Nigeria's payments industry is facing a new data-residency requirement. On 15 June 2026, the Central Bank of Nigeria (CBN) issued a circular requiring financial institutions and participants facilitating payments within Nigeria to ensure that payment transaction data generated within Nigeria is stored and managed in Nigeria.
The requirement takes effect from 1 January 2027. For banks, fintechs, payment service providers and other affected participants, this means understanding where payment data is stored, processed, backed up and accessed.
For procurement teams, data residency is becoming an important vendor-selection question: Where will our data sit, who can access it, and can the vendor support our regulatory obligations?
What Are the CBN Payment Data Storage Regulations?
The CBN payment data storage regulations come from the CBN's circular titled Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System, issued on 15 June 2026.
Read the official CBN circular on data localisation
The circular requires:
“All Financial Institutions and participants facilitating payments within Nigeria shall ensure that payments transaction data generated within Nigeria are stored and managed in Nigeria in accordance with data protection laws and regulations applicable in Nigeria.”
The circular covers the payments ecosystem, including banks, microfinance banks, mobile money operators, switching and processing companies, payment service providers and other relevant licensed participants.
The important point is that the CBN requirement is specifically framed around payment transaction data generated within Nigeria. It should not be interpreted as a blanket rule requiring every type of customer or business data to be stored in Nigeria.
Where does Customer Data Sit Under the CBN Data Localisation Rule?
This is the practical question banks and fintechs need to answer. For payment transaction data generated within Nigeria, the CBN requires that the data be stored and managed in Nigeria from 1 January 2027.
That means an organisation should look beyond the location of its main database.
For example, a Nigerian fintech may have its primary transaction database hosted in Nigeria but use:
An offshore backup environment
A foreign disaster recovery environment
An international analytics platform
A third-party fraud-monitoring service
A cloud service that replicates data across regions
External vendors or subprocessors that can access transaction information
The organisation therefore needs to understand the complete path of its payment data.
A simple question such as “Is our database hosted in Nigeria?” may not be enough to establish whether the organisation's payment-data environment meets the requirement.
The CBN circular does not prescribe a specific cloud provider or technology architecture. The key requirement is that relevant payment transaction data generated in Nigeria is stored and managed in Nigeria.
Does CBN Data Localisation Mean All Customer Data Must Stay in Nigeria?
Not necessarily.
The CBN requirement specifically concerns payment transaction data generated within Nigeria. It does not say that every category of customer, employee or corporate data handled by a financial institution must always remain in Nigeria.
This distinction matters because financial institutions are also subject to Nigeria's wider data-protection framework.
The Nigeria Data Protection Act 2023 governs the processing of personal data and includes provisions dealing with transfers of personal data outside Nigeria.
The CBN's localisation requirement and Nigeria's data-protection requirements therefore need to be considered together.
For example, a payment transaction may contain personal information about a customer. An institution needs to consider both where that payment data must be stored under the CBN requirement and whether any processing or transfer of the personal data complies with the applicable data-protection requirements.
For a broader view of the regulatory environment affecting financial institutions,
See our AML Regulations in Nigeria guide.
What Payment Data Needs to Be Stored and Managed in Nigeria?
The CBN circular does not provide a detailed technical list of every field that qualifies as payment transaction data.
Organisations should therefore begin by identifying the payment information their systems generate and handle.
Depending on the payment model, this can include:
Transaction records
Transaction references and identifiers
Payment amounts and timestamps
Settlement and reconciliation information
Payment-processing records
Information relating to parties to a transaction
Relevant transaction logs and records
The exact data set will depend on the organisation's systems and payment activities.
The important point is to identify which information forms part of the payment transaction and then map where that information is stored, processed, transmitted and backed up.
What Does “Stored and Managed in Nigeria” Mean?
The CBN uses both “stored” and “managed” in the circular. Storage is relatively straightforward: where is the data physically or electronically held?
Management raises a broader operational question about the systems and services used to handle that data.
The CBN circular does not provide a technical definition listing every activity covered by “managed.” However, organisations should consider the wider technology environment supporting their payment data.
This includes questions such as:
Where is the production database hosted?
Where are backups stored?
Where is the disaster recovery environment?
Which applications process the data?
Which third parties can access it?
Where are relevant logs retained?
Can the data be replicated to another jurisdiction?
What happens to the data if a third-party service fails?
This makes data localisation in Nigeria more than a question about the physical location of one server.
How Does CBN Data Localisation Affect Cloud Infrastructure?
Cloud infrastructure makes data residency more complicated because a single application can rely on multiple services and locations.
A financial institution evaluating a cloud or technology provider should ask:
Where is the production environment located?
Where is the database hosted?
Where are backups stored?
Where is disaster recovery infrastructure located?
Does the service replicate data automatically?
Which subprocessors can access the data?
Where do those subprocessors operate?
Can payment data be transferred outside Nigeria during normal operations or disaster recovery?
The CBN data localisation requirement does not amount to a general ban on international cloud providers.
The relevant question is whether the particular architecture and deployment can meet the CBN requirement for payment transaction data generated within Nigeria to be stored and managed in Nigeria.
What Happens to Backups and Disaster Recovery Data?
Backups deserve particular attention. A financial institution may have its primary payment database in Nigeria while keeping backup or disaster recovery copies elsewhere.
If those copies contain payment transaction data generated within Nigeria, the organisation needs to assess them as part of its localisation review.
The CBN circular does not separately state that “all backups must be in Nigeria.” However, because the requirement covers payment transaction data being stored and managed in Nigeria, organisations should not assume that offshore backups automatically fall outside the requirement.
The same applies to disaster recovery.
A useful question for technology and compliance teams is:
If our Nigerian payment environment failed today, where would the system recover and where would the underlying payment data be located?
That question can reveal localisation issues that are not visible when reviewing only the primary production environment.
How Does CBN Data Localisation Affect Third-Party Vendors?
Third-party providers are an important part of the data-residency assessment. A bank or fintech may keep its core payment database in Nigeria while using external providers for:
If these providers receive, process, store or access payment transaction data, their role should be included in the organisation's data-flow review.
This is particularly important during procurement.
A vendor saying that it “supports Nigerian customers” does not, by itself, demonstrate Nigerian data residency.
Procurement and compliance teams should ask:
Where is our data stored?
Where is it processed?
Where are backups kept?
Which subprocessors can access it?
Can any part of the workflow transfer payment data outside Nigeria?
Can the vendor provide evidence of its data-residency arrangements?
These questions should be answered before implementation rather than after a system has already been integrated into the organisation's payment environment.
A Practical Scenario: When Vendor Procurement Becomes a Compliance Question
Consider a Nigerian fintech selecting a new transaction-monitoring platform.
During procurement, the vendor confirms that its primary infrastructure is hosted in Nigeria.
The fintech initially considers the requirement satisfied.
The compliance team then asks:
Where are transaction-monitoring backups stored?
The vendor confirms that backups are replicated to an environment outside Nigeria.
The team then asks:
Does the platform send transaction information to any third-party analytics service?
The vendor confirms that some transaction data is processed by an external provider.
Finally:
Where is the disaster recovery environment?
The vendor confirms that it is also outside Nigeria.
The procurement question has now changed.
It is no longer simply:
“Does this vendor host in Nigeria?”
It becomes:
“Can this vendor's complete architecture support our obligations under the CBN's data localisation requirement?”
The fintech may need to assess whether the vendor can provide a Nigerian deployment, isolate Nigerian payment data, change its backup arrangements or otherwise redesign the environment before proceeding.
This is why data localisation in Nigeria should be considered during vendor due diligence, not only when a regulatory deadline is approaching.
What Should Banks and Fintechs Do Before January 2027?
The first step is to understand where payment transaction data actually goes.
1. Map payment data flows
Identify where payment transaction data is generated, collected, stored, processed and transmitted.
Include the systems connected to the core payment environment.
2. Identify where the data is stored
Check production databases, replicas, backups and disaster recovery environments.
Do not assume that all copies of the data are located in the same place.
3. Review third-party vendors
Identify providers that receive, process, store or access payment transaction data.
Review their hosting locations, subprocessors and data-transfer arrangements.
4. Review contracts
Check whether vendor contracts clearly address data location, security, subcontracting, access, incident notification and data deletion.
5. Identify gaps
Compare the current environment against the CBN requirement that relevant payment transaction data generated within Nigeria is stored and managed in Nigeria.
6. Remediate before the deadline
Where gaps exist, determine whether the organisation needs to migrate data, change a vendor, redesign part of its infrastructure or introduce additional controls.
7. Keep evidence
Maintain records of the assessment, vendor responses, infrastructure changes and controls implemented.
This gives compliance and procurement teams evidence they can refer to when assessing regulatory readiness or onboarding new technology providers.
How Does the CBN Requirement Interact With the Nigeria Data Protection Act?
The CBN payment data storage regulations operate alongside Nigeria's data-protection framework.
The CBN circular itself requires payment participants to comply with applicable Nigerian data-protection laws and regulations when storing and managing payment transaction data.
The Nigeria Data Protection Act 2023 provides the broader framework for processing personal data, including requirements relevant to international transfers of personal data.
This means financial institutions should not treat CBN localisation and data protection as separate, unrelated exercises.
A payment record may contain personal data. The institution therefore needs to consider:
Whether the data falls within the CBN's payment transaction data requirement
Where that data is stored and managed
Whether personal data is being transferred outside Nigeria
Whether any such transfer satisfies the applicable data-protection requirements
The practical starting point is therefore data mapping and classification.
Why Data Localisation Is Becoming a Procurement Requirement
For banks and fintechs, data localisation Nigeria is increasingly becoming a technology procurement question.
A compliance or procurement team evaluating a new payment, fraud, monitoring, analytics or compliance platform may need to ask questions that previously sat mainly with IT.
- Where will our data sit?
- Where will it be processed?
- Where will backups be kept?
- Which third parties can access it?
- Can the vendor support Nigerian data-residency requirements?
- Can the vendor provide evidence of where relevant data is stored and managed?
These questions are easier to answer before implementation than after a system has been integrated into the organisation's technology environment.
For affected payment participants, the CBN data localisation deadline therefore needs to be considered when selecting new vendors, renewing existing contracts and reviewing current infrastructure.
Preparing for the 2027 CBN Data Localisation Deadline
The CBN payment data storage regulations give affected payment participants a clear compliance date: 1 January 2027.
The challenge is not simply identifying one Nigerian data centre. Organisations need to understand the full lifecycle of payment transaction data across applications, cloud infrastructure, backups, disaster recovery systems and third-party vendors.
The practical starting point is simple:
- Map the data.
- Map the infrastructure.
- Map the vendors.
- Identify anything that takes relevant payment transaction data outside Nigeria.
- Remediate the gaps before the deadline.
For banks, fintechs and payment providers, data localisation in Nigeria is ultimately about knowing where payment transaction data sits, how it is managed and whether the organisation can demonstrate that its technology environment supports the CBN's requirements.
Building for a More Secure and Localised Payments Ecosystem
The CBN's 1 January 2027 deadline gives banks, fintechs and other payment participants limited time to understand how payment transaction data moves through their technology environment.
Compliance starts with visibility. Organisations need to know where relevant payment data is stored, processed, backed up and accessed, including through third-party vendors and cloud infrastructure.
At Youverify, security and data protection are fundamental to how we build and operate our compliance infrastructure. Youverify maintains ISO 27001 certification for information security, ISO 27018 for the protection of personally identifiable information in the cloud, and SOC 2 Type 2. You can review our compliance certifications, Information Security Policy, and GDPR commitments.
As financial institutions review their technology and compliance environments ahead of the 2027 deadline, working with providers that take security, privacy and regulatory requirements seriously is an important part of building a resilient compliance infrastructure.
Looking to strengthen your compliance and risk workflows? Speak with our experts.