Services Cloud Products About Contact
August 3, 2026 8 min read

CBN Data Localisation 2027: What Nigerian Fintechs Need to Do Now to Stay Compliant

CBN Data Localisation 2027: What Nigerian Fintechs Need to Do Now to Stay Compliant

The Central Bank of Nigeria's June 2026 circular is clear: all payment data processed by licensed financial institutions and fintechs must be hosted within Nigerian borders by January 2027. That gives you roughly six months to assess, plan, and execute a data residency migration — or face enforcement actions that could include licence suspension.

This isn't theoretical. The CBN has shown increasing willingness to enforce data governance rules, and the January 2027 deadline carries real consequences. If your payment data currently lives in AWS us-east-1, Google Cloud's Iowa region, or any server outside Nigeria, you need a plan today.

What Data Must Stay in Nigeria?

The circular specifically covers payment-related data. Based on the regulatory text and CBN guidance documents, the following must be hosted domestically:

Non-payment data like marketing analytics, internal HR records, and general application code can remain offshore. But anything that touches a customer's money or financial identity must be in Nigeria.

Your Cloud Compliance Options

Option 1: AWS Africa (Cape Town) Region

AWS's af-south-1 region in Cape Town is the closest AWS region to Nigeria. While not in Nigeria itself, it's on the African continent and offers ~80ms latency from Lagos. However, for strict CBN compliance, Cape Town may not satisfy the "within Nigeria" requirement depending on how the CBN interprets "domestic."

AWS has announced its "sovereign by design" approach for African financial services, which includes data processing guarantees and contractual commitments about data location. Engage AWS's compliance team directly to understand whether Cape Town satisfies your specific licensing requirements.

Option 2: Local Nigerian Data Centres

Companies like Kasi Cloud, MainOne (now Equinix), and Rack Centre offer colocation and managed hosting within Lagos. These guarantee Nigerian data residency with no ambiguity. The trade-off: fewer managed services, more operational overhead, and potentially higher costs for equivalent compute.

For fintechs that need absolute certainty on compliance, a local data centre for payment data — with non-sensitive workloads remaining on AWS — is the safest bet.

Option 3: Hybrid Architecture

This is the approach we recommend for most Nigerian fintechs. Keep your application logic, APIs, and non-sensitive processing on AWS (where you get Lambda, DynamoDB, CloudFront, and the full service catalogue). Route payment data specifically to Nigerian-hosted infrastructure using data classification and routing rules.

The architecture typically looks like:

NDPR Compliance Overlap

The Nigeria Data Protection Regulation (NDPR) and CBN's data localisation requirements overlap significantly but aren't identical. NDPR governs all personal data, not just payment data, and has its own requirements around consent, data minimisation, and breach notification.

The good news: if you architect for CBN compliance correctly, you'll cover most NDPR requirements simultaneously. Both require:

The key difference: NDPR allows cross-border data transfer with adequate safeguards (like Standard Contractual Clauses), while CBN's localisation mandate is absolute for payment data — no exceptions, no adequacy determinations.

Steps to Assess Your Current Data Residency

Before you can migrate, you need a clear picture of where your data actually lives. Most fintechs are surprised by what they find.

  1. Audit your infrastructure: Map every database, storage bucket, cache, and queue. Document the AWS region (or hosting location) for each.
  2. Classify your data: Tag each data store as "payment data," "customer PII," "operational," or "analytics." The first two categories fall under CBN requirements.
  3. Check third-party services: Your payment processor, KYC provider, email service, and analytics tools may store data offshore. Review their data processing agreements.
  4. Map data flows: Trace how payment data moves through your system. It might start in Lagos, pass through a US-hosted API, and land in an EU database. Every hop matters.
  5. Document gaps: List every instance where regulated data exists outside Nigeria. Prioritise by volume and sensitivity.

Timeline: What to Do Now

With roughly six months until the January 2027 deadline, here's a realistic timeline:

Don't wait until November. Migrations always take longer than expected, and the CBN isn't known for deadline extensions.

Need help assessing your compliance posture?

NeuraGrid offers free compliance-focused architecture assessments for Nigerian fintechs. We'll audit your current data residency, identify gaps against CBN and NDPR requirements, and design a migration path that meets the January 2027 deadline.

Book your free assessment →