\u2014 produces the regulatory-command asymmetry that structurally overrides Nigerian prescriptive jurisdiction, and then offers recommendations for rectifying it.<\/p>\n<p><strong>The Architecture and the Instrument<\/strong><\/p>\n<p>Nigeria\u2019s data sovereignty architecture is ambitious. Signed on 12 June 2023, \u00a0<a href=\"https:\/\/placng.org\/i\/wp-content\/uploads\/2023\/06\/Nigeria-Data-Protection-Act-2023.pdf\">the Nigeria Data Protection Act 2023<\/a> (NDPA), establishes extraterritorial application in section 2(2), applying to any data controller or processor handling the personal data of Nigerian subjects,\u00a0regardless of location. To regulate data flows, section 41 restricts cross-border transfer of personal data,\u00a0conditioning it under sections 41(1) and 42 on the recipient providing an adequate level of protection that is substantially similar to the NDPA.\u00a0Alternatively, section 43 permits cross-border transfers under six specific exceptions known under the NDPA as derogations. Finally, the Act creates the Nigeria Data Protection Commission (NDPC) as the primary regulator. <a href=\"https:\/\/ndpc.gov.ng\/wp-content\/uploads\/2025\/03\/NDP-ACT-GAID-2025-MARCH-20TH.pdf\">The General Application and Implementation Directive<\/a> (GAID) 2025\u00a0operationalises the NDPA with detailed compliance obligations, such as the requirements, per art.\u00a07, for data controllers and processors to register with the NDPC and to file NDP Act Compliance Audit Returns with the same NDPC, not later than the 31st of March every year. The draft Nigeria Digital Sovereignty and Fair Data Compensation Bill 2025 and the draft National AI Commission Bill 2025\u2014both illustrations of political momentum for digital sovereignty\u2014 are currently in <a href=\"https:\/\/iapp.org\/news\/a\/nigeria-moves-toward-comprehensive-ai-regulation\">active legislative development<\/a>. This is among the most comprehensive digital-sovereignty packages in <a href=\"https:\/\/carnegieendowment.org\/features\/africa-digital-regulations\">Africa<\/a>. These frameworks, however, have not secured effective data sovereignty and, given the structural subordination of territorial jurisdiction to external legal commands, are unlikely to do so. Effective data sovereignty necessitates the actual operational\u2014not just legal\u2014capacity of a state to determine the conditions under which data generated by, about, or held in respect of its residents and territory can be accessed, processed, or transferred.<\/p>\n<p><a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/2713\">Section 2713 of Title 18<\/a> of the US Code, the reason for the lack of effective data sovereignty, added by the <a href=\"https:\/\/www.justice.gov\/criminal\/media\/999391\/dl?inline\">CLOUD Act<\/a>, compels providers subject to US jurisdiction to preserve, back up, and disclose the contents of wire or electronic communications and other records within the provider\u2019s possession, custody, or control, regardless of whether the data is located inside or outside the United States. The statute operates on the corporate parent and reaches any data the parent controls, including data held by Nigerian subsidiaries and on infrastructure located in Lagos or elsewhere. Section 2523 authorises executive agreements creating reciprocal direct-access channels with qualifying foreign governments. Presently, only the <a href=\"https:\/\/www.justice.gov\/criminal\/criminal-oia\/cloud-act-agreement-between-governments-us-united-kingdom-great-britain-and-northern\">United Kingdom<\/a> and <a href=\"https:\/\/www.justice.gov\/criminal\/criminal-oia\/cloud-act-agreement-between-governments-us-and-australia\">Australia<\/a> qualify and have entered into such agreements.<\/p>\n<p>The NDPA and the CLOUD Act therefore constitute competing assertions of jurisdiction\u00a0over the same data \u2014 personal data of Nigerian residents held by US-parented providers \u2014 with incompatible commands. The NDPA regulates the same entity that is subject to the CLOUD Act\u2019s command. This is the regulatory-command asymmetry: a familiar tension between jurisdiction to prescribe and jurisdiction to enforce, but one that is produced here not through inter-state conflict of laws in the classical sense but through the corporate form itself.\u00a0The attempt to treat this asymmetry simply as a conflict-of-laws issue presupposes a symmetric relationship between states and an adjudicable disputation that is not obtainable in the specific instance. First, the jurisdictional conflict is asymmetric: the US command reaches the corporate parent regardless of what Nigeria commands the local subsidiary, and Nigeria has no symmetrical capacity to reach a US parent if it disagreed. Second, this asymmetry is not a feature of any disputation, characteristic of conflict-of-laws analyses, but rather a consequence of how the corporate form and US extraterritorial jurisdiction constitute the architecture in which Nigeria\u2019s data sovereignty is foreclosed. Put differently, the conflict is adjudicated <em>before<\/em> a conflict-of-law analysis.\u00a0Contrarily, a <a href=\"https:\/\/law.yale.edu\/sites\/default\/files\/area\/center\/isp\/documents\/extraterritorial_enforcement_paper.pdf\">Yale ISP white paper<\/a>\u00a0on this issue, which focused on the conflict-of-laws register, engaged with the Global South in passing. Moreover, the same paper accepted that \u201cthe primary reason for the failure to resolve the internet jurisdictional puzzle to\u00a0date lies in the compartmentalization of the discourse\u201d but failed to engage a political-economy lens.<\/p>\n<p>By converting structural questions into technical-juridical questions of choice-of-law, choice-of-remedy, choice-of-jurisdiction, comity analysis etc., the choice-of-law analysis presupposes an adjudicable issue that, as we will see below, is decided not by \u201cwhat is the choice-of-law\u201d but rather \u201cif we are compelled, we hand over the data.\u201d<\/p>\n<p><strong>Regulatory-Command Asymmetry<\/strong><\/p>\n<p>The asymmetry is not theoretical. On 10 June 2025, Anton Carniaux, legal director of Microsoft France, appeared before the French Senate inquiry commission. Asked under oath whether Microsoft France could guarantee French customer data against the reach of US authority, Carniaux\u00a0<a href=\"https:\/\/www.actuia.com\/en\/news\/sensitive-data-and-cloud-act-microsoft-france-admits-it-cannot-oppose-an-american-injunction\/\">replied<\/a>: \u201cIf we are compelled, we hand over the data.\u201d<\/p>\n<p>This admission demonstrates a structural issue. It names the mechanism this post calls the regulatory-command asymmetry, i.e. the structural subordination of host-state civil regulation to home-state criminal investigation commands over the same corporate entity. Several features produce this outcome.<\/p>\n<ol>\n<li><em>Addressee mismatch.<\/em> Host-state regulation binds the local subsidiary (e.g.\u00a0Microsoft Nigeria Ltd). Home-state command binds the corporate parent (Microsoft Corporation). These are distinct legal persons. A Nigerian sanction of Microsoft Nigeria does not reach, nor prevent, Microsoft Corporation\u2019s \u00a7 2713 obligation. The asymmetry here reflects a deficit of political leverage: although section 2 of the NDPA is directed at the foreign parent company, enforcement in practice is politically costly, aside from the bureaucratic and judicial obstacles to enforcing against a foreign parent (as evidenced by the Federal Competition and Consumer Protection Commission\u2019s $220 million <a href=\"https:\/\/fccpc.gov.ng\/violations-tribunal-upholds-fccpcs-220-million-fine-against-meta-whatsapp\/\">fine<\/a> against Meta\/WhatsApp, which remains unpaid). Robust enforcement might also expose Nigeria to designation under the <a href=\"https:\/\/ustr.gov\/issue-areas\/intellectual-property\/special-301\">USTR Special 301 report<\/a>, a diplomatic and economic tool used to pressure foreign governments to remove barriers targeting US companies, potentially through withdrawing trade preferences or escalating to formal trade disputes.<\/li>\n<li><em>Control-doctrine mismatch.<\/em> Under the CLOUD Act, Microsoft Corporation has \u2018control\u2019 of data held by its subsidiaries for the purposes of \u00a7 2713. The parent can produce the subsidiary\u2019s data regardless of the subsidiary\u2019s resistance. The asymmetry here flows from infrastructural and economic power.<\/li>\n<li><em>Sanction-severity<\/em><em> and Market-power<\/em><em> mismatch.<\/em> Nigerian enforcement of the NDPA operates principally through civil penalties. Under section 48(4), penalties may reach up to 2 percent of annual gross revenue for data controllers of major importance. If a provider refuses to disclose data as required by \u00a7 2713 Cloud Act, the Courts can enforce the obligation through a contempt of court <a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/18\/401\">under 18 U.S.C. \u00a7 401<\/a>. Rational corporate decision-making selects the lesser sanction; thus,\u00a0criminal compulsion with the prospect of deprivation of liberty outranks civil fines. More crucially, a US corporation that pushes against US authority risks losing government contracts, regulatory goodwill, technology export licenses, capital-market access, and the ecosystem that sustains its corporate agenda, whereas a Nigerian fine is only a tactical rather than existential cost.<\/li>\n<li><em>Instrument mismatch.<\/em> Nigerian digital-sovereignty engagement with US hyperscalers is conducted principally through MoUs and MoU-equivalent arrangements that are not published, not ratified, and not legally enforceable in ways that could override US public-law compulsion on the hyperscaler\u2019s parent. This stands in contrast to the government-to-government executive agreements under the CLOUD Act, which create a procedural mechanism for foreign qualifying governments to assert their interests in cross-border data disputes\u2014a mechanism unavailable to countries like Nigeria not party to such an agreement.<\/li>\n<\/ol>\n<p>The asymmetry is therefore not a drafting defect in the NDPA. Pending legislative interventions requiring data localisation will prove no more useful. The deeper implication \u2014 which the European Union has confronted \u2014 is that <a href=\"https:\/\/gdpr-info.eu\/art-48-gdpr\/\">Article 48 GDPR<\/a>, which restricts the transferral of data upon a court order under certain conditions, could not prevent the Carniaux admission. Nigerian drafting will not do better than the GDPR by legislating harder.<\/p>\n<p>A second dimension compounds the first. The CLOUD Act\u2019s \u00a7 2703(h) provides a statutory comity framework but only for customers of providers in qualifying countries under \u00a7 2523. Non-qualifying states, including Nigeria and effectively all of Africa, are left with residual <a href=\"https:\/\/office.voelkerrechtsblog.org\/9.4.0-acf6d914e878574b82d913eb56967c2d\/web-apps\/apps\/documenteditor\/main\/index.html?_dc=9.4.0-129&amp;lang=en&amp;customer=ONLYOFFICE&amp;type=desktop&amp;frameEditorId=iframeEditor&amp;mode=view&amp;isForm=false&amp;compact=true&amp;parentOrigin=https:\/\/nx52645.your-storageshare.de&amp;uitheme=theme-system&amp;fileType=docx#:~:text=To%20address%20concerns%20raised%20by,government%20provides%20%22robust%20substantive%20and\">common-law comity analysis<\/a>. Common-law comity tends to favour the US interests since it is discretionary, provider-initiated, depends on the forum court\u2019s initiative, and is ultimately applied in a way that prioritises domestic interests. Nigerian data subjects are thus doctrinally excluded from the procedural protections that US law extends to customers in qualifying countries: qualifying countries receive reciprocal access and statutory comity; non-qualifying countries receive neither.<\/p>\n<p><strong>The Path Forward?<\/strong><\/p>\n<p>First, the path forward begins with the recognition that ambitious data-localisation laws and genuine expressions of data sovereignty cannot, on their own, renegotiate the structural asymmetry between Nigeria and US hyperscalers.<\/p>\n<p>Second, <em>architectural measures<\/em>. For designated categories of sensitive Nigerian data \u2014 National Identification Numbers, Bank Verification Numbers, health-registry data, financial KYC data, and government communications \u2014 the NDPC should require processing on infrastructure outside the \u00a7 2713 \u2018possession, custody, or control\u2019 chain. This would require a national cloud solution.<\/p>\n<p>Third, <em>collective action<\/em>. Nigeria\u2019s leverage deficits are individual; collective action reduces them. <a href=\"https:\/\/au.int\/en\/treaties\/protocol-agreement-establishing-african-continental-free-trade-area-digital-trade\">The AfCFTA Protocol on Digital Trade<\/a> provides the continental instrument which commits AU member states to permitting cross-border data transfers subject to legitimate public policy restrictions, requires member states to adopt personal data protection frameworks, and commits them to cooperation on data governance. Nigeria should advocate for an annex, parallel to Article 48 GDPR, requiring that production of African-held personal data to non-African governments be channelled through mutual legal assistance treaties or an African Union framework instrument. A continental blocking norm is materially harder for the United States to punish bilaterally than a Nigerian one.<\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>The regulatory-command asymmetry raises questions that go beyond Nigeria and beyond the NDPA. The classical architecture of international law assumes that the extraterritorial reach of one state\u2019s laws is contested, where it is contested at all, in the forum of inter-state relations: through the Lotus reservation, through comity analysis, through mutual legal assistance, and ultimately through the sovereign equality of states expressed in Article 2(1) of the UN Charter. The CLOUD Act operates in a different register. It does not assert jurisdiction over Nigerian territory; it asserts jurisdiction over a corporate parent whose subsidiaries happen to hold data generated on Nigerian territory. The conflict is displaced from the inter-state plane to the corporate-structural plane, and the tools classical international law has developed for the former do not reach the latter.<\/p>\n<p>For states outside the \u00a7 2523 club \u2014 basically every state on the African continent \u2014 the consequence is that jurisdiction to prescribe and jurisdiction to enforce come apart in a manner that sovereignty instruments cannot, by themselves, close. Nigeria\u2019s prescriptive reach under section 2(2) NDPA is lawful and\u00a0uncontroversial as a matter of principles of international law, such as territoriality and active personality. Its enforcement reach against Microsoft Corporation, Alphabet, or Amazon is not a legal question at all.\u00a0It is a question of political economy, of infrastructure, and of the asymmetric costs of assertion. Recognising this is the precondition for any serious response.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The urgency of reconciling the territorial limits of sovereign jurisdiction with the deterritorialised movement of data is a question of data sovereignty.\u00a0Within Africa, this question is ambitiously addressed by Nigeria\u2019s package of regulatory frameworks, which combines a comprehensive data protection statute, detailed implementation regulations, a draft Digital Sovereignty Bill, and a national AI policy\u2014\u00a0a combination [&hellip;]<\/p>\n","protected":false},"author":35,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6639],"tags":[4868,3616,3912,4772],"authors":[8013],"article-categories":[6000],"doi":[],"class_list":["post-28774","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-data-protection","tag-global-south","tag-jurisdiction","tag-sovereignty","authors-samuel-w-ugwumba","article-categories-article"],"acf":{"subline":"Nigeria\u2019s Data Sovereignty Instruments and the US CLOUD Act"},"meta_box":{"doi":"10.17176\/20260604-190051-0"},"_links":{"self":[{"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/posts\/28774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/users\/35"}],"replies":[{"embeddable":true,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/comments?post=28774"}],"version-history":[{"count":3,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/posts\/28774\/revisions"}],"predecessor-version":[{"id":28780,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/posts\/28774\/revisions\/28780"}],"wp:attachment":[{"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/media?parent=28774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/categories?post=28774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/tags?post=28774"},{"taxonomy":"authors","embeddable":true,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/authors?post=28774"},{"taxonomy":"article-categories","embeddable":true,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/article-categories?post=28774"},{"taxonomy":"doi","embeddable":true,"href":"https:\/\/voelkerrechtsblog.org\/de\/wp-json\/wp\/v2\/doi?post=28774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}