Nigeria's Data Localisation Puzzle: Two Regulators, One Compliance Maze

Nigeria is asking banks, fintechs, and payment companies to keep more data at home. On June 15, 2026, the Central Bank of Nigeria introduced rules requiring financial institutions and payment system participants to store and manage payment transaction data generated in Nigeria locally by January 1, 2027. Two months later, the government unveiled its National Digital Cloud Policy, a broader framework for cloud adoption, data classification, cybersecurity, and digital infrastructure. Both share the premise that critical digital infrastructure should not sit entirely beyond Nigeria's regulatory reach. But their mandates differ, and that difference is where the compliance headache begins.
Two Regulators, Two Mandates, One Infrastructure
The CBN is concerned with financial stability, payment systems, and operational risk. NITDA's role is broader, covering technology standards, cloud infrastructure, and digital systems. As one observer put it, the situation can be a puzzle, but the tension is less a clash between regulators than a question of how their mandates overlap. That overlap exists because financial services depend on the same infrastructure that broader technology regulation governs. A bank can be regulated by the CBN while hosting applications with a cloud provider subject to NITDA standards. A fintech can process payments under a CBN licence while relying on local data centres, foreign software, or cross-border backup services. The Nigeria Data Protection Commission adds another layer, particularly where personal data and cross-border transfers are concerned.
Concurrent Compliance Is the New Reality
This does not mean one mandate cancels out the other. A bank cannot disregard a CBN rule because NITDA has a wider technology remit. But CBN authority over a bank does not automatically displace NITDA requirements for the infrastructure supporting it. Rahma Ibiyeye, managing partner at Regcompass Consults, frames the distinction as one between the infrastructure and the regulated institution using it. A bank could use a data centre that meets NITDA standards and still have to show the CBN that its payment data is stored, secured, managed, and recoverable in line with financial-sector rules. That is the logic of concurrent compliance. Where both regimes validly apply, a business must comply with both.
The Hard Part: Turning Principles Into Technical Rules
For businesses, this means deciding where production data, backups, disaster-recovery systems, and security logs can sit. Cloud providers must determine whether their infrastructure meets national standards and financial-sector requirements. The question is not simply whether data should be local. It is which data, under what conditions, on what infrastructure, and under whose supervision. The two frameworks may be complementary: the CBN's rule targets payment transaction data, while the National Digital Cloud Policy takes a more graduated approach to government and regulated data. A fintech could localise core Nigerian payment data while using cross-border infrastructure for less sensitive workloads, provided other legal requirements are met. That would give Nigeria greater control without isolating its digital economy from global cloud providers.
Who Leads on Standards?
Adeoye Abodunrin, an AI expert, argues the agencies need a clearer division of responsibilities. NITDA, he said, should lead on technical standards for cloud systems, data centres, and digital infrastructure, while the CBN should apply those standards to banks and payment companies, adding requirements specific to financial-sector risk. Ibiyeye draws a sharper distinction around licensing. The CBN can require banks and other financial institutions to use cloud infrastructure that meets specified standards as part of its oversight of operational and technology risk. But independently licensing or certifying the cloud provider would be different: it would move the CBN beyond regulating a financial institution's risk and closer to directly regulating the technology provider itself.
Key Takeaways
- The CBN requires payment transaction data generated in Nigeria to be stored locally by January 1, 2027.
- NITDA's National Digital Cloud Policy creates a broader framework covering cloud adoption, data classification, and cybersecurity.
- Businesses face 'concurrent compliance' — they must satisfy both CBN and NITDA rules where both validly apply.
- The key unresolved questions: what counts as primary payment data, whether backups can remain abroad, and whether disaster-recovery systems must be local.
- Experts suggest NITDA should lead on technical standards while the CBN applies them to financial institutions.
Keep Reading


