Nigeria appears to have growing local data-centre capacity, but compliance is ultimately a migration, cybersecurity and resilience problem not simply a question of available server space.
Nigeria’s January 2027 Payment Data Rule: What Banks and Fintechs Must Localise
From 1 January 2027, CBN-regulated payment operators must keep payment transaction data generated in Nigeria within the country. The rule does not mean every banking or fintech workload must move, but systems that store, process, replicate or back up regulated payment data may require significant changes.
Nigeria’s payment-data localisation deadline is no longer a distant policy announcement. From 1 January 2027, Central Bank of Nigeria Circular PSS/DIR/PUB/CIR/001/004 requires payment transaction data generated in Nigeria to be stored and managed in the country, putting banks, fintechs and other licensed payment operators under pressure to complete the necessary migration and architecture changes before the deadline.
The CBN is not ordering every workload back to Nigeria
The distinction is important. The circular covers payment transaction data, rather than imposing a blanket requirement to move every application used by a bank or fintech.
It applies to deposit money banks, micro finance banks, mobile money operators, switching and processing companies, payment terminal service providers, payment solution service providers, super agents and other licensed participants in Nigeria’s payments ecosystem.
Compliance therefore begins with finding where the relevant data actually travels. A payment company could store transaction records in one environment, process them elsewhere, send logs to security systems and maintain backups or disaster-recovery copies in another location. Recent industry discussions have consequently focused on identifying where payment data is stored, processed and backed up, rather than simply transferring files from a foreign server to a Nigerian one.
Nigeria may have capacity, but migration is the harder problem
At a recent Lagos roundtable reported by Punch, industry and government participants argued that Nigeria has available data-centre capacity, while warning about shortages of specialised migration skills, pricing pressures and fibre security. Nigeria’s commercial facilities currently provide roughly 50–56MW of live computing capacity, with considerably more infrastructure in development.
At the same discussion, moderator Ayobami Olajide estimated that Nigeria’s ten largest banks spend close to ₦200 billion per quarter on cloud and IT services. That figure was presented as an industry estimate rather than an audited sector total, but it illustrates the scale of the systems involved.
The readiness question is also contested. One industry executive told BusinessDay that many banks are already well advanced while fintechs and digital banks with more overseas infrastructure have further to go. Other technology and cybersecurity stakeholders have argued that the transition period is too short and warned against rushed migration.
Moving payment data can mean redesigning applications
Modern financial services can depend on managed databases, analytics platforms, security tools, identity systems and networking services supplied by large international cloud providers. Moving regulated data may therefore require applications to be refactored when equivalent services or architectures differ locally.
Punch reported one Nigerian microfinance bank describing migration considerations including encryption at rest and in transit, firewall configuration, VPN and leased-line connectivity, IP re-addressing and security-by-design architecture.
Disaster recovery matters too. Keeping payment data inside Nigeria should not translate into putting primary infrastructure, backups and connectivity behind a single point of failure.
That makes this different from Nigeria’s broader Cloud First policy. Cloud First primarily concerns how public institutions procure and use cloud services. The CBN rule creates a specific obligation around payment transaction data in a financial system where outages can immediately affect transfers, merchants and consumers.
Nigeria is simultaneously trying to expand the physical infrastructure underneath that transition. Industry leaders are discussing growth from roughly 50MW towards 200MW of data-centre capacity over five years, reinforcing the wider trend TVA has examined around Africa’s growing dependence on data centres and cloud infrastructure.
More megawatts will help, but capacity alone cannot guarantee the specialised cloud services, skilled engineers, secure fibre routes and tested recovery processes financial institutions need.
Our Recommendation
Banks, fintechs and payment providers should treat the January deadline as a data-mapping and resilience exercise, not simply a hosting move. The immediate task is to identify every location where regulated payment data is stored, processed, backed up or replicated, then establish whether the proposed local architecture preserves security, redundancy and recovery capability.
Migration speed matters, but payment reliability matters more. A localisation project that satisfies geography requirements while creating new single points of failure would solve one risk by introducing another.
Sources & Verification
Central Bank of Nigeria — Circular PSS/DIR/PUB/CIR/001/004
Aluko & Oyebode — Legal analysis of the CBN circular
Punch — Data localisation raises skills and security concerns
TechCabal — CBN’s local data order puts Nigeria’s data centres to the test
BusinessDay — Banks ready, fintechs lag as deadline approaches
Frequently asked questions
What is the CBN’s data localisation deadline for banks and fintechs?
The CBN’s current payment-data localisation requirement takes effect from 1 January 2027. Regulated payment operators are expected to ensure that payment transaction data generated in Nigeria is stored and managed within the country by then.
Does the CBN rule require banks to move all their data to Nigeria?
No. The requirement is specifically focused on payment transaction data, not every workload, application or dataset used by a bank or fintech. However, institutions still need to identify where that payment data is processed, replicated, logged and backed up.
Which financial institutions are affected by the rule?
The requirement applies broadly across Nigeria’s regulated payments ecosystem, including banks, micro-finance banks, mobile money operators, switching and processing companies, payment service providers, super agents and other licensed participants.
Does Nigeria have enough local data-centre capacity for the migration?
Industry participants argue that Nigeria has growing local data-centre capacity, but available server space is only part of the problem. Specialist migration skills, secure fibre connectivity, application dependencies, disaster recovery and resilience are also important.
What should banks and fintechs do before the January 2027 deadline?
They should first map where regulated payment data is stored, processed, backed up and replicated. From there, they need to test whether the proposed local architecture preserves security, redundancy, business continuity and recovery capability rather than treating compliance as a simple server move.
Follow TechView Africa on WhatsApp
Get TechView Africa updates on WhatsApp. Follow our channel for practical technology news, product guides and digital trends from Nigeria and across Africa.










Leave a comment
Comments cannot be edited or deleted after posting. Please review your comment before submitting.
No comments yet. Start the conversation.