0

By Osasome, C.O

Nigeria’s data protection regulator launches forensic probe into alleged unauthorised bank-account creation using students’ personal data and warns tertiary institutions over compliance

The Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd following complaints alleging that students’ personal data may have been used to open bank accounts without a lawful basis.

RELATED: NDPC issues compliance notices to 649 Nigerian tertiary institutions, urges stronger privacy protection

The investigation has been directed by NDPC National Commissioner and Chief Executive Officer Dr Vincent Olatunji. It will examine how the affected students’ personal information was collected, processed, disclosed and potentially used by the parties involved.

ADVERTISEMENT
ALSO READ: Committee of Nigerian Vice Chancellors seeks partnership with NDPC on data protection for students

According to the regulator, the probe would also determine the respective roles and responsibilities of the institutions. In addition, it will assess whether their actions complied with the Nigeria Data Protection Act, 2023 (NDPA).

NDPC Orders Comprehensive Forensic Investigation

In a statement signed by Babatunde Bamigboye, Head of Legal, Enforcement & Regulations at the NDPC, investigators have been directed to conduct a comprehensive assessment of the circumstances surrounding the alleged processing of the students’ personal data.

RELATED: NDPC issues compliance notices to 649 Nigerian tertiary institutions, urges stronger privacy protection

The investigation will also examine the potential risks to the rights and freedoms of the affected data subjects.

ADVERTISEMENT

This intervention highlights the increasing regulatory scrutiny surrounding the use of personal information by educational institutions and private-sector organisations involved in providing services to students.

The investigation is expected to establish whether there was a valid legal basis for processing the data. It will also ascertain if affected students were adequately informed about how their personal information would be used.

Probe to Examine DPIAs, Profiling and Data Sharing

The NDPC said the forensic investigation will cover several critical areas of data-protection compliance.

These include:

ADVERTISEMENT
  • Data Protection Impact Assessments (DPIAs);
  • The lawfulness and transparency of credit scoring and profiling;
  • Use of automated decision-making systems;
  • Adequacy of privacy notices;
  • Data-sharing arrangements;
  • Lawful bases for processing personal data;
  • Data minimisation;
  • Purpose limitation;
  • Data-retention policies; and
  • Technical and organisational measures for protecting data-subject rights.

The breadth of the investigation indicates that the regulator is examining the entire data-processing chain rather than focusing solely on the alleged opening of bank accounts.

The outcome could therefore provide an important test of how the NDPA applies to collaborations between universities, financial institutions and technology companies.

NDPC Warns Universities and Colleges Over Compliance

The investigation comes months after the NDPC intensified enforcement across Nigeria’s tertiary education sector.

In February, the Commission issued compliance notices to 649 tertiary institutions across the country, covering federal, state and private universities, polytechnics, colleges of education and technical colleges.

The institutions were given 21 days to provide evidence demonstrating compliance with Nigeria’s data-protection requirements.

The sector-wide intervention formed part of the Commission’s broader efforts to ensure that educational institutions properly implement the provisions of the Nigeria Data Protection Act 2023.

Following the latest investigation, the NDPC has reiterated its warning to educational institutions that have yet to comply with its existing directives.

The Commission urged non-compliant institutions to take immediate steps to meet their data-protection obligations.

Why Student Data Requires Stronger Protection

Universities and other tertiary institutions are among the country’s largest custodians of personal and, in some cases, highly sensitive information.

Educational institutions routinely collect and process large volumes of data, including:

  • Student admission and identity information;
  • Academic and examination records;
  • Financial information;
  • Biometric information;
  • Staff employment records;
  • Health and welfare information;
  • Research data; and
  • Intellectual property.

The scale and diversity of information held by universities make them attractive targets for cybercriminals. They create significant risks if data is improperly collected, shared, retained or secured.

A data breach or unlawful processing could expose students and staff to identity theft, financial fraud, and discrimination.They are equally exposed to reputational damage and other violations of their fundamental privacy rights.

Lawful Basis Is Central to Student Data Processing

The latest NDPC investigation also brings renewed attention to the principle that organisations cannot simply collect or use personal data because the information is available to them.

Under Nigeria’s data-protection framework, organisations must establish an appropriate lawful basis for processing personal data. They must communicate relevant information to data subjects. Also, they are to ensure that processing is consistent with the purpose for which the information was collected.

This becomes particularly important where personal information collected by a university is subsequently shared with a bank, fintech company or technology provider.

Institutions must therefore carefully establish what data is being shared, why it is being shared, who will receive it, the legal basis for the sharing and what safeguards are in place.

Credit Scoring and Automated Decisions Under Scrutiny

The NDPC’s decision to examine credit scoring, profiling and automated decision-making is particularly significant given the growing integration of financial technology into higher education.

Digital platforms increasingly use automated systems to assess individuals, make recommendations or determine eligibility for financial products and services.

Where students’ personal data is used for profiling or automated decision-making, transparency and safeguards become critical.

The NDPC’s investigation will therefore examine whether affected individuals were adequately informed. It will also establsihed whether appropriate safeguards were in place to protect their rights.

NDPC and Universities Had Earlier Engagement

The regulator’s current enforcement drive follows earlier efforts to strengthen data-protection capacity within Nigeria’s university system.

In September 2023, the NDPC and the Committee of Vice Chancellors of Nigerian Universities (CVCNU) explored a partnership. This partnership focused on capacity building for vice chancellors and university data-protection officers.

The initiative recognised the growing importance of institutional privacy governance as universities increasingly digitise admissions, academic administration, research, finance and student services.

The collaboration also underscored the need for university leadership to understand their responsibilities as custodians and processors of large volumes of personal information.

From Compliance to Institutional Data Governance

The latest enforcement action signals a shift from viewing data protection simply as a technical or legal requirement to treating it as an essential component of institutional governance.

For universities, compliance increasingly requires the involvement of senior management, legal departments, ICT teams, procurement units, academic administrators and data-protection officers.

Institutions must also ensure that third-party service providers handling student information are subject to appropriate contractual, technical and organisational safeguards.

The NDPC’s warning suggests that educational institutions cannot assume that responsibility for personal data ends when information is transferred to an external service provider.

A Broader Test for Nigeria’s Privacy Regime

The investigation involving UNILAG, Lotus Bank and Hackerbella could have implications beyond the three organisations.

It comes at a time when Nigerian universities, banks, fintech companies and technology providers are increasingly collaborating to deliver digital services to students.

Such partnerships can improve financial inclusion and access to digital services. But they can also create complex data-sharing relationships that require clear accountability.

The NDPC’s intervention could therefore reinforce a broader principle: digital innovation involving students must be matched by equally strong privacy, transparency and accountability safeguards.

As the enforcement of the Nigeria Data Protection Act gains traction nationwide, a new reality is emerging for data handlers. Universities and other institutions entrusted with personal information can expect intensified regulatory oversight. The key challenge will be to present verifiable evidence of compliance, moving beyond simple declarations of adherence.

More in News

You may also like