NDPC probes UNILAG, Lotus Bank, Hackerbella over data breaches
Summarized and contextualized by DistantNews.
At a glance
- Nigeria's data protection commission is investigating the University of Lagos, Lotus Bank, and Hackerbella Ltd for allegedly using student data without consent.
- The probe follows public complaints that personal data was used to open bank accounts unlawfully.
- The commission emphasizes the responsibility of institutions holding student data and warns non-compliant educational bodies to act immediately.
Nigeria's data protection authority has launched a forensic investigation into the University of Lagos, Lotus Bank, and Hackerbella Ltd. This action stems from public complaints alleging the misuse of students' personal data to open bank accounts without a legal basis.
The Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd following public complaints alleging the use of studentsโ personal data to open bank accounts without a lawful basis.
Dr. Vincent Olatunji, the National Commissioner and Chief Executive Officer of the Nigeria Data Protection Commission (NDPC), has instructed the investigation team to thoroughly assess how the students' personal data was collected, used, and disclosed. The team will also scrutinize the roles of all parties involved and their adherence to the Nigeria Data Protection Act of 2023.
The investigation will examine critical areas such as Data Protection Impact Assessments, the lawfulness of credit scoring or profiling activities, the use of automated decision-making systems, the adequacy of privacy notices, data-sharing agreements, lawful bases for data processing, data minimization, purpose limitation, retention policies, and the safeguards in place for data subjects' rights. The NDPC stressed that institutions entrusted with personal data bear a heightened responsibility for lawful, fair, transparent, and secure processing.
The investigation will, among others, cover Data Protection Impact Assessments (DPIAs); the lawfulness and transparency of any credit scoring or profiling activities; the use of automated decision-making systems; the adequacy of privacy notices; data-sharing arrangements; lawful bases for processing; data minimisation; purpose limitation; retention policy; and appropriate technical and organisational safeguards for data subjectsโ rights.
The commission issued a stern warning to educational institutions that have not yet complied with existing data protection directives, demanding immediate adherence. The investigation is currently ongoing.
Accordingly, the NDPC warns educational institutions that are yet to comply with its existing data protection compliance directives to do so immediately.
Originally published by The Punch. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.