
CBN, NDPA and the cybersecurity framework: one compliance programme, not three
The CBN localisation directive overlaps with the NDPA 2023 and the CBN risk-based cybersecurity framework. How to run one programme with one set of controls and one evidence pack.
A Nigerian bank or payment provider in late 2026 faces three regulatory instruments that all reach into the same systems: the CBN data localisation circular of 15 June 2026, the Nigeria Data Protection Act 2023, and the CBN's risk-based cybersecurity framework. Each has its own owner in most institutions (the CTO, the data protection officer, the CISO) and each is tempted to run its own project. That produces three data inventories, three sets of controls, three evidence packs, and three overlapping migration plans. It also produces gaps at the seams. This article argues for one programme and shows how the three frameworks map onto shared controls.
What each framework asks for
The CBN data localisation directive
Payment transaction data (primary processing, databases, backups, IAM, encryption keys and audit logs) must be stored and managed in Nigeria by 1 January 2027. No foreign storage or processing, no dependency on foreign cloud infrastructure, no cross-border replication. Plus: localisation clauses in supplier contracts, audit rights, inspection facilitation, breach notification protocols, data mapping and updated data governance.
The Nigeria Data Protection Act 2023
Personal data of Nigerian data subjects must be processed lawfully, for specified purposes, with security appropriate to the risk. The Act establishes data subject rights, restricts cross-border transfers to jurisdictions with adequate protection or under appropriate safeguards, requires records of processing, mandates breach notification, and requires data protection impact assessments for high-risk processing.
The CBN risk-based cybersecurity framework
Regulated institutions must maintain a cybersecurity governance structure, risk assessment, control implementation and continuous monitoring. It covers identity and access, encryption, logging and monitoring, incident response, third-party risk, and business continuity, with reporting obligations to the CBN.
Where they overlap
Payment transaction data is almost always personal data (it identifies account holders), so the NDPA applies to the same records the localisation directive covers. The cybersecurity framework governs the controls that protect those records. In practice the three instruments make overlapping demands on the same artefacts:
| Requirement | Localisation directive | NDPA 2023 | Cybersecurity framework |
|---|---|---|---|
| Data inventory / data map | Required | Records of processing | Asset inventory |
| Cross-border transfer control | Prohibited for payment data | Restricted; safeguards required | Third-party risk |
| Encryption and key custody | Keys in Nigeria | Appropriate security | Encryption controls |
| Identity and access management | IAM in Nigeria | Access limitation | IAM controls |
| Audit logging | Logs in Nigeria | Accountability | Logging and monitoring |
| Backups and recovery | Backups in Nigeria | Availability, integrity | Business continuity |
| Supplier contracts | Localisation and audit clauses | Processor agreements | Third-party risk |
| Breach notification | Protocols required | Notification to NDPC and subjects | Incident reporting to CBN |
| Governance | Updated data governance | DPO, DPIA | Cyber governance, board oversight |
Every row is one control with three regulatory citations. Building the control three times is waste; building it once with three citations is a programme.
One programme: how to structure it
One data map
The single most valuable artefact. It records every system holding payment or personal data, its location, its operator, its backup and log destinations, its key custodian and the lawful basis for processing. That one document is simultaneously the localisation data map, the NDPA record of processing and the cybersecurity asset inventory. Build it once, own it centrally, and make every other workstream reference it rather than copy it.
One control catalogue
Define each control once ("encryption keys for payment data are generated and held in a Nigerian HSM-backed KMS with quarterly rotation") and tag it with every framework it satisfies. Auditors and inspectors from different bodies then read the same control description and the same evidence.
One evidence pack
Architecture diagrams, key ceremony records, DR test results, log retention reports, contract schedules, access reviews and breach drills all go into one repository with one index. Each item lists which framework requirements it evidences. When any of the three regulators inspects, the pack is already assembled.
One governance forum
The CTO, DPO and CISO co-chair. The programme reports to the board through the existing risk committee. Decisions about architecture (which facility, which pattern, which KMS) are taken once with all three perspectives in the room, which is faster than taking them three times.
Where the frameworks diverge
Running one programme does not mean pretending the instruments are identical. Three differences matter:
- Scope of data. The localisation directive covers payment transaction data whether or not it is personal. The NDPA covers personal data whether or not it is payment-related. The union is larger than either; the data map should classify each dataset on both axes.
- Cross-border rules. The NDPA permits transfers with safeguards. The localisation directive does not, for payment data. Where they conflict, the stricter rule governs the payment perimeter. Non-payment personal data can still move under NDPA safeguards if the institution chooses.
- Reporting lines. The NDPA reports to the Nigeria Data Protection Commission; the CBN instruments report to the CBN. Breach notification protocols must satisfy both timelines and both recipients.
Architecture that satisfies all three
The design that satisfies the strictest instrument satisfies the others. A Nigerian private cloud with:
- A defined payment-data perimeter with in-country compute, storage, backup and DR
- An in-country KMS backed by an HSM
- Self-hosted identity with role-based access, MFA and access reviews
- An in-country observability and SIEM stack with retention that meets the longest requirement
- Immutable, in-country backups tested by restore
- Supplier contracts with localisation, audit and processor clauses
gives the localisation directive its residency, the NDPA its security and accountability, and the cybersecurity framework its controls and monitoring. Our data governance platform family covers the cataloguing, lineage and retention tooling that supports the shared data map; the CBN data localisation resource covers the architecture patterns.
A sequencing note
The localisation directive has the hardest date: 1 January 2027. Use it as the forcing function for the whole programme. Controls built for localisation (data map, key custody, log residency, backup residency, supplier clauses) are the same controls the NDPA and the cybersecurity framework require. Institutions that treat the localisation deadline as an opportunity to consolidate will finish the year with one programme and one evidence pack. Institutions that treat it as a standalone infrastructure project will finish with a migrated database and the same three inventories they started with.
This is not legal advice. This article summarises regulatory instruments for technical planning purposes. Consult your legal and compliance advisers on how each applies to your institution.
NuxFamily builds the platform side of this programme: the private cloud, key management, identity, observability and backup that a unified control catalogue can point to. It has done so under European banking regulation for two decades. To discuss how a single programme could work for your institution, see our CBN data localisation resource or contact us.


