Your Business Phone Number Is Registered to Your Former Staff Member Who Controls the WhatsApp Account Now?


A fashion business based in Ikeja, Lagos, spent three years building its primary sales channel on a single mobile number. The number appeared on printed receipts, outdoor banners, and the business's Instagram bio. Customers saved it as the official store contact. Orders were taken, payments confirmed, and deliveries arranged through WhatsApp Business using that line. Airtime and data bundles were paid directly from the company's bank account.

When the lead sales representative resigned, she took the SIM card with her.

The owner assumed the line belonged to the business. After all, the firm purchased the SIM card, funded its usage for thirty-six months, and generated every customer interaction attached to it. However, when the owner attempted to request a SIM replacement at an MTN service center, the request was rejected.

The line had been registered in the employee's name using her personal National Identification Number (NIN) during her first week at work.

This situation exposes a common vulnerability for Nigerian small businesses: confusing daily operational use with formal legal control.

Operational Access Does Not Equal Subscriber Registration

Understanding who controls a business line requires separating three distinct elements:

  • Possession: Holding the physical SIM card or controlling the smartphone housing it.
  • Operational Use: Using the line for business communications, customer relationship management, and financial transactions.
  • Subscriber Registration: The legal record tying the Mobile Station International Subscriber Directory Number (MSISDN) to an individual's biometric identity and NIN in the Nigerian Communications Commission (NCC) Central Database.

Under the NCC Registration of Telephone Subscribers Regulations, a telephone line is linked to the individual whose biometrics (fingerprints and facial image) and NIN were captured during registration.

┌──────────────────────────────────────────────────────────┐
│                   SUBSCRIBER REGISTRATION                │
│    Legal owner tied to NIN/Biometrics in NCC Database    │
└─────────────────────────────┬────────────────────────────┘
                              │
            ┌─────────────────┴─────────────────┐
            ▼                                   ▼
┌───────────────────────┐           ┌───────────────────────┐
│     POSSESSION        │           │    OPERATIONAL USE    │
│ Physical SIM / Phone  │           │  WhatsApp, Banking,   │
│       Control         │           │   Customer Contacts   │
└───────────────────────┘           └───────────────────────┘

Mobile network operators (MTN, Airtel, Globacom, 9mobile) recognize the registered subscriber as the exclusive account holder. Paying for a line's airtime from a corporate bank account does not transfer subscriber registration.

Unless the SIM was registered as a corporate line—using Corporate Affairs Commission (CAC) incorporation documents, a taxpayer identification number (TIN), and an authorized corporate representative resolution—the line remains the personal subscriber property of the individual registered in the telecom database.

Simultaneously, subscriber registration does not grant the individual ownership of the intellectual property, goodwill, customer databases, or trade secrets generated during employment. While the employee may control the telecom line, they do not automatically own the underlying business assets managed through it.

Technical Control of WhatsApp and Connected Services

When an employee leaves with a business-critical SIM card, the control of digital platforms linked to that number shifts.

       SIM Card Control (SMS / Voice Verification)
                            │
      ┌─────────────────────┼─────────────────────┐
      ▼                     ▼                     ▼
┌───────────┐         ┌───────────┐         ┌───────────┐
│ WhatsApp  │         │ Financial │         │ Digital   │
│ Account   │         │ Services  │         │ Platforms │
└─────┬─────┘         └─────┬─────┘         └─────┬─────┘
      │                     │                     │
      ├─ SMS Verification   ├─ Bank OTPs          ├─ Email Recovery
      ├─ 2-Step PIN Reset   ├─ POS Terminals      ├─ Instagram/Facebook
      └─ Session Control    └─ Payment Gateways   └─ Domain Admin

WhatsApp Account Mechanics

WhatsApp ties account identity to the physical telephone number. Registration relies on an SMS or voice call verification code delivered to the active SIM.

  • Session Persistence vs. Re-verification: If the business retains the phone running WhatsApp, the account remains functional temporarily. However, WhatsApp periodically prompts for re-verification, during device transfers, or when network updates occur. If the former employee triggers a verification request on a new device, the code will be delivered to their SIM, granting them control of the WhatsApp account on that new device.
  • Two-Step Verification: If the business configured Two-Step Verification (a 6-digit PIN) within WhatsApp, the former employee cannot complete the setup on a new device immediately, even with the SMS code. However, if no recovery email was set, WhatsApp allows the PIN to be reset after a 7-day period, handing full access to whoever holds the active SIM.
  • Linked Devices: WhatsApp allows primary phone accounts to link up to four secondary devices (such as WhatsApp Web or Desktop). If the former employee gains control of the primary mobile account, they can log out all secondary linked devices used by the business with a single tap.
  • Backups and Chat History: WhatsApp chat backups are tied to individual cloud accounts (Google Drive for Android, iCloud for iOS), not to the SIM card itself. Acquiring the SIM allows an employee to register a fresh WhatsApp instance, but it does not automatically give them access to historical chat backups unless they also possess the credentials for the business's cloud storage account.

Connected Authentication Systems

The risks extend beyond instant messaging. In Nigeria's digital commerce ecosystem, a phone number often serves as the primary multi-factor authentication (MFA) token across multiple services:

                  ┌──────────────────────────────┐
                  │    CENTRAL BUSINESS NUMBER   │
                  └──────────────┬───────────────┘
                                 │
     ┌───────────────────────────┼───────────────────────────┐
     ▼                           ▼                           ▼
┌─────────┐                 ┌─────────┐                 ┌─────────┐
│Banking/ │                 │  Social │                 │Operations│
│ Payments│                 │  Media  │                 │ Platforms│
└────┬────┘                 └────┬────┘                 └────┬────┘
     ├─ Bank Account OTPs        ├─ Instagram Recovery       ├─ Google Workspace
     ├─ Paystack/Monnify Login   ├─ Facebook Admin           ├─ Domain Registrars
     └─ POS Admin Portals        └─ TikTok Business          └─ Delivery Logistics

Changing account passwords across these platforms does not secure them if the primary recovery method remains set to SMS verification directed to the former employee's phone number.

Immediate Steps When an Employee Retains a Business SIM

If an employee leaves taking a SIM card used for business operations, complete these steps immediately:

  1. Map All Associated Accounts: Audit every digital service using the line. Prioritize core banking, payment gateways, primary email addresses, social media profiles, and cloud storage.
  2. Migrate Multi-Factor Authentication: Immediately change the recovery phone number across all critical services to a secure, business-owned alternative. Switch authentication from SMS-based verification to Time-based One-Time Password (TOTP) apps (such as Google Authenticator or Microsoft Authenticator) or security keys where available.
  3. Audit WhatsApp Linked Devices: If the business still has operational access to the active WhatsApp session on a workplace device, open Settings > Linked Devices and review all active sessions. Log out any unrecognized or remote devices.
  4. Export Customer and Operational Data: Export chat logs, contact lists, and transaction records from the active session. Under the Nigeria Data Protection Act (NDPA), a business must safeguard the personal data of its customers, including transaction details and phone numbers collected during operation.
  5. Secure Secondary Recovery Emails: Ensure that recovery email addresses attached to social accounts or payment platforms are strictly controlled by management and do not route to the former employee's personal or company inbox.
  6. Document Operational History: Compile evidence demonstrating the business's investment in and operational control of the number. Collect airtime payment receipts from company bank accounts, branded marketing materials, customer invoices, and employment agreements.
  7. Review Network Provider Options: Contact the telecom operator to evaluate line management options. Operators cannot transfer a line registered to an individual without that individual's explicit consent or a formal court order.

Resolving Disputes and Evidence Requirements

When a former employee refuses to return a SIM card or consent to a number transfer, distinguish between administrative operator requests and legal disputes.

┌────────────────────────────────────────────────────────────────────────┐
│                        DISPUTE RESOLUTION PATHWAY                       │
└───────────────────────────────────┬────────────────────────────────────┘
                                    │
           ┌────────────────────────┴────────────────────────┐
           ▼                                                 ▼
┌─────────────────────────────────────┐   ┌──────────────────────────────┐
│       ADMINISTRATIVE (TELCO)        │   │         LEGAL ACTION         │
│ Requires registered owner consent   │   │ Requires documentary proof   │
│   or corporate registration docs    │   │   to establish ownership     │
└─────────────────────────────────────┘   └──────────────┬───────────────┘
                                                         │
                                          ┌──────────────┴───────────────┐
                                          ▼                              ▼
                                 ┌──────────────────┐          ┌──────────────────┐
                                 │  Civil Remedies  │          │ Data Security    │
                                 │ Conversion/Breach│          │ Criminal Code/   │
                                 │   of Contract    │          │ Cybercrimes Act  │
                                 └──────────────────┘          └──────────────────┘

Network operators are governed by strict NCC regulatory frameworks regarding subscriber data privacy. An operator will not reassign a SIM card based on commercial invoices or airtime receipts alone.

To pursue legal options or formal mediation, a business must compile supporting documentation:

  • Employment Documentation: Contracts specifying job roles, provisions regarding company property, and clauses governing non-disclosure or data ownership.
  • Financial Proof: Bank statements demonstrating consistent purchase of airtime, data, or subscription services for the number directly from corporate accounts.
  • Commercial Evidence: Invoices, receipts, waybills, and advertisements proving the number was publicly presented as the enterprise's official channel.
  • Internal Communications: Written correspondence (emails, letters, or chat logs) showing the employee acknowledged using the line on behalf of the business.

This evidence does not alter subscriber registration in the NCC database directly. However, it provides the legal basis to claim breach of contract, conversion of company property, or unlawful conversion of trade secrets under relevant Nigerian commercial laws.

Contexts That Change Ownership Analysis

Determining the proper handling of a phone line depends on how the number was introduced to the business:

┌──────────────────────────────────────────────────────────────────────────┐
│                      ORIGIN OF THE TELEPHONE NUMBER                      │
└────────────────────────────────────┬─────────────────────────────────────┘
                                     │
           ┌─────────────────────────┴─────────────────────────┐
           ▼                                                   ▼
┌───────────────────────────────────┐               ┌──────────────────────┐
│        COMPANY-ISSUED LINE        │               │   PRE-EXISTING LINE  │
│  Line procured for business use   │               │ Personal SIM brought │
│   Registered to employee during   │               │    by employee to    │
│            employment             │               │   the enterprise     │
└─────────────────┬─────────────────┘               └──────────┬───────────┘
                  │                                            │
                  ▼                                            ▼
┌───────────────────────────────────┐               ┌──────────────────────┐
│ Stronger business claim for SIM   │               │ Business claim limited│
│ return / Re-assignment consent    │               │ to data/contacts, not│
│                                   │               │ physical SIM line    │
└───────────────────────────────────┘               └──────────────────────┘

Scenario 1: The Company-Issued Line

A restaurant in Enugu purchases a new SIM card specifically for managing online orders via WhatsApp Business. The store manager registers the SIM in their own name because the business owner has not set up a corporate telecom account. The business pays for all usage.

  • Analysis: The line was established solely for corporate operations. While the SIM remains registered to the employee individually, the employee holds the business asset in trust. Refusing to transfer the line upon termination constitutes a clear breach of fiduciary duty and conversion of business property.

Scenario 2: The Pre-Existing Personal Line

A salesperson at an Aba wholesale distribution firm uses his personal SIM card—which he has owned and used for five years prior—to handle client communications. The business reimburses his monthly airtime expenses. Upon resignation, the employee retains the SIM.

  • Analysis: The business cannot claim ownership of the telephone number itself. The line was a pre-existing personal asset. The business's legal interest is restricted strictly to the proprietary customer databases, order logs, and business records accumulated during employment, not the physical SIM card or telephone number.

Distinguishing Corporate Assets from Personal Identifiers

To prevent line disputes, small enterprises must separate company-managed telecom assets from employee personal identities.

FeatureCompany-Issued Corporate LineEmployee Personal Line Used for Work
SIM RegistrationRegistered under Corporate CAC details and Corporate TINRegistered under Employee's personal NIN and biometrics
Telco ControlDesignated company signatories manage line replacements and updatesEmployee exclusively controls SIM swaps, porting, and line updates
WhatsApp Account OwnershipBusiness controls primary registration credentials and recovery pathsEmployee can reclaim account via SMS verification at any time
Banking & MFA IntegrationLinked to corporate accounts and business management portalsRisks exposing corporate verification tokens to personal devices
Exit ResolutionSIM card remains with the business during offboardingNumber leaves with the employee; contacts must be exported

Operational Controls for Small Enterprises

Small and medium enterprises operating without dedicated IT departments can implement straightforward controls to manage communication channels securely:

┌────────────────────────────────────────────────────────────────────────┐
│                   STRUCTURED SMALL-BUSINESS CONTROL                    │
├────────────────────────────────────────────────────────────────────────┤
│ 1. Corporate SIM Registration                                          │
│    Register lines using CAC documents + Corporate TIN                  │
├────────────────────────────────────────────────────────────────────────┤
│ 2. Centralized Authentication                                          │
│    Tie all accounts to a manager-controlled email domain               │
├────────────────────────────────────────────────────────────────────────┤
│ 3. App-Based MFA Adoption                                              │
│    Use Authenticator Apps instead of SMS-based verification            │
├────────────────────────────────────────────────────────────────────────┤
│ 4. Clear Offboarding Protocols                                         │
│    Revoke device permissions and linked sessions on departure          │
└────────────────────────────────────────────────────────────────────────┘
  1. Register Lines Corporately: Procure enterprise or corporate SIM cards registered under the business's legal name using CAC documentation, official tax identification, and board resolutions. Avoid using personal registrations for official lines.
  2. Centralize Digital Authentication: Route all account recoveries, WhatsApp secondary emails, and platform logins through a corporate email address (e.g., admin@company.ng) controlled by the founder or operations lead, rather than an employee's personal inbox.
  3. Adopt Authenticator Apps: Shift critical administrative logins away from SMS-based verification toward authenticator apps managed on company-controlled devices.
  4. Use Multi-Agent WhatsApp Management: Utilize WhatsApp Business API services or multi-device features that allow team members to communicate with clients through desktop interfaces, leaving the primary physical SIM card secured in management's possession.
  5. Establish Clear Employment Agreements: Include explicit provisions in employment contracts stating that all phone numbers purchased or assigned for work, alongside associated customer data and WhatsApp Business profiles, remain exclusive company property.

Pre-Offboarding Security Checklist

Before an employee holding operational responsibilities completes their final day, execute this operational review:

┌──────────────────────────────────────────────────────────────────────┐
│                    PRE-OFFBOARDING CHECKLIST                         │
├──────────────────────────────────────────────────────────────────────┤
│ [ ] Confirm corporate SIM registration status with operator          │
│ [ ] Log out all remote WhatsApp linked devices                       │
│ [ ] Re-verify Two-Step Verification PINs and recovery emails         │
│ [ ] Transfer SMS-based banking alerts to alternative company lines   │
│ [ ] Export customer databases, order logs, and chat histories        │
│ [ ] Change passwords for accounts accessible by the departing staff  │
│ [ ] Collect all company-owned physical SIM cards and devices         │
└──────────────────────────────────────────────────────────────────────┘

Unlawful Recovery Actions to Avoid

When attempting to recover access to business accounts, business owners must avoid actions that create legal or regulatory exposure:

  • Unauthorized SIM Swaps: Attempting to execute a SIM replacement at a telco service outlet by impersonating the registered owner or using fraudulent documentation violates Nigerian telecommunication regulations and criminal law.
  • Account Hacking or Credential Theft: Attempting to force entry into an employee's personal email or cloud accounts to intercept verification codes violates the Cybercrimes (Prohibition, Prevention, etc.) Act.
  • Public Defamation: Publishing unverified accusations of theft, fraud, or dishonesty on social media platforms creates civil liability for libel.
  • Unlawful Self-Help: Withholding legally accrued terminal entitlements or personal property to force the surrender of a SIM card can trigger civil litigation and labor disputes.

Instead, rely on documented contractual rights, formal administrative applications through network operators where corporate documentation exists, or legal dispute resolution channels.

0 Comments