CBN Data Localisation 2027: What Nigerian Fintechs Need to Do Now to Stay Compliant
The Central Bank of Nigeria's June 2026 circular is clear: all payment data processed by licensed financial institutions and fintechs must be hosted within Nigerian borders by January 2027. That gives you roughly six months to assess, plan, and execute a data residency migration — or face enforcement actions that could include licence suspension.
This isn't theoretical. The CBN has shown increasing willingness to enforce data governance rules, and the January 2027 deadline carries real consequences. If your payment data currently lives in AWS us-east-1, Google Cloud's Iowa region, or any server outside Nigeria, you need a plan today.
What Data Must Stay in Nigeria?
The circular specifically covers payment-related data. Based on the regulatory text and CBN guidance documents, the following must be hosted domestically:
- Transaction records: All payment transaction logs, including amounts, timestamps, sender/receiver details, and status
- Customer PII: Names, addresses, BVN, NIN, phone numbers, and any personally identifiable information tied to payment accounts
- Payment logs: API call logs, webhook records, reconciliation data, and settlement records
- KYC documents: Identity verification documents, selfies, utility bills, and associated metadata
- Account records: Wallet balances, account statements, and financial history
Non-payment data like marketing analytics, internal HR records, and general application code can remain offshore. But anything that touches a customer's money or financial identity must be in Nigeria.
Your Cloud Compliance Options
Option 1: AWS Africa (Cape Town) Region
AWS's af-south-1 region in Cape Town is the closest AWS region to Nigeria. While not in Nigeria itself, it's on the African continent and offers ~80ms latency from Lagos. However, for strict CBN compliance, Cape Town may not satisfy the "within Nigeria" requirement depending on how the CBN interprets "domestic."
AWS has announced its "sovereign by design" approach for African financial services, which includes data processing guarantees and contractual commitments about data location. Engage AWS's compliance team directly to understand whether Cape Town satisfies your specific licensing requirements.
Option 2: Local Nigerian Data Centres
Companies like Kasi Cloud, MainOne (now Equinix), and Rack Centre offer colocation and managed hosting within Lagos. These guarantee Nigerian data residency with no ambiguity. The trade-off: fewer managed services, more operational overhead, and potentially higher costs for equivalent compute.
For fintechs that need absolute certainty on compliance, a local data centre for payment data — with non-sensitive workloads remaining on AWS — is the safest bet.
Option 3: Hybrid Architecture
This is the approach we recommend for most Nigerian fintechs. Keep your application logic, APIs, and non-sensitive processing on AWS (where you get Lambda, DynamoDB, CloudFront, and the full service catalogue). Route payment data specifically to Nigerian-hosted infrastructure using data classification and routing rules.
The architecture typically looks like:
- Application layer: AWS (Lambda/ECS) — handles business logic
- Payment data store: Nigerian-hosted database (encrypted, access-controlled)
- Analytics/reporting: AWS — using anonymised, non-PII data
- Backups: Nigerian-hosted with encrypted replication
NDPR Compliance Overlap
The Nigeria Data Protection Regulation (NDPR) and CBN's data localisation requirements overlap significantly but aren't identical. NDPR governs all personal data, not just payment data, and has its own requirements around consent, data minimisation, and breach notification.
The good news: if you architect for CBN compliance correctly, you'll cover most NDPR requirements simultaneously. Both require:
- Encryption at rest and in transit
- Access controls and audit logging
- Data classification and inventory
- Incident response procedures
The key difference: NDPR allows cross-border data transfer with adequate safeguards (like Standard Contractual Clauses), while CBN's localisation mandate is absolute for payment data — no exceptions, no adequacy determinations.
Steps to Assess Your Current Data Residency
Before you can migrate, you need a clear picture of where your data actually lives. Most fintechs are surprised by what they find.
- Audit your infrastructure: Map every database, storage bucket, cache, and queue. Document the AWS region (or hosting location) for each.
- Classify your data: Tag each data store as "payment data," "customer PII," "operational," or "analytics." The first two categories fall under CBN requirements.
- Check third-party services: Your payment processor, KYC provider, email service, and analytics tools may store data offshore. Review their data processing agreements.
- Map data flows: Trace how payment data moves through your system. It might start in Lagos, pass through a US-hosted API, and land in an EU database. Every hop matters.
- Document gaps: List every instance where regulated data exists outside Nigeria. Prioritise by volume and sensitivity.
Timeline: What to Do Now
With roughly six months until the January 2027 deadline, here's a realistic timeline:
- Months 1–2: Complete data audit, classify all data stores, identify gaps
- Months 2–3: Design target architecture, select local hosting partner, plan migration
- Months 3–5: Execute migration in phases, starting with the highest-risk data
- Month 6: Validation, testing, and documentation for CBN reporting
Don't wait until November. Migrations always take longer than expected, and the CBN isn't known for deadline extensions.
Need help assessing your compliance posture?
NeuraGrid offers free compliance-focused architecture assessments for Nigerian fintechs. We'll audit your current data residency, identify gaps against CBN and NDPR requirements, and design a migration path that meets the January 2027 deadline.
Book your free assessment →