NDPC probes UNILAG, Lotus Bank, other, over alleged data violations
Summarized and contextualized by DistantNews.
At a glance
- Nigeria's Data Protection Commission (NDPC) is investigating the University of Lagos, Lotus Bank, and Hackerbella Ltd for alleged data protection law violations.
- The probe follows complaints that students' personal data were used to open bank accounts without consent.
- The NDPC aims to assess data handling practices and ensure compliance with the Nigeria Data Protection Act, 2023.
The Nigeria Data Protection Commission (NDPC) has launched a forensic investigation into the University of Lagos (UNILAG), Lotus Bank, and Hackerbella Ltd concerning alleged violations of data protection laws. The commission's Head of Legal, Enforcement, and Regulations, Babatunde Bamigboye, announced the investigation, which stems from public complaints about students' personal data being used to open bank accounts without a lawful basis.
Dr. Vincent Olatunji, the National Commissioner of NDPC, has directed the investigation team to conduct a thorough assessment of the circumstances surrounding the collection, use, and disclosure of the affected students' personal data. The team will also clarify the roles and responsibilities of each party involved in the alleged data processing and evaluate their compliance with the Nigeria Data Protection Act of 2023.
The investigation will, among others, cover Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of any credit scoring or profiling activities, and the use of automated decision-making systems.
The investigation will scrutinize various aspects of data handling, including Data Protection Impact Assessments (DPIAs), the legality and transparency of any credit scoring or profiling activities, and the use of automated decision-making systems. It will also examine the adequacy of privacy notices, data-sharing agreements, lawful bases for processing, data minimization principles, purpose limitation, retention policies, and the implementation of technical and organizational safeguards to protect data subjects' rights.
Bamigboye emphasized that institutions entrusted with personal data have a responsibility to ensure lawful, fair, transparent, and secure processing. He also warned educational institutions that have not yet complied with existing data protection directives to do so promptly, stressing that adherence to these regulations is crucial for safeguarding individuals' rights and promoting responsible data governance within the education sector.
Institutions entrusted with the personal data of students, staff and other members of their communities had the responsibility to ensure that such data were processed lawfully, fairly, transparently and securely.
Originally published by Vanguard. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.