By Opeyemi Bello
Data localisation is one of those rare policies that almost everyone agrees with in principle and argues about in practice.On 15 June 2026, the Central Bank of Nigeria issued circular PSS/DIR/PUB/CIR/001/004, signed by Dr Rakiya Yusuf, Director of the Payments System Supervision Department, directing financial institutions to localise payment data. The circular signals a new posture of systemic oversight, under which the largest fintechs would be supervised as critical financial infrastructure rather than as startups. And it mandates data localisation, which has attracted the most attention, because it is by far the most operationally demanding.
It requires that all payment transaction data generated in Nigeria be “stored and managed within Nigeria” by 1 January 2027. Read broadly, as the law firms parsing it have, the requirement extends to transaction databases, settlement and reconciliation records, switching logs, merchant and issuer records, audit trails, and, critically, backups and disaster-recovery systems. The circular supplements rather than replaces the Nigeria Data Protection Act 2023, leaving covered institutions subject to two compliance regimes at once. It specifies no fixed penalties of its own, only discretionary “supervisory sanctions”; the single quantified monetary penalty in the surrounding framework belongs to the NDPA, at up to ₦10 million or two per cent of annual gross revenue. Firms are expected to comply by a hard deadline, to a standard the circular never fully defines, under a penalty it never quantifies.
The principle behind the policy deserves broad support. A country’s payment data is a strategic national asset. The regulator supervising a trillion-naira payments ecosystem should not have to rely on a foreign court, a foreign cloud provider, or another government’s cooperation to access data needed for oversight. Financial sovereignty is not protectionism; it is prudent regulation.
The macroeconomic case is real too. Technext puts Nigerian spending with foreign cloud providers at around $ 850 million a year, paid in scarce dollars earned in a currency that lost roughly 70% of its value between 2020 and 2024. Keeping that expenditure at home is a legitimate ambition, and naira-denominated hosting is a genuine hedge.
Where the policy falters is not in its objective but in its execution. The CBN has instructed the industry to achieve full localisation by January 2027, roughly six months after issuing the circular, without ensuring the infrastructure, cloud ecosystem, and operational readiness required to make that transition viable. In effect, it has asked the industry to drive on roads that have not yet been built. We do not have to speculate about the consequences. Another central bank tried this eight years ago, and the deadline did not hold.
It would be naive to read the circular in isolation. It is the latest move in a two-year pattern of the CBN tightening its grip on the fintech sector. In November 2023, the Bank introduced stricter KYC requirements widely seen as targeting fintech onboarding. A few months later, it overhauled the rules for international money transfer operators, raising the minimum capital requirement to US$1 million, imposing a ₦10 million non-refundable licensing fee, and excluding fintech companies from holding those licences altogether. Then, on 29 April 2024, it ordered five of the country’s best-known fintechs; OPay, Moniepoint, Kuda, PalmPay and Paga, to stop onboarding new customers entirely, two days after the EFCC froze 1,146 accounts linked to illicit foreign-exchange dealing.
The issue is not that the CBN should supervise the industry. It should. The concern is that it has repeatedly reached for the bluntest regulatory instrument available: impose a hard deadline first and deal with the operational consequences later. Data localisation reflects that same instinct, only this time it targets the industry’s underlying infrastructure rather than its business processes. That makes feasibility not an academic question, but the central one.
The platforms Nigerian fintechs actually run on have no home in Nigeria. AWS, Microsoft Azure and Google Cloud do not operate a full data-centre region in the country. AWS has run a Local Zone in Lagos since January 2023, but a Local Zone is a latency extension of a parent region rather than a standalone one, and its parent is Cape Town. Azure’s nearest region is Johannesburg, as is Google Cloud’s. Equiano lands in Lagos, but a subsea cable delivers connectivity, not compute. For most institutions, then, compliance is not a configuration change. It means migrating live production workloads off the infrastructure on which a decade of Nigerian fintech has been built. That is not simply an ambitious migration programme. It is a race against physical constraints.
Migrate them to what? Nigeria has roughly 50 to 56 megawatts of live commercial data-centre capacity, by the reckoning of trackers including TechCabal and ConnectingAfrica; counting announced and under-construction facilities, the installed figure rises to between 124 and 137 megawatts. Those are two different measures, frequently blurred into one.
South Africa operates about 355 megawatts across more than 50 facilities, which is precisely why AWS, Microsoft, and Google have their African regions there.
The roster shows why the doubt is reasonable. Rack Centre runs a 13.5-megawatt off-grid gas plant in Lagos and added a 12-megawatt hall in March 2025, bringing its entire footprint to a single campus. Open Access Data Centres has committed more than 240 million dollars to reach 24 megawatts by 2027, with only the first 12-megawatt phase near-term. Kasi Cloud’s campus is billed at 100 megawatts on full build-out with only its first phase live; Equinix, which bought MainOne for 320 million dollars in 2022, has a 20-megawatt site planned at Alaro City; Airtel’s Nxtra arm is building 38 megawatts in Eko Atlantic. Those all mature during or after 2027, at or beyond the deadline, and none has been tested at the scale of a national payments switch.
The commercial terms differ too: where the hyperscalers seeded a generation of startups with free tiers and credits, local providers charge commercial rates from the first invoice.
The operators themselves disagree about how ready the country is. The chief executive of Open Access Data Centres has argued publicly that physical capacity is not the constraint and that institutions have no reason to delay. A co-founder of Kasi Cloud, someone with every incentive to talk the sector up, has instead asked whether Nigeria has enough cloud computing and storage platforms to carry a migration of this size, and the chief technology officer of the fintech Rank has located the problem in these facilities’ processing capacity rather than their floor space, untested under real load. When the people selling the capacity are the ones raising the caveats, the caveats deserve weight.
The policy also treats data-centre floor space as equivalent to cloud infrastructure. It is not. A building filled with racks does not automatically become a managed cloud platform capable of running high-availability financial workloads at national scale. The real question is whether Nigeria has enough mature cloud platforms, with proven storage, networking, orchestration, and operational resilience, to absorb this migration without compromising reliability. The policy assumes the answer is yes. That assumption has yet to be demonstrated.
Huawei is the notable exception. In December 2024, it launched what it describes as Nigeria’s first hyperscale cloud region, offering more than thirty managed cloud services, with another US$400 million off-grid facility announced for Ogun State. If any provider can satisfy the CBN’s localisation ambition today, Huawei is probably the strongest candidate. Yet that exposes an uncomfortable irony. A policy justified in the name of data sovereignty may ultimately shift Nigeria’s payment infrastructure away from American cloud providers and towards a Chinese one. The policy does not eliminate dependence on foreign infrastructure. It merely changes which foreign infrastructure Nigeria depends on.
AWS presents the opposite problem. Its Lagos Local Zone genuinely allows certain workloads and data to remain in Nigeria, but it is not a full AWS region. The control plane remains in Cape Town, and several core managed services, including Amazon RDS, are unavailable locally.
be both “stored and managed” within Nigeria depends entirely on a phrase the circular never defines. The most obvious compliance path therefore rests on the very ambiguity the policy leaves unresolved.
Power presents an equally serious challenge. Nigeria’s electricity grid supplies only about 5,000-6,000 MW to a population of more than 230 million people. Most commercial data centres compensate for power outages with diesel generation and other backup systems, often at two or three times the cost of grid electricity, as fuel prices continue to rise. The irony is difficult to ignore. In the name of resilience, the policy proposes moving critical payment infrastructure from globally distributed cloud platforms onto an electricity ecosystem that is materially less resilient than the one it replaces.
The problem extends beyond electricity. Roughly fourteen of the country’s seventeen operational data centres sit in Lagos. Fintechs that today rely on geographically separated cloud regions for failover would instead cluster critical infrastructure within a single metropolitan area, precisely at the moment the circular forbids keeping a disaster-recovery copy abroad. The safety net disappears just as the tightrope becomes narrower.
Who, then, can realistically comply?
For a Tier-1 bank, localisation is an infrastructure project. Large banks have operated their own data centres for decades. They already employ the systems engineers, procurement teams, security specialists and 24-hour operations staff needed to run mission-critical infrastructure. The capital expenditure is significant, but familiar.
The defining innovation of the last decade was that infrastructure no longer had to be owned.
The public cloud transformed servers from capital expenditure to operating expense. Startups rented computing power by the hour instead of buying racks, maintaining hardware and building disaster-recovery sites. Modern fintechs are built not only on rented servers but also on managed databases, object storage, message queues, identity services, and autoscaling capabilities that local colocation alone cannot replace. That lowered the cost of entry and allowed small engineering teams to compete with institutions hundreds of times their size.
The localisation mandate risks reversing that advantage. Where mature managed cloud services are unavailable locally, firms are pushed back towards owning or colocating physical infrastructure, procuring hardware, building redundancy, staffing operations teams and paying for diesel-backed resilience. Those are capabilities that cloud-native fintechs were deliberately designed not to build and a capital line they cannot casually fund.
So, the cost of compliance falls unevenly, a point Nairametrics has made in its own analysis of the circular. What is a manageable infrastructure investment for an incumbent bank is a change to the operating model of a fintech. A policy meant to strengthen the payments ecosystem may end up raising barriers to entry, weakening competition and reinforcing the position of the very incumbents fintech was created to challenge.
There is an irony here. A startup improvising a colocation deployment under deadline pressure may present a greater operational and security risk than the mature, geographically resilient infrastructure of the bank it was meant to challenge.
That competitive distortion is not merely a banking question; it is also a digital-economy question. In the first week of July, the Ministry of Communications, Innovation and Digital Economy emphasised that cross-cutting digital-economy issues require coordinated policymaking, broad consultation and regulatory certainty. It is difficult to think of a policy that better illustrates the need for that coordination than a nationwide mandate affecting the infrastructure on which Nigeria’s fintech industry depends.
Even a firm with the capital and capacity to comply would run into a second problem: it is unclear what compliance looks like. The circular sets a destination and a date, but almost none of the engineering detail a migration of this kind requires.
It does not define which data fields are in scope. “Payment transaction data” reads broadly in the law-firm summaries, but a compliance team has to decide, field by field, whether customer identifiers, device metadata, internal risk scores, and archived logs fall within the perimeter or outside it. It sets no recovery time or recovery point objective, which is the single number that determines what a compliant in-country disaster-recovery site must actually be built to.
It names no audit cadence and no auditor. And it does not say whether a synchronised in-country copy satisfies the rule or whether the primary system itself must sit onshore, which is the difference between a manageable migration and a wholesale re-platforming.
The circular’s other reforms inherit the same gap. It signals that the largest fintechs will be supervised as critical financial infrastructure without saying what makes an institution large enough to qualify. And it attaches no penalty schedule to any of it, only discretionary supervisory sanctions.
Ambiguity of this kind is often mistaken for a light touch. It is the opposite. A firm that cannot see the standard must either over-build against the strictest plausible reading or under-build and hope. The cost of guessing falls hardest on exactly the institutions described above; the startups and mid-tier operators who cannot keep specialist counsel on retainer to interpret a regulator’s silence.
Nigeria would not be the first country to attempt this, and the closest precedent deserves attention, not as prophecy, but as a caution. In April 2018, the Reserve Bank of India (RBI) directed payment operators to store all payments data locally within six months. The deadline proved unrealistic. Full compliance from the major card networks did not arrive until 2022, and only after the RBI barred non-compliant networks from onboarding new customers. A six-month mandate ultimately took almost four years to enforce. The delay itself is not the most instructive part. The real lesson is that the RBI spent more than a year clarifying what compliance actually meant.
Two aspects of India’s experience are worth keeping in mind. First, localisation did not derail domestic innovation. India’s home-grown payments ecosystem expanded rapidly throughout the transition, suggesting that data localisation is not inherently hostile to innovation. Second, there is little evidence that localisation alone materially reduced fraud or improved regulatory access to data. Those outcomes depend far more on governance, legal cooperation and data integrity than on the physical location of a server. The lesson is therefore narrower than either advocates or critics sometimes suggest: data localisation can work. Unrealistic deadlines rarely do. And Nigeria is starting from a thinner infrastructure base than India was.
That is also Nigeria’s opportunity. The objective is not the problem. The sequencing is.
The CBN should replace the current cliff-edge deadline with phased milestones over 18 to 24 months, beginning with data mapping, followed by primary storage, then disaster recovery, and only then processing. That would allow infrastructure to be built, tested and proven as firms migrate onto it, rather than forcing an entire industry onto capacity that is still maturing.
At the same time, the Bank should resolve the circular’s most consequential ambiguity. Does compliance require the primary system itself to sit in Nigeria, or is a synchronised in-country copy sufficient? The difference determines whether firms face a manageable migration or a wholesale re-platforming.
The more durable solution is to create the conditions that enable hyperscalers to establish local regions or mirrored infrastructure. That would give the CBN the supervisory access it seeks while allowing financial institutions to migrate on a timeline dictated by infrastructure readiness rather than regulatory deadlines.
Finally, the obligations should reflect institutional scale. A two-year-old fintech should not face the same infrastructure burden as a Tier-1 bank, and the mandate should be paired with local hosting incentives so that compliance does not simply price the smallest innovators out of the market. Nor should localisation proceed without parallel investment in its prerequisites: reliable power, geographically distributed data-centre capacity, and a mature domestic cloud ecosystem. Regulation cannot create infrastructure simply by requiring it.
Nigeria is right to want its payment data at home. But sovereignty is built as much on infrastructure as on regulation. Right now, the destination is correct. The sequence is not. You build the road first. Then you move the traffic.
•Bello is Chief Technology Officer, CashAfrica. He can be reached through [email protected]; 09063083534
Follow Us on Google News
Follow Us on Google Discover