Students' data may have opened bank accounts — Nigeria is investigating

By Emeka Briggs
Tweet image from @Nairametrics

Nigeria's data regulator has launched a forensic probe into UNILAG, Lotus Bank and Hackerbella over claims students' personal data was used to open accounts without consent.

Share

The Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank, and technology company Hackerbella Ltd over allegations that students' personal data were used to open bank accounts without their knowledge or lawful basis. The investigation was announced on 12 August 2026 in Abuja.

Babatunde Bamigboye, NDPC's Head of Legal, Enforcement and Regulations, disclosed the probe, citing directions from National Commissioner Dr. Vincent Olatunji. The move follows public complaints that triggered the regulator's scrutiny of how the three institutions handled student data.

The investigation will conduct what the NDPC describes as a comprehensive assessment of how affected students' data were collected, used, and disclosed, and will determine the roles and responsibilities of UNILAG, Lotus Bank, and Hackerbella. The regulator is explicitly testing compliance with the Nigeria Data Protection Act (NDPA) 2023, including consent, purpose limitation, transparency, and other data protection principles.

NDPC's forensic scope is unusually detailed. According to a Nairametrics report, investigators will examine Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of any credit scoring or profiling activities, and the use of automated decision-making systems. The probe will also assess the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation, purpose limitation, retention policy, and technical and organisational safeguards for data subjects' rights.

The investigation centres on whether bank accounts were opened without a lawful basis — which would breach NDPA requirements for valid consent and lawful processing. The core allegation is that students' personal data fed into an account-opening process they never knowingly authorised.

The case has deep roots. Prior investigative reporting by the Foundation for Investigative Journalism (FIJ) found that UNILAG's Smart ID Card project, run in partnership with Lotus Bank, opened bank accounts for tens of thousands of students and staff through processes that violated data privacy regulations and student rights. FIJ documented that UNILAG's official website also collected visitors' names and email addresses without a privacy policy explaining data handling — itself an NDPA violation. As of early July 2026, FIJ noted there was no publicly available evidence that any of the universities investigated had faced fines, compensation orders, or other NDPA sanctions.

Lotus Bank has partnered with UNILAG since 2024 to produce Smart ID Cards that double as bank cards. The bank's published Privacy Notice states that it uses personal information with consent or other lawful reasons, and that account opening is tied to performance of a contractual agreement with the customer. It also asserts that Lotus Bank does not knowingly allow children under 18 to open online accounts, and it names the NDPC as the regulator to whom customers may complain if personal information is used in a way that is unacceptable under the NDPA.

Hackerbella Ltd is consistently described in coverage as a technology company involved alongside UNILAG and Lotus Bank in the data processing arrangements under investigation, but public details about its products, incorporation, or leadership are limited. The Punch Nigeria recap and other outlets reproduce the core NDPC announcement without additional interpretation, reflecting how little is yet known about the vendor's role.

This investigation matters far beyond the three named institutions. It is one of the clearest public tests of the NDPA 2023 against major, mainstream institutions rather than just startups. The NDPA empowers the NDPC to investigate data breaches and, where violations are found, order remedies, compensation, or fines up to ₦10 million or 2% of annual gross revenue for institutions of major importance.

The outcome will shape how aggressively the regulator enforces against high-profile data controllers across education, banking, and tech. Nigerian universities increasingly partner with banks and technology companies for Smart ID cards, digital identity, and campus payments — UNILAG–Lotus Bank is one of the most visible examples. This case raises questions about consent, profiling, and automated account opening in similar partnerships nationwide.

Technology companies like Hackerbella that build onboarding, ID, or account-opening systems for banks and universities are now squarely in the NDPC's enforcement lens. The investigation's focus on DPIAs, automated decision-making, and credit scoring will affect how vendors architect and document such systems across Nigeria and other African markets.

Babatunde Bamigboye framed the scope directly:

"The investigation will, among others, cover Data Protection Impact Assessments, the lawfulness and transparency of any credit scoring or profiling activities, and the use of automated decision-making systems. It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation, purpose limitation, retention policy, and appropriate technical and organisational safeguards for data subjects' rights."

FIJ's investigation captured the gap this probe now addresses:

"At the time of publishing this report, there is no publicly available evidence that any of the institutions named above have faced a fine, compensation order, or other sanction under the NDPA."

As of 12 August 2026, coverage focuses on the commencement of the investigation. There is no public outcome yet — no confirmed findings, penalties, or orders. The NDPC has not issued any determination on whether UNILAG, Lotus Bank, or Hackerbella actually violated the NDPA.

The next signal to watch is whether the NDPC issues interim orders or public updates on the forensic findings. A previous NDPC action — an investigation into an alleged data breach at the Corporate Affairs Commission in April 2026 — shows the regulator is willing to pursue large institutions. If this probe concludes with sanctions or compensation orders for affected students, it would set a precedent for every Nigerian university, bank, and tech vendor operating campus fintech partnerships. For now, the investigation remains open and unresolved.

Share this article

Help others discover this story

https://www.techblit.com/students-data-may-have-opened-bank-accounts-nigeria-is-investigating