Home Latest Insights | News CBN Data Localisation Deadline: What to Check Before Signing a Cloud Service Agreement

CBN Data Localisation Deadline: What to Check Before Signing a Cloud Service Agreement

CBN Data Localisation Deadline: What to Check Before Signing a Cloud Service Agreement

Introduction

In 2022, I wrote a piece titled “Cloud Heavy: Data Computing & Protection”, arguing that proponents of data sovereignty and data localisation would, sooner or later, win the policy argument. At the time, it was a forward-looking observation rather than a live compliance issue: cloud computing was expanding across Nigerian businesses faster than the regulatory framework around it, and the localisation debate was still largely theoretical for most organisations outside the most heavily regulated sectors.

Four years later, that prediction is no longer theoretical. It is a compliance deadline.

The Directive That Changed the Conversation

On 16 June 2026, the Central Bank of Nigeria (CBN) issued a directive requiring that all regulated payment transaction data generated in Nigeria be stored and managed within Nigerian borders by 1 January 2027. The directive applies to deposit money banks, microfinance banks, mobile money operators, switching companies, payment service providers, and other regulated financial participants; an ecosystem that processes tens of billions of digital transactions annually.

The National Information Technology Development Agency (NITDA) has since moved to operationalise the directive through a Certified Cloud Register, developed under its National Sovereign Cloud Initiative. From October 2026, regulated institutions handling sensitive data are expected to source cloud infrastructure, data centre, managed service, and AI infrastructure providers from this national register. The register is intended to give regulated institutions a common, independently assessed standard for verifying that a provider meets Nigeria’s technical and regulatory requirements, filling a gap that, until now, left compliance verification largely to each institution’s own due diligence.

Together, the CBN directive and the NITDA framework mark the clearest signal yet that Nigeria’s regulators view data location as inseparable from regulatory control. Where data resides increasingly determines who can see it, audit it, and respond quickly when something goes wrong; and that logic is unlikely to remain confined to the financial sector.

Why This Matters Beyond Banks and Fintechs

It is tempting to treat this as a financial-sector story. It is not, not entirely. The broader signal (that Nigerian regulators are prepared to mandate where data physically sits) has implications for any business handling data the state considers sensitive: health records, government contracts, critical national infrastructure, and increasingly, data feeding AI systems. Organisations outside the immediate scope of the CBN directive should read this as a preview, not an exception.

What to Look Out for When Negotiating a New Cloud Service Agreement

For institutions now negotiating agreements with local cloud service providers, or preparing to migrate from an existing foreign provider, the pressure to move quickly is real. But speed and diligence are not naturally compatible, and a cloud services agreement signed under deadline pressure tends to be the agreement an organisation is stuck living with. A few areas deserve particular attention.

1. Data classification and scope

The CBN directive targets payment transaction data specifically, not an organisation’s entire IT estate. Before signing, the agreement should precisely define which data categories are being localised, and confirm that other data may still be legitimately processed elsewhere where the law permits. Over-localising adds unnecessary cost; under-localising is a compliance breach waiting to surface during a regulatory audit.

2. Certification status

Confirm, as a contractual condition, that the provider is on, or has a warranted, dated commitment to join, NITDA’s Certified Cloud Register. A provider that cannot demonstrate this status transfers regulatory risk to the client organisation, regardless of what the marketing material says.

3. Service levels, redundancy, and disaster recovery

Local cloud and data centre infrastructure in Nigeria has expanded significantly, but multi-region failover, automated recovery, and the depth of redundancy that global hyperscalers have built over decades are not replicated overnight. Industry voices have already flagged concerns about the capacity of local infrastructure to absorb large-scale migration without disruption to live financial services. Agreements should include specific, measurable SLAs on uptime and recovery time objectives, not “commercially reasonable efforts” language backed by meaningful financial remedies when they are missed.

4. Audit and inspection rights

Localising infrastructure does not localise legal responsibility. As a data controller or processor under the Nigeria Data Protection Act (NDPA) 2023, an organisation’s compliance obligations remain its own even where the underlying infrastructure is outsourced. The agreement should preserve contractual audit rights, request evidence of security controls, and receive breach notification within a defined and enforceable window.

5. Exit, portability, and data return

This is the clause most often deprioritised while attention is focused on getting the migration done. What happens to the organisation’s data (and how quickly can it be retrieved, in a usable format), if the relationship ends, or if the provider loses its certification? Data return and secure deletion obligations should be negotiated at the outset, while the client still has leverage, not after a dispute has already begun.

6. Pricing, egress, and migration costs

Egress fees from the current (frequently foreign) provider, dual-running costs during transition, and any early termination penalties under the existing contract should all be modelled before negotiations with the new provider begin, and where possible, shared or offset contractually.

7. Regulatory change clauses

The CBN directive, the NITDA register, and the broader National Digital Cloud Policy adopted in August 2026 are all recent and still being implemented in practice. Agreements should be drafted to anticipate further regulatory evolution rather than freeze today’s requirements in place, since the framework governing this space is unlikely to be final.

8. Governing law and dispute resolution

With the underlying data now sitting within Nigeria, Nigerian law and Nigerian courts (or a Nigeria-seated arbitration clause, where preferred) should generally govern the relationship. This is worth confirming explicitly rather than assuming — particularly where a local provider proposes standard-form terms that were not drafted with this migration wave in mind.

Will There Be Disputes?

Almost certainly, and probably concentrated in three areas.

SLA breaches. As local infrastructure is tested at a scale it has not previously carried, gaps in capacity, uptime, or disaster recovery are likely to surface, and with them, disputes over whether contractual service levels were met.

Scope disagreements. What counts as “regulated” or “sensitive” data requiring localisation is not always self-evident, particularly for fintechs running hybrid architectures that blend local and international infrastructure. Disputes over classification are a foreseeable friction point between institutions and their regulators, and between institutions and their cloud providers.

Exit disputes with displaced providers. As institutions migrate away from foreign cloud providers, disagreements over early termination fees, data extraction timelines, and residual liability for data still resident abroad during the transition window are likely.

None of this is a reason to delay migration; the regulatory deadline does not move because a contract is complicated. It is a reason to negotiate deliberately rather than quickly, and to treat the agreement itself as the primary risk-management tool available during this transition.

Closing Thought

I made the argument in 2022 that data localisation was a matter of when, not if. It is no longer a policy debate; it is a January 2027 compliance deadline with a national certification register attached. Organisations that treat their new cloud service agreements as a formality to get through will discover, in time, that the contract signed under pressure is the one they are bound by.

No posts to display

Post Comment

Please enter your comment!
Please enter your name here