Nigeria’s Data Localisation Maze: Fintechs Stuck Between Two Regulators

Nigeria’s central bank has ordered banks, fintechs and payment operators to store and manage payment transaction data within the country by January 1, 2027【1†L1-L3】【2†L1-L3】. The directive, issued on June 15, 2026, gives regulated entities roughly six months to shift payment‑related data offshore to onshore infrastructure【3†L1-L3】. Two months later the Nigerian government unveiled its National Digital Cloud Policy, a broader framework covering cloud adoption, data classification, cybersecurity and digital infrastructure【1†L8-L12】. Both initiatives share the goal of keeping critical data within Nigeria’s regulatory reach, but they stem from different mandates, creating a compliance overlap that fintechs and banks must navigate.

The reality: how the rules actually work

The CBN’s rule is sector‑specific: it applies to financial institutions and payment system participants and targets payment transaction data generated in Nigeria【1†L15-L18】. NITDA’s National Digital Cloud Policy, by contrast, is horizontal—it sets technical standards for cloud systems, data centres and digital infrastructure that any regulated entity using cloud services must meet【1†L20-L24】. The Nigeria Data Protection Commission (NDPC) adds a third layer when personal data or cross‑border transfers are involved【1†L26-L28】.

Because banks and fintechs rely on the same cloud and data‑centre infrastructure that broader technology regulation governs, they can find themselves subject to two or three sets of requirements simultaneously. A bank that hosts its core banking application on a foreign cloud provider must still show the CBN that its payment data is stored, secured, managed and recoverable in line with financial‑sector rules, while also proving to NITDA that the underlying infrastructure satisfies national cloud standards【1†L30-L36】. The NDPC may then scrutinise any personal‑data elements of that same dataset for adequacy of consent and transfer safeguards.

Legal experts describe this as “concurrent compliance”: where multiple regimes validly apply, the entity must comply with all of them【1†L38-L42】. There is no hierarchy that lets a regulated player ignore one set of rules because another regulator has a wider remit【1†L44-L48】.

The pain point: who this hits and what it costs

The overlap hits anyone processing Nigerian payment traffic—commercial banks, payment processors, mobile money operators, switching companies and fintechs that rely on offshore cloud services for core transaction workloads. For a typical mid‑size fintech that currently stores 70 % of its payment logs in an overseas AWS region, the CBN deadline forces a migration of potentially terabytes of data to local data centres or a Nigerian availability zone before January 2027【2†L4-L7】. That migration carries direct costs: data transfer fees, re‑architecture of backup and disaster‑recovery (DR) pipelines, and potential downtime during cutover.

Operationally, the pain multiplies. Teams must now maintain duplicate environments—one set of configurations to satisfy NITDA’s cloud‑security baseline, another to satisfy CBN‑specific operational‑risk controls (e.g., stricter encryption key management, immutable audit logs for payment data)【1†L50-L55】. If the NDPC is involved, additional data‑subject‑request handling and impact‑assessment paperwork appear.

Financially, the bill can be steep. Local data‑centre pricing in Lagos and Abuja remains a premium over hyperscale rates, and the need to duplicate DR sites locally can effectively double infrastructure spend. Moreover, the lack of clear technical guidance—e.g., whether backups may remain abroad or if a foreign provider can comply via a Nigerian availability zone—forces firms to over‑provision to stay safe【1†L57-L62】.

Failure modes: where this breaks in the real world

The first failure mode is mis‑scoping. The CBN rule explicitly covers “payment transaction data,” but many firms interpret it broadly to include ancillary logs, analytics extracts and customer‑profile data, leading to unnecessary localisation and inflated costs【1†L64-L68】. The second is infrastructure mismatch. A bank might move its primary payment database to a NITDA‑certified local data centre but keep its real‑time fraud‑detection model on an overseas GPU cluster, unaware that the model processes payment‑derived features and thus falls under the CBN’s purview【1†L70-L74】.

A third failure mode is regulatory arbitrage fatigue. As the NDPC issues guidance on cross‑border transfers under the Nigeria Data Protection Act, firms may find themselves re‑evaluating legal bases for data flows that were previously deemed compliant under the CBN rule alone, creating a moving target for compliance teams【1†L76-L80】.

Finally, there is a vendor lock‑in risk. Local providers that achieve NITDA certification may raise prices knowing that banks and fintechs have few alternatives that satisfy both sets of rules, squeezing margins especially for smaller players【1†L82-L85】.

The blueprint: what to do on Monday morning

  1. Map your data flows – Produce a detailed inventory that tags each data store (primary payment DB, backups, logs, analytics, customer PII) with its origin, current location, and applicable regulator(s). Use the CBN’s definition of payment transaction data as the baseline; anything outside that tag only needs NITDA/NDPC consideration if it contains personal data【1†L87-L92】.
  2. Classify workloads by sensitivity – Separate core payment transaction data (must be onshore by Jan 2027) from non‑payment workloads (e.g., marketing analytics, internal HR systems) that can remain offshore if they do not trigger NDPC rules【1†L94-L98】.
  3. Engage providers early – Ask your cloud vendor whether they offer a Nigerian availability zone or a local‑partner data‑centre that meets both NITDA’s technical standards and the CBN’s operational‑risk requirements. Get contractual commitments on data residency, encryption key control and audit‑log accessibility【1†L100-L105】.
  4. Update DR and backup policies – Determine whether the CBN permits asynchronous backups to be stored abroad; if not, design a tiered backup strategy where the primary copy is local and a secondary copy resides in a different Nigerian zone to satisfy both regulators and reduce RPO/RTO【1†L106-L111】.
  5. Build a compliance checklist – Create a living spreadsheet that maps each data item to CBN, NITDA and NDPC controls, assigns owners, and tracks evidence (configurations, contracts, audit reports). Review it quarterly as guidance evolves【1†L112-L117】.

Sources

  1. How Nigeria’s overlapping data rules affect fintechs and banks
  2. Nigeria orders banks and fintechs to keep payment data at home by 2027
  3. CBN gives banks, fintechs six months to localise payment data