Stanbic IBTC Runs Foul Of 2023 NDPA Act, To Pay N15 Million Fine

Stanbic IBTC Runs Foul Of 2023 NDPA Act, To Pay N15 Million Fine

Stanbic IBTC Runs Foul Of 2023 NDPA Act

 

OpenLife News reports that Stanbic IBTC Bank, a tier 1 bank in Nigeria has run foul of the 2023 Nigeria Data Protection Act in which case the High Court of the Federal Capital Territory has fined the Bank N15 million for unlawfully retaining and processing the personal data of two former customers after they terminated their banking relationship, in what lawyers have described as a landmark data protection ruling.

The Nigeria Data Protection Act, NDPA 2023 is Nigeria’s primary data privacy law, establishing the Nigeria Data Protection Commission (NDPC) and setting rules for how public and private organizations collect, process, and store personal data.

In a judgment delivered on July 29, 2026, by Justice Kayode Agunloye, the court also ordered the bank to erase all personal data relating to the claimants that it is not legally required to retain and issued a perpetual injunction restraining Stanbic IBTC from further processing, using or transmitting their information for marketing.The suit, CVI2190/25, was filed on June 10, 2025, by Mr. David Ogundipe and Mr. Salami Toluope Ibrahim.

They asked the court to enforce their rights under the Nigeria Data Protection Act, 2023, Section 37 of the 1999 Constitution, and the Federal Competition and Consumer Protection Act, 2018.

According to court documents, the claimants operated a corporate account with Stanbic IBTC but later instructed the bank to close it following unresolved issues.

The bank complied.

However, the claimants alleged that despite the closure, Stanbic IBTC continued sending promotional emails and text messages to their corporate and personal addresses and phone numbers.

Through their solicitors, they formally demanded that the bank stop processing their personal and corporate data for marketing purposes.

Stanbic IBTC Runs Foul Of 2023 NDPA  Act, To Pay N15 Million Fine
Stanbic IBTC

The bank acknowledged the request and assured them the messages would stop.

But the claimants told the court the communications continued weeks later, prompting legal action.In his judgment, Justice Agunloye held that the bank had no lawful basis under the NDPA to keep processing the claimants’ data after the relationship ended and consent was withdrawn.

“The continued retention and processing of the claimants’ personal data after the termination of their banking relationship, without establishing any lawful basis under the Nigeria Data Protection Act, was unlawful,” the judge ruled.

He further held that the use of their data for marketing violated their constitutional right to privacy and amounted to an unfair trade practice under the FCCPA.

The court ordered Stanbic IBTC to “erase or delete all personal data relating to the Claimants which it is not otherwise required by law to retain” and to cease all processing except where required by statutory or regulatory obligations.

A perpetual injunction was also granted restraining the bank, its agents and assigns from further processing the claimants’ data for marketing or any unauthorised purpose.The claimants had sought N250 million in damages.

The court described that as excessive but awarded N15 million as general damages for “persistent unsolicited communications, failure to meaningfully respond to requests for data erasure, and the inconvenience and invasion of privacy suffered.” Justice Agunloye also awarded N500,000 as cost of suit, rejecting the claimants’ request for N7 million on grounds that it was not strictly proved.

He ordered 10% post-judgment interest per annum until payment is made.

The judge, however, declined to order wholesale deletion of all records, noting that banks have statutory obligations under banking regulations and anti-money laundering laws to retain certain customer records.Summarising, the court declared that Stanbic IBTC’s actions violated the NDPA, the Constitution, and the FCCPA.

Reacting, lead counsel for the claimants, O.E. Oluwadamisi of Earnest Attorneys LP, called the ruling “a landmark decision that significantly strengthens the enforcement of data protection rights in Nigeria.”

“This judgment sends a clear message that compliance with the Nigeria Data Protection Act is not optional,” he said.

“Once consent is withdrawn and there is no lawful basis for continued processing, organisations cannot continue using an individual’s personal data merely for commercial convenience,” Ogundipe, one of the claimants, said the judgment was a victory for millions of Nigerians.

“Customers do not lose control of their personal information simply because they once had a relationship with a financial institution,” he said. “We hope this decision will encourage organisations across the country to take their data protection obligations more seriously.”

The ruling is expected to set a precedent for how financial institutions handle customer data post-account closure in Nigeria.

About Author

Share This