GrowthX: Digital Sovereignty Goes Beyond Data Storage, Stakeholders Say
Expert in technology industry have suggested that Nigeria’s push for digital sovereignty must go beyond keeping data within the country to include local control, technical capability, security, privacy and the freedom to choose global technology partners.
The experts disclosed this during the first panel session titled “Data Localisation, Security & Future of Payments in Nigeria,” at the inaugural GrowthX by Techeconomy conference in Lagos, where they examine how Nigeria can localise critical data without compromising security, resilience and the performance of digital services
Dr Krishnan Ranganath, chief executive officer, UniCloud Africa, said digital sovereignty should not be reduced to the physical location of servers, insisting that genuine sovereignty rests on three key pillars including control, capability and choice.
“Digital sovereignty, from my own perspective, shouldn’t be, generally, people just think it’s just having your data stored in a server, either in Vegas or Abuja.
“For me, I look at three things. Sovereignty should be, first and foremost, under control. Nigeria and Nigerian institutions should be able to decide on how they control their own infrastructure.”
Ranganath added that local skills were equally important, warning that having infrastructure within Nigeria without the capacity to manage it would amount to sovereignty only on paper.
“Secondly, I talk about capability. So, sovereignty without skill is what I call sovereignty on paper,” Ranganath said.
He argued that Nigerians should have the expertise required to operate and manage the infrastructure supporting the country’s digital economy.
“The last one has to do with where actually this digital infrastructure lies. Now, we are in a situation where we talk about digital sovereignty and the internet is a global space. Nigerians should also be able to decide about choice.
“We should be able to decide which global partners we want to equally work with. It shouldn’t be that it is being forced on you and you have no other options.”
Ranganath said Nigeria was making progress through the growth of local data centres and Internet Exchange Points (IXPs), as well as government policies aimed at strengthening the domestic digital infrastructure ecosystem.
He however stressed the need to deepen local skills so that the country would not remain dependent on foreign entities to manage critical infrastructure. The topic also highlighted the cybersecurity implications of bringing more data into the country.
Roseline Ilori, founder and chief executive officer of Bridge57 Solutions, cautioned that data localisation alone would not eliminate cybersecurity risks.
“Localisation of our data is very important but the fact that we are localising data does not mean we are also localising cyber security.
“If we localise vulnerability, the fact that it is now local does not mean it is no longer there,” Ilori said.
Ilori said organisations must continue to apply strong security controls, including multi-factor authentication and access management, while maintaining globally recognised security standards.
She also raised concerns about privacy, noting that the physical location of data should not give government or other actors unrestricted access to citizens’ information.
“Now our data is local, does it mean the government can just request for any data because it is just there? Should we just have access? We should not trade that for the privacy of the citizens,” Ilori said.
The panel also examined the importance of trust in Nigeria’s emerging local data infrastructure. Ranganath noted that certifications and standards could establish minimum requirements, but argued that trust had to be built through consistent performance and operational excellence.
“Trust is earned over time,” he said.
He explained that data-centre operators and cloud providers would need to demonstrate reliability, security, uptime and strong connectivity before businesses could confidently move critical workloads to local infrastructure.
For Blessing Ehize, chief technology officer, First City Monument Bank (FCMB), banks generally viewed data localisation as a positive direction, but argued that the major concerns were how the transition would happen and whether the industry had sufficient time to implement it without affecting customers.
“I think for the banks it is a good direction. Localisation is always a good thing,” he said.
Ehize said the directive would have implications for how banks design their technology architecture, particularly because many financial institutions had adopted cloud-based systems to meet performance, scalability and resilience requirements.
“Now if we are coming back we need to first understand how we architect for the kind of performance our consumers and our customers are looking for. Because not necessarily that they are looking for anything less than what we have. So they are asking for more,” Ehize said.
He identified resilience as another major consideration, particularly around what would happen to customers and transactions if local infrastructure experienced disruptions.
The discussion also involves building sufficient computing capacity, resilient infrastructure, cybersecurity controls, skilled manpower and reliable connectivity.
The panelists highlighted the need for continued engagement between regulators and industry players as the January 2027 deadline approaches.
The CBN’s directive requires banks, fintech companies, mobile money operators and other licensed payment operators to ensure that payment transaction data generated in Nigeria is domiciled locally from January 1, 2027.


