Skip to content
CBN data localisation deadline, 1 Jan 2027: 99d 00h 31m left.Talk to us
NuxFamily
CBN compliance 7 min read· NuxFamily Engineering

CBN, NDPA and the cybersecurity framework: one compliance programme, not three

The CBN localisation directive overlaps with the NDPA 2023 and the CBN risk-based cybersecurity framework. How to run one programme with one set of controls and one evidence pack.

A Nigerian bank or payment provider in late 2026 faces three regulatory instruments that all reach into the same systems: the CBN data localisation circular of 15 June 2026, the Nigeria Data Protection Act 2023, and the CBN's risk-based cybersecurity framework. Each has its own owner in most institutions (the CTO, the data protection officer, the CISO) and each is tempted to run its own project. That produces three data inventories, three sets of controls, three evidence packs, and three overlapping migration plans. It also produces gaps at the seams. This article argues for one programme and shows how the three frameworks map onto shared controls.

What each framework asks for

The CBN data localisation directive

Payment transaction data (primary processing, databases, backups, IAM, encryption keys and audit logs) must be stored and managed in Nigeria by 1 January 2027. No foreign storage or processing, no dependency on foreign cloud infrastructure, no cross-border replication. Plus: localisation clauses in supplier contracts, audit rights, inspection facilitation, breach notification protocols, data mapping and updated data governance.

The Nigeria Data Protection Act 2023

Personal data of Nigerian data subjects must be processed lawfully, for specified purposes, with security appropriate to the risk. The Act establishes data subject rights, restricts cross-border transfers to jurisdictions with adequate protection or under appropriate safeguards, requires records of processing, mandates breach notification, and requires data protection impact assessments for high-risk processing.

The CBN risk-based cybersecurity framework

Regulated institutions must maintain a cybersecurity governance structure, risk assessment, control implementation and continuous monitoring. It covers identity and access, encryption, logging and monitoring, incident response, third-party risk, and business continuity, with reporting obligations to the CBN.

Where they overlap

Payment transaction data is almost always personal data (it identifies account holders), so the NDPA applies to the same records the localisation directive covers. The cybersecurity framework governs the controls that protect those records. In practice the three instruments make overlapping demands on the same artefacts:

RequirementLocalisation directiveNDPA 2023Cybersecurity framework
Data inventory / data mapRequiredRecords of processingAsset inventory
Cross-border transfer controlProhibited for payment dataRestricted; safeguards requiredThird-party risk
Encryption and key custodyKeys in NigeriaAppropriate securityEncryption controls
Identity and access managementIAM in NigeriaAccess limitationIAM controls
Audit loggingLogs in NigeriaAccountabilityLogging and monitoring
Backups and recoveryBackups in NigeriaAvailability, integrityBusiness continuity
Supplier contractsLocalisation and audit clausesProcessor agreementsThird-party risk
Breach notificationProtocols requiredNotification to NDPC and subjectsIncident reporting to CBN
GovernanceUpdated data governanceDPO, DPIACyber governance, board oversight

Every row is one control with three regulatory citations. Building the control three times is waste; building it once with three citations is a programme.

One programme: how to structure it

One data map

The single most valuable artefact. It records every system holding payment or personal data, its location, its operator, its backup and log destinations, its key custodian and the lawful basis for processing. That one document is simultaneously the localisation data map, the NDPA record of processing and the cybersecurity asset inventory. Build it once, own it centrally, and make every other workstream reference it rather than copy it.

One control catalogue

Define each control once ("encryption keys for payment data are generated and held in a Nigerian HSM-backed KMS with quarterly rotation") and tag it with every framework it satisfies. Auditors and inspectors from different bodies then read the same control description and the same evidence.

One evidence pack

Architecture diagrams, key ceremony records, DR test results, log retention reports, contract schedules, access reviews and breach drills all go into one repository with one index. Each item lists which framework requirements it evidences. When any of the three regulators inspects, the pack is already assembled.

One governance forum

The CTO, DPO and CISO co-chair. The programme reports to the board through the existing risk committee. Decisions about architecture (which facility, which pattern, which KMS) are taken once with all three perspectives in the room, which is faster than taking them three times.

Where the frameworks diverge

Running one programme does not mean pretending the instruments are identical. Three differences matter:

  • Scope of data. The localisation directive covers payment transaction data whether or not it is personal. The NDPA covers personal data whether or not it is payment-related. The union is larger than either; the data map should classify each dataset on both axes.
  • Cross-border rules. The NDPA permits transfers with safeguards. The localisation directive does not, for payment data. Where they conflict, the stricter rule governs the payment perimeter. Non-payment personal data can still move under NDPA safeguards if the institution chooses.
  • Reporting lines. The NDPA reports to the Nigeria Data Protection Commission; the CBN instruments report to the CBN. Breach notification protocols must satisfy both timelines and both recipients.

Architecture that satisfies all three

The design that satisfies the strictest instrument satisfies the others. A Nigerian private cloud with:

  • A defined payment-data perimeter with in-country compute, storage, backup and DR
  • An in-country KMS backed by an HSM
  • Self-hosted identity with role-based access, MFA and access reviews
  • An in-country observability and SIEM stack with retention that meets the longest requirement
  • Immutable, in-country backups tested by restore
  • Supplier contracts with localisation, audit and processor clauses

gives the localisation directive its residency, the NDPA its security and accountability, and the cybersecurity framework its controls and monitoring. Our data governance platform family covers the cataloguing, lineage and retention tooling that supports the shared data map; the CBN data localisation resource covers the architecture patterns.

A sequencing note

The localisation directive has the hardest date: 1 January 2027. Use it as the forcing function for the whole programme. Controls built for localisation (data map, key custody, log residency, backup residency, supplier clauses) are the same controls the NDPA and the cybersecurity framework require. Institutions that treat the localisation deadline as an opportunity to consolidate will finish the year with one programme and one evidence pack. Institutions that treat it as a standalone infrastructure project will finish with a migrated database and the same three inventories they started with.


This is not legal advice. This article summarises regulatory instruments for technical planning purposes. Consult your legal and compliance advisers on how each applies to your institution.

NuxFamily builds the platform side of this programme: the private cloud, key management, identity, observability and backup that a unified control catalogue can point to. It has done so under European banking regulation for two decades. To discuss how a single programme could work for your institution, see our CBN data localisation resource or contact us.

Get the briefing in your inbox

One email a week on CBN compliance and sovereign infrastructure.

One email a week on CBN compliance and sovereign infrastructure. Unsubscribe anytime.

All insights

Get the briefing in your inbox

One email a week on CBN compliance and sovereign infrastructure.