Key Takeaways
- The Nigeria Data Protection Commission has opened a forensic investigation into UNILAG, Lotus Bank and Hackerbella Ltd over alleged data protection violations.
- The probe follows public complaints that students' personal data were used to open bank accounts without lawful basis.
- NDPC will assess compliance with the Nigeria Data Protection Act 2023, including data processing transparency, privacy notices and safeguards for data subjects' rights.
- Educational institutions have been warned to comply with existing data protection directives.
Investigation Commences
The Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of the Nigeria Data Protection Act 2023.
Babatunde Bamigboye, Head of Legal, Enforcement and Regulations at the commission, disclosed the development in a statement issued in Abuja. The probe is being conducted at a time when regulatory oversight of personal data handling has become increasingly stringent across Nigeria.
Efforts to obtain a reaction from UNILAG's Head of Communication Unit, Alhaja Ajoke Ibrahim Alaga, were unsuccessful. She requested that a text message be sent, which was done, but no response was received hours later and subsequent calls were unanswered at press time. Lotus Bank and Hackerbella Limited could not be reached for comment either.
What Triggered the Probe
According to the NDPC, the investigation follows public complaints alleging that students' personal data were used to open bank accounts without lawful basis. National Commissioner Vincent Olatunji directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, use and disclosure of the affected students' personal data.
The inquiry will determine the roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.
Scope of the Investigation
Bamigboye explained that the investigation will assess the parties' compliance with obligations under the Nigeria Data Protection Act, 2023. Areas under review include Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of any credit scoring or profiling activities, and the use of automated decision-making systems.
The commission will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation, purpose limitation, retention policy, and appropriate technical and organisational safeguards for data subjects' rights. Potential risks to the rights and freedoms of the affected students will also be evaluated.
A Warning to Institutions
Bamigboye stressed that institutions entrusted with the personal data of students, staff and other members of their communities have a responsibility to ensure such information is processed lawfully, fairly, transparently and securely. He warned educational institutions that had yet to comply with the commission's existing data protection directives to do so without further delay.
Compliance with data protection regulations is essential to protecting the rights and freedoms of data subjects and promoting responsible data governance in the education sector. This case highlights the growing scrutiny of data handling practices across Nigeria's academic and financial sectors, and it underscores the need for robust internal controls, clear consent mechanisms and transparent data-sharing agreements.
Why This Matters
This investigation signals a firmer regulatory stance on data protection in Nigeria and could reshape how educational institutions and their financial partners handle student data. The outcome may set a precedent for accountability, reinforcing that personal information must never be exploited without a lawful basis.
