CBN’s Data Localisation Rules Are Really About Keeping Nigeria’s Payments System Running
Nigeria's new data-localisation requirements for banks and fintechs are being discussed as a question of where financial data should be stored.
But the Central Bank of Nigeria is making a broader argument.
For the regulator, keeping payment data inside Nigeria is only useful if financial institutions can also access it, protect it, recover it and continue operating when something goes wrong.
That distinction is becoming increasingly important as Nigeria's financial system becomes more dependent on cloud infrastructure, data centres, connectivity providers, software vendors and other technology companies.
Speaking at TechCabal's Insights Power Brunch in Lagos on September 10, Dr Rakiya Yusuf, Director of the CBN's Payment System Supervision Department, stressed that localisation and resilience are not the same thing.
The message from the regulator is effectively this: putting a database in a Nigerian data centre does not automatically make Nigeria's financial system more resilient.
A bank could have its primary infrastructure in Nigeria but keep its disaster-recovery environment offshore. It could store data locally while remaining dependent on a foreign provider's control systems. Or several major financial institutions could move their workloads to the same local provider and unintentionally create a new concentration risk.
For the CBN, those scenarios matter because a technology failure at a major financial institution can quickly become a payments-system problem.
The January 2027 deadline is approaching
In June, the CBN directed banks, payment companies, switches and other participants in Nigeria's payments system to locally store and manage payment data generated in Nigeria, with the requirement taking effect from January 1, 2027.
The directive forms part of the regulator's broader effort to strengthen the security, oversight and resilience of the country's increasingly digital payments ecosystem.
That ecosystem has expanded dramatically.
The CBN's Payments System Vision 2028 identifies security, trust, interoperability and stronger regulatory oversight among the principles guiding the next phase of Nigeria's payments infrastructure.
The regulator's concern is therefore not simply about geography.
It is about whether institutions have enough control over critical infrastructure to continue serving customers when technology fails.
Local data does not automatically mean resilient data
Consider a bank with its primary customer database physically hosted in Nigeria.
On paper, it could satisfy the idea of localisation.
But what happens if the primary facility goes offline?
If the bank's backup is stored outside Nigeria, its disaster-recovery arrangements may still depend on cross-border infrastructure.
And what happens if the local provider's systems fail?
If the bank has no practical migration path to another provider, it may still be vulnerable to a prolonged outage.
There is another potential problem.
Several banks and payment companies could rely on the same data centre, cloud infrastructure, connectivity provider or critical software platform.
In that scenario, moving everything “locally” could actually concentrate risk.
That is why the CBN is asking institutions to think about where data resides, who controls it, who can access it, how it is backed up and how quickly it can be recovered or moved.
Banks are being asked to understand their entire technology dependency chain
Yusuf's message to financial institutions is that the localisation transition cannot be left solely to technology departments.
The implications stretch across:
Technology
Cybersecurity
Risk management
Legal
Compliance
Operations
Finance
Business continuity
Executives therefore need a much clearer picture of their organisations' data infrastructure.
That starts with basic questions.
Where does customer and payment data originate?
Where is it processed?
Where is it stored?
Where are backups located?
Who has access?
Which vendors can access it?
What happens if a technology provider becomes unavailable?
And perhaps most importantly:
Can the institution move its critical workloads and data somewhere else if it needs to?
That last question is becoming increasingly important as banks and fintechs rely on third-party infrastructure.
Cloud dependence is now a regulatory issue
Financial institutions increasingly use cloud services for applications, storage, analytics, cybersecurity and other workloads.
Cloud computing can improve scalability and reduce the need for companies to build every piece of infrastructure themselves.
But it also creates dependencies.
A bank may rely on a cloud provider for infrastructure, another company for managed security, another for connectivity and several software vendors for critical applications.
The result can be a technology supply chain that is significantly larger than the financial institution itself.
The CBN has already highlighted third-party and cloud-service visibility as a risk area in its cybersecurity regulatory work. Its risk-based cybersecurity framework requires financial institutions to maintain information about cloud providers and other third parties.
The localisation rules add another layer.
Institutions now need to understand not just who hosts their data, but also how those providers affect their ability to continue operating during a disruption.
The biggest risk may be the dependency nobody mapped
A bank could believe its systems are resilient because it has a backup environment.
But that backup may depend on the same network provider as the primary system.
Or the recovery environment may rely on a third-party authentication service.
Or the bank may have access to its data but not the software needed to restore it.
Or the data may technically be recoverable but take too long to restore to keep payment services operating.
These are the kinds of questions behind the CBN's broader definition of resilience.
The regulator wants institutions to understand the entire lifecycle of critical data, rather than treating storage location as the only issue.
What happens when a provider fails?
A practical test of the new approach is a simple scenario:
A bank's primary data centre goes offline.
Can customers still make payments?
Can the bank access transaction records?
Can the institution switch to another environment?
Can critical applications continue operating?
Can data be restored without compromising its integrity?
How long does recovery take?
And can the regulator understand what happened?
These questions matter because financial infrastructure is interconnected.
A problem at one institution can affect merchants, consumers, payment processors, switches and other banks.
Nigeria's central bank has previously introduced measures aimed at reducing single points of failure in payment infrastructure. For example, the CBN has required dual connectivity arrangements for certain payment operations to reduce downtime when one network path becomes unavailable.
The broader principle is similar: critical financial services should not depend on one fragile point of failure.
Data sovereignty is not about shutting out global technology companies
The CBN is also making an important distinction about foreign technology providers.
Nigeria's push for greater data sovereignty does not necessarily mean that banks and fintechs must abandon international cloud providers or foreign technology companies.
Global technology firms already play significant roles in Nigeria's technology ecosystem.
The issue is whether those companies can provide services to critical financial institutions while operating within Nigerian requirements around regulation, security, resilience and data governance.
That creates a more nuanced model.
Nigeria can continue to use global technology while requiring critical financial infrastructure to remain sufficiently visible, controllable and recoverable under Nigerian regulatory oversight.
The objective is therefore not simply:
“Foreign technology out, local technology in.”
It is closer to:
“Critical financial infrastructure must remain resilient and governable, regardless of who provides the technology.”
The industry still needs clearer implementation rules
The policy raises practical questions that financial institutions need answered.
For example:
What exactly qualifies as payment transaction data?
How will hybrid cloud environments be treated?
Can some processing still happen outside Nigeria?
Where must disaster-recovery systems be located?
What happens to existing contracts with international technology providers?
How should multinational financial institutions structure their systems?
And what happens when a particular technology service cannot realistically be replicated locally?
These are not merely technical questions.
They affect architecture, contracts, investment decisions, risk management and potentially the cost of operating financial services in Nigeria.
The CBN has indicated that it is engaging industry stakeholders and working toward additional implementation guidance.
That guidance could be particularly important for institutions that already operate complex hybrid environments.
Compliance could force banks to map infrastructure they previously took for granted
For financial institutions, the immediate task is therefore not necessarily moving every workload.
It is finding out exactly what they already have.
That means creating detailed maps of:
Data flows — where information originates and where it moves.
Workloads — which applications process critical information.
Vendors — which companies provide infrastructure or services.
Backups — where copies of critical information are stored.
Connectivity — which networks connect critical systems.
Access — who can control or retrieve the information.
Recovery — how quickly systems can be restored.
Migration — whether workloads can actually be moved if a provider becomes unavailable.
This is why the CBN is encouraging institutions to begin the process before the deadline rather than waiting for every implementation detail to be resolved.
The cost of doing this properly could be significant
For banks and fintechs, complying with the new requirements could involve more than moving servers.
Institutions may need to redesign cloud architectures, establish additional backup environments, negotiate new vendor contracts, improve connectivity redundancy, conduct cybersecurity assessments and test disaster-recovery procedures.
Smaller fintechs could face particular challenges.
Large banks may have the resources to operate multiple environments and negotiate complex infrastructure contracts.
Smaller payment companies may depend much more heavily on a handful of external technology providers.
That could make the cost and complexity of compliance uneven across the industry.
At the same time, stronger infrastructure resilience could reduce the financial and reputational costs of prolonged outages.
Nigeria's payments growth makes resilience more important
The timing of the policy is closely connected to the scale of Nigeria's digital payments market.
The CBN's Payments System Vision 2028 describes a payments ecosystem that is expected to become more secure, interoperable and globally integrated.
As transaction volumes increase, the consequences of infrastructure failures become larger.
A brief outage that once affected a relatively small number of transactions can now disrupt merchants, consumers, businesses and other financial institutions simultaneously.
That makes infrastructure resilience an economic issue rather than simply an IT concern.
If Nigerians cannot make payments because a critical system is unavailable, businesses can lose sales, workers can lose access to funds and other financial institutions can be affected by the same disruption.
The real test will be recovery, not server location
Nigeria's localisation policy is therefore moving the conversation toward a more important question.
It is not simply:
“Where is the data?”
It is:
“Can Nigeria's financial system keep functioning when something goes wrong?”
A locally hosted database that cannot be recovered quickly is not enough.
A backup that cannot be accessed during a crisis is not enough.
A local system that depends on one provider is not enough.
And infrastructure that regulators cannot adequately supervise during a major disruption is not enough.
The CBN's broader objective is to create a payments ecosystem where critical institutions understand their dependencies and can recover from failures without turning an individual technology incident into a systemic financial disruption.
Nigeria's data-localisation debate is often reduced to a question of where data is stored.
The CBN is pushing the industry toward a more complicated — and arguably more consequential — question: who controls the infrastructure, how dependent is the institution on it, and what happens when it fails?
That changes the compliance conversation.
Banks and fintechs cannot simply move a database into a Nigerian facility and consider the job finished.
They need to understand their data flows, cloud dependencies, backup arrangements, connectivity, vendors and recovery procedures.
The January 2027 deadline therefore represents more than a data-storage requirement.
It is a test of whether Nigeria's rapidly expanding digital payments industry can build enough resilience, recoverability and operational independence to withstand the failures that inevitably come with increasingly complex technology infrastructure.
For the financial sector, the ultimate measure of localisation may not be how many servers sit inside Nigeria.
It may be how quickly the system can recover when those servers — or anything connected to them — stop working.
