Nigeria Data Protection Commission Opens Investigation into UNILAG, Lotus Bank, and Hackerbella Over Alleged Student Data Misuse
Key Takeaways
- •The NDPC is investigating UNILAG, Lotus Bank, and Hackerbella Ltd over allegations that students' personal data was used to open bank accounts without a lawful basis.
- •The investigation was announced on 11 August and ordered by NDPC National Commissioner Dr. Vincent Olatunji to assess how the affected students' data was collected, used, and disclosed.
- •Under the Nigeria Data Protection Act, 2023, the NDPC can impose penalties reaching 2% of an organisation's annual gross revenue for serious data protection violations.
- •The probe will scrutinise data protection impact assessments, automated decision-making systems, privacy notices, retention policies, and data-sharing arrangements across all three entities.
- •The NDPC has warned educational institutions that have not yet complied with existing data protection directives to do so immediately.

The Nigeria Data Protection Commission (NDPC) has launched a forensic investigation into the University of Lagos (UNILAG), Lotus Bank, and Hackerbella Ltd after public complaints alleged that students' personal data was used to open bank accounts without any lawful basis.
According to a press release dated 11 August and signed by Babatunde Bamigboye, the commission's Head of Legal, Enforcement and Regulations, NDPC National Commissioner and Chief Executive Officer Dr. Vincent Olatunji has directed the investigation team to conduct a comprehensive assessment of how the affected students' personal data was collected, used, and disclosed.
The investigation marks one of the most significant enforcement actions taken under the Nigeria Data Protection Act, 2023, which established the NDPC as a statutory regulator with powers to impose substantial penalties—up to 2% of an organisation's annual gross revenue for serious violations. The case also intersects with the Central Bank of Nigeria's regulatory oversight of financial institutions, as Lotus Bank's involvement raises questions about compliance with both data protection and banking-sector customer due diligence requirements.
Scope of the Investigation
The NDPC stated that the probe will scrutinize the roles and responsibilities of all three parties involved, along with their broader compliance obligations under the Nigeria Data Protection Act, 2023. Specific areas under review include:
- Data Protection Impact Assessments (DPIAs)
- The lawfulness and transparency of any credit scoring or profiling activities
- The deployment of automated decision-making systems
- Adequacy of privacy notices and data-sharing arrangements
- Lawful bases for processing, data minimisation, and purpose limitation
- Retention policies and the technical and organisational safeguards protecting data subjects' rights
The commission further noted that the investigation will assess the potential risks to the rights and freedoms of the affected students.
NDPC's Warning to Educational Institutions
The commission emphasized that institutions entrusted with the personal data of students, staff, and other community members bear a heightened responsibility to ensure such data is processed lawfully, fairly, transparently, and securely.
"Accordingly, the NDPC warns educational institutions that are yet to comply with its existing data protection compliance directives to do so immediately," the commission said in its statement.
As of publication, UNILAG, Lotus Bank, and Hackerbella Ltd have not issued public responses to the allegations.