Nigeria’s Data Rules Create Overlapping Compliance Demands for Banks and Fintechs
Nigeria’s financial institutions and payment companies are preparing for local data-storage requirements from the Central Bank of Nigeria, while a broader national cloud policy introduces additional...
Nigeria’s banks, fintechs and payment companies may have to meet overlapping requirements from several regulators as the country strengthens its rules on data localisation, cloud infrastructure and digital security.
Table Of Content
On June 15, 2026, the Central Bank of Nigeria introduced requirements for financial institutions and payment system participants to store and manage payment transaction data generated in Nigeria locally by January 1, 2027.
Two months later, the Nigerian government unveiled its National Digital Cloud Policy. The policy establishes a wider framework covering cloud adoption, data classification, cybersecurity and digital infrastructure.
Different mandates, overlapping responsibilities
The CBN’s rules are focused on payment transaction data, while the National Digital Cloud Policy adopts a more graduated approach to government and regulated data. The two frameworks therefore address related but different aspects of how financial services use digital infrastructure.
The CBN is responsible for financial stability, payment systems and operational risk. NITDA has a broader mandate covering technology standards, cloud infrastructure and digital systems. The Nigeria Data Protection Commission adds another layer, particularly in relation to personal data and cross-border transfers.
Awe described the relationship between the CBN and NITDA as “a question of regulatory overlap” rather than a direct clash between regulators.
Rahma Ibiyeye said a financial institution may need to comply with both CBN rules and NITDA requirements governing the infrastructure that supports its operations.
“There is a legal boundary between the roles of the CBN and NITDA,” Ibiyeye said. “Although that boundary does not mean that only one regulator can regulate an arrangement involving cloud or data-centre services.”
She characterised the situation as “concurrent compliance,” adding: “Where both regimes validly apply, it must comply with both.”
Questions for financial institutions and cloud providers
The regulatory overlap means businesses will need to assess where production data, backups, disaster-recovery systems and security logs are located. Financial services companies may rely on cloud providers, local data centres, foreign software and cross-border backup services, making those infrastructure decisions part of their compliance planning.
However, the available regulatory interpretation does not establish what qualifies as primary payment data. It also does not determine whether backups or disaster-recovery systems must be located in Nigeria, or whether a foreign cloud provider could meet the requirements through a Nigerian availability zone or a local data-centre partner.
Cloud providers, meanwhile, must determine whether their infrastructure meets national standards as well as requirements applicable to the financial sector.
Ibiyeye said the CBN could require financial institutions to use cloud infrastructure that meets specified standards. She distinguished that responsibility from independently licensing or certifying cloud providers, which would represent a different regulatory role.
Proposed division of duties
Adeoye Abodunrin proposed that NITDA lead on technical standards for cloud systems, data centres and digital infrastructure, while the CBN applies those standards to banks and payment companies and adds financial-sector risk requirements.
“NITDA should be the lead technical regulator … while the CBN would be in charge of the financial content and context with the banking guidelines and strategic inputs,” Abodunrin said.
The detailed technical rules for implementing the two frameworks have not been established in the available information. For financial institutions and payment companies, the immediate confirmed deadline is January 1, 2027, when the CBN’s local-storage and management requirements for payment transaction data generated in Nigeria are due to take effect.
No Comment! Be the first one.