NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Student Data Violations

The Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over allegations that students’ personal data were used to open bank accounts without a lawful basis.

 

The investigation followed public complaints concerning the alleged collection, use and disclosure of students’ personal information by the affected organisations.

 

In a statement signed by the Head of Legal, Enforcement and Regulations, Babatunde Bamigboye, Esq., the NDPC said the National Commissioner and Chief Executive Officer, Dr Vincent Olatunji, had directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the processing of the students’ data, including the specific roles and responsibilities of each of the parties involved.

 

The Commission said the probe would also determine the extent to which the organisations complied with their obligations under the Nigeria Data Protection Act, 2023, and assess potential risks to the rights and freedoms of affected data subjects.

 

According to the NDPC, the investigation will cover several areas of data protection compliance, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, automated decision-making systems, privacy notices and data-sharing arrangements.

 

The probe will further examine the lawful bases for processing the data, data minimisation and purpose limitation principles, retention policies, as well as the adequacy of technical and organisational safeguards for protecting data subjects’ rights.

 

The Commission stressed that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.

 

The NDPC consequently warned educational institutions that are yet to comply with its existing data protection compliance directives to do so immediately.

 

The Commission said the ongoing investigation would establish the facts surrounding the complaints and determine appropriate regulatory action based on its findings.

Related posts