Nigeria’s drive to domicile critical digital and payment data locally will not automatically translate into digital sovereignty unless the country also develops the technical capacity, security safeguards and institutional control required to manage its digital infrastructure, technology experts have said.
The experts spoke at the inaugural GrowthX by Techeconomy conference in Lagos during a panel session titled, “Data Localisation, Security & Future of Payments in Nigeria,” where they examined the implications of Nigeria’s data localisation drive and the need to balance domestic control with security, resilience, privacy and access to global technology.
Chief Executive Officer of UniCloud Africa, Dr Krishnan Ranganath, said digital sovereignty should not be defined merely by where servers are physically located, stressing that genuine sovereignty must be built around control, capability and choice.
“Digital sovereignty, from my own perspective, shouldn’t be, generally, people just think it’s just having your data stored in a server, either in Vegas or Abuja.
“For me, I look at three things. Sovereignty should be, first and foremost, under control. Nigeria and Nigerian institutions should be able to decide on how they control their own infrastructure.”
According to him, local ownership of infrastructure would mean little if Nigeria lacked the skills required to operate and maintain critical digital systems.
“Secondly, I talk about capability. So, sovereignty without skill is what I call sovereignty on paper,” Ranganath said.
He maintained that Nigeria must build a strong pool of local professionals capable of managing the infrastructure that underpins its digital economy, rather than simply relocating equipment and data within the country.
Ranganath also identified choice as a critical component of digital sovereignty, arguing that Nigeria should retain the freedom to determine which international technology partners it works with.
“The last one has to do with where actually this digital infrastructure lies. Now, we are in a situation where we talk about digital sovereignty and the internet is a global space. Nigerians should also be able to decide about choice.
“We should be able to decide which global partners we want to equally work with. It shouldn’t be that it is being forced on you and you have no other options.”
He said Nigeria was already making progress through the expansion of local data centres and Internet Exchange Points (IXPs), alongside government policies designed to strengthen the domestic digital infrastructure ecosystem.
However, he stressed that developing local expertise must remain a priority if the country is to avoid replacing dependence on foreign infrastructure with dependence on foreign technical expertise.
The cybersecurity dimension of data localisation also featured prominently during the discussion, with experts warning that moving data into the country would not, by itself, make it safer.
The Founder and Chief Executive Officer of Bridge57 Solutions, Roseline Ilori, said localisation must be accompanied by robust cybersecurity measures and effective privacy protections.
“Localisation of our data is very important, but the fact that we are localising data does not mean we are also localising cybersecurity.
“If we localise vulnerability, the fact that it is now local does not mean it is no longer there,” Ilori said.
She urged organisations to maintain strong security controls, including multi-factor authentication and effective access-management systems, while adhering to globally recognised security standards.
Ilori further cautioned against weakening citizens’ privacy protections in the name of data sovereignty, stressing that local storage should not translate into unrestricted access to personal information.
“Now our data is local, does it mean the government can just request any data because it is just there? Should we just have access? We should not trade that for the privacy of the citizens,” she said.
The panel also considered the question of trust, particularly as Nigerian businesses are expected to increasingly rely on locally hosted cloud and data-centre infrastructure.
Ranganath said while certifications and technical standards could establish minimum requirements, confidence in local infrastructure would ultimately depend on consistent operational performance.
“Trust is earned over time,” he said.
He explained that local data-centre operators and cloud providers would have to demonstrate reliability, security, uptime and robust connectivity before businesses would be willing to migrate critical workloads from established global infrastructure.
For the Chief Technology Officer of First City Monument Bank (FCMB), Blessing Ehize, the banking industry generally supports data localisation, but the key issues are how the transition will be implemented and whether financial institutions will have adequate time to make the necessary technological adjustments without disrupting customers.
“I think for the banks it is a good direction. Localisation is always a good thing,” he said.
Ehize said the policy would require banks to reassess aspects of their technology architecture, particularly as many financial institutions had adopted cloud-based platforms to deliver scalability, performance and resilience.
“Now, if we are coming back, we need to first understand how we architect for the kind of performance our consumers and our customers are looking for. Because not necessarily that they are looking for anything less than what we have. So they are asking for more,” he said.
He identified resilience as another major concern, particularly the ability of local infrastructure to sustain banking operations and customer transactions in the event of outages or other disruptions.
The panelists consequently called for greater investment in computing capacity, resilient infrastructure, cybersecurity, skilled manpower and reliable connectivity, alongside sustained consultation between regulators and industry stakeholders.
Their concerns come as the January 2027 deadline for compliance with the Central Bank of Nigeria’s data localisation directive draws closer. The directive requires banks, fintech companies, mobile money operators, and other licensed payment operators to ensure that payment transaction data generated in Nigeria is domiciled locally as of January 1, 2027.
The experts agreed that the success of the policy would ultimately depend not only on where Nigeria stores its data, but on whether the country has the capacity, security, resilience and institutional control to manage that data effectively while preserving access to global technology and protecting citizens’ privacy.
