The verdict in three sentences
A Lagos SME that touches card numbers falls under PCI DSS: the only sensible decision is to delegate compliance to a hosted gateway (Flutterwave, Paystack), placing you in SAQ-A with near-zero compliance cost. Conversely, storing cards yourself requires SAQ-D and an annual audit of 5-15 million FCFA, out of reach for an SME. Mobile money escapes PCI but remains subject to GDPR, local data law (NDPR in Nigeria, Benin's 2009-09 law) and CBN rules.
SAQ-A or SAQ-D: the structuring decision
PCI scope hinges on one question: do card details pass through or get stored on your servers? If not, your compliance burden collapses.
| Criterion | SAQ-A (hosted gateway) | SAQ-D (in-house storage) |
|---|---|---|
| Card data on your servers | No (tokenization) | Yes |
| Self-assessment questionnaire | ~22 questions | 300+ questions |
| External audit (QSA) | Not required | Required |
| Annual compliance cost | ~0-500,000 FCFA | 5-15M FCFA |
| Liability on a breach | Reduced | Maximum |
| Suitable for an SME | Yes | No |
Gateway tokenization is the default: the customer enters their card on a form hosted by Flutterwave or Paystack, and you only receive a token. You exit the heavy PCI scope while collecting normally.
Mobile money, GDPR and local law: the 2026 checklist
Mobile money involves no card, so no PCI — but you collect personal data (number, name, history). Here is the minimum compliance checklist.
| Measure | Goal | Priority |
|---|---|---|
| TLS 1.2+ / HTTPS everywhere | Protect data in transit | Critical |
| CSP + HSTS headers | Block injection and downgrade | High |
| Encryption of data at rest | Protect the database | High |
| Transaction logging | Traceability, disputes | High |
| GDPR notices + consent | Legal compliance | Critical |
| Data processing register | Local law (NDPR, Benin law) | Medium |
| Retention/deletion policy | Data minimization | Medium |
These measures are achievable for an SME without an audit budget: they're good engineering practice and clear documentation, not a costly certification.
Mini case study
Fatou is launching an online cosmetics store in Lagos and wanted to "store cards to ease repeat purchases." An SAQ-D audit quote came to about 7 million FCFA/year — impossible. By using Paystack tokenization (SAQ-A) and mobile money (outside PCI), her compliance burden dropped to implementing CSP headers, HTTPS, GDPR notices and a processing register: a 600,000 FCFA one-off effort versus 7M/year. One-click repeat purchases remain possible via the token stored at the gateway, without ever touching a card number.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Does my SME need PCI DSS certification?
If you use a hosted gateway that tokenizes cards, you fall under SAQ-A: a simplified self-assessment of about twenty questions, no external audit. You don't bear the cost of heavy certification.
Is mobile money covered by PCI DSS?
No, PCI DSS only covers payment cards. Mobile money remains subject to GDPR and local data laws (NDPR in Nigeria, Benin's 2009-09 law), which require consent, security and traceability.
How much does an SAQ-D audit cost?
Between 5 and 15 million FCFA per year depending on size, QSA auditor and scope. That's why no SME should store card numbers itself: tokenization avoids this cost.
Which security headers should I prioritize?
HTTPS/TLS 1.2+ everywhere, Content-Security-Policy, HSTS, X-Content-Type-Options and Referrer-Policy. These headers block the most common attacks and configure at no significant extra cost.
Does GDPR apply to a Nigerian store?
Yes if you target or process data of EU residents (diaspora included), and Nigeria's NDPR applies in all cases. Plan for consent, a processing register and a retention policy.
Let's talk about your project. We secure your payments via tokenization and bring your site into GDPR and local-law compliance without a costly audit. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
