Banks, fintechs, switches and other payment companies have until 1 January 2027 to store and manage payment data generated in Nigeria inside the country. The Central Bank of Nigeria (CBN) issued the directive in June 2026, and a senior official has now explained what the regulator actually wants to see.
“Localisation is not the same thing as resilience,” said Dr Rakiya Yusuf, Director of the CBN’s Payment System Supervision Department, speaking at a TechCabal Insights event with Amazon Web Services on 10 September, as reported by TechCabal.
More than moving a database
Nigeria processed more than ₦1.2 quadrillion in transactions in 2025, and the CBN says that growth is why it wants more control over critical financial data. Yusuf asked whether an institution had really achieved resilience if its main database moves to Nigeria but its backup stays abroad, or if everything runs locally but is still controlled from an offshore dashboard.
The CBN expects institutions to:
- Know what data they hold, where it is processed, stored and backed up, and who can access it.
- Map their dependence on cloud providers, data centres, connectivity and software vendors (a typical Nigerian bank has 200 or more key suppliers).
- Test what happens when a main site, network link or provider fails, and how fast services can be restored or moved.
- Treat the work as a board-level programme, not a job left to the IT or security team.
Yusuf said further implementation guidance is coming, covering questions such as what counts as payment transaction data and how hybrid and disaster-recovery setups will be treated. She stressed that the policy does not mean Nigeria is turning away from global technology companies.
Two regulators, one set of systems
The CBN rule sits alongside the National Digital Cloud Policy, which the federal government unveiled in August and which NITDA oversees. Lawyers who spoke to TechCabal described this as “concurrent compliance”: a bank may use a data centre that meets NITDA’s standards and still have to prove to the CBN that its payment data is secure and recoverable. The Nigeria Data Protection Commission adds a third layer where personal data crosses borders.
Unanswered questions include whether backups can stay abroad, whether disaster-recovery systems must be local, and whether a foreign cloud provider can comply through a Nigerian data centre partner.
What it means for businesses
With three months to the deadline, fintechs and banks should already be mapping their data flows, reviewing vendor contracts and testing recovery plans. For local data centre and cloud companies, the rule is a large commercial opportunity, provided they can meet both the CBN’s and NITDA’s standards.



