TRENDING

Nigerian Court Orders Stanbic IBTC to Pay ₦15 Million in a Landmark Data Privacy Ruling

By: indexprima

August 23, 2026

Image Source:

Share

A High Court in Abuja has ordered Stanbic IBTC Bank to pay ₦15 million to two former customers after ruling that the bank kept using their personal data to send marketing messages long after they had closed their accounts. Justice Kayode Agunloye of the Federal Capital Territory High Court delivered the judgment on July 29, finding that Stanbic IBTC breached both the customers’ constitutional right to privacy and the Nigeria Data Protection Act, 2023, by continuing to process their information after they had withdrawn consent.

What Stanbic IBTC Actually Did Wrong

The case centered on two former customers who had ended their banking relationship with Stanbic IBTC, only to keep receiving promotional messages from the bank afterward. According to the court, the bank not only continued the unsolicited communications but also failed to act on the customers’ requests to have their data deleted. The judgment described the resulting harm in fairly direct terms: an invasion of privacy, compounded by the bank’s refusal to erase the data and the ongoing distress caused by persistent, unwanted contact.

A Nigerian Right to Be Forgotten

What makes this ruling significant beyond the two individuals involved is the legal principle behind it. Justice Agunloye held that once a banking relationship ends and a customer withdraws consent, an institution loses its legal basis to keep processing that person’s data for marketing purposes, a principle several legal commentators have described as Nigeria’s clearest judicial affirmation yet of a “right to be forgotten.” That concept has existed in data protection frameworks elsewhere for years, but this judgment gives it real teeth under Nigerian law specifically, rather than leaving it as an abstract provision in the NDPA that companies could quietly ignore.

What the Court Actually Ordered

The ruling goes further than just the damages payment. Alongside the ₦15 million award, the court ordered Stanbic IBTC to delete every piece of the claimants’ personal data that it isn’t legally required to retain, and it barred the bank from further using, sharing, retaining, or processing their information for marketing or any other purpose without lawful authority. That combination, a monetary penalty plus an enforceable deletion order plus a forward-looking restriction, is a considerably more complete remedy than a fine alone, and it gives the claimants a real mechanism to confirm the bank actually complies rather than just paying up and continuing as before.

Why ₦15 Million, Not ₦250 Million

The claimants had originally sought ₦250 million in damages, and the court’s decision to award roughly 6% of that figure is worth noting on its own. Justice Agunloye described the larger sum as excessive, settling instead on ₦15 million as adequate compensation for the specific harms proven, the privacy invasion, the refusal to delete data, and the distress from repeated contact. That gap suggests Nigerian courts are still calibrating what proportionate damages look like under a relatively young data protection law, and future NDPA cases will likely be measured against this figure as an early benchmark.

A Second Enforcement Track Is Opening Up

This case matters for reasons beyond Stanbic IBTC specifically. Nigeria’s data protection enforcement has so far been dominated by the Nigeria Data Protection Commission’s own regulatory investigations and fines, the kind of enforcement covered when the NDPC pursued breach cases against companies like the Corporate Affairs Commission earlier this year. This ruling shows a second enforcement track working in parallel: individual customers using the courts directly to enforce their rights under the NDPA, without waiting for a regulator to act first. For any company that keeps customer contact information around well past the point where the customer relationship has actually ended, a functioning private right of action changes the calculus considerably, since it means legal exposure no longer depends entirely on whether the NDPC happens to investigate.

Part of a Rougher Stretch for Stanbic IBTC

This isn’t the only regulatory matter Stanbic IBTC has faced recently. Nigeria’s Securities and Exchange Commission separately fined the bank’s investment banking subsidiary over an unrelated public-offer compliance issue, and the bank has faced earlier central bank penalties tied to cryptocurrency transaction monitoring. None of those matters are connected to this privacy case, but taken together, they add up to a period where Nigerian regulators and courts are giving Stanbic IBTC’s compliance practices closer scrutiny than usual.

Why It’s Worth Watching

For a country still building out how its 2023 data protection law actually gets enforced in practice, a ₦15 million court judgment is a modest number in isolation, but the precedent behind it is not. Any Nigerian company holding onto former customers’ data for marketing purposes now has a concrete example of what happens when someone actually takes that practice to court.