Balancing Act: How Nigeria’s Dual Data Sovereignty Rules Impact Financial Institutions

Nigeria is pursuing data localization with two frameworks—one from the Central Bank of Nigeria (CBN) focused on financial institutions, and another national policy covering all digital infrastructure. While both aim to keep critical data within Nigeria’s regulatory reach, their different mandates create compliance complexities for banks and fintechs.

The CBN rule requires payment transaction data generated in Nigeria to be stored locally by January 1, 2027. This came two months after the government launched its National Digital Cloud Policy, which sets broader standards for cloud adoption, cybersecurity, and digital infrastructure.

Concurrent Compliance

Experts like Rahma Ibiyeye of Regcompass Consults explain that these frameworks operate on principles of “concurrent compliance.” Meaning institutions must meet requirements from both regulators where applicable—a bank subject to CBN rules while using cloud services governed by NITDA standards, for example.

“There is a legal boundary between the roles of the CBN and NITDA,” Ibiyeye noted. “But that doesn’t mean one regulator’s authority automatically overrides the other.”

Strategic Data Placement

Rather than seeing this as conflicting mandates, officials like NITDA Director-General Dr. Kashifu Awe view it as regulatory overlap—particularly where financial services rely on shared digital infrastructure.

This creates opportunities for strategic data placement: Fintechs might need to localize core payment data while using cross-border infrastructure for less sensitive workloads, provided they meet all legal requirements.

Key Questions Remain

The practical application raises questions like:

  • What qualifies as “primary” payment data?
  • Can backups reside abroad?
  • Must disaster-recovery systems be local?
  • How can foreign providers demonstrate compliance through Nigerian infrastructure?