July 9, 2026

THE CENTRAL BANK OF NIGERIA 2027 DATA SOVEREIGNTY PARADOX: RECONCILING NIGERIA’S DATA LOCALIZATION MANDATE WITH CONSTITUTIONAL PRIVACY AND THE NDPA 2023 STANDARD

The financial technology industry in Nigeria has been directed recently by The Central Bank of Nigeria (CBN), to the effect that all Banks, Fintech companies, payment service providers and allied businesses are mandated to commence localization of all Financial Transaction Data (FTD) by moving their data service provider and storage facilities to locally built infrastructural servers, starting from the January 1st, 2027. This is a transformative paradigm shift in Nigeria’s digital infrastructure.

Consequently, the fintech industry has been agog with commentators having varying opinion on the subject while the popular objective reveals that this policy is intended as a mechanism for national data sovereignty along the lines of banking and other financial undertakings within the Nigerian fiscal regime and a measure to prevent or reduce fraud and corporate larceny. This mandate exists to create storage of personal and financial data, which in recent times includes biometric data and other extremely sensitive materials. The storage indicated above extends to all personal and banking financial transaction data and its intended retention is purposed beyond the ambit of the knowledge or consent of the affected data subject. This portends a usurpation of ownership rights and the privacy on sensitive data.

It is noteworthy that this policy creates a state of precarious tension when considered against the constitutional right to privacy and the stringent frameworks established by the Nigeria Data Protection Act (NDPA) 2023. In exploring these issues, the physical localization must not be mistaken for security; rather, it is a legal obligation for policy actors to ensure that “data sovereignty” howbeit desirable, does not become a pretext for the capricious compromise of data subjects’ rights or yield into a calculated monopolistic capture of sensitive information by favored entities.

 

More importantly, the right to privacy in Nigeria is not merely a statutory creation; it is guaranteed as a fundamental constitutionally mandatory human right. Section 37 of the 1999 Constitution of the Federal Republic of Nigeria (as amended) protects the privacy of citizens, their homes, correspondence, telephone conversations, and telegraphic communications. In view of the principle of the constitution being the grundnorm, any laws, regulations, principles or policy, including the mandate for localized data storage, must as a matter of enforceability and legal applicability, survive the test of “constitutional conformity and reasonable justification in a democratic society within the subsisting legal order.”

Hence, the push by the Central Bank for data sovereignty through local server mandates must not infringe on the inherent privacy rights of the citizen. To navigate this background properly, there is a huge responsibility on Data controllers, legally compelling them to ensure that the processing of personal data is conducted in a manner that protects the fundamental rights and freedoms of data subjects as guaranteed by the Constitution while preserving their control on their respective data as far as reasonably workable.

 

It is further noteworthy that the NDPA 2023 establishes the Nigeria Data Protection Commission (NDPC) as the guardian of these rights. The localization mandate poses a direct challenge to the Act’s core principles, which are predicated on the following:

• Retention and Destruction: The NDPA mandates that data should not be retained for longer than is necessary to achieve the purpose for which it was collected.
• The Localization Trap: There is a grave risk that “permanent” or convertible local storage, which if left unregulated, could foster a culture of indefinite data hoarding, unchecked data espionage, data security compromise and high risk propensity for data management, all of which directly violates the principle of purpose-limited retention.
• Right to Erasure: Data subjects maintain the right to request the deletion or erasure of their personal data. Financial entities must implement technical protocols to ensure that local servers remain agile enough to facilitate such requests, preventing local storage from becoming an immutable vault of sensitive information. This is especially the case in the light of the upsurge in technical security biometrics within the fintech industries where human biometric data has become subsumed with their financial information and records such as fingerprints, eye retina scans, facial recognition amongst others.

Safeguarding the Process by Preventing Arbitral Capture

A central danger of mandatory localization is curtailing data subject right of control on the one hand, as discussed above, and the potential for “institutional capture,” where centralized data storage becomes susceptible to the interests of specific entities or political actors. To prevent this, the policy’s legal framework must strictly enforce accountability of data controllers by taking cognizance of the following:

1. Impartial Data Governance: Regulators have a non-delegable duty to ensure that the localized infrastructure is neutral. It must not be compromised to benefit any particular party or entity, whether through preferential access to analytics or the weaponization of transactional data.
2. Architectural Transparency: The principle of “Privacy by Design” must be mandatory. Controllers must utilize state-of-the-art security measures to prevent unauthorized access or the corruption of data integrity.
3. Strict Liability for Controllers: The NDPA imposes significant obligations on data controllers to prove that their processing activities—including their storage choices—are transparent, secure, and compliant with the interests of the data subject.
Conclusion and Policy Recommendations

Data sovereignty is a hollow victory if it sacrifices the individual’s autonomy for state or private interests. As Nigeria marches toward the 2027 benchmark, whilst also preparing for the 2027 General Elections, the government must be seen as purposive in its economic approach. The government must move beyond the geography of the server to the institutional integrity and security framework of the said localized data servers and the readiness of ensuring constitutional conformity as well as statutory compliance.

Harmonization: The CBN must, as a matter of course, synchronize its directives with the NDPC, being the data polices, to ensure that operational banking rules do not override the statutory protections very clearly provided for in the 2023 NDPA.
Regulatory Vigilance: The NDPC must be empowered to conduct regular, independent audits of all localized data centers to ensure that no entity is exploiting the mandate for illicit influence or anti-competitive advantage.
Data Subject-Centric Sovereignty: Ultimately, the law must recognize that the most critical form of sovereignty is the citizen’s control over his or her own digital life. Hence, Data Subjects must be availed the opportunity to maintain a reasonable quantum of control so as to sustain the integrity of their privacy rights and implementing the same for the purpose of securing institutional data security.

Olufemi Franklin Olufemi Jr. Esq.
Partner and Practice Group Lead, Corporate, Commercial & Industrial Law.

Law Corridor
Headquarters
Plot 638 Marberries Street, Katampe District, Abuja
Hotlines
We are here for you!
Get in touch
Social Pages
We are social and you can connect with us on social media
Law Corridor
Headquarters
Plot 638 Marberries Street, Katampe District, Abuja
Get in touch
Social links
We are social and you can connect with us on social media

Copyright by Law Corridor. All rights reserved.