By Simpson Global Media News Desk.
Nigeria’s banks, fintech companies and payment-service operators are entering a critical phase in the country’s push to keep financial transaction data within its borders, with technology executives warning that only about 14 weeks remain before the Central Bank of Nigeria’s January 1, 2027 compliance deadline.
The issue moved back into sharp focus in Lagos on Thursday, September 24, where technology and banking executives raised concerns about the pace and practical interpretation of the Central Bank of Nigeria’s data-localisation directive.
The discussion comes as financial institutions assess which systems, databases, cloud workloads, backups and processing environments must be moved or redesigned to comply with the new rules.
The CBN directive requires covered payment operators to ensure that payment transaction data generated within Nigeria is stored and managed locally from January 1, 2027. The requirement affects deposit money banks, microfinance banks, mobile money operators, switching and processing companies, payment terminal service providers, payment solution service providers, super agents and other licensed payment operators.
But the technology challenge is considerably more complicated than simply moving computer servers from another country into a Nigerian data centre.
Banks and fintechs operate interconnected technology environments involving core banking applications, payment processors, card systems, mobile applications, cloud platforms, disaster-recovery facilities, cybersecurity systems, analytics tools and international connectivity.
Industry executives now say institutions need to determine exactly which components of those systems fall within the localisation requirement and how they can be moved without weakening reliability or security.
The clock is already running
The CBN issued its payment-system circular in June, setting January 1, 2027 as the date for local storage and management of payment transaction data generated within Nigeria.
By September 2026, the technology industry had entered what BusinessDay described as a 14-week race to prepare for the deadline.
The publication reported that banks and fintechs must reassess their core banking systems, cloud applications, disaster-recovery arrangements and international connections as part of the transition.
The timing matters because large financial institutions do not operate their technology infrastructure as a single system.
A bank may have its core banking platform in one environment, card processing in another, mobile applications connected to cloud services elsewhere, backup systems in a separate location and international software services integrated across the entire architecture.
Moving one component can therefore affect several others.
For a financial institution, the objective is not merely to demonstrate that a server exists inside Nigeria. The institution must also understand where information is replicated, processed, backed up and transmitted.
That makes the deadline both a regulatory and an engineering challenge.
What the CBN wants
The CBN’s June directive was introduced as part of broader measures to strengthen oversight of Nigeria’s rapidly expanding electronic payments ecosystem.
The central bank said the payments environment had undergone significant structural changes as electronic transactions and digital financial services expanded and certain operators gained substantial market presence.
The circular also introduced other requirements, including ultimate beneficial ownership disclosures and market-structure provisions for payment operators.
For technology departments, however, the data-localisation provision is one of the most significant changes.
The basic requirement is that payment transaction data generated in Nigeria should be stored and managed within the country.
The policy is designed to give Nigerian regulators greater access to critical financial information and strengthen control over data generated by the domestic payments system.
It also fits into a wider global debate over data sovereignty, in which countries are seeking greater control over information generated within their jurisdictions.
Nigeria’s digital economy has expanded rapidly over the past decade, making the question of where financial information is stored increasingly important.
Millions of transactions now pass through banks, fintech applications, mobile-money platforms, payment switches, merchant systems and other digital channels.
The technology supporting those transactions is therefore becoming part of the country’s critical infrastructure.
Technology executives question the six-month transition
At the GrowthX Forum in Lagos, technology and banking executives raised concerns about the implementation process.
According to The Guardian, FCMB Chief Technology Officer Blessing Ehize said industry participants had struggled to obtain sufficient clarity on exactly what the CBN considers subject to local storage and what may continue operating through hybrid cloud arrangements.
Ehize said financial-sector technology executives had sought engagement through industry groups but wanted clearer guidance on the technical interpretation of the requirement.
That distinction is important because modern banking infrastructure rarely operates entirely on-premises.
A bank can use a combination of physical servers, private cloud, public cloud, colocation facilities and software services.
A single payment may also generate information that is subsequently copied into fraud-monitoring systems, analytics platforms, customer-service applications, regulatory systems and disaster-recovery environments.
The question for banks is therefore not simply, “Where is the main database?”
It is also, “Where does the information go after the transaction?”
That is why industry participants are asking for clearer technical guidance before completing major migrations.
The fintech sector faces a different challenge
Nigeria’s large commercial banks generally have greater technology budgets, established information-security teams and more extensive infrastructure arrangements.
Smaller fintech companies and newer digital banks may face a different set of pressures.
BusinessDay reported in July that most Tier-1 and Tier-2 banks had already localised significant portions of their transaction data, while fintechs, digital banks and other financial institutions with overseas-hosted workloads were still assessing migration strategies.
For a smaller technology company, moving workloads can involve significant expenses.
There may be existing contracts with international cloud providers.
Applications may have been designed around foreign cloud regions.
Software licences may depend on particular infrastructure.
Technical teams may have built systems around international disaster-recovery arrangements.
Moving those systems can therefore require architectural changes rather than a simple transfer of files.
The financial implications are particularly relevant for startups operating in a more difficult investment environment.
Technology companies that once had relatively easy access to international venture capital are now under greater pressure to demonstrate profitability and efficient use of capital.
A sudden infrastructure migration can therefore affect operating costs at the same time companies are trying to control expenditure.
At the GrowthX Forum, eTranzact Deputy Managing Director Hakeem Adeniji-Adele argued that the six-month implementation window was tight because of the amount of data and infrastructure that may need to be moved.
He suggested that a phased approach could separate storage from computing requirements rather than requiring every affected institution to change its entire architecture simultaneously.
The debate over cloud computing
The data-localisation policy arrives at a time when Nigerian financial institutions are increasingly using cloud computing.
Cloud technology allows companies to access computing resources without owning every physical server on which their applications operate.
For banks and fintechs, cloud infrastructure can provide scalability, redundancy and access to specialised technology.
However, if critical data is hosted in a foreign cloud region, the institution must determine whether that arrangement satisfies the new Nigerian requirement.
That is creating a new demand for local cloud infrastructure.
The transition is not necessarily a choice between Nigerian infrastructure and the international cloud.
Instead, technology executives are examining hybrid models in which regulated workloads are kept within Nigeria while international services remain connected where permitted.
The architecture could involve local data storage and processing for regulated financial information, combined with carefully controlled international services for applications or workloads that are outside the localisation requirement.
BusinessDay reported that banks are examining commercial colocation facilities as one possible route.
Under that model, a financial institution does not necessarily have to build and operate an entire data centre itself.
Instead, it can place equipment in a professionally managed facility that provides power, cooling, physical security, connectivity and access to network operators and cloud providers.
That could reduce the cost and complexity of establishing completely independent infrastructure.
Nigeria’s data-centre market is becoming more important
The localisation requirement is already changing the conversation around Nigeria’s data-centre industry.
Local operators are expanding capacity as demand for domestic hosting increases.
Open Access Data Centres, for example, has reported increased interest from fintech companies and financial institutions seeking local colocation and cloud services.
OADC Chief Executive Officer Ayotunde Coker said in an interview reported by Nairametrics that the CBN directive was creating new discussions around data hosting, while also raising questions about infrastructure capacity, resilience and power.
Coker said the company was seeing increased demand for colocation and cloud services and expected further expansion as financial institutions assessed their infrastructure needs.
He has also argued that Nigeria has the connectivity and infrastructure base required to increase data-centre capacity substantially.
That expansion could have effects beyond banking.
More data centres require engineers, cybersecurity specialists, network professionals, power infrastructure, cooling systems, fibre connections, equipment suppliers and other technology services.
The data-localisation requirement could therefore create a wider domestic technology market around financial infrastructure.
Power remains a major question
A data centre is only as reliable as the infrastructure supporting it.
Financial institutions require systems that can operate continuously.
A payment platform cannot simply shut down because electricity is unavailable.
This makes power one of the central questions in Nigeria’s data-centre expansion.
Data centres require electricity for servers, cooling, networking and security systems.
AI workloads require even greater computing density, making power availability increasingly important as the technology industry expands beyond conventional enterprise computing.
BusinessDay reported that OADC is considering additional power arrangements, including gas-based options, as it expands its infrastructure.
The issue means that Nigeria’s data-localisation programme is closely connected to the country’s broader infrastructure challenge.
Keeping financial information in Nigeria requires more than physical server space.
It requires dependable electricity, multiple fibre routes, reliable telecommunications, cybersecurity, physical security, disaster recovery and technical expertise.
If one component fails, the entire system can be affected.
Resilience is as important as localisation
One of the central questions facing banks is whether moving data into Nigeria can be done without creating new concentration risks.
A bank could theoretically comply with localisation rules but still create vulnerability if all critical infrastructure is concentrated in one facility or dependent on one connectivity provider.
Technology specialists therefore distinguish between data sovereignty and resilience.
Data sovereignty concerns where information is controlled and stored.
Resilience concerns whether systems can continue operating when something goes wrong.
A resilient banking architecture normally requires redundancy.
That can include backup systems, multiple connectivity routes, alternative power supplies and disaster-recovery arrangements.
Coker has advised institutions to examine their architecture rather than simply move servers because the location of the infrastructure alone does not determine resilience.
For financial institutions, this means the migration process must account for both compliance and continuity.
A bank that moves its primary systems without adequately planning backup and recovery could create a new operational risk.
The same applies to fintech companies that depend heavily on cloud services.
The AI dimension
The debate is becoming even more significant because artificial intelligence is increasing demand for computing power.
Financial institutions are using AI and machine-learning systems for activities such as fraud detection, risk assessment, customer support, analytics and operational automation.
Those systems depend heavily on data.
As financial institutions increase their use of AI, the question of where sensitive financial data is stored, processed and accessed becomes more important.
BusinessDay recently described Nigeria’s data-localisation requirement as a test of financial institutions’ AI readiness because organisations increasingly need to understand who controls the infrastructure and data underlying their AI systems.
This creates a longer-term technology question.
Nigeria is not only deciding where payment records should be stored.
The country is also developing the infrastructure that could determine where future digital services are processed.
If more financial data remains in Nigeria, local data centres and cloud providers could become increasingly important to AI development, analytics and other high-computing applications.
That could encourage investment in higher-capacity facilities.
But it also means that infrastructure standards must keep pace with the computing demands of emerging technologies.
The opportunity for local cloud providers
For Nigerian cloud and data-centre companies, the regulatory change presents a potential expansion opportunity.
More financial institutions seeking local hosting could increase demand for colocation, managed cloud services, cybersecurity and connectivity.
The January deadline could also encourage banks that previously relied heavily on international cloud regions to reconsider how much infrastructure they maintain domestically.
Coker told ThisDay that OADC was already seeing more fintech companies and financial institutions discussing data hosting at its facilities.
The broader technology ecosystem could benefit if the increased demand leads to investment in infrastructure rather than simply a short-term migration exercise.
That distinction is important.
If companies only move enough information to satisfy a regulatory requirement, Nigeria may gain limited long-term infrastructure benefits.
If the policy encourages sustained investment in data centres, cloud platforms, connectivity and power, the impact could extend considerably further.
The risk of a “digital island”
Industry executives have also warned against creating a technology environment that becomes disconnected from international infrastructure.
Modern digital services depend on global networks.
Nigerian companies may need to interact with international banks, cloud platforms, software providers, cybersecurity services, payment networks and customers outside the country.
A localisation strategy therefore has to maintain interoperability.
The objective is not simply to isolate data physically.
It is to ensure that sensitive information remains under the required domestic controls while businesses continue to operate in an interconnected global technology environment.
This is one reason industry participants have called for clearer technical standards.
Without a detailed roadmap, different institutions could interpret the rules differently.
That could produce inconsistent architectures and unnecessary costs.
What banks need to examine now
With January approaching, financial institutions have a limited period to map their technology environments.
The first step is identifying the data covered by the CBN requirement.
The second is determining where that data currently resides.
That includes primary databases, backups, disaster-recovery systems, logs, analytics platforms and third-party processors.
The third is assessing which workloads can be moved directly and which require architectural redesign.
Banks also need to evaluate their contracts with international cloud providers.
Some agreements may have been designed around foreign data regions and could require renegotiation.
They must also examine network connections.
Moving a database to Nigeria does not necessarily mean every application interacting with it has also been moved.
The connections between systems therefore become a critical part of the compliance exercise.
Cybersecurity cannot be treated as an afterthought
Any large-scale data migration creates cybersecurity risks.
Information may be exposed during transfers if appropriate controls are not in place.
New infrastructure also creates new security configurations that need to be tested.
Banks must therefore ensure that localisation does not come at the expense of security.
The CBN’s broader regulatory push is occurring against the backdrop of increasing dependence on digital financial services.
More transactions are conducted electronically, while customers increasingly depend on mobile and online platforms.
A major technology failure can therefore have consequences beyond a single company.
It can disrupt merchants, consumers and other financial institutions.
That makes resilience, security and redundancy central to the localisation process.
What happens after January 1?
The January 1, 2027 deadline is not the end of Nigeria’s data-sovereignty debate.
It is likely to become the beginning of a longer process of developing domestic digital infrastructure.
The immediate question is whether affected financial institutions can meet the requirement.
The longer-term question is what Nigeria builds around it.
If demand for local hosting increases, data-centre operators could expand.
Cloud providers could deploy more local services.
Telecommunications companies could strengthen fibre connectivity.
Cybersecurity companies could gain new opportunities.
Power providers could develop infrastructure targeted at data centres.
Universities and technology-training organisations could see greater demand for engineers and specialists capable of managing increasingly complex digital infrastructure.
In that sense, the localisation policy has the potential to influence Nigeria’s technology ecosystem well beyond financial services.
The regulatory dialogue remains central
The strongest point emerging from the latest industry discussions is that technology companies and financial institutions are not necessarily rejecting the principle of local data storage.
Instead, the debate is increasingly focused on implementation.
At the GrowthX Forum, industry executives raised questions about definitions, timelines, infrastructure and engagement with regulators. The Guardian reported that some participants wanted a more structured and phased implementation process.
The CBN, meanwhile, has maintained the January 1, 2027 deadline contained in its directive.
The gap between the regulatory requirement and the technical concerns raised by industry now represents one of the most important issues in Nigeria’s digital-finance ecosystem.
For banks and fintechs, the priority is no longer simply monitoring the policy.
They must determine what the policy means for their own technology architecture.
A larger test for Nigeria’s digital infrastructure
Nigeria’s data-localisation programme is ultimately becoming a test of how prepared the country is to host increasingly important digital infrastructure.
The country already has a growing data-centre industry, extensive telecommunications networks, major financial technology companies and a large digital consumer market.
The next stage is whether those components can operate together at the scale required by a modern financial system.
The CBN’s January deadline has accelerated that conversation.
Banks have to examine their systems.
Fintechs have to assess their cloud arrangements.
Data-centre operators have to prepare for additional demand.
Telecommunications companies have to maintain reliable connectivity.
Power providers have to support infrastructure that cannot afford frequent interruptions.
Regulators have to provide sufficiently clear rules for technology teams to implement.
And cybersecurity specialists have to ensure that the migration does not create new vulnerabilities.
The deadline is therefore about more than where Nigerian payment data sits.
It is about the infrastructure supporting the country’s increasingly digital economy.
With roughly 14 weeks remaining, the technology industry is moving from discussion into implementation.
What happens between now and January will determine whether the transition becomes primarily a compliance exercise or a broader step toward a larger domestic cloud, data-centre and digital-infrastructure ecosystem.
For Nigeria’s banks and fintechs, the immediate task is clear: map the data, understand the architecture, identify the infrastructure gaps and begin the transition.
For the wider technology sector, the January deadline represents something bigger — a test of whether Nigeria can turn the demand for local data storage into sustained investment in the infrastructure needed to store, process and secure the next generation of digital services.



Comments
Post a Comment