ABUJA, Nigeria — The Central Bank of Nigeria (CBN) has directed all banks and fintech companies to store payment transaction data generated in Nigeria on local servers from January 1, 2027, a move aimed at enhancing regulatory oversight and data protection within the financial system.
The directive was contained in a circular issued to all deposit money banks, merchant banks, payment service banks, mobile money operators, payment solution service providers, and other financial institutions on Monday. The CBN cited the need to strengthen the country’s data sovereignty, improve the security of financial information, and facilitate more effective monitoring of payment transactions by regulatory authorities.
According to the circular, all financial institutions operating in Nigeria are required to ensure that all payment transaction data generated within the country is stored on physical servers located within Nigeria’s territorial borders. The directive applies to both local and international fintech companies offering payment services to Nigerian customers.
The CBN gave financial institutions a transition period ending on December 31, 2026, to fully comply with the new requirements. During this period, banks and fintechs are expected to migrate their data storage infrastructure from foreign servers to local data centres, or to establish new local data storage facilities that meet the CBN’s security and technical standards.
The central bank explained that the decision was driven by several factors, including the rapid growth of digital payments in Nigeria, increasing concerns about cross-border data flows and privacy, and the need to ensure that Nigerian authorities have unfettered access to payment data for regulatory, investigative, and policy-making purposes.
The CBN further noted that storing payment data locally would reduce the risk of unauthorized access by foreign entities, protect Nigerian citizens from potential data breaches originating outside the country, and allow for faster response times during system disruptions or security incidents. It also aligns with global trends toward data localisation, with countries such as India, Russia, China, and several European nations implementing similar requirements.
The directive has significant implications for international fintech companies operating in Nigeria, many of which currently store customer transaction data on servers located in Europe, the United States, or other African countries. These companies may need to invest in local data centre infrastructure or partner with Nigerian-based cloud service providers to achieve compliance.
The CBN also stated that it would issue detailed technical, security, and operational guidelines for the local storage of payment data before the January 2027 deadline. Financial institutions are expected to conduct regular audits of their data storage practices and submit compliance reports to the CBN on a quarterly basis.
The central bank warned that non-compliance with the directive would attract severe penalties, including fines, suspension of operating licences, and prohibition from offering payment services in Nigeria. The CBN also reserved the right to conduct on-site inspections of data storage facilities to verify compliance.
Industry reaction to the directive has been mixed. Major banks in Nigeria, many of which already maintain local data centres for core banking operations, are expected to adapt with relative ease. However, smaller fintech startups and international payment companies may face significant cost and logistical challenges in meeting the new requirements.
The Fintech Association of Nigeria issued a preliminary statement acknowledging the CBN’s right to set data governance rules but called for an extended transition period for smaller players. The association also urged the CBN to provide clarity on data protection standards, cross-border data transfers for processing purposes, and the treatment of historical data currently stored on foreign servers.
Data privacy advocates have largely welcomed the directive, arguing that it strengthens Nigeria’s data sovereignty and reduces the risk of Nigerian citizens’ financial information being exposed to foreign surveillance or corporate misuse. However, some have called on the National Assembly to expedite the passage of a comprehensive data protection bill to provide a legal framework for such directives.
The Nigeria Data Protection Commission (NDPC), which is still in its formative stages, has expressed support for the CBN’s move. The commission noted that data localisation is a key component of the proposed Nigeria Data Protection Act and that the CBN’s directive aligns with global best practices.
As the January 2027 deadline approaches, banks and fintech companies have been advised to begin planning their migration strategies immediately. For now, the CBN has made its position clear: payment data generated in Nigeria must stay in Nigeria, and financial institutions that fail to comply will face the consequences.




