← Back to list

When Digital Platforms Scale Faster Than Their Compliance: Lessons from the Glovo and Chowdeck…

The recent Techpoint Africa investigation into Glovo and Chowdeck’s onboarding systems reveals something far more significant than a gap in…

Deborah ogbelade · 2026-05-11 23:11 · 0 claps · 6.2 min read
#compliance #corporate-governance #kyb #law-and-technology #consumer-protection
Open on Medium ↗
Wiki topics: ⚖️ · Law & Justice

When Digital Platforms Scale Faster Than Their Compliance: Lessons from the Glovo and Chowdeck Investigation

The recent Techpoint Africa investigation into Glovo and Chowdeck’s onboarding systems reveals something far more significant than a gap in digital platform security. It exposes a pattern that is quietly spreading across Nigeria’s digital economy: platforms are scaling faster than their compliance structures can keep up with. The investigation was straightforward in its method and alarming in its result. Techpoint Africa successfully created fake restaurant profiles on both platforms using false information and misappropriated business identities. Neither platform detected the impersonation. Neither flagged the inconsistency. Both onboarding processes were completed without meaningful resistance. That is not a technology failure. It is a compliance failure. And the implications stretch well beyond two food delivery apps.

The Onboarding Problem: Know Your Business Is Not Optional

At the heart of this issue is a weak Know Your Business (KYB) framework or in some cases, the near-total absence of one. KYB is the business-facing equivalent of KYC (Know Your Customer). It requires platforms to verify the identity, legitimacy, and operational standing of the vendors they onboard before granting them access to consumers. In a well-structured KYB process, a vendor would be required to provide verifiable CAC registration details, a valid Tax Identification Number (TIN), proof of business address, and food handling certifications where applicable. Those details would then be cross-checked against official records before the vendor goes live.

What the Techpoint Africa investigation suggests is that this cross-checking either did not happen or was insufficiently robust on both platforms. A fake restaurant with stolen business assets was approved and made available to real consumers. That is an onboarding control failure with direct consumer protection consequences. In regulated financial services, this level of verification failure would attract regulatory sanctions, fines, and potentially licence suspension. In food delivery, it currently attracts little more than a news cycle.

Also, food delivery platforms process significant volumes of consumer data, including names, phone numbers, addresses, payment information, and order histories. Weak onboarding systems increase the risk of data misuse by fraudulent actors. Under the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive (GAID) 2025, organizations are legally mandated to implement appropriate technical and organizational safeguards to protect personal data

Consumer Protection: The Real Casualty

When a fake restaurant is live on a delivery platform, the consumer becomes the most exposed party in the transaction. The risks are layered. There is the obvious financial risk which is paying for a product that may never arrive or that bears no relation to what was advertised. There is the food safety risk, consuming products prepared in unregistered, uninspected, and unregulated environments. And there is the identity and fraud risk such as sharing personal data, payment information, and delivery addresses with an entity whose legitimacy has never been verified.

Nigeria’s Federal Competition and Consumer Protection Commission (FCCPC) has been increasingly vocal about platform accountability in the digital economy. The FCCPC Act 2018, particularly section 125, places obligations on businesses to ensure that their operations do not expose consumers to deceptive, unfair, or harmful practices. A platform that allows unverified vendors to access consumers without adequate checks is arguably in breach of that standard, regardless of whether the platform itself initiated the deception.

NAFDAC’s jurisdiction over food safety adds another regulatory layer. Food businesses operating in Nigeria are expected to meet certain registration and safety standards. A platform that onboards vendors without verifying those standards is not merely negligent but potentially complicit in distributing unregulated food products to unsuspecting consumers. The erosion of consumer trust that follows an exposure like this is difficult to quantify but easy to underestimate. In a market where brand loyalty on food delivery platforms is already thin and switching costs are low, trust is the product. Lose it, and the platform has very little left to sell.

The Regulatory Gap That Makes This Possible

Part of why this problem persists is structural. Nigeria does not currently have sector-specific regulation governing digital food delivery platforms. Oversight is fragmented between the FCCPC, NAFDAC, and in some cases state-level consumer protection agencies, with no single regulatory body taking clear ownership of platform accountability in this space. Compare that to fintech. Nigerian fintech companies operating under CBN oversight face stringent KYC and KYB obligations. Customer onboarding processes must meet defined standards. Compliance failures attract regulatory penalties, operational restrictions, and in serious cases, licence revocation. The compliance burden is high precisely because the potential for consumer harm is high. The consumer harm potential in food delivery is arguably just as significant as people are consuming physical products that directly affect their health, yet the regulatory standard applied to the platforms enabling that consumption is considerably lower. This asymmetry is unsustainable. As digital food delivery continues to scale across Nigerian cities, the regulatory framework governing it must evolve to match the risk profile of the sector.

The Business Risk Perspective: Compliance as a Commercial Issue

It is tempting to frame this as purely a regulatory or ethical issue. It is not. For platform operators and their investors, weak compliance systems represent a material commercial risk. Reputational damage from a single investigation of this nature can trigger consumer backlash, vendor distrust, and media scrutiny that far exceeds the cost of building a robust verification system in the first place. In an era where a single Twitter thread can shift public sentiment overnight, the reputational exposure of a compliance gap is no longer a slow burn but an immediate crisis management challenge.

There is also the litigation dimension. A consumer who suffers harm whether financial, physical, or both, as a result of purchasing from an unverified vendor on a platform has a potential cause of action against that platform under the FCCPA and applicable tort principles. As awareness of consumer rights grows in Nigeria, so does the appetite for holding platforms legally accountable.

For investors conducting due diligence on these platforms, governance and compliance infrastructure increasingly factor into risk assessments. A platform that cannot demonstrate robust vendor verification controls is a platform with an unpriced liability sitting on its balance sheet. That matters at every stage of a funding conversation.

Practical Recommendations

For platforms operating in this space, the path forward requires deliberate investment in compliance infrastructure rather than incremental improvements to existing processes.

  1. CAC and TIN validation should be mandatory and automated at the point of onboarding, with results cross-referenced against official government databases before a vendor profile is activated. This is not a novel capability, fintech platforms have been doing it for years.
  2. Periodic vendor audits should be built into the operational model, not treated as exceptional events. A vendor that passed verification six months ago may not meet the same standards today. Ongoing monitoring is part of what makes a compliance system functional rather than performative.
  3. AI-driven verification tools are increasingly capable of flagging inconsistencies in submitted documentation, detecting duplicate business identities, and identifying patterns associated with fraudulent onboarding. Platforms with the technical capacity to deploy these tools have an obligation to do so.
  4. Regulatory collaboration with the FCCPC and NAFDAC would allow platforms to participate in shaping the compliance standards that will inevitably apply to their sector, rather than reacting to them after the fact. Proactive engagement is almost always commercially preferable to reactive compliance.
  5. Finally, consumer complaint escalation systems need to be visible, functional, and genuinely responsive. A consumer who suspects they have interacted with a fraudulent vendor should have a clear, accessible mechanism for reporting that concern and receiving a meaningful response.

Conclusion

The Glovo and Chowdeck investigation is worth taking seriously not because of what it says about two companies, but because of what it says about a pattern. Across Nigeria’s digital economy, platforms are acquiring users, processing transactions, and building market share at a pace that their internal compliance and governance structures are struggling to match. That gap is manageable when things are going well. It becomes a crisis the moment something goes wrong.

The real lesson from this investigation is that compliance can no longer be treated as a secondary operational function. In today’s digital economy, trust, governance, and compliance are competitive advantages and the platforms that recognize this earliest will be the ones best positioned to scale sustainably, attract institutional capital, and withstand regulatory scrutiny as it intensifies. Compliance is not the friction that slows growth. It is the infrastructure that makes growth defensible. The question Nigerian startups must now ask is simple: Are compliance and governance systems evolving at the same pace as growth?

References

  1. Techpoint Africa, ‘We impersonated a restaurant on Glovo and Chowdeck; the platforms never noticed’
  2. Section 125 FCCPA 2018
  3. NDPA Act 2023
  4. NDP-ACT GAID 2025

메타데이터
post_id
f93fbca89d79
slug
when-digital-platforms-scale-faster-than-their-compliance-lessons-from-the-glovo-and-chowdeck-f93fbca89d79
url
https://medium.com/@deborahogbelade/when-digital-platforms-scale-faster-than-their-compliance-lessons-from-the-glovo-and-chowdeck-f93fbca89d79
canonical_url
https://medium.com/@deborahogbelade/when-digital-platforms-scale-faster-than-their-compliance-lessons-from-the-glovo-and-chowdeck-f93fbca89d79
author_url
https://medium.com/@deborahogbelade
status
ok
fetched_at
2026-06-11 21:11:36