The Nigeria Data Protection Commission, NDPC, has openendpcd a forensic investigation into the University of Lagos, UNILAG, Lotus Bank, and tech firm Hackerbella Ltd over allegations that students’ personal data was used to open bank accounts without consent or lawful basis.

The Commission revealed in a statement signed by Babatunde Bamigboye , Esq. Head, Legal, Enforcement and Regulations on Tuesday 11th of August, 2026 that the probe was triggered by multiple public complaints received from students and stakeholders who alleged their National Identification Numbers, matriculation details, and other personal information were processed to create bank accounts they did not authorize.

It was disclosed that, the National Commissioner and CEO of NDPC, Dr. Vincent Olatunji, has directed the investigation team to conduct a “comprehensive assessment” of the circumstances surrounding how the affected students’ data was collected, used, and disclosed.

According to the NDPC, the team will audit compliance across 10 key areas under the Nigeria Data Protection Act, 2023: Lawful basis and purpose limitation: Whether there was valid consent and if data was used only for the stated purpose

Data minimisation and retention: If only necessary data was collected and for how long it will be stored
Transparency : Adequacy of privacy notices given to students
Data-sharing agreements: Contracts and safeguards between UNILAG, Lotus Bank, and Hackerbella
Data Protection Impact Assessments, DPIAs: Whether risks were assessed before the project rolled out
Automated decision-making and profiling: The lawfulness of any credit scoring linked to the accounts
Technical and organisational safeguards: Security measures to protect students’ rights and prevent misuse

In addition, the investigation will examine the specific roles of each party: UNILAG as the data controller holding student records, Lotus Bank as the financial institution, and Hackerbella Ltd, which is understood to have provided the technology platform linking the institution to the bank.

“The Commission will determine whether the processing activities complied with the NDP Act and whether the rights and freedoms of the affected data subjects were put at risk,” Bamigboye said.

Aside that, the NDPC used the announcement to issue a stern warning to all educational institutions nationwide.

“Institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such data is processed lawfully, fairly, transparently and securely,” the statement read.

It urged schools, polytechnics, and universities that are yet to comply with NDPC’s data protection compliance directives to do so “immediately” or face regulatory action.

Student data breaches are a growing concern in Nigeria’s push for digital financial inclusion. Banks and fintechs often partner with universities for mass account openings, scholarships, and stipend disbursements. However, data protection experts say such projects must be backed by explicit consent and clear agreements to avoid “function creep” using data for purposes beyond what students agreed to.

Reports further disclosed that If violations are found, the NDPC can impose fines of up to 2% of an organization’s annual gross revenue for a data controller of major importance, or up to ₦10 million for others, in addition to enforcement orders and possible prosecution.

The Commission assured that it will publish its findings and recommendations at the conclusion of the forensic assessment.

louisa olaniyi

Louisa Olaniyi is a seasoned media expert with experience spanning over two decades in both print, electronics and social media. The multi-award winning Broadcast Journalist, Tech enthusiast, TV host and producer, is also professional master of ceremonies (MC) and a certified voiceover artist.

Leave a Reply

Your email address will not be published. Required fields are marked *