NEWS

CBN Gives Banks and Fintechs Until 2027 to Localise Payment Data

  • July 7, 2026
  • 8 min read
CBN Gives Banks and Fintechs Until 2027 to Localise Payment Data

The Central Bank of Nigeria has directed banks, fintech companies, mobile-money operators and other licensed payment providers to ensure that payment transaction data generated in Nigeria is stored and managed within the country.

The requirement takes full effect on January 1, 2027, giving affected institutions roughly six months from the circular’s June 2026 publication to restructure systems that currently depend on foreign servers, offshore cloud platforms or overseas processing teams.

The directive is part of a broader CBN circular that also introduces limits on market concentration in card payments, stronger beneficial-ownership disclosure requirements and additional regulatory oversight of Nigeria’s payments industry.

What the CBN ordered

The CBN circular requires financial institutions and payment participants operating in Nigeria to ensure that payment transaction data generated within the country is both stored and managed in Nigeria.

The wording is important because the requirement appears to go beyond keeping a duplicate copy of transaction records on a Nigerian server. Payment firms may also need to examine where the data is processed, analysed, accessed and administered.

The circular was issued on June 15, 2026, under reference PSS/DIR/PUB/CIR/001/004 and signed by Rakiya O. Yusuf, Director of the CBN’s Payments System Supervision Department.

Full compliance with the localisation requirement begins on January 1, 2027.

Who is covered?

The rule applies broadly across Nigeria’s regulated payments ecosystem.

Institutions named in reporting and legal analysis of the circular include:

  • deposit money banks;
  • microfinance banks;
  • mobile-money operators;
  • switching and processing companies;
  • payment solution service providers;
  • payment terminal service providers;
  • super agents; and
  • other licensed payment operators.

The obligation is tied to payment data generated in Nigeria rather than simply to where a company is headquartered.

This means a foreign-owned processor, cloud-based fintech or international payment company may still fall within the scope when it processes transactions involving Nigerian users.

What does “localise payment data” mean?

Data localisation generally requires specified information to be stored or processed inside the country where it was generated.

Under the CBN directive, Nigerian payment data must be stored and managed domestically in line with applicable data-protection laws.

The circular itself refers broadly to payment transaction data. Legal analysis suggests that institutions may need to assess systems containing or using information such as:

  • transaction records;
  • card information;
  • settlement records;
  • payment instructions;
  • authentication information;
  • Bank Verification Number-related data;
  • transaction metadata;
  • fraud-detection models;
  • analytics pipelines; and
  • risk-scoring systems.

The exact scope will depend on how the CBN interprets and enforces the circular.

Firms should therefore avoid assuming that only their main transaction database is covered. Backup systems, customer-support tools, fraud platforms, vendor integrations and remote administrative access may also require review.

Storing data locally may not be enough

A major compliance question is whether a company can keep its primary server in Nigeria while allowing an overseas team or foreign vendor to access the data remotely.

Kiet Law’s analysis argues that foreign access may itself amount to cross-border processing, even where the server is physically located in Nigeria.

That interpretation has significant implications for companies relying on:

  • international cloud-management teams;
  • overseas fraud analysts;
  • foreign software vendors;
  • offshore customer-support centres;
  • global data warehouses; and
  • multinational compliance operations.

A fintech may therefore need more than a Nigerian hosting provider. It may also need to change access controls, internal workflows and contracts governing how foreign employees and vendors interact with Nigerian payment information.

The circular’s wording does not publicly clarify every permitted exception, so affected firms may need further guidance from the CBN before deciding whether limited offshore access remains lawful.

Why the CBN is introducing the requirement

Nigeria’s digital-payment industry has expanded rapidly, increasing the amount of sensitive financial information handled by banks, fintechs and payment processors.

The CBN’s payments supervision mandate includes promoting safety, accountability, transparency and strong internal controls across the payment system.

The localisation rule is intended to improve the regulator’s visibility over payment infrastructure, strengthen consumer protection and reduce operational risks linked to dependence on offshore systems, according to reporting on the circular.

Keeping payment data inside Nigeria may make it easier for regulators to:

  • access information during investigations;
  • conduct compliance inspections;
  • respond to fraud and cyber incidents;
  • enforce Nigerian privacy laws;
  • reduce reliance on foreign infrastructure; and
  • maintain access during international service disruptions.

It may also give the CBN greater confidence that critical payment information remains within its effective regulatory reach.

How the rule relates to Nigeria’s data-protection law

The CBN says locally generated payment data must be managed in accordance with Nigerian data-protection laws.

The Nigeria Data Protection Commission is the authority established under the Nigeria Data Protection Act 2023 to enforce data-privacy obligations and promote responsible handling of personal information.

The Act already places responsibilities on organisations that determine how personal data is processed. The localisation directive adds a more specific sector requirement for payment transaction data.

This creates two overlapping obligations for affected firms:

  1. they must protect and process personal data lawfully under the Nigeria Data Protection Act; and
  2. they must ensure that covered payment data is stored and managed inside Nigeria under the CBN directive.

A system may therefore comply with general privacy safeguards but still fall short of the CBN rule if key payment data remains hosted or managed abroad.

What banks and fintechs may need to change

Companies that already operate fully local infrastructure may require only limited adjustments.

Others may face substantial migration work before January 2027.

Potential changes include:

Moving databases to Nigerian data centres

Firms using foreign-hosted databases may need to transfer primary transaction records and backups to local infrastructure.

Restructuring cloud services

International cloud providers may need to offer Nigerian hosting regions or work through approved local data-centre partners.

Restricting foreign access

Payment companies may need to limit the ability of overseas employees, contractors and vendors to view or administer Nigerian transaction data.

Migrating analytics and fraud tools

Transaction monitoring, fraud detection and risk-scoring systems may also need to operate locally where they consume Nigerian payment data.

Reviewing third-party contracts

Service agreements with processors, software companies and cloud vendors may need to be amended to include localisation, audit and access-control requirements.

Building local recovery systems

Disaster-recovery and business-continuity arrangements may need to use Nigerian facilities rather than offshore backup locations.

These changes can take months because companies must migrate live financial systems without interrupting customer payments.

Possible benefits of data localisation

The policy could bring several advantages to Nigeria’s financial system.

Stronger regulatory access

The CBN may be able to obtain payment records more quickly during audits, fraud investigations and consumer disputes.

Better operational resilience

Local infrastructure could reduce dependence on overseas systems and international connectivity.

Growth for Nigerian data centres

The deadline could increase demand for domestic cloud, cybersecurity and data-centre services. Industry participants have expressed confidence that Nigeria’s local infrastructure sector can support the transition.

Greater control over sensitive financial information

Payment records can reveal account details, transaction patterns, locations and commercial behaviour. Localisation may reduce the number of foreign jurisdictions through which this information moves.

Improved enforcement

Keeping data within Nigeria may make it easier to enforce court orders and regulatory requirements against payment providers.

The rule could also increase costs

Localisation can create significant financial and technical burdens.

Large banks may already operate Nigerian data centres, but smaller fintechs often depend on international cloud platforms because they are flexible, scalable and relatively inexpensive.

Migrating to local infrastructure may require companies to invest in:

  • new servers;
  • local cloud contracts;
  • cybersecurity controls;
  • compliance audits;
  • system redesign;
  • staff training; and
  • new disaster-recovery arrangements.

Smaller companies could face proportionally higher costs because they do not have the transaction volumes or capital resources of major banks.

There is also a risk that strict localisation could reduce access to advanced global tools where equivalent local infrastructure is unavailable.

Will foreign cloud services be banned?

The circular does not necessarily mean that every foreign technology provider will be prohibited from serving Nigerian financial institutions.

However, payment firms will need to demonstrate that covered data is stored and managed in Nigeria.

A foreign cloud provider could potentially remain involved by hosting through Nigerian infrastructure, operating a compliant local region or working with a domestic partner.

What may become more difficult is the use of foreign server regions as the primary location for Nigerian payment records.

Companies will also need clarity on whether encrypted offshore backups, limited technical access and anonymised analytics remain permissible.

What happens to companies that do not comply?

The CBN has said it will monitor compliance and may impose supervisory sanctions where institutions fail to meet the circular’s requirements.

The exact penalty will likely depend on the nature and seriousness of the breach, as well as the powers available under Nigeria’s banking and payment regulations.

Possible regulatory consequences could include fines, remediation orders, restrictions on operations or action against an institution’s licence.

Given the complexity of moving payment systems, companies that wait until late 2026 may struggle to complete testing and migration before the January deadline.

Henry Murangiri
About the author

Henry Murangiri

Co-Founder of Blockwisely

Crypto Trader | Blockchain Researcher | Blockchain Developer

Share:
About Author

Henry Murangiri

Crypto Trader | Blockchain Researcher | Blockchain Developer

Leave a Reply

Your email address will not be published. Required fields are marked *

ETHSafari