New CBN data policy: Putting the cart before the horse
On 15 June 2026, the Central Bank of Nigeria issued circular PSS/DIR/PUB/CIR/001/004, signed by Dr Rakiya Yusuf, Director of the Payments System Supervision Department, directing financial institutions to localise payment data. The circular signals a new posture of systemic oversight, under which the largest fintechs would be supervised as critical financial infrastructure rather than as […]
On June 15, 2026, the Central Bank of Nigeria (CBN) released a circular (PSS/DIR/PUB/CIR/001/004), signed by Dr Rakiya Yusuf, the Director of the Payments System Supervision Department. This circular directed financial institutions to localize payment data and supervise fintechs as critical financial infrastructure, rather than startups.
The most operationally demanding aspect of this directive is data localisation, which requires all payment transaction data to be stored and managed within Nigeria by January 1, 2027. This regulation extends to transaction databases, settlement and reconciliation records, switching logs, merchant and issuer records, audit trails, backups and disaster-recovery systems.
The CBN's circular supplements the Nigeria Data Protection Act 2023, creating two compliance regimes simultaneously. The circular does not stipulate fixed penalties, only discretionary "supervisory sanctions." The principle behind this policy is to protect a country's payment data as a strategic national asset, and to ensure financial sovereignty, rather than relying on foreign courts, cloud providers, or other governments.
However, the execution of this policy is flawed, as the CBN instructed the industry to achieve full localisation by January 2027, without ensuring the necessary infrastructure, cloud ecosystem, and operational readiness. This approach has been seen before, when another central bank attempted a similar deadline eight years ago, which was not met.
The CBN's tightening grip on the fintech sector is evident through previous actions, such as introducing stricter KYC requirements, raising minimum capital requirements for international money transfer operators, and ordering five major fintechs to stop onboarding new customers. The issue lies in the CBN's approach, which repeatedly uses the most stringent regulatory instrument available: imposing a hard deadline without considering the operational consequences.
Data localisation is a logical extension of this strategy, but it targets the industry's underlying infrastructure rather than its business processes. The platforms Nigerian fintechs currently use, such as AWS, Microsoft Azure, and Google Cloud, do not have a full data-centre region in Nigeria. Instead, these cloud providers have localized zones in Cape Town, Johannesburg, or Equiano lands in Lagos, which are not standalone data-centres.
This means that most institutions cannot comply with the policy by merely configuring their existing infrastructure. Instead, they must migrate their live production workloads to a new infrastructure, which is a formidable challenge. The question arises: to where? Nigeria has limited commercial data-centre capacity, ranging from 50 to 56 megawatts, depending on the source.
Far more is needed to support the scale of a national payments switch. The available options, such as Rack Centre, Open Access Data Centres, Kasi Cloud, Equinix, and Airtel's Nxtra, are all set to mature or complete their projects during or after 2027, the deadline set by the CBN. Furthermore, none of these facilities have been tested at the scale required for a national payments switch. Therefore, it is reasonable to express doubt about their ability to meet the policy's demands.
Written by urgent.news from Daily Trust's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.