Financial institutions and fintech operators have been told to complete data audits, migration and independent verification before the compliance date.
The Central Bank of Nigeria has ruled out an extension of its January 1, 2027 deadline for financial institutions and fintech companies to store and manage payment transaction data generated in Nigeria within the country.
The directive was restated in Lagos at the CloudReady Nigeria Financial Services Roundtable organised by Africa Hyperscalers. CBN Director of Payments Systems Supervision Rakiya Opemi Yusuf, represented by Assistant Director Babatunde Ajiboye, said affected organizations should begin or accelerate their migration plans immediately.
According to the bank, its June 15, 2026 circular covers the full lifecycle of payment data, including creation, processing, storage and disposal. Compliance therefore requires more than moving an archive or relocating a server.
The CBN urged institutions to audit and classify their information, agree on suitable Nigerian hosting architecture and contracts, test the arrangements and obtain independent confirmation that migration requirements had been met.
The Nigeria Data Protection Commission also stressed the strategic importance of data sovereignty. Its chief executive, Vincent Olatunji, represented by Ibukunoluwa Owa, said Africa accounted for only a small fraction of global data-centre capacity and needed stronger domestic infrastructure to reduce exposure to external dependencies.
Olatunji linked the effort to national digital and cloud policies intended to support local skills, infrastructure investment and cloud services.
Africa Hyperscalers Executive Director Temitope Osunrinde said Nigeria had already set a policy direction towards sovereign cloud services, but implementation would depend on workable technical guidance, reliable infrastructure, trusted providers and coordination among regulators.
Representatives of local cloud and data-centre providers, including Nobus Cloud, Open Access Data Centres and Layer 3, said they were preparing to support the transition.
The central bank’s message to regulated entities was that the deadline remained fixed and compliance preparations should include governance, security, continuity and verification arrangements rather than a last-minute transfer of data.