NIGERIA’S FOREIGN EXCHANGE MARKET: RECENT REGULATORY REQUIREMENTS FOR BDC OPERATORS AND BANKS

BY ADERONKE ALEX-ADEDIPE & HILLARY OKOROTIE

Introduction

On February 10, 2026, the Central Bank of Nigeria (CBN) issued a circular on the Participation of Licensed Bureau De Change Operators in the Nigerian Foreign Exchange Market, permitting licensed Bureau De Change (BDC) operators to participate in the Nigerian Foreign Exchange Market (NFEM).

Following the commencement of BDC operators’ participation in the NFEM, the CBN, on July 15, 2026, issued the Guidance on the Purchase of Foreign Exchange by Bureau De Change Operators Through Authorized Dealer Banks in the Nigerian Foreign Exchange Market (the “Guidance Notice”). The Guidance Notice establishes the procedures governing the purchase of foreign exchange by BDC operators through authorized dealer banks and outlines the obligations of dealer banks in facilitating such transactions.

In this newsletter, we provide insights on the obligations of BDC operators and authorized dealer banks.

What Are the Obligations of Dealer Banks and BDC Operators Under the Guidance Notice?

Under the Guidance Notice, dealer banks and BDC operators are required to undertake the following:

  1. Due Diligence Processes
    Under the Guidance Notice, dealer banks are required to conduct Know Your Customer (KYC) and Customer Due Diligence (CDD) checks  before engaging in any foreign exchange transaction with a BDC operator. As part of this process, dealer banks must obtain and verify the BDC operator’s incorporation documents, valid operating license, as well as beneficial ownership information. Where a BDC operator is identified as presenting a higher risk following the due diligence assessment, the dealer bank is required to apply Enhanced Due Diligence (EDD) measures before proceeding with the transaction. 
  2. Fulfilment of Foreign Exchange Purchase Requests
    Requests by BDC operators to purchase foreign exchange must be submitted through the CBN’s Foreign Exchange Purchase Tracker Portal (the “Portal”) to the preferred authorized dealer BDC operators are required to register on the Portal and provide real-time updates of all foreign exchange purchase transactions. . Upon receipt of the BDC’s purchase request, the dealer bank may either approve or reject the request through the Portal. Where a request is rejected, the dealer bank must state the reason for the rejection on the Portal.The Guidance Notice also permits BDC operators to submit multiple foreign exchange purchase requests within a week, provided that the value of the purchases does not exceed the prescribed weekly purchase limit of US$150,000.

     

  3. Disbursement of Funds to BDC Operators
    In processing and fulfilling a foreign exchange purchase request, dealer banks are required to disburse foreign exchange only into foreign exchange settlement accounts maintained by the BDC operators with licensed financial institutions. Dealer banks must ensure that all disbursements are made solely to the BDC operator’s designated settlement account and not to the account of any third party. Any disbursement of foreign exchange to a third-party account constitutes a breach of the Guidance Notice and may attract sanctions against the dealer bank by the CBN. 
  4. Retention of Purchased Foreign Exchange
    BDC operators are required to sell all foreign exchange purchased through the NFEM within 24 hours. Any outstanding balance must be sold within 24 hours. Failure to comply may result in regulatory sanctions, including the forfeiture of the outstanding balance to the CBN or the suspension of the BDC operator’s license. In addition, BDC operators are required to disclose any outstanding balance in their foreign exchange purchase request for the following week. 

What Are the Penalties for Non-Compliance?

The CBN has prescribed sanctions for breach of its circular on the Participation of Licensed Bureau De Change Operators in the Nigerian Foreign Exchange Market and the Guidance Notice. BDC operators that fail to comply with these directives may be subject to monetary penalties, suspension or revocation of their operating license, or suspension of their access to the NFEM.

Similarly, dealer banks that fail to comply with the CBN’s directives when transacting with BDC operators may have their status as authorized dealer banks revoked. Where a breach involves suspected criminal conduct, the CBN may also refer the matter for criminal investigation and prosecution to the appropriate authorities

Conclusion

The CBN’s objective in permitting BDC operators to purchase foreign exchange through authorized dealer banks in the Nigerian Foreign Exchange Market (NFEM) is to improve liquidity within the formal foreign exchange market. The framework is also intended to curb abuses and arbitrage in the foreign exchange market. If properly implemented therefore, it is expected that these policies will sustain the current stability in the market.

For more information on the participation of BDC operators in NFEM, please see our previous newsletter.

 

NIGERIA’S FINANCIAL MARKETS REFORM – THE VIRTUAL ASSETS COORDINATION EXECUTIVE ORDER 2026 AND SEC’S PROPOSED CROSS-BORDER TRADING RULES

BY SEUN TIMI-KOLEOLU & ENIOLA SOGBESAN

Introduction

Nigeria continues to take significant steps towards modernizing its financial markets by creating a more transparent, innovative and globally competitive investment ecosystem. Two recent developments reflect this direction: the Presidential Executive Order on Virtual Assets Coordination 2026 (the “Executive Order”) and the Securities and Exchange Commission’s (SEC) Proposed Rules on Cross-Border Securities Trading and Custody (the “Proposed Rules”). Although they address different segments of the financial market, both initiatives are aimed at strengthening Nigeria’s regulatory framework, inter-agency coordination, and supporting responsible innovation.

In this newsletter, we examine the key highlights of these developments and their implications for investors, capital market operators, fintech companies and other stakeholders. We also consider how these reforms fit into Nigeria’s broader efforts to align its financial/capital markets with international best practices while encouraging growth, protecting investors and enhancing regulatory coordination.

  1. The Presidential Executive Order on Virtual Assets Coordination 2026
    President Bola Ahmed Tinubu on July 17, 2026 signed the Presidential Executive Order on Virtual Assets Coordination, 2026 (the “Executive Order”). The Order which takes effect immediately, is a response to a largely fragmented regulatory landscape that has exposed Nigerians to unchecked losses from unregulated operators. The Executive Order aims to protect investors while promoting responsible innovation and preserving financial system integrity.Key Highlights of the Executive OrderIt is important to note that the Executive Order does not establish a new regulator but rather establishes a mechanism for coordination amongst existing regulators such as SEC, Central Bank of Nigeria (CBN), Nigeria Revenue Service (NRS), Nigerian Financial Intelligence Unit (NFIU) and Office of the National Security Adviser (ONSA). The key highlights of the Executive Order include-
  • the establishment of a Virtual Asset Council (the “Council”) chaired by the CBN Governor, with the Director-General of the SEC and the Chairman of the Nigeria Revenue Service serving as Vice-Chairs;
  • the establishment of a Virtual Asset Office (VAO) to serve as the operational arm and secretariat of the Council;
  • a functional allocation of regulatory responsibilities among regulators –
      1. SEC – regulation of virtual assets that constitute securities and investment products;
      2. CBN – supervision of payment, settlement, custody and other non-security virtual asset activities within its statutory mandate;
      3. NRS – issue a specialized tax policy for the taxation of virtual assets;
      4. NFIU – oversight for AML/CFT compliance
      5. ONSA – coordination of national security and intelligence.
  • the establishment of a dedicated CBN regulatory sandbox for virtual asset and blockchain-based innovation.Implications and Opportunities for Virtual Asset Service ProvidersThe Executive Order signals a more coordinated regulatory framework for virtual assets, with clearer allocation of responsibilities among regulators and stricter oversight of anti-money laundering and counter-terrorism financing (AML/CFT) standards. Virtual Asset Service Providers (VASPs) should also monitor opportunities to participate in the CBN’s proposed regulatory sandbox, as well as anticipated tax guidance from the Nigeria Revenue Service (NRS). Collectively, these developments are expected to provide greater regulatory certainty for compliant operators while potentially increasing enforcement against operators that do not meet the applicable regulatory requirements.

    As of the date of this newsletter, we note that the official text of the Executive Order has not been publicly released, and we expect it to be released shortly. Once published, a detailed review of its provisions will be necessary to assess its implications for VASP’s and other participants in Nigeria’s digital asset ecosystem.

B. Proposed Rules On Cross-Border Securities Trading and Custody
The Securities and Exchange Commission (SEC) on July 2, 2026 published a draft of its “Proposed Rules on Cross-Border Securities Trading and Custody” (the “Proposed Rules”). The Proposed Rules represent a significant step by the SEC towards establishing a comprehensive regulatory framework for Nigerian investors’ wishing to invest in foreign securities. The Proposed Rules seek to regulate the provision of cross-border securities trading services by SEC-registered brokers, while strengthening investor protection, enhancing regulatory oversight, and promoting the integrity of cross-border investment activities.

  1. Scope/Applicability
    The Proposed Rules are applicable to every broker licensed by the SEC that provides Nigerian investors access to foreign securities listed or traded on a foreign securities exchange. More specifically, the Proposed Rules applies to the following services –
    1. trading in foreign securities on behalf of Nigerian investors;
    2. execution of cross-border securities transactions through foreign intermediaries;
    3. custody and safekeeping of foreign securities belonging to Nigerian investors;
    4. maintenance of records of beneficial ownership of foreign securities; and
    5. the protection of investor rights and assets within indirect holding structures.
  1. Licensing Requirements
    Under the Proposed Rules, a broker is prohibited from providing cross-border securities trading services without first obtaining a prior “No Objection” from the SEC.To obtain a No Objection from the SEC, a broker must submit an application which include but not limited to the following documents –
    1. detailed description of the proposed cross-border trading services;
    2. identification of foreign exchanges to which access shall be provided;
    3. details of foreign brokers and custodians to be engaged;
    4. description of custody and settlement arrangements; and
    5. policies governing safeguarding of client assets.

The Proposed Rules clearly prohibit a broker from facilitating foreign securities trading, unless it maintains a minimum net liquid capital of not less than ₦2 billion.

  1. Approval Requirements for Foreign Brokers?
    Prior to engaging in foreign securities transaction through a foreign broker, a Nigerian broker shall ensure that the foreign broker satisfies the following conditions –
    1. the foreign broker must be licensed and supervised by a securities regulator;
    2. it must operate within jurisdictions that are members of the International Organization of Securities Commissions (IOSCO) and whose regulator is a signatory to the IOSCO Multilateral Memorandum of Understanding or any other cooperation arrangement with the SEC;
    3. it must maintain adequate financial resources, operational capacity, custody safeguards, and client asset protection mechanisms;
    4. where applicable, it is a participant in recognized clearing and settlement systems; and
    5. the foreign broker is not subject to any material regulatory sanction, restrictions, suspension, or enforcement action that may impair its operations or expose investors to undue risk.
  1. Regulatory Assessment and Recognition of Foreign Brokers
    Under the Proposed Rules, a broker shall not enter any arrangement or any other business relationship with a foreign broker for the purpose of providing cross-border securities trading without the prior approval or a “No Objection” of the SEC.An application for approval to engage a foreign broker shall be accompanied by the following:
    1. the proposed agreement between the foreign and Nigerian broker;
    2. details of the services to be provided by the foreign broker;
    3. details of custody, clearing, settlement, and operational arrangements;
    4. evidence of the foreign broker’s licensing and regulatory authorization status;
    5. a status report, letter of good standing, or fit and proper confirmation issued by the foreign broker’s regulator and
    6. such other information as the SEC may require.
  1. Investor Protection
    The Proposed Rules require every foreign security purchased on behalf of a Nigerian investor to be held by a regulated foreign custodian or clearing participant. Also, all securities purchased by an investor must be segregated from the assets of the broker or custodian.Under the Proposed Rules, every broker is required to ensure that –
    1. proper books and records are maintained to clearly distinguish the assets of each investor from the assets of the broker;
    2. no investor asset is utilized for the benefit of the broker or any other investor without the prior written authorization of the affected investor client and the approval of the SEC, where applicable; and
    3. adequate systems and controls are established to ensure the continuous protection, reconciliation, and traceability of client assets.
  1. What are the reporting obligations of Brokers under the Proposed Rules?The Proposed Rules require a broker to submit quarterly reports to the SEC. The details of the report shall include the following –

      1. aggregate value of foreign securities held by Nigerian investors;
      2. custody locations of such securities; and
      3. reconciliation statements.
  2. Fees and Sanctions.The SEC shall be entitled to a fee 0.35% on the purchase of every foreign security by a Nigerian investor and this fee may be reviewed by the SEC from time to time. Upon collecting the fee, the Broker shall submit monthly transaction returns and fee remittance reports to the SEC in the form and manner prescribed by the SEC including reconciliations of transactions executed through foreign intermediaries.Where a broker fails to comply with the Proposed Rules, such broker shall be subject to sanctions such as suspension, monetary penalties, revocation of registration and any other sanction that the SEC may impose.

    Conclusion

    The Virtual Assets Coordination Executive Order 2026 and SEC’s Proposed Rules on Cross-Border Trading of Foreign Securities and Custody, represent important milestones in Nigeria’s efforts to strengthen the regulatory architecture of its financial markets. While the Proposed Rules is still in its draft form, it seeks to provide a structured framework for access to foreign securities, and the Executive Order enhances regulatory coordination for virtual assets. Together, these developments reflect a broader policy objective of positioning Nigeria’s financial markets to support innovation while aligning with international regulatory standards.

NAICOM’S GUIDELINES FOR FOREIGN HEALTH INSURANCE PROVIDERS: KEY COMPLIANCE CONSIDERATIONS FOR INSURERS AND POLICYHOLDERS IN NIGERIA

BY ADERONKE ALEX-ADEDIPE & OLUWAYEMI IBIRINDE

Introduction

On 31 March 2026, the National Insurance Commission (“NAICOM”) issued the Guidelines for the Operation of Foreign or International Health Insurance Providers (the “Guidelines”) pursuant to the Nigerian Insurance Industry Reform Act, 2025 (“NIIRA 2025”). The Guidelines establish, for the first time, a comprehensive regulatory framework governing foreign or international private medical insurers and reinsurers (“IPMI-R Providers”) seeking to provide health insurance services to entities registered or individuals who are resident in Nigeria.

Historically, international health insurance products were commonly procured directly from offshore insurers by multinational corporations, expatriates and high-net-worth individuals without any comprehensive regulatory framework governing such activities in Nigeria. Industry reports estimated that this resulted in approximately US$2 billion in annual premium outflows, while limiting regulatory oversight and the participation of domestic insurers. The Guidelines seek to address these gaps by requiring foreign health insurers to obtain NAICOM’s approval before operating in Nigeria, establishing approved local partnerships and complying with specified consumer protection, reporting and governance obligations.

In this newsletter, we examine the key provisions of the Guidelines and highlight some of the legal and commercial considerations for insurers and policyholders.

Who Do the Guidelines Apply To?

The Guidelines apply to all International Private Medical Insurers or Reinsurers (IPMI-R Providers) seeking to transact, market, underwrite or otherwise engage in health insurance business emanating from Nigeria.

Specifically, they apply to:

  1. foreign health insurers and reinsurers offering products to entities registered in Nigeria;
  2. foreign providers offering health insurance to persons residing in Nigeria; and
  3. intermediaries and authorised representatives acting on behalf of foreign health insurers.

Accordingly, the regulatory focus is not the location of incorporation of the insurer but whether the health insurance business or clientele originates from Nigeria.

What are the Key Compliance Requirements?

  1. Prior NAICOM Approval

The most significant change introduced by the Guidelines is that no foreign health insurer may transact, market or underwrite health insurance business originating from Nigeria without obtaining the prior written approval of NAICOM.

Similarly, no Nigerian entity or individual may transfer health insurance risks to an IPMI-R Provider unless that provider has received NAICOM’s approval.

The Guidelines further provide that where NAICOM does not communicate its approval or rejection within ten (10) working days after receiving complete documentation, the application shall be deemed approved.

  1. Mandatory Local Partnership Model

Unlike the previous regulatory position, the Guidelines prohibit foreign insurers from directly issuing health insurance policies to Nigerian entities or persons residing in Nigeria except through an authorised representative domiciled in Nigeria.

Every approved IPMI-R Provider must adopt one of the following operational models:

  • Model 1: Domestic Insurer Partnership;
  • Model 2: Domestic Administrator or Intermediary Partnership; or
  • Model 3: Health Maintenance Organisation (HMO) Partnership.

These partnership models ensure that licensed Nigerian entities participate in premium administration, claims support, regulatory reporting and other operational functions.

To obtain approval, an IPMI-R Provider must submit comprehensive documentation including:

  1. evidence of incorporation in its home jurisdiction;
  2. proof of regulatory licensing in its home jurisdiction;
  3. detailed product descriptions;
  4. a business plan;
  5. premium worksheets;
  6. proposed Nigerian intermediaries;
  7. its preferred operational model; and
  8. any additional information requested by NAICOM.
  1. Consumer Protection Requirements

The Guidelines introduce several customer protection obligations designed to improve accountability and transparency.

Approved providers are required to:

  1. provide clear information regarding policy terms and exclusions;
  2. ensure products meet customers’ needs;
  3. establish effective complaints management procedures;
  4. include claims settlement procedures within policy documentation; and
  5. ensure complaints are handled fairly through their Nigerian representatives or intermediaries.

These obligations significantly strengthen the position of Nigerian policyholders.

  1. Reporting and Ongoing Regulatory Obligations

Approved providers are required to submit quarterly production returns to NAICOM and pay the prescribed Insurance Supervisory Service (ISS) Levy.

The Guidelines therefore establish continuing regulatory oversight rather than a one-time approval process.

Compliance Considerations

Pending further regulatory guidance, organisations that utilise international health insurance arrangements should consider the following.

a. Review Existing Insurance Arrangements

Multinational companies should determine whether their current international health insurance programmes involve IPMI-R Providers that have obtained, or intend to obtain, NAICOM approval.

b. Assess Existing Partnership Structures

Foreign insurers should evaluate whether their existing operating model aligns with one of the three partnership structures prescribed under the Guidelines and identify any restructuring that may be required.

c. Review Distribution and Intermediary Arrangements

Insurers, brokers, HMOs and third-party administrators should assess whether their contractual arrangements adequately reflect the roles and reporting obligations contemplated under the Guidelines.

d. Strengthen Compliance Frameworks

Organisations should establish internal governance procedures to monitor ongoing compliance with NAICOM’s approval requirements, reporting obligations and customer protection standards.

e. Review Existing Policies

The Guidelines permit policies issued before the effective date to continue until expiry. However, organisations should review renewal arrangements to ensure that future policies comply with the new regulatory framework.

Penalties for Non-Compliance

The Guidelines introduce significant sanctions for non-compliance.

  1. Any entity registered in Nigeria or person residing in Nigeria that transacts health insurance business with an unapproved IPMI-R Provider may be liable to a penalty of not less than the total premium involved.
  2. The Guidelines also required providers to regularise their operations within the prescribed ninety-day transitional period. Failure to satisfy the approval requirements may result in rejection of the application and suspension of the issuance of new policies and renewals.

Conclusion

With the Guidelines having taken effect on 31 March 2026, multinational employers, foreign insurers, HMOs, brokers and other intermediaries, should immediately prioritize assessing existing operational structures and contractual arrangements to ensure continued compliance with the new regulatory framework. Organisations that undertake this assessment proactively will be better positioned to navigate future regulatory developments while minimising compliance risks.

ONE AFRICA, ONE CLICK: WHAT THE AFCFTA DIGITAL TRADE PROTOCOL MEANS FOR AFRICA

BY SEUN TIMI-KOLEOLU & EFE OKPARAVERO

Introduction

Last week, Lagos hosted the AfCFTA Digital Trade Forum 2026, bringing together policymakers, regulators, financial institutions, technology companies, legal practitioners, and other stakeholders from across Africa and beyond under the theme, “Digital Trade for a Connected African Market.”

The Forum underscored the growing momentum behind the AfCFTA Protocol on Digital Trade. This Protocol seeks to govern the cross-border exchange of goods, services and other tradeable items that are facilitated by digital platforms and technologies. For more information on this, see our article here.

In light of the discussions and developments emerging from the Lagos Forum, this is an opportune moment to revisit the Protocol, assess the progress made to date, and consider the practical steps African countries and businesses should take to prepare for its implementation.

Changes Since the Adoption of the Protocol by the African Union on 18 February 2024

The most significant development has been the adoption of eight supplementary Annexes on 16 February 2025, transforming the Protocol from a mere framework into a more operational instrument setting out detailed rules for implementation.

Three notable annexes include:

  1. Annex on Rules of Origin: The Rules of Origin (ROO) Annex was introduced to provide clarity on the ‘African origin requirements’ for digital products (mentioned in Article 5 of the Protocol) by introducing a two-tier test. Under these new rules, both the supplying enterprise or platform must be African-owned and operated, and the digital content itself must qualify as African content to enjoy preferential treatment under AfCFTA.
  2. Annex on Cross-Border Digital Payments: This Annex sets out practical measures (improving on Article 15 of the Protocol) to promote secure and efficient digital payment systems across the African market. Such measures include requirements and guidance on interoperable payment infrastructure; electronic know-your-customer (e-KYC) processes; open application programming interfaces (APIs); fraud prevention mechanisms; and regulatory cooperation on anti-money laundering and counter-terrorist financing (AML/CFT).
  3. Annex on Cross-Border Data Transfer: This Annex (mentioned in Article 20 of the Protocol) now creates an adequacy-based system for the free flow of data between countries engaging in digital trade. To fulfill the adequacy requirement, countries are required to maintain a domestic data protection framework which at a minimum meets the standards set out in Articles 5 to 14 of this Annex, such as Personal Data Protection by Design and Default; Data Minimisation; and Competent Data Protection Authorities etc.

Beyond the regulatory framework, there have been continent-wide initiatives such as:

  1. AfCFTA Digital Inclusion and Entrepreneurship Programme (ADIEP): Delivered in partnership with Google, ADIEP is reported to have trained more than 7,500 SMEs across 19 African countries through 25 cohorts between November 2025 and June 2026, equipping businesses with skills in artificial intelligence, cross-border e-commerce and cloud technologies.
  2. Pan-African Payment and Settlement System (PAPSS): PAPSS is expected to reduce the cost, complexity and settlement time of cross-border transactions, supporting one of the Protocol’s central objectives of seamless digital trade across Africa. For more on PAPSS, see here.
  3. Africa Digital Access and Public Infrastructure for Trade (ADAPT): An implementation initiative, launched in November 2025 by the AfCFTA Secretariat, ADAPT designated Nigeria, Kenya and Morocco as its pilot countries. This initiative focuses on strengthening digital public infrastructure through digital identity systems; payment integration; and the digitisation of trade documentation.

What This Means Commercially

Africa’s digital economy is projected to grow from approximately US$180 billion today to US$712 billion by 2050, hence the stakes are quite high. For businesses, the Protocol is expected to deliver:

  1. Greater market access: Harmonised rules will make it easier for businesses to reach customers across Africa without establishing a physical presence in every market, reducing regulatory fragmentation and expansion costs.
  2. Stronger compliance obligations: Businesses will need to enhance data governance, privacy frameworks and cross-border transfer arrangements as digital trade rules become more aligned across jurisdictions.
  3. Improved digital payments: Interoperable payment systems, supported by initiatives such as PAPSS, could reduce transaction costs and improve settlement efficiency, while requiring stronger AML/CFT/KYC compliance from financial institutions and Fintechs.

Ratification Status

Adoption is distinct from entry into force. Under Article 47 of the Protocol and Article 23 of the AfCFTA Agreement, the Protocol enters into force 30 days after the 22nd State Party deposits its instrument of ratification. That threshold has not yet been met, meaning the Protocol remains a framework for future implementation rather than an enforceable regime.

Nigeria has advanced its implementation efforts as a Co-Champion of the Protocol, with the Federal Executive Council approving Nigeria’s ratification on 6 November 2025.

The Protocol, however, does not yet have the force of law within Nigeria, as treaties require domestication by the National Assembly pursuant to Section 12 of the Constitution of the Federal Republic of Nigeria 1999 (as amended).

Recommendations

Going forward, we recommend the following:

A. State Parties should:

  1. Identify gaps or discrepancies between their domestic legal frameworks and the Protocol, take steps to align their laws with the provisions of the Protocol.
  2. Accelerate ratification of the Protocol and incorporate it into their domestic legal frameworks to ensure effective implementation.
  3. Promote regulatory cooperation with other State Parties by working towards greater harmonisation of digital trade regulations, particularly in areas such as data protection, cybersecurity, digital identity, electronic transactions and consumer protection.

B. Businesses should:

  1. Prepare ahead of the Protocol’s entry into force by monitoring ratification and regulatory developments,
  2. Review contracts and data governance practices to align them with the Protocol
  3. Strengthen cybersecurity, AML/CFT/KYC frameworks and digital payment capabilities to meet emerging cross-border digital trade requirements.

Conclusion

The AfCFTA Digital Trade Protocol represents a significant step towards building a better connected and competitive African digital economy. Whilst the Protocol is not yet operational, ongoing implementation initiatives signal a clear shift towards greater digital integration. Governments and businesses that begin preparations now will be better positioned to take advantage of the opportunities created by a single African digital market.

CBN’S DATA LOCALISATION DIRECTIVE – COMPLIANCE CONSIDERATIONS FOR PAYMENT SYSTEM PARTICIPANTS

BY ADERONKE ALEX-ADEDIPE & PROMISE ITAH

Introduction

On June 15, 2026, the Central Bank of Nigeria (“CBN“) issued a Circular on Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System (the “Circular“). Among other regulatory reforms, the Circular introduces a significant data localisation requirement directing all financial institutions and participants facilitating payments within Nigeria—including banks, payment service providers, mobile money operators and other payment participants— (collectively “Payment System Participants”) to ensure that data generated in relation to payment transactions in Nigeria is stored and managed in Nigeria by January 1, 2027.

In this newsletter, we examine the scope of the CBN’s data localisation requirements, their interaction with existing data protection obligations, and some of the key legal, contractual and operational considerations which Payment System Participants should consider in preparation for compliance.

  1. Who does the Circular Apply to?
    The Circular applies to payment transaction data generated through Nigeria’s payments system. Although the Circular does not define the term “payment transaction data”, it intuitively includes information generated in connection with a payment transaction, including the payer’s and beneficiary’s payment details, transaction amounts, payment references, authentication records, settlement and routing information, transaction logs and other related technical data required to process, verify or record a payment.

    The Circular also appears to frame the localisation requirement by reference to payment transaction data generated within Nigeria, rather than the location in which the business is principally domiciled. On this basis, therefore any Payment System Participant processing payment transaction data generated within Nigeria may be expected to comply with this requirement, regardless of their country of domicile.

  1. What are the Key Compliance Requirements?

    a. Local Processing and Storage
    Payment System Participants must ensure that payment transaction data is both stored and managed within Nigeria. This extends beyond maintaining a local copy of data and requires that the primary processing environment, databases, backups and operational control remain on infrastructure located within Nigeria.

    The requirement for payment transaction data to be “managed” in Nigeria may also have implications for administrative activities such as access management, database administration, encryption key management and audit logging, particularly where these functions are performed through offshore infrastructure or personnel.

    b. Technology and Infrastructure
    The Circular is likely to require many Payment System Participants to review their technology infrastructure, particularly where payment services rely on foreign cloud service providers or systems hosted outside Nigeria. Given the requirement for payment transaction data generated within Nigeria to be stored and managed locally, organisations should assess whether their existing technology architecture involves the storage, processing or replication of payment transaction data outside Nigeria. Areas that may require review include:

    • cloud hosting arrangements and the location of servers;
    • disaster recovery and backup systems;
    • analytics and monitoring platforms that process payment data;
    • testing and development environments that use live or production payment data; and
    • third-party APIs and other technology integrations that may transfer payment data outside Nigeria.

Payment System Participants operating hybrid or multiple cloud environments should assess whether payment data is stored, replicated or processed outside Nigeria and, where necessary, implement appropriate technical or operational changes before the compliance deadline.

c. Vendor and Outsourcing Arrangements

Whilst it is commonplace for Payments System Participants to assign data processing and storage activities to third parties, the Circular does not appear to transfer the obligations from Payment System Participants to service providers in such instance. Accordingly, organisations should review their contractual arrangements with cloud service providers, payment processors, application programming interface (API) providers and other technology vendors to assess whether those arrangements support compliance with the localisation requirement. In particular, organisations should consider whether their contracts adequately address:

    • the requirements for payment data to be stored and managed within Nigeria;
    • restrictions on processing payment data outside Nigeria;
    • rights to conduct audits and facilitate regulatory inspections;
    • controls over the use of subcontractors that may have access to payment data;
    • obligations to promptly notify the Payment System Participant of any data breaches or incidents; and
    • termination rights where a vendor is unable to comply with the localisation requirements.
  1. How does the Circular Interact with the Nigeria Data Protection Act (NDPA)?

The Circular complements rather than replaces the NDPA. While the NDPA regulates the processing and international transfer of personal data through recognised transfer mechanisms and safeguards, the CBN Circular imposes an additional regulatory obligation applicable specifically to payment transaction data. Accordingly, compliance with the NDPA alone will not satisfy the CBN’s localisation requirements.

  1. Practical Compliance Steps

Pending any further guidance from the CBN, Payment System Participants should consider taking the following steps to prepare for implementation:

    1. conducting a comprehensive data mapping exercise to identify where payment data is stored, processed and transmitted;
    2. assessing existing cloud and infrastructure arrangements for localisation risks;
    3. reviewing third-party vendor relationships and contractual provisions;
    4. updating internal data governance, outsourcing and information security policies;
    5. establishing board and management oversight of the implementation programme; and
    6. maintaining adequate documentation to demonstrate compliance during regulatory inspections.

Conclusion

The CBN’s payment data localisation requirements represent a significant development in the regulation of Nigeria’s payments ecosystem. By requiring payment transaction data generated within Nigeria to be stored and managed in Nigeria, the Circular appears intended to strengthen regulatory oversight, enhance operational resilience and support the security of Nigeria’s payments infrastructure. For Payment System Participants, the immediate priority will be to assess whether existing technology infrastructure, data governance frameworks and third-party vendor arrangements are consistent with the new localisation requirement. Given the breadth of the obligation and the absence of detailed implementation guidance, organisations that begin assessing their compliance position ahead of the January 2027 implementation date will be better positioned to address any legal, operational or contractual gaps as further guidance emerges.