All articles
Compliance17 August 2026

The CBN has set a Clock. Nigerian Banks and Fintechs Have Until January 2027

The CBN has set a Clock. Nigerian Banks and Fintechs Have Until January 2027

For IT leaders in Nigerian banks, fintechs, and mobile money companies this is the most important regulatory deadline on your calendar right now.

The Central Bank of Nigeria has issued a directive that effectively ends the era of offshore payment data storage. From January 1, 2027, all payment transaction data generated within Nigeria must be stored and managed locally, on Nigerian soil, in accordance with Nigerian data protection laws. No partial compliance, just local storage.

The directive, issued by the CBN’s Payments System Supervision Department, was addressed to the full spectrum of Nigeria’s financial infrastructure; deposit money banks, microfinance banks, mobile money operators, switching companies, payment terminal service providers, payment solution service providers, super agents, and all other licensed payment operators. All institutions facilitating payments within Nigeria must ensure that payment transaction data generated in the country are stored and managed locally. It is a hard regulatory requirement with a hard deadline, issued by Nigeria’s apex bank to one of its most systemically important sectors.

The directive cites the rapid expansion of Nigeria’s digital payments ecosystem, now one of Africa’s largest, and acknowledges that this growth has brought real concerns; market concentration, operational dependence on foreign infrastructure, ownership transparency, and the storage of critical financial data outside Nigerian jurisdiction. That last point is the one that should focus minds in every IT and infrastructure team across the sector.

When your payment transaction data lives on a foreign server, whether that’s AWS in Ireland, Azure in the Netherlands, or any other offshore cloud environment, you are operating with a dependency that the CBN has now explicitly determined is unacceptable for Nigerian financial data, because the data needs to be here. For banks, any payment infrastructure currently relying on offshore cloud storage or foreign data centres for transaction data needs an architecture review. For fintechs, many were built cloud-native on foreign hyperscale infrastructure. The path to compliance requires either negotiating local data residency commitments with cloud providers, or migrating affected workloads to locally hosted environments. Neither is a fast process. For payment processors and switching companies, the directive covers the full payments stack. If any node in your processing chain stores transaction data offshore, it is in scope.

Not every organisation that needs to comply has the in-house data centre capability to do so. And building that capability from scratch, the power, the physical security, the connectivity, the management overhead is neither fast nor cheap. This is precisely where the Nigerian data centre ecosystem becomes strategically important. Institutions that invest in the right local infrastructure partnerships now will meet the January 2027 deadline with confidence, while those that treat it as a 2026 problem will be scrambling.

Where does your payment transaction data currently live at the infrastructure level? Which servers, in which jurisdictions, managed by which providers? Which of those environments

are offshore? What does a compliant local hosting architecture look like for your specific workload profile? Colocation, managed hosting, and private cloud. How does local hosting affect your connectivity architecture? Moving data to local infrastructure while maintaining the performance your users and systems expect requires low-latency and direct connectivity. The two decisions are linked. January 2027 sounds distant. Security validation, backup, disaster recovery planning, Infrastructure migration at enterprise scale does not happen in weeks. Procurement, deployment, migration, testing, cutover build the timeline backwards from the deadline and you will find that the work needs to start now.

It would be a mistake to treat this CBN directive as an isolated event. It is part of a consistent and accelerating regulatory direction that has been building for several years. The NDPA mandates data sovereignty and cross-border transfer safeguards across all sectors. NITDA’s guidelines require sovereign data to remain within Nigeria. The Critical National Information Infrastructure Order places BVN and NIN data under enhanced localisation requirements. The National Cloud Policy advocates in-country hosting for sensitive government and financial data. The CBN directive is the financial sector’s version of a trend that is now industry-wide; Nigerian regulators are asserting sovereignty over Nigerian data, and they are giving the market deadlines to comply.

The CBN has also introduced market structure requirements alongside the data localisation directive, caps on market share in card issuing and merchant acquiring, mandatory monthly reporting, and enhanced beneficial ownership disclosure. The compliance burden across the sector is significant and multi-dimensional. But the data localisation requirement is the one with the longest lead time, the deepest infrastructure implications, and the highest cost of getting wrong.

If you are a CTO, IT Director, or Head of Infrastructure at a Nigerian bank, fintech, or payment operator the conversation about local hosting infrastructure needs to happen in your next planning cycle and not the one after.

At inq. Nigeria, we work with financial institutions and enterprises to build locally hosted, secure, and compliant infrastructure designed for Nigeria’s evolving regulatory environment. If you are reviewing your data localisation readiness ahead of the January 2027 CBN deadline, we would welcome the conversation.

Next article

Your Institutional Memory should not Split across Different Apps

More on Compliance

Ready to put this into practice?

Talk to our experts about connectivity, cloud, security and digital solutions for your business.