
It usually starts the same way. A phone buzzes with a loan offer, a betting promo, or a campaign jingle from a politician whose rally you never attended, sent to a number you are fairly certain you never shared with that sender.
Multiply that moment by tens of millions of subscribers across Nigeria and Ghana, and a quieter, more structural question emerges: not just why the message arrived, but how the number got there in the first place, and why the laws written to stop this keep failing to.
Both countries have, on paper, answered the “how do I stop this” question. Nigeria’s Do-Not-Disturb (DND) service, run through the short code 2442, lets any subscriber text “STOP” to block unsolicited commercial SMS and calls; a partial version lets them opt back into specific sectors like banking or real estate. The Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Commission (NDPC) back this up with the standard architecture of modern privacy law: consent as the lawful basis for processing, a right to object to direct marketing, and penalties that can now reach ₦10 million or 2% of a company’s annual gross revenue. Ghana’s equivalent, the Data Protection Act 2012 (Act 843), predates Nigeria’s by over a decade and gives data subjects a similar right to prevent processing for the purposes of direct marketing, enforced by the Data Protection Commission (DPC).
None of this has stopped the messages.
The Pipeline Nobody Signs Off On

The mechanics behind unsolicited SMS are less mysterious than they feel. A message reaches a phone through a bulk SMS aggregator, a commercial platform that sells SMS “credits” to any business willing to pay, typically a few naira in Nigeria or Pesewas in Ghana per message. To send at scale, that business registers a sender ID, the short brand name recipients see instead of a phone number, and picks a route: a cheaper “promotional” route that respects DND registration, or a pricier “transactional” or “corporate” route explicitly built to reach DND-registered numbers for order confirmations, OTPs, and account alerts.
That second category is where the consent model quietly breaks down. Aggregator platforms market corporate and transactional routes as tools to reach customers even on DND, and while the stated rules require that businesses already hold consent before using them, nothing in the technical chain verifies that consent exists before a message is sent. The aggregator sells credits; the sender writes the message; the network delivers it. Whether the number on the list was scraped from a SIM-registration database, bought from a data broker, harvested from a delivery app, or handed over for one purpose and reused for another is not something any node in that chain is built to check. The burden of noticing, and objecting, lands on the person holding the phone.
The same absence of verification that lets marketers skip consent also lets fraud through. Nigeria’s NCC introduced a ₦10 million bulk-SMS licensing regime in 2025 partly to shut down unlicensed “grey routes” that had become a channel for phishing and fraudulent messages alongside ordinary spam. Sender-ID spoofing, where a scammer registers or hijacks an alphanumeric ID close enough to a bank’s or delivery company’s that the fake message lands in the same thread as genuine ones, is a well-documented technique precisely because the registration process was built to stop brand confusion, not to authenticate who is actually sending. A pipeline that cannot verify a marketer’s consent to message you also cannot reliably verify that the “sender” is who it claims to be.
The real-world cost of that confusion is not abstract. In a post that circulated on X, @brokaramazov99 flagged an active scam in which fraudsters were piggybacking on an MTN loyalty campaign, sending an SMS blast under the sender ID “MTNInfo” with a fake prize-redemption link. The message was indistinguishable from a legitimate MTN alert at a glance. “There is a serious social engineering scam going on that @MTNNG needs to urgently address,” he warned.
It is a near-perfect demonstration of what an unverified pipeline enables: once any sender can reach any number without prior authentication, scammers also use the same door. The inbox that normalises unsolicited contact from strangers is the same inbox that makes a fraudulent message harder to spot, and @Babyqoflife shared a personal experience when she posted that her mother had nearly paid ₦50,000 in response to a scam message she believed was legitimate. The replies on the thread were more recognition than surprise.


After years of receiving unsolicited promotional messages, Abuja resident Ola said he no longer engages with most of them. “These days, I don’t click any links from promotional SMS. We’ve seen too many scams, so I just assume they’re fake,” he said. The habit may protect him from fraud, but it also means legitimate messages are often dismissed without being opened.
Political messaging adds a second layer to the same problem. Ahead of Nigeria’s 2027 elections, the NDPC and the electoral commission INEC have opened a joint effort to secure the personal data of roughly 94 million registered voters, with NDPC’s national commissioner Vincent Olatunji publicly warning that campaigns are becoming increasingly data-driven and that his commission is watching how political actors collect information. An independent audit of 21 registered Nigerian political parties found that not one met the minimum data-protection requirements under the NDPA; several were found collecting National Identification Numbers, voter cards, and biometric data with no stated policy, no documented consent, and no accountability trail. Voter registers, campaign databases, and card-reader logs sit alongside commercial marketing lists as sources feeding the same unsolicited-SMS pipeline, just with a partisan sender ID attached.
Nigeria: Enforcement Is Arriving, But After The Fact

In Nigeria, 2025 and 2026 were the years enforcement stopped being merely a provision on paper. The NDPC fined MultiChoice Nigeria ₦766.2 million over unsatisfactory remediation of a data-handling breach and fined Fidelity Bank ₦555.8 million for processing personal data without informed consent. In August 2025, it ordered more than 1,300 organisations to prove compliance within 21 days or face enforcement orders and possible criminal liability. Courts have started backing this up directly: a Federal High Court ordered GTCO to stop unsolicited marketing to non-customers, and in a separate 2026 ruling, ordered Stanbic IBTC to pay ₦15 million to two former customers who kept receiving marketing messages after ending their banking relationship and asking the bank to stop — affirming that a customer’s objection is valid the moment it is made, with no further justification required.
That last point matters, because it exposes the shape of the gap. These wins exist because individuals- a young lawyer contesting his own spam, and a bank customer fighting unwanted marketing messages, went to court. The regulatory machinery reacts to complaints and audits; it does not, by design, verify consent at the point where a marketing list is assembled or a sender ID is approved. A subscriber can text STOP to 2442 and still receive promotional messages routed as “transactional.” They can register on DND and still be added to a fresh list a broker resells next month, and have no way to see which of the dozens of organisations that hold their number obtained it lawfully. Fixing that after the fact, one lawsuit or one embarrassing audit at a time, is not the same as closing the gap.
Ghana: The Same Principle, A Thinner Enforcement Record

Ghana’s Act 843 is, in some ways, a cleaner piece of law than the NDPA: its direct-marketing objection right is explicit, and its Data Protection Commission has existed since 2012, giving it more than a decade’s head start. Enforcement has been visible but sparse. In August 2023, the DPC brought in officials from Quick Credit and Investment Micro Credit, Hisense Ghana, and Marwako Fast Food for questioning over alleged data-protection breaches, a rare instance of the regulator naming companies rather than issuing general guidance. A year later, Ghana’s National Communication Authority opened public consultation on new rules specifically targeting spam promotional messages from network operators, suggesting the telecom regulator, not the data regulator, still leads on the SMS problem itself.
That division of labour is itself revealing. When Ghanaian subscribers complained publicly about a wave of political text messages in 2020, the Ghana Chamber of Telecommunications, representing MTN, Vodafone, and AirtelTigo, put out a statement distancing operators from the messages entirely, explaining that political parties don’t get numbers from telcos at all but from independent “content providers” who assemble phone-number databases from various sources including online and social media, while parties separately gather numbers through their own fundraising and events. It is, in effect, an industry admission that nobody in the chain is verifying where a number originally came from, only that it wasn’t them who put it there. Where Nigeria’s problem in 2026 looks like a regulator that reacts once harm has already reached the courts, Ghana’s looks like regulators pointing fingers at a different part of the pipeline. Different failure modes, same outcome: the number still ends up on the list, and the individual is still the one expected to notice, object, and escalate.
The Complaint Has Been on the Record For a Decade

None of this is new discovery; what’s changed is the scale and the legal language around it. The loophole at the centre of Nigeria’s DND system was flagged within a week of its 2016 launch, when Quartz Africa reported that MTN argued the rule applied only to third-party marketers, not to the network’s own promotional texts. A year later, Techpoint Africa noted that roughly 4 million subscribers had activated DND with limited effect, and by 2018 Technext was reporting that most of the remaining spam volume traced back to the operators’ own promotional codes. The complaint has stayed live ever since: years of Nairaland threads, with titles like “6.5m Nigerians Activate DND Code” and “Why You Shouldn’t Subscribe to DND,” show subscribers still comparing notes on which network ignores the STOP command and which sender IDs to block manually. The same complaint has been aired by end users for the better part of a decade with no structural fix.
Beyond Nigeria and Ghana

The same consent-in-law versus consent-in-practice gap shows up wherever a data protection statute meets a bulk-messaging industry built to route around it. Kenya’s Data Protection Act treats the right to object to direct marketing as absolute in principle, yet its regulator, the ODPC, closed only 96 complaints and issued 76 fines in the whole of 2025, a small number set against a subscriber base of over 61 million registered SIM lines. South Africa’s POPIA has gone further in spelling out the distinction. Its direct-marketing rules generally require prior consent for unsolicited electronic marketing, rather than allowing businesses to treat the opportunity to opt out later as consent. The Information Regulator’s guidance has further clarified how those rules apply, including controversially treating telephone marketing as electronic communication requiring prior consent. Yet, that clarity on paper hasn’t translated into fewer complaints: grievances about unwanted calls, texts, and emails keep flowing into the regulator regardless. Nigeria and Ghana are not an isolated pair; they are the two best-documented cases of a pattern that recurs across the continent’s data protection regimes.
In the EU, the directive is similar to South Africa’s. Its ePrivacy Directive generally requires opt-in consent before a marketing SMS is sent: an opt-out link doesn’t satisfy the rule, and a sender has to be able to demonstrate that consent existed at the point of contact, not merely honour a STOP reply afterwards. It’s not that European regulators catch every violation (cross-border enforcement is famously uneven across member states), but the legal default puts the burden on the sender before the message lands, which is the piece missing from Nigeria’s and Ghana’s frameworks.
In the EU, as in South Africa, organisations are expected to keep records showing when and how consent was obtained and may be required to produce those records during an investigation. The burden is shifted upstream, toward the organisation sending the message, rather than downstream onto the individual receiving it.
Does the EU’s directive work better than SA’s and can it be a blueprint for other African countries, and as a pathway to better enforcement for South Africa? The answer is not black and white.
The EU’s experience shows that shifting the burden upstream is an important starting point, but the rule is only as useful as the ability to enforce it. Its longer history with this approach provides some lessons, but uneven enforcement across member states also shows that it is not a silver bullet. For Nigeria and Ghana, both the EU and South Africa provide useful examples of what it looks like to make the sender responsible for establishing consent before contact is made. South Africa already has that framework; the gap appears to be in making it work more effectively, including proactively testing compliance and requiring organisations to prove that consent exists, rather than relying so heavily on complaints from people who have already received unwanted messages.
The Pattern Underneath African Markets

Strip away the country-specific details and a single hypothesis holds across every market examined here: data protection regimes built around individual consent and individual opt-out place the entire cost of enforcement on the person least equipped to bear it. A subscriber cannot audit an aggregator’s client list, cannot see which broker sold their number to a political party, and cannot tell a “corporate route” message with genuine consent behind it from one without. The instruments available to them- DND codes, STOP replies, formal complaints, lawsuits- are all after-the-fact remedies for a before-the-fact failure: nobody upstream had to prove consent existed before the message was sent.
Strong accountability would flip that sequence, requiring aggregators and sender-ID holders to demonstrate a lawful basis for a number before a campaign goes out, not after a subscriber complains. Nigeria’s growing fine sheet and Ghana’s founding statute both gesture at that principle. Neither, in practice, has yet built the infrastructure to enforce it before the SMS lands. Until one does, the honest answer to “who gave them my number” will keep being: almost certainly someone who was never required to ask.

