NewsMacroNigeria's Data Localisation Push: Why Local Servers Are Only the First Step

Nigeria's Data Localisation Push: Why Local Servers Are Only the First Step

Author: Techcabal·

Key Takeaways

  • The CBN's June 15, 2026 directive requires banks, fintechs, mobile money operators and payment switching networks to keep payment transaction data generated in Nigeria, including backups, disaster recovery and logs, within the country, with a January 1, 2027 compliance deadline.
  • TechCabal Insights, in partnership with the AWS Partner Network, will host a Power Brunch on September 10 bringing together executives, regulators, cloud providers and technology leaders to examine data localisation in practice.
  • Descasio co-founder Femi Olugbesan argues that changing a database's physical location is not the same as having sovereignty over it, and that the real work is managing the full data lifecycle, including backups, access, analytics and AI usage.
  • Olugbesan cautions that rushed migrations could raise costs and reduce resilience, and recommends data dependency mapping, risk classification and staged workload moves, with limited exceptions where local capabilities do not yet exist.
  • If implemented properly with clear, risk-based rules, localisation could function as industrial policy, unlocking investment in Nigerian data centres, cloud services and AI infrastructure and positioning the country as a West African digital hub.
Nigeria's Data Localisation Push: Why Local Servers Are Only the First Step

Nigeria's financial sector faces a January 1, 2027 deadline to comply with the Central Bank of Nigeria's data-localisation rules, and the country's debate over data sovereignty is shifting away from the simple question of where servers sit. The harder, more practical questions are now front and centre: What happens to backups? Who can access the data? Where is it analysed? Can critical systems run independently of overseas infrastructure? And does Nigeria possess enough local capacity to manage the transition without driving up costs or creating new risks?

The debate sits within a wider legal framework. Nigeria's Nigeria Data Protection Act, signed into law in June 2023, established the Nigeria Data Protection Commission and sets general rules on cross-border data transfers, while earlier guidance — including circulars from the National Information Technology Development Agency (NITDA) — had already pushed for certain categories of data to be stored in-country. The CBN's directive extends that logic into the financial system, where payments data is treated as sensitive.

Those questions come into focus on Thursday, September 10, when TechCabal Insights, in partnership with the Amazon Web Services (AWS) Partner Network, hosts its Power Brunch. The event will bring together CEOs, CTOs, regulators, financial services executives, cloud providers, infrastructure companies and other technology leaders to examine what data localisation means in practice.

For Femi Olugbesan, co-founder and chief information officer of Descasio and one of the speakers at the event, the distinction between localisation and sovereignty is critical.

"Changing the address of the data is not the same as having sovereignty over it," Olugbesan said.

The CBN's June 15, 2026 directive requires banks, fintechs, mobile money operators and payment switching networks to keep payment transaction data generated in Nigeria within the country. The requirements reach beyond primary databases to backups, disaster recovery and logs, and data management must also remain locally governed.

Moving a database from an overseas environment into a Nigerian data centre, however, addresses only part of the problem. A bank could host its primary records in Lagos and still send information abroad for analytics, technical support, security monitoring or backup. In such a case, the data sits physically inside Nigeria while important parts of its operational lifecycle remain outside the country.

"The real work is understanding the full life of the data — where it is created, where it is backed up, which teams can see it, where it is analysed and which AI models are allowed to touch it," Olugbesan said.

That reframes localisation from an emergency hosting exercise into a business transformation project.

The complexity behind the migration

For organisations preparing for the deadline, the hardest part may not be moving the data itself.

"Data can be copied," Olugbesan said. "The difficult part is moving the operating model around it without breaking the business."

Large organisations have built up years of dependencies across their technology environments. Customer platforms may run in one location and identity services in another, while backups, security monitoring, payment connections, reporting tools and vendor support sit elsewhere. Untangling those connections becomes difficult once an organisation must draw a firm geographic boundary around its data.

Cost adds another layer of complexity. Localisation could force organisations to duplicate systems, maintain additional recovery environments, hire or retrain technical teams, and redesign applications originally built around global cloud infrastructure. A rushed migration could therefore produce unintended consequences: higher costs and reduced resilience.

Instead, Olugbesan believes organisations should begin with a data and dependency map, classify information by risk, and move workloads in controlled stages. Some systems may need localisation immediately, others isolation or redesign, while limited exceptions may be necessary where equivalent capabilities do not yet exist in Nigeria.

The broader question is whether regulation can deliver greater control without merely relocating existing complexity.

Can Nigeria's infrastructure keep pace?

That question will matter as demand for local cloud and data-centre capacity grows.

Nigeria has credible data-centre operators and an expanding technology infrastructure market. Yet Olugbesan says it would be unrealistic to assume every regulated workload can move locally at once while receiving the same breadth of services and maturity available in established global cloud regions.

Capacity is not simply server space. It includes reliable power, diverse fibre routes, physical and cyber security, skilled operations teams, spare parts, and disaster recovery systems that have actually been tested. For newer workloads, it also means managed data platforms, high-performance computing and local access to GPU capacity for artificial intelligence.

If regulation-driven demand outpaces the market's ability to add those capabilities, businesses could face higher prices, longer migration queues and excessive concentration of critical workloads in a handful of facilities — a scenario that could weaken resilience, precisely the opposite of what data sovereignty is meant to achieve.

The pressure also creates opportunity. Predictable demand from banks, fintechs and government could unlock investment in data centres, connectivity, energy, cybersecurity and technical skills. Nigeria could become more than a domestic storage market; with the right investment, it could emerge as a regional hub for cloud and digital infrastructure in West Africa.

Where should Nigeria draw the line?

The Power Brunch also unfolds against a broader policy debate over how far data localisation should go. Nigeria is not alone in facing this trade-off: governments including India, Indonesia and Saudi Arabia have adopted or considered data-localisation requirements of their own, and global cloud providers have responded by building in-country regions — evidence that regulation and international infrastructure investment can, in some markets, coexist.

Olugbesan argues regulators should distinguish between genuinely strategic information and data that can safely cross borders with appropriate safeguards. Core financial records, payment and settlement data, national identity information, certain health records, critical infrastructure data, and credentials capable of unlocking those systems all have a strong case for remaining under Nigerian jurisdiction and control.

A blanket requirement covering every data category, however, could impose high costs without necessarily improving security. Anonymised analytics, public information, lower-risk collaboration data and certain temporary processing activities could be handled across borders, provided that encryption, contractual accountability, auditability and clear retention limits are in place.

The key, Olugbesan argues, is classification. Regulators need clear risk categories and equally clear rules for storage, processing and access. Businesses need to know what data is covered, what constitutes compliance, and when exceptions can be granted. Without that clarity, companies may struggle to plan investments and technology architectures around the rules.

From compliance to capability

Ultimately, the localisation debate is becoming a test of Nigeria's ability to build digital capability.

Olugbesan wants a single, practical implementation framework that regulators and operators can work from, rather than broad instructions interpreted differently across institutions. Such a framework, he argues, should be technology-neutral, risk-based, and supported by realistic transition periods, reporting requirements, audits and transparent exceptions.

More importantly, localisation should be used to build the domestic technology market. Government and large regulated institutions rank among Nigeria's biggest technology buyers, and their procurement decisions could create dependable demand for Nigerian cloud services, data centres, cybersecurity, connectivity and AI infrastructure. According to Olugbesan, localisation could become an industrial policy if done properly, giving Nigerian technology companies a stronger base from which to serve the wider African market and creating the infrastructure needed for sovereign AI.

Sovereignty in this sense does not mean shutting Nigeria off from global technology. It means having enough infrastructure, skills, security and governance to decide what must remain under Nigerian control, what can safely cross borders, and how strategically important data can be converted into economic value.

That is the bigger question the September 10 Power Brunch will put before the executives shaping Nigeria's digital economy: can the country enforce localisation while building the capability to make that localisation meaningful? The answer will determine whether the CBN's deadline becomes simply a compliance exercise or the beginning of a more capable Nigerian digital infrastructure ecosystem.