Nigeria's data rules: what they require, and what they do not

Published: · 8 min read · By Olu

Nigeria Data Protection Data Residency NDPA NDPR Compliance Lagos
Nigeria data residency: what the rules require

Two separate Nigerian rules get discussed as though they were one. They are not, they do not say the same thing, and treating them as interchangeable leads organisations to either over-build or miss a deadline entirely.

The first is the Nigeria Data Protection Act 2023, the country's general data protection law. The second is a Central Bank of Nigeria directive covering payment transaction data, which takes effect on 1 January 2027. One governs how personal data may leave Nigeria. The other requires a specific category of data to stay.

This article separates them, then looks at what each means in practice for where infrastructure sits.

The two rules side by side

 Nigeria Data Protection Act 2023CBN payment-data directive
ScopePersonal data, all sectorsPayment transaction data generated in Nigeria
Core requirementGoverns transfer abroad, permitted under defined conditionsData stored and managed in Nigeria
Localisation mandate?NoYes, for data in scope
DeadlineIn force since June 20231 January 2027
Who decidesNigeria Data Protection Commission determines adequacyCentral Bank of Nigeria
Who it reachesData controllers and processors generallyBanks, microfinance banks, mobile money operators, switching and processing companies, payment terminal and solution providers, super agents

The rest of this article takes each row in turn.

What replaced the NDPR

Many people still search for the NDPR, so it is worth being clear about what happened to it. The Nigeria Data Protection Regulation 2019 was the country's first substantial data protection instrument. It has been superseded by the Nigeria Data Protection Act 2023, which created the Nigeria Data Protection Commission as an independent regulator.

If you built a posture against the NDPR and have not revisited it since the Act came into force, that is the gap worth closing first.

What the Act says about sending data abroad

The key point for infrastructure decisions, and the one most often got wrong:

The Act does not require personal data to be stored physically inside Nigeria. There is no blanket localisation mandate in it. What it governs is cross-border transfer, which is permitted where defined conditions are met, with the Commission determining whether a destination offers an adequate level of protection.

The practical reading: hosting Nigerian personal data abroad is not automatically unlawful. It is conditional, and the condition has to be satisfied and documented.

We are an infrastructure provider, not your counsel, so we will not summarise the conditions here. Read them at the source:

If your transfers are material to the business, the answer you want comes from a Nigerian data protection lawyer reading your specific processing, not from an article.

The payment-data directive is a different rule

The Central Bank's directive is narrower and stricter. It requires that payment transaction data generated in Nigeria be stored and managed in Nigeria, and it takes effect on 1 January 2027. Reporting on the circular indicates it reaches banks, microfinance banks, mobile money operators, switching and processing companies, payment terminal and solution providers, and super agents.

That is a residency requirement in a way the general Act is not. If you touch Nigerian payment data, this is the one with a date attached.

CBN Data Localisation: Nigeria's 2027 Deadline Explained
A closer look at the directive, who it reaches, and the question most people ask about it first.

Why conflating them costs you

The two errors run in opposite directions, and both are expensive.

Assuming the Act mandates localisation leads organisations to repatriate everything, including workloads with no residency obligation at all, at considerable cost and disruption for no regulatory gain.

Assuming the payment directive is as flexible as the Act is the more dangerous error. Cross-border transfer under the general law is conditional and arguable. A requirement that payment data be stored and managed in Nigeria, from a fixed date, is neither.

The two rules also apply to different data. Personal data and payment transaction data overlap, but they are not the same set, and an obligation attaching to one does not automatically attach to the other.

Does Nigeria have the capacity?

The first question asked of any residency requirement is whether the country can absorb it. On data centre capacity, the answer is yes.

Nigeria runs between 50 and 56 megawatts of live commercial data centre capacity. Counting what is installed and awaiting commissioning, the figure is closer to 124 megawatts, with projections reaching 210 to 300 megawatts by 2030. That makes Nigeria the second-largest market on the continent after South Africa, at roughly fifteen per cent of installed African capacity.

So the buildings and the power exist. That is not the constraint.

Floor space is not a platform

A megawatt is floor space, power and cooling. It is not compute you can provision. The relevant question for anyone facing a residency requirement is not whether Nigeria has data centres, but whether there are cloud platforms inside them that you can actually deploy on: an instance running in minutes, storage that scales, and backups that stay in the same jurisdiction as the primary.

Those are different things, and the gap between them is where migration projects stall. Industry commentary on the directive has consistently pointed at the same underlying constraints: power reliability, cooling, and the availability of engineers who have run infrastructure at this scale.

The exercise worth doing

If you think you are in scope, the useful first step is not to shop for a facility. It is to map your data.

  • Which systems generate Nigerian payment data, as opposed to merely touching it.
  • Where it rests. The primary database, yes, but also caches, message queues and file stores.
  • Where it gets copied. Analytics pipelines, log aggregation, error tracking, and backups. Backups are where most of these projects discover their real problem, because a compliant primary with an offshore backup has not solved anything.
  • Who can reach it. Residency is about geography, but a regulator asking about personal data will also ask who inside your organisation can read it, and how that is enforced.
  • Then separate what genuinely has to move from what merely has to stop leaving.

That exercise usually shrinks the scope of work considerably, and it tells you what you are actually buying before you buy it.

Residency is necessary, not sufficient

Putting a server in the right country satisfies a location requirement. It does not, by itself, answer the questions a data protection regulator is more likely to ask: who can access the data, how that access is controlled, and what happens when someone asks for their data back.

Those are platform questions, and they are worth checking against any cloud hosting provider you shortlist, not just ours:

  • Access control that is actually enforced. Role-based team accounts, so an analyst and a billing contact do not share one login.
  • Scoped, IP-restricted API keys, so an automation credential cannot quietly become a master key.
  • App-based two-factor authentication with recovery codes, plus session and device tracking you can revoke. Note whether SMS is offered as a second factor, and treat it as a weakness rather than a feature.
  • Network isolation. A platform-level firewall enforced beneath the guest operating system, so a compromised server cannot simply switch it off, and private networking between your own machines.
  • Data export and deletion you can perform yourself, without raising a ticket and waiting. Subject access and erasure obligations are difficult to meet if your provider is the bottleneck.

AFRICLOUD provides each of those, and you should expect them as a baseline rather than a differentiator.

Where AFRICLOUD fits

We run a Lagos PoP, our third region alongside Lisbon and Johannesburg. That gives three jurisdictions to place data in: Nigeria, South Africa, and Portugal inside the EU. For a Nigerian workload, compute and storage stay on Nigerian soil.

Including the backups, which is the part most often missed. Worth being precise about what that means: on-demand snapshots, up to five per server with one-click rollback, are included. Automated daily backups, which keep three rolling restore points with self-service restore, are a paid add-on. Both stay in the same region as the server they protect. If your residency obligation covers copies as well as primaries, and it usually does, that distinction is the one to check with any provider.

Measured in-country, Lagos is 0.2 ms, Abuja 9.9 ms and Kano 18.9 ms. It is the same platform we run in Europe and Southern Africa: AMD EPYC compute, all-NVMe storage, fully automated provisioning, bring-your-own-IP with BGP to your own machine at no charge, and a public REST API that is documented and open to read. A VPS in Lagos runs the same image and the same tooling as one in Lisbon, which matters if you are splitting a workload across jurisdictions rather than moving all of it.

Billing is in your own currency, naira included, with card, PayPal, mobile money and cryptocurrency accepted, and you can choose hourly or monthly per resource. Support is available 24/7 over chat and email.

Cloud Servers in Lagos Nigeria: AFRICLOUD's Third Region Is Live
The Lagos region, and what runs on it.

If you want the detail on in-country hosting for Nigeria, that lives on our Nigeria page, and the region itself is described on the Lagos data centre page.

What to take from this

The Nigeria Data Protection Act 2023 governs how personal data leaves the country, under conditions, with the Commission deciding adequacy. It is not a localisation mandate. The Central Bank's payment-data directive is a residency requirement with a date, 1 January 2027, and a defined set of institutions in scope.

Work out which of the two applies to which of your systems before you move anything. Whatever you decide, decide early: the institutions that start now will find it manageable.

This article describes publicly reported regulatory requirements and is not legal advice. Specific compliance requires individual legal assessment.

Deploy Now