Continental Postal Services of Hebland

How Nigeria’s overlapping data rules affect fintechs and banks

Nigeria is asking banks, fintechs, and payment companies to keep more data at home just as the government builds a broader framework for cloud infrastructure and data sovereignty. The question is not whether Nigeria wants localisation. It does. The question is whether two regulators, working from different mandates, can implement it without creating a costly compliance maze.

On June 15, 2026, the Central Bank of Nigeria (CBN) introduced rules requiring financial institutions and payment system participants to store and manage payment transaction data generated in Nigeria locally by January 1, 2027. Two months later, the Nigerian government unveiled its National Digital Cloud Policy, creating a broader framework for cloud adoption, data classification, cybersecurity and digital infrastructure.

Both frameworks share the premise that critical digital infrastructure should not sit entirely beyond Nigeria’s regulatory reach. But their mandates differ. The CBN is concerned with financial stability, payment systems, and operational risk. National Information Technology Development Agency (NITDA)’s role is broader, covering technology standards, cloud infrastructure and digital systems.

Awe told me that the situation can be a bit of a puzzle, but he sees the tension less as a clash between regulators than as a question of how their mandates overlap. “I look at it more as a question of regulatory overlap,” he said.

Different mandates, shared systems

The overlap exists because financial services depend on the same infrastructure that broader technology regulation governs. A bank can be regulated by the CBN while hosting applications with a cloud provider, subject to NITDA standards. A fintech can process payments under a CBN licence while relying on local data centres, foreign software or cross-border backup services.

Awe said the CBN can impose technology and cloud requirements on financial institutions because of its sector-specific mandate, while NITDA has a broader responsibility for national information technology and cloud policy. The Nigeria Data Protection Commission adds another layer, particularly where personal data and cross-border transfers are concerned.

The result is a regulatory landscape in which responsibility for data localisation is spread across multiple institutions, with each approaching the issue from a different statutory mandate.

That does not mean one mandate automatically cancels out the other. A bank cannot disregard a CBN rule because NITDA has a wider technology remit. But CBN authority over a bank does not automatically displace NITDA requirements for the infrastructure supporting it.

Rahma Ibiyeye, managing partner at Regcompass Consults, sees the distinction as one between the infrastructure and the regulated institution using it.

“There is a legal boundary between the roles of the CBN and NITDA,” Ibiyeye said. “Although that boundary does not mean that only one regulator can regulate an arrangement involving cloud or data-centre services.”

A bank could use a data centre that meets NITDA standards and still have to show the CBN that its payment data is stored, secured, managed and recoverable in line with financial-sector rules.

That is the logic of “concurrent compliance. Where both regimes validly apply, it must comply with both,” Ibiyeye said.

For businesses, that means deciding where production data, backups, disaster-recovery systems and security logs can sit, while cloud providers must determine whether their infrastructure meets national standards and financial-sector requirements.

The question, therefore, is not simply whether data should be local. It is which data, under what conditions, on what infrastructure and under whose supervision.

Not every dataset is sovereign

The two frameworks may be complementary. The CBN’s rule targets payment transaction data, while the National Digital Cloud Policy takes a more graduated approach to government and regulated data.

A fintech could therefore need to localise core Nigerian payment data while using cross-border infrastructure for less sensitive workloads, provided other legal requirements are met.

That would give Nigeria greater control without isolating its digital economy from global cloud providers. The harder task is translating broad principles into technical rules: What qualifies as primary payment data? Can backups remain abroad? Must disaster-recovery systems be local? Can a foreign provider comply through a Nigerian availability zone or a local data centre partner?

Adeoye Abodunrin, an AI expert, argues that the agencies need a clearer division of responsibilities. NITDA, he said, should lead on technical standards for cloud systems, data centres and digital infrastructure, while the CBN should apply those standards to banks and payment companies, adding requirements specific to financial-sector risk.

“NITDA should be the lead technical regulator … while the CBN would be in charge of the financial content and context with the banking guidelines and strategic inputs,” Abodunrin said.

Ibiyeye draws a sharper distinction around licensing. The CBN can require banks and other financial institutions to use cloud infrastructure that meets specified standards as part of its oversight of operational and technology risk. 

But independently licensing or certifying the cloud provider would be different: it would move the CBN beyond regulating a financial institution’s risk and closer to directly regulating the technology provider itself.

True scale demands moving beyond surface-level integrations to robust execution. We’ve filtered the noise out of Moonshot 2026, optimising the conference strictly for high-calibre connections between startup founders, global financial operators, enterprise leaders and individuals rewiring Africa’s technical frameworks. Get 20% off Early Bird tickets for a limited time.


Crédito: Link de origem

Leave A Reply

Your email address will not be published.