Nigeria has issued a new National Digital Cloud Policy, and it carries very consequential implications. It replaces the 2019 Nigeria Cloud Computing Policy, reframes cloud infrastructure as a matter of national economic strategy rather than routine government IT, and sets out, for the first time, a coordinated framework covering investment, government adoption, and data sovereignty in a single instrument. For anyone building, financing, hosting on, or advising in Nigeria’s digital economy, it is pivotal to re-evaluate alongside the Policy.
This review sets out key elements of the Policy, where the shift from the 2019 Policy lies, and what it means in practice.
Legal Framework of the Policy
- The Policy does not stand alone; It is the capstone of the National Sovereign Cloud Initiative (NSCI), and it is expressly implemented through a suite of companion instruments: the National Cloud Guideline 2026, the National Cloud Technical Guideline 2026, the National Digital Infrastructure Assurance Framework (NDIAF), and an investment-facing National Cloud Investment Strategy. The Policy expressly points that those instruments implement it, and in the event of conflict on matters within its scope, the Policy prevails.
- The policy is subject to existing legislation: The policy sits beneath existing law and is read together with the Nigeria Data Protection Act 2023, the Cybercrimes (Amendment) Act 2024, and the NITDA Act 2007, and where the Policy conflicts with those statutes, the statutes govern. The Policy is a policy and governance instrument, not primary legislation, and it should be read as such.
- Delayed Enforceability of the Policy Parts; The Policy is organized in four parts, and they do not all take effect at once. Parts I, II and IV, covering investment, government adoption, and implementation, take effect on publication. Part III, the sovereignty framework, takes effect only on Presidential approval. At the time of writing, that means the market-development and government-adoption machinery is live, while the data-residency obligations that have attracted the most attention are pending assent.
Part I: Economic Imperatives and Market Development
Part I treats global cloud capability, deployed in Nigeria and connected to Nigerian firms and talent, as the fastest route to a competitive domestic industry, and it adopts a hybrid model, infrastructure in Nigeria operating alongside international capacity within a common governance framework, in preference to localization mandates.
The Policy is candid that the constraints on Nigeria’s cloud build-out are not about demand. It identifies them precisely: unreliable and costly grid power, fiscal treatment of imported equipment, regulatory friction across multiple approving institutions, foreign-exchange exposure, fragmented public demand, and an absence of coordination. Each, the Policy says, is a coordination or policy failure that policy can address, rather than a market failure.
The response is a coordinated package of incentives built on stated principles, non-discrimination, transparency, proportionality, predictability and accountability, applied by reference to the scale of investment made in Nigeria rather than the nationality of the investor. In practice this includes import-duty relief on data-center and associated power, cooling and environmental-control equipment, capital-allowance treatment suited to long-life assets, and clarity on the tax treatment of exported cloud services. Notably, fiscal incentives are channelled through the existing Nigerian Investment Promotion Commission mechanisms, Pioneer Status and the One-Stop Investment Centre, rather than a new parallel regime.
Two features stand out for investors.
- Anchor Demand; The Federal Government intends to use its own aggregated purchasing, backed by a ringfenced Anchor Capacity Fund, as a commercial incentive, converting government cloud spending into a demand signal of sufficient scale to support project finance.
- The Approval In Principle pathway; a structured, time-bound route from expression of interest through regulatory review to a documented statement of standing, with full certification to follow. The Policy is careful to state what an AIP is not: it is not a license, a procurement commitment, a fiscal-incentive approval, a land allocation, a foreign-exchange guarantee, or a grant of exclusivity.
On foreign exchange, the Policy is honest about its own limits. It does not itself establish FX policy, which remains with the Central Bank, and it commits to no specific FX facilitation mechanism, placing coordination with the CBN and NIPC instead. Investors reading the Policy should note that this consistently-cited precondition for hyperscale capital is acknowledged but, as yet, unresolved on the face of the document.
Part II: Government Cloud Adoption
Part II makes cloud the default for government. All Federal Ministries, Departments and Agencies must adopt cloud as the default deployment model for new systems, confirming and operationalizing the Cloud First principle first introduced in 2019 but, on the Policy’s own assessment, implemented unevenly for want of governance, funding and aggregation. Exemptions are available on national-security, technical or operational grounds, but they must be justified, time-bound and recorded.
The mechanism that gives this force is aggregation through Galaxy Backbone Limited. GBB is designated the primary digital infrastructure provider and operates a dual role: aggregating government demand for cloud capacity from multiple registered providers and reselling it to MDAs under framework agreements, and designing and operating shared government platforms. Procurement runs through a National Digital Marketplace, jointly governed by NITDA, the Bureau of Public Procurement and GBB, on which only certified providers may be listed.
For the market, the safeguard to watch is non-exclusivity. The Policy states plainly that GBB’s aggregation role does not confer regulatory, supervisory or market-exclusion authority over competing providers, that framework arrangements must preserve genuine provider choice and portability, and that architectures creating single-vendor dependency for critical workloads are to be avoided. Whether that safeguard holds in practice, given GBB’s central position as both aggregator and default host, is one of the genuine questions the Policy leaves for implementation.
III: Sovereignty for Government and Regulated Data
Part III is where most commentary has focused, and it is where reading the actual text matters most, because the Policy is narrower than the headlines suggest.
Sovereignty requirements apply only to sovereign data, defined as data generated by the Federal Government and its agencies, or data generated under Federal regulation, license or directive that has been formally designated. Everything else, the overwhelming majority of commercial activity, falls outside Part III and is governed by ordinary commercial and regulatory law, including the NDPA. The Policy states this expressly, and it is the single most important reassurance for private-sector clients.
Sovereign data is sorted into four classification levels, with hosting obligations attaching to the classification rather than to the sector or the provider. Level 4 (Classified) must be hosted exclusively in Nigeria under sovereign control. Level 3 (Highly Sensitive, including regulated financial, health, biometric and identity data) must be stored in Nigeria at rest, with processing in approved environments. Level 2 (Sensitive) may sit in hybrid environments, including approved international infrastructure, subject to authorization. Level 1 (Open) carries no residency restriction. Cross-border processing of sovereign data is permitted where authorized, and is assessed against the adequacy of protection in the receiving jurisdiction under the NDPA transfer regime.
Two areas here deserve emphasis. First, the Policy commits to proportionality and least restriction: residency requirements are calibrated to sensitivity, and where a control objective can be met by encryption, key custody or contractual safeguard rather than physical residency, the less restrictive measure is preferred. Second, turning regulated private-sector data into sovereign data is not automatic. It requires a deliberate act of designation, justified against identified national interest, and, where it would impose Level 4 or Level 3 obligations, Presidential approval on the recommendation of the Federal Executive Council. The Policy builds in a deliberate asymmetry: relaxing a requirement is administratively straightforward, while tightening one requires the highest level of approval. For regulated businesses, that is a meaningful procedural protection against residency creep.
Intellectual Property and Contractual Considerations
For a technology practice, the Policy’s most valuable provisions are the ones that are easy to overlook, because they are where the commercial and legal risk actually sits. Here are a few of the considerations contemplated from the policy.
- The Policy runs anti-lock-in and portability obligations throughout. Sovereign data must remain portable, providers must support export in non-proprietary formats, exit assistance must be contractually enforceable and tested rather than assumed, and systems must interoperate through open standards and documented interfaces. Framework and marketplace agreements must carry enforceable service levels, audit rights, data-ownership clauses affirming that the institution retains its data, and exit provisions with defined repatriation timelines. Each of these is, in substance, an intellectual-property and licensing negotiation, and each is where a poorly drafted contract quietly cedes control.
- The Policy also ties local participation to technology transfer. Investors taking incentives undertake structured capability-development commitments, measurable knowledge transfer, skills initiatives aligned with the Three Million Technical Talent programme, progressive localization of operational capability against agreed milestones, framed as partnership obligations rather than market-access barriers. The unstated but unavoidable question these provisions raise is the one running through the whole Policy: hosting data in Nigeria does not, by itself, confer control over the foreign-owned software, systems and processors that give that data value. The technology-transfer terms, the licensing arrangements and the IP ownership provisions in each agreement are where genuine sovereignty is either secured or signed away.
Practical Implications
- For investors and data-center developers, the Policy offers a more predictable pathway than before, an AIP process, designated strategic-infrastructure status, incentives channelled through existing NIPC mechanisms, and anchor demand, while leaving the two hardest commercial questions, firm FX facilitation and reliable power, acknowledged but not yet resolved on the face of the document.
- For cloud service providers and service integrators, the Policy creates a certification-gated market: listing on the Digital Marketplace, registration under the NDIAF, and compliance with mandatory contractual and service-level requirements become conditions of serving government. The non-exclusivity and portability safeguards are the provisions to hold the Government to.
- For regulated private-sector businesses, the message is more reassuring than feared: cross-border data flows are preserved, sovereignty obligations attach only to a defined and designated class of data, and the designation process is deliberately demanding. The prudent step is to map data holdings against the four-level classification now, so that any future designation is met from a position of readiness rather than surprise.
Conclusion
The National Digital Cloud Policy is, on balance, an investment-oriented and open instrument that reserves sovereignty controls for a narrow, defined category of data and subjects the tightest of those controls to Presidential approval. It is coherent, it is candid about the constraints it must overcome, and it is more measured than an initial glance at the word “sovereignty” might imply.
Its success will turn on implementation: whether GBB’s central role coexists with a genuinely competitive market, whether the FX and power questions are answered in a way investors can bank, and whether the companion Guidelines and Assurance Framework translate the Policy’s principles into workable technical and contractual reality. Those are the things worth watching, and the things on which the value, for investors, providers and Nigerian businesses alike, will ultimately depend.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Readers should seek independent legal advice based on their specific circumstances.
--
Read the original publication at Olisa Agbakoba Legal


