NewsMacroNigeria's Overlapping Data Rules Create a Compliance Test for Fintechs and Banks

Nigeria's Overlapping Data Rules Create a Compliance Test for Fintechs and Banks

Author: Techcabal·

Key Takeaways

  • •The Central Bank of Nigeria introduced rules on June 15, 2026, requiring financial institutions and payment system participants to store and manage Nigerian payment transaction data locally by January 1, 2027.
  • •The National Digital Cloud Policy, unveiled roughly two months after the CBN rules, establishes a broader framework covering cloud adoption, data classification, cybersecurity, and digital infrastructure.
  • •The CBN focuses on financial stability and payment-system risk, while NITDA oversees technology standards and cloud infrastructure, with the Nigeria Data Protection Commission adding requirements around personal data and cross-border transfers.
  • •Experts say institutions may face concurrent compliance, meaning businesses must satisfy both regulatory regimes where both validly apply to their data and infrastructure arrangements.
  • •Key technical questions, such as whether backups can remain abroad and how foreign providers can comply, remain unresolved even though the CBN's compliance deadline is fixed.
Nigeria's Overlapping Data Rules Create a Compliance Test for Fintechs and Banks

Nigeria is pressing banks, fintechs, and payment companies to keep more of their data at home just as the government builds a broader framework for cloud infrastructure and data sovereignty. The question is not whether Nigeria wants data localisation — it does — but whether two regulators working from different mandates can implement it without creating a costly compliance maze.

On June 15, 2026, the Central Bank of Nigeria (CBN) introduced rules requiring financial institutions and payment system participants to store and manage payment transaction data generated in Nigeria locally by January 1, 2027. Roughly two months later, the Nigerian government unveiled its National Digital Cloud Policy, creating a broader framework for cloud adoption, data classification, cybersecurity, and digital infrastructure.

Both frameworks share the premise that critical digital infrastructure should not sit entirely beyond Nigeria's regulatory reach. Their mandates differ, however. The CBN is concerned with financial stability, payment systems, and operational risk, while the National Information Technology Development Agency (NITDA) carries a broader role covering technology standards, cloud infrastructure, and digital systems.

Awe described the situation as something of a puzzle, but said he sees the tension less as a clash between regulators than as a question of how their mandates overlap. "I look at it more as a question of regulatory overlap," he said.

Different mandates, shared systems

The overlap exists because financial services depend on the same infrastructure that broader technology regulation governs. A bank can be regulated by the CBN while hosting applications with a cloud provider that is subject to NITDA standards. A fintech can process payments under a CBN licence while relying on local data centres, foreign software, or cross-border backup services.

According to Awe, the CBN can impose technology and cloud requirements on financial institutions because of its sector-specific mandate, while NITDA holds broader responsibility for national information technology and cloud policy. The Nigeria Data Protection Commission adds another layer, particularly where personal data and cross-border transfers are concerned.

The result is a regulatory landscape in which responsibility for data localisation is spread across multiple institutions, each approaching the issue from a different statutory mandate.

That does not mean one mandate automatically cancels out the other. A bank cannot disregard a CBN rule because NITDA has a wider technology remit. Conversely, CBN authority over a bank does not automatically displace NITDA requirements for the infrastructure supporting it.

Rahma Ibiyeye, managing partner at Regcompass Consults, sees the distinction as one between the infrastructure and the regulated institution using it.

"There is a legal boundary between the roles of the CBN and NITDA," Ibiyeye said. "Although that boundary does not mean that only one regulator can regulate an arrangement involving cloud or data-centre services."

Under that logic, a bank could use a data centre that meets NITDA standards and still have to show the CBN that its payment data is stored, secured, managed, and recoverable in line with financial-sector rules. That is the logic of "concurrent compliance. Where both regimes validly apply, it must comply with both," Ibiyeye said.

For businesses, that means deciding where production data, backups, disaster-recovery systems, and security logs can sit, while cloud providers must determine whether their infrastructure meets both national standards and financial-sector requirements.

The question, therefore, is not simply whether data should be local. It is which data, under what conditions, on what infrastructure, and under whose supervision.

Not every dataset is sovereign

The two frameworks may be complementary. The CBN's rule targets payment transaction data, while the National Digital Cloud Policy takes a more graduated approach to government and regulated data.

A fintech could therefore need to localise core Nigerian payment data while using cross-border infrastructure for less sensitive workloads, provided other legal requirements are met That would give Nigeria greater control without isolating its digital economy from global cloud providers.

The harder task is translating broad principles into technical rules: What qualifies as primary payment data? Can backups remain abroad? Must disaster-recovery systems be local? Can a foreign provider comply through a Nigerian availability zone or a local data centre partner?

Adeoye Abodunrin, an AI expert, argues that the agencies need a clearer division of responsibilities. NITDA, he said, should lead on technical standards for cloud systems, data centres, and digital infrastructure, while the CBN should apply those standards to banks and payment companies, adding requirements specific to financial-sector risk.

"NITDA should be the lead technical regulator … while the CBN would be in charge of the financial content and context with the banking guidelines and strategic inputs," Abodunrin said.

Ibiyeye draws a sharper distinction around licensing. The CBN can require banks and other financial institutions to use cloud infrastructure that meets specified standards as part of its oversight of operational and technology risk. But independently licensing or certifying the cloud would be different: it would move the CBN beyond regulating a financial institution's risk and closer to directly regulating the technology provider itself.

Those interpretive questions do not yet have settled answers, but the CBN's deadline is already fixed. Financial institutions and payment system participants have until January 1, 2027, to store and manage payment transaction data generated in Nigeria locally — which puts decisions about backups, disaster recovery, and provider arrangements on a fixed timeline while the technical rules that would answer those questions are still being worked out.

Source: TechCabal