By Royal Ibeh, BusinessDay
Nigerian banks and high-volume fintechs are approaching the Central Bank of Nigeria’s January 1, 2027 data-localisation deadline with an architectural challenge that goes beyond moving databases into the country.
Some financial institutions may consider keeping applications and business logic on foreign public clouds while hosting regulated payment data on infrastructure in Nigeria, hyperscalers told BusinessDay.
The approach, commonly described as split-cloud architecture, can reduce the immediate disruption associated with moving entire systems. However, the hyperscalers stated that it can also create new dependencies between applications running outside Nigeria and data stored locally.
For financial institutions, the issue is therefore not only where payment data is stored. It is also where applications run, where data is processed, where backups are held and how systems communicate across borders.
The CBN’s June 2026 circular requires financial institutions and payment participants to ensure that payment transaction data generated in Nigeria is stored and managed in Nigeria from January 1, 2027.
The requirement covers banks, payment service providers, switching and processing companies, mobile money operators and other licensed participants.
This turns data localisation into an architecture decision rather than simply a database exercise.
The Performance Question
The attraction of split-cloud is straightforward, Temitope Osunrinde, director of Africa Hyperscalers, told BusinessDay, adding that, “A financial institution can move regulated databases to domestic infrastructure while retaining applications and other workloads already running on an international cloud platform.”
However, separating application compute from locally hosted data can introduce latency and operational risk, Osunrinde warned.
Distance matters. When applications are hosted outside Nigeria but need to access data in Lagos, transactions have to travel across an international network path.
The effect will depend on the application design, network quality, number of database requests, caching and whether different processes can run at the same time, the executive director explained.
For systems that process authentication, fraud checks, account validation and ledger updates as part of a transaction, repeated communication between application and database environments can become an important performance consideration, Osunrinde stated.
He added that the risk is particularly relevant for high-volume payment platforms, where small delays across individual processes can become more significant when repeated across large numbers of transactions.
Financial institutions therefore need to test their actual applications rather than assume that moving the database will have no effect on performance, he advised.
The Economics Of Partial Migration
Cost is another issue, Osunrinde disclosed, adding that, moving only regulated data into Nigeria may reduce the immediate cost and disruption of a wider cloud migration, but a split environment can also leave an institution paying for infrastructure in more than one location.
“A bank may continue to incur foreign-cloud charges for application hosting, computing, storage, analytics and other services while also paying for domestic infrastructure. Cross-border data transfer can add another cost depending on the architecture and cloud provider. Foreign-exchange exposure is also relevant for Nigerian institutions paying international cloud providers in dollars or other foreign currencies,” he added.
This creates a broader question for technology executives: does the proposed architecture reduce the institution’s total technology cost over several years, or simply reduce the cost of meeting the immediate localisation requirement?
The answer will differ from one institution to another, Osunrinde replied, while explaining that the calculation should include cloud consumption, data-transfer charges, infrastructure, connectivity, disaster recovery, cybersecurity, technical support and the cost of operating duplicate environments.
Data sovereignty also extends beyond the physical location of a database. Section 41 of the Nigeria Data Protection Act sets conditions for transferring personal data outside Nigeria.
“For financial institutions, this means understanding where information is processed, accessed, replicated, backed up and transferred.
“A foreign-hosted application accessing a Nigerian database does not, by itself, establish that an institution has breached the CBN directive or the Nigeria Data Protection Act. But it does show why server location alone cannot answer every question about data sovereignty,” he stated.
The CBN’s localisation requirement operates within the financial system, while Nigeria’s wider data-protection and cloud-policy framework is also developing.
For CIOs and CTOs, Osunrinde advised that the practical requirement is to map the entire data journey.
“That includes the primary database, application servers, APIs, analytics platforms, fraud systems, logs, backups and disaster-recovery environments. They also need to know whether any of these systems send regulated information outside Nigeria and under what conditions,” he urged.
Migration Creates Its Own Risks
Full cloud migration is not without risk. Financial institutions running critical applications must consider application compatibility, data integrity, downtime, cybersecurity, business continuity and disaster recovery before moving workloads.
Osunrinde said a rushed migration can create operational problems even when the destination infrastructure is suitable; this is why the localisation deadline should not be treated simply as a date for moving databases.
“Institutions need migration plans that distinguish between workloads that must be localised, workloads that can remain on international infrastructure and workloads that may need to be redesigned. The architecture should also account for what happens when connectivity between environments is disrupted.
“A system that depends on an offshore application reaching a Nigerian database needs a clear operating model for network failure. Similarly, a locally hosted primary database may still have a recovery environment outside Nigeria, creating another question for compliance and resilience planning,” he said.
India Offers A Useful Precedent
Nigeria is not the first emerging market to address the tension between global cloud infrastructure and domestic payment-data requirements.
In 2018, the Reserve Bank of India directed payment-system operators to store payment-system data in India. The regulator subsequently clarified requirements concerning processing outside the country, including domestic storage and repatriation of data.
India’s experience shows that domestic payment-data storage does not necessarily require financial institutions to abandon international technology.
Instead, the regulatory and technical framework needs to establish clear rules around storage, processing, transfer, replication and recovery.
For Nigeria, the lesson is relevant as banks and other payment companies assess how much of their technology stack needs to be redesigned ahead of the 2027 deadline, Osunrinde averred.
Nigeria’s Cloud Infrastructure Is Expanding
The debate is also taking place as Nigeria’s domestic digital infrastructure expands.
A major Tier III data centre in Lagos has an initial 4.5MW capacity as part of a planned 9MW two-phase development. Its first phase involved about $100 million in data-centre infrastructure and a further $20 million in cloud infrastructure.
Osunrinde, said the CBN requirement could accelerate investment across this ecosystem.
“This policy is unlike many previous digital infrastructure initiatives because two important institutions: the Central Bank of Nigeria and the National Information Technology Development Agency, are advancing complementary measures from different regulatory directions,” Osunrinde
He said the alignment could expand as regulators recognise that data sovereignty, cloud adoption and digital infrastructure are increasingly connected to economic resilience and national competitiveness.
What CIOs Need To Examine
For CEOs, CIOs and CTOs, the January deadline provides an opportunity to review cloud architecture beyond compliance.
“The first question is where regulated payment data is stored. The next is where the applications that process that data are running,” Osunrinde stated.
Technology leaders should also map every major dependency between applications, databases, APIs, fraud systems, analytics platforms, logs, backups and disaster-recovery environments, he advised, while urging them to test how those systems behave when international connectivity is disrupted and determine whether critical transactions can continue.
“Cost should be assessed over the life of the architecture rather than only during migration. This includes foreign-cloud bills, foreign-exchange exposure, data-transfer charges, domestic infrastructure, connectivity and duplicated systems. Security and data protection requirements should also be built into the design rather than treated as an afterthought.
“For some institutions, a hybrid or split-cloud model may remain appropriate for specific workloads. For others, greater localisation may make more sense. The important issue is that the decision should be based on the institution’s regulatory obligations, workload requirements, risk tolerance and long-term economics,” he added.
Looking Forward
The CBN has set January 1, 2027 as the deadline for payment transaction data generated in Nigeria to be stored and managed in Nigeria.
The challenge for financial institutions is now to determine what that requirement means for the architecture supporting their payment operations.
Moving a database is one part of the process. Understanding every application, network, backup, recovery and data-transfer dependency is another.
Nigeria’s expanding data-centre, fibre and cloud infrastructure is creating more domestic options for critical workloads. But technology leaders still have to determine which workloads should move, which can remain elsewhere and how the resulting architecture will perform.
The central question is therefore not simply whether payment data is sitting on a server in Nigeria. It is whether the entire architecture can deliver compliance, performance, resilience, security and sustainable cost as Nigeria’s digital financial system continues to grow.
