Introduction
Few questions in Nigerian financial services regulation now provoke as much quiet anxiety in boardrooms as this one: where, precisely, must payment data live? For banks, fintechs, payment service providers and other participants in Nigeria's payments ecosystem, the question is no longer academic. It goes to the heart of infrastructure strategy, outsourcing arrangements, cost structure, investor confidence, supervisory engagement and regulatory survival.
The position has now become more definite. By its circular of 15 June 2026, the Central Bank of Nigeria directed all financial institutions and participants facilitating payments within Nigeria to ensure that payment transaction data generated within Nigeria are stored and managed in Nigeria, in accordance with Nigerian data protection laws and regulations. Affected institutions are required to comply fully with this requirement effective 1 January 2027. The circular is therefore not a general prohibition on all offshore processing of personal data. Rather, it creates a specific localisation obligation for payment transaction data generated in Nigeria, while other categories of personal data continue to be governed principally by the Nigeria Data Protection Act 2023 and its cross-border transfer framework. For banks, fintechs, payment service providers and other affected institutions, this distinction is critical: payment transaction data must now be treated as a regulated domestic-residency category, whereas other personal data may still be transferred abroad only where the applicable legal basis, safeguards and documentation requirements are satisfied.
This piece examines the current legal architecture, the direction of regulatory travel, and what a defensible compliance posture looks like for banks, fintechs, payment service providers and other institutions operating in or targeting the Nigerian payments market.
What is Data Localization?
Data localisation refers to a legal or regulatory requirement that certain categories of data must be stored, and in some cases managed or processed, within a specified jurisdiction. Governments and regulators typically adopt localisation requirements to enhance regulatory oversight, strengthen control over critical information, support national security objectives, improve supervisory access to data and reduce dependence on foreign infrastructure. Depending on the applicable legal framework, localisation obligations may apply to all data, particular categories of personal data, or sector-specific data such as financial, telecommunications or health information.
Data localisation is often used interchangeably with data residency, but the two concepts are not the same. The confusion is understandable: both terms are concerned with where data is kept, and both arise frequently in discussions about cloud hosting, outsourcing and cross-border data transfers. The distinction, however, is important. Data residency describes the factual or operational location of data; that is, the country or region in which data is stored, whether because of a business decision, a customer requirement, a cloud configuration or an internal technology policy. Data localisation goes further. It imposes a legal obligation requiring specified categories of data to remain within a particular jurisdiction. In other words, residency may be a matter of infrastructure choice; localisation is a matter of regulatory compliance.
The Circular has therefore transformed what may previously have been treated as an operational preference into a binding regulatory requirement for payment transaction data generated within Nigeria.
The Legal Architecture
The NDPA and Cross-Border Data Transfers
The Nigeria Data Protection Act 2023 ("NDPA") is the principal legislation governing the processing of personal data in Nigeria. Importantly, the Act does not impose a general requirement that personal data must be stored within Nigeria. Rather, it regulates the circumstances under which personal data may be transferred outside Nigeria.
Under Part VIII of the NDPA, cross-border transfers are generally permitted where the recipient jurisdiction, organisation or transfer mechanism provides an adequate level of protection or where another lawful basis recognised by the Act exists. These mechanisms include standard contractual clauses, binding corporate rules, approved codes of conduct, certification mechanisms and other safeguards recognised by the Nigeria Data Protection Commission ("NDPC"). In limited circumstances, transfers may also be justified by consent, contractual necessity, public interest considerations, legal claims or the protection of vital interests.
Accordingly, the NDPA adopts a model of regulated international transfers rather than mandatory localisation. The central question under the Act is not where personal data is stored, but whether any transfer outside Nigeria is lawful, properly documented and supported by appropriate safeguards.
The GAID and Enhanced Accountability for International Data Transfers
The position became more significant with the issuance of the General Application and Implementation Directive ("GAID") by the NDPC in March 2025. The GAID, which came into force in September 2025, operationalises the NDPA by prescribing more detailed compliance requirements for organisations that process personal data.
Of particular relevance to banks, fintechs and payment service providers is the GAID's emphasis on accountability in relation to cross-border transfers. Organisations transferring personal data outside Nigeria must be able to demonstrate the legal basis for the transfer, maintain appropriate documentation, undertake due diligence on third-party processors and implement contractual and technical safeguards that satisfy the requirements of the NDPA.
The significance of these obligations is amplified by the financial sector's reliance on global technology infrastructure. Many banks and fintechs utilise cloud services, payment processing platforms, analytics tools and data storage solutions whose infrastructure may span multiple jurisdictions. Even where customer-facing operations are conducted in Nigeria, data replication, disaster recovery arrangements and support functions may involve cross-border access to personal data. Such arrangements potentially constitute international transfers requiring compliance with the NDPA and the GAID.
Why the NDPA Framework Is No Longer the Entire Story
For several years, the principal legal question for financial institutions was whether offshore storage or processing of customer data could be justified under the NDPA's transfer framework. If the relevant legal safeguards were in place, the transfer was generally permissible.
The Circular changes that analysis. Unlike the NDPA, which focuses on the conditions for lawful international transfers, the Circular introduces a sector-specific requirement that payment transaction data generated within Nigeria must be stored and managed within Nigeria.
The distinction is significant. Compliance with the NDPA may permit a transfer of personal data outside Nigeria where adequate safeguards exist. The Circular, however, raises a separate and potentially stricter requirement for payment transaction data within the regulated financial sector. The issue is therefore no longer merely whether a transfer is lawful under data protection legislation, but whether the underlying payment data may leave Nigeria at all.
It is this intersection between general data protection law and sector-specific financial regulation that lies at the heart of the emerging data localisation regime for banks, fintechs and payment service providers
The CBN's Data Localisation Mandate for Payment Transaction Data
The regulatory position changed significantly on 15 June 2026 when the Central Bank of Nigeria ("CBN"), through its Payments System Supervision Department, issued Circular No. PSS/DIR/PUB/CIR/001/004 on Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure and Systemic Oversight Measures in the Nigeria Payments System (The “Circular”). The Circular provides that:
"All Financial Institutions and participants facilitating payments within Nigeria shall ensure that payments transaction data generated within Nigeria are stored and managed in Nigeria in accordance with data protection laws and regulations applicable in Nigeria."
At first glance, the Circular appears to introduce a new regulatory requirement. In reality, it is better understood as the culmination of a longer regulatory trajectory within the Nigerian financial sector. For several years, the CBN has consistently favoured domestic control over critical payment infrastructure, payment processing activities and sensitive financial data. The 2026 Circular is significant because it converts that supervisory preference into an express and sector-wide localisation mandate for payment transaction data.
Localisation Before the Circular
The foundations of the current regime can be traced to earlier CBN instruments. The Guidelines on Operations of Electronic Payment Channels in Nigeria prohibit card schemes and payment operators from requiring transaction processing, authorisation or switching to occur outside Nigeria where the transaction originates in Nigeria and involves a Nigerian issuer. Such transactions are expected to be processed and settled through domestic arrangements. Similarly, the Regulatory Framework for Bank Verification Number Operations and Watch-List restricts the transfer of BVN information outside Nigeria without prior regulatory approval.
Collectively, these measures demonstrate that the CBN's concern has never been limited to data protection in the conventional privacy sense. Rather, the regulator has consistently sought to ensure that critical components of Nigeria's payments infrastructure remain subject to effective domestic oversight and regulatory control. The 2026 Circular extends that philosophy beyond specific payment activities and identity systems to payment transaction data itself.
More Than a Data Protection Requirement
The significance of the Circular lies in the fact that it operates differently from the NDPA. Under the NDPA, the principal legal question is whether a transfer of personal data outside Nigeria satisfies the statutory conditions for cross-border transfer. The framework is therefore one of regulated international transfers. Subject to appropriate safeguards, personal data may generally be hosted or processed outside Nigeria.
The Circular adopts a different approach. It proceeds on the basis that payment transaction data generated within Nigeria should be stored and managed within Nigeria. The emphasis is not on the legality of transfer mechanisms but on the location of the data itself.
This distinction is critical. A payment service provider may have a lawful basis under the NDPA to transfer personal data to an overseas cloud environment. That fact alone may no longer be sufficient where the data in question falls within the category of payment transaction data covered by the Circular. In practical terms, compliance with data protection law does not automatically guarantee compliance with financial services regulation.
Implications for Outsourcing and Cloud Infrastructure
The Circular will have significant implications for institutions that rely on global technology infrastructure. Many banks, fintechs and payment service providers utilise international cloud providers whose architecture distributes storage, processing, backup and disaster recovery functions across multiple jurisdictions. In some cases, even where primary systems are hosted in Nigeria, data replication, analytics environments, monitoring tools and support functions may involve offshore processing.
These arrangements were traditionally analysed primarily through the lens of the NDPA's transfer rules. Going forward, they are likely to be scrutinised through a broader regulatory lens that includes the CBN's expectations regarding localisation, operational resilience, supervisory access and control over critical payment infrastructure.
This is not entirely surprising. Under BOFIA and the CBN's outsourcing framework, regulated institutions have never enjoyed complete freedom to relocate critical functions or infrastructure without regulatory scrutiny. The location of systems supporting core financial services has long been regarded as a matter of prudential supervision, not merely information technology management. The Circular reinforces that position by bringing payment transaction data squarely within the localisation conversation.
An Emerging Multi-Regulator Compliance Environment
The most important consequence of the Circular is that payment transaction data in Nigeria can no longer be analysed through a single regulatory lens. A bank, fintech or payment service provider must now navigate overlapping obligations arising from multiple regulatory frameworks. Personal data engages the NDPA and the supervisory jurisdiction of the Nigeria Data Protection Commission. Payment transaction data engages the CBN's localisation requirements. Telecommunications-related data may attract obligations under the regulatory framework administered by the Nigerian Communications Commission.
The result is an increasingly layered compliance environment in which institutions must satisfy multiple regulators simultaneously. Compliance with one framework does not necessarily amount to compliance with another. The legal challenge going forward is not simply understanding each regime in isolation, but ensuring that the organisation's data governance, technology architecture and operational models can withstand scrutiny across all of them.
Enforcement Is No Longer Theoretical
Any residual complacency about data governance and cross-border data transfers should have been dispelled by recent regulatory enforcement activity. The Nigeria Data Protection Commission ("NDPC") has demonstrated an increasing willingness to impose substantial sanctions where organisations fail to comply with applicable data protection requirements.
Most notably, the Commission's ₦766.2 million penalty against Multichoice Nigeria included findings relating to the unlawful transfer of personal data outside Nigeria. During the same period, the NDPC concluded its landmark enforcement action against Meta and issued compliance notices to more than one thousand organisations across sectors including banking, pensions, insurance and gaming, requiring them to demonstrate compliance within compressed timelines.
The significance of these developments extends beyond the organisations directly affected. They underscore a broader regulatory reality: compliance obligations relating to data governance, accountability and international transfers are now being actively supervised and enforced.
The message emerging from both the NDPC and the CBN is increasingly clear: cross-border data flows are permitted where legally justified, appropriately documented and adequately safeguarded, but they are no longer assumptions to be taken for granted.
What This Means in Practice for Financial Institutions
The most immediate consequence of the Circular is infrastructural. Banks, fintechs, payment service providers and other participants facilitating payments within Nigeria must identify all payment transaction data generated within Nigeria and ensure that such data is stored and managed in Nigeria by 1 January 2027.
Achieving this objective requires substantially more than a contractual amendment with a cloud provider. Institutions will need to undertake comprehensive data-mapping exercises, classify and segregate payment transaction data, review existing vendor arrangements, assess infrastructure dependencies, develop migration roadmaps, conduct testing, establish governance oversight mechanisms and maintain documentation capable of withstanding regulatory scrutiny.
Particular attention should be paid to environments that may not traditionally be viewed as primary repositories of payment data. Core banking platforms, payment gateways, switching infrastructure, fraud-monitoring systems, analytics environments, backups, disaster recovery architecture and support tools may all contain or process payment transaction data falling within the scope of the localisation requirement.
Given the scale of potential remediation, institutions that delay implementation planning until late 2026 may find themselves facing significant operational and regulatory risk.
The Commercial and Strategic Dimension of Localisation
It would be incomplete, however, to view localisation solely through a compliance lens. Critics have argued that data localisation requirements may increase operational costs, reduce flexibility, complicate cloud deployment models and place additional pressure on domestic digital infrastructure. Concerns have also been expressed regarding the extent to which localisation requirements may sit uneasily alongside broader objectives relating to digital trade and regional integration under initiatives such as the African Continental Free Trade Area.
The competing policy considerations are equally substantial. Localisation can enhance regulatory visibility, strengthen supervisory access to critical information, reduce dependence on foreign infrastructure and improve resilience against geopolitical and foreign legal risks. It may also stimulate investment in domestic data-centre capacity, cloud infrastructure and local technical expertise.
From a business perspective, the economic analysis is more nuanced than is sometimes acknowledged. Compliance will inevitably involve expenditure. Migration projects, locally hosted redundancy arrangements and infrastructure restructuring may increase costs in the short to medium term.
Yet there is a corresponding commercial upside. Demonstrable data sovereignty is increasingly becoming a competitive advantage. The ability to show regulators, enterprise customers, banking partners and investors that critical payment data is fully aligned with Nigerian regulatory expectations can strengthen confidence, accelerate approvals and reduce diligence concerns. In an environment characterised by increasing regulatory scrutiny, localisation may ultimately become as much a commercial differentiator as a compliance obligation.
Disaster Recovery and Operational Resilience
The migration of payment transaction data to domestic infrastructure raises equally important questions concerning operational resilience. Modern financial institutions typically maintain complex backup arrangements, disaster recovery environments and secondary processing capabilities designed to ensure continuity during cyber incidents, infrastructure failures and other operational disruptions.
The Circular requires payment transaction data generated within Nigeria to be stored and managed in Nigeria. However, it does not expressly address every implementation scenario that institutions may encounter, including encrypted offshore backups, cross-border data replication, remote technical support, cyber-security monitoring or geographically distributed disaster recovery architecture.
Pending additional regulatory guidance, institutions would be prudent to adopt a conservative approach. Existing disaster recovery arrangements should be reviewed carefully, cross-border data dependencies should be documented, and any transfer of personal data should continue to satisfy the requirements of the NDPA and GAID.
Where critical infrastructure or material outsourcing arrangements are affected, proactive engagement with the CBN may help mitigate future regulatory uncertainty.
Building a Defensible Compliance Position
In our experience, institutions best positioned to withstand regulatory scrutiny share several common characteristics. They maintain comprehensive and continually updated data inventories identifying what categories of data are processed, where they are stored, who may access them and whether they are transferred across borders. They distinguish clearly between payment transaction data subject to the CBN's localisation requirement, BVN and other regulated financial identity data subject to sector-specific restrictions, and general personal data governed principally by the NDPA and GAID.
They also maintain robust governance structures, complete required NDPC registration obligations, appoint appropriately qualified Data Protection Officers, conduct Data Privacy Impact Assessments where required, maintain records of processing activities and implement suitable transfer mechanisms for any personal data transfers that remain permissible under Nigerian law.
Equally important, they review cloud, outsourcing and data-processing agreements to ensure that storage, support, access and subcontracting arrangements remain aligned with evolving regulatory requirements. Most importantly, they treat the 1 January 2027 deadline as a strategic compliance milestone requiring board-level oversight rather than as a technology project that can be resolved at the final stage of implementation.
Conclusion
The introduction of mandatory localisation for payment transaction data marks a significant evolution in Nigeria's regulatory approach to digital financial services. The combined effect of the CBN's 15 June 2026 Circular, the NDPA, the GAID and existing sector-specific requirements is the emergence of a layered regulatory framework in which payment transaction data is subject to a distinct localisation obligation, while cross-border transfers of other categories of personal data remain subject to safeguards, accountability measures and regulatory oversight.
For banks, fintechs, payment service providers and other participants in Nigeria's payments ecosystem, the question is no longer whether data localisation will affect business operations. The more pressing question is how quickly and effectively affected institutions can align their infrastructure, governance frameworks, outsourcing arrangements and regulatory engagement strategies with the new requirements.
Institutions that begin implementation early are likely to be better positioned for regulatory compliance, stronger supervisory confidence, enhanced operational resilience and sustained participation in Nigeria's increasingly regulated digital payments market.
References
[1] CBN Circular - PSS/DIR/PUB/CIR/001/004 - CIRCULARON INTRODUCTION OF MARKET STRUCTURE REQUIREMENTS, DATA LOCALISATION, ULTIMATEBENEFICIAL OWNERSHIP DISCLOSURE, AND SYSTEMIC OVERSIGHT MEASURES IN THE NIGERIAPAYMENTS SYSTEM.pdf
[2] Matthew Kosinski, 'Data Sovereigntyvs Data Residency: What's the Difference?' (IBM) https://www.ibm.com/think/topics/data-sovereignty-vs-data-residency accessed 21 July 2026.
[3] Nigeria Data Protection Act, 2023 – Section 41,42 and 43.
[4] Samson Akintaro *NDPC fines Multichoice Nigeria ₦766.2 million for violating NDP Act* (Nairametrics, 6 July 2025) https://nairametrics.com/2025/07/06/ndpc-fines-multichoice-nigeria-n766-2-million-for-violating-ndp-act/ accessed21 July 2026.









