Court Orders Stanbic IBTC To Pay N15m Over Unlawful Use Of Customer Data
A High Court of the Federal Capital Territory has ordered Stanbic IBTC Bank to pay N15 million in damages for unlawfully retaining and processing the personal data of two former customers after they closed their account.
In a judgment delivered on July 29, 2026, Justice Kayode Agunloye also directed the bank to delete all personal data relating to the claimants that it is not legally required to retain. He issued a perpetual injunction restraining the bank from further processing or using their information for marketing purposes.
The suit, marked CV/2190/25, was filed on June 10, 2025, by David Ogundipe and Salami Tolulope Ibrahim.
The claimants sought enforcement of their rights under the Nigeria Data Protection Act, NDPA 2023, Section 37 of the 1999 Constitution, and the Federal Competition and Consumer Protection Act, FCCPA 2018.
According to court documents, the claimants operated a corporate account with Stanbic IBTC and later instructed the bank to close it over unresolved issues.
Although the bank complied with the closure, it allegedly continued to send promotional emails and text messages to their corporate and personal contacts.
The claimants, through their solicitors, formally demanded that the bank stop processing their data for marketing. The bank acknowledged the request and assured them the messages would stop. However, the communications reportedly continued, prompting the legal action.
Justice Agunloye held that the bank had no lawful basis under the NDPA to continue processing the claimants’ personal data after the banking relationship ended and consent was withdrawn.
He ruled that the continued retention and processing violated the NDPA and infringed on their constitutional right to privacy. The court also held that using the data for marketing constituted an unfair trade practice under the FCCPA.
The judge ordered Stanbic IBTC to delete all personal data relating to the claimants not required by law and restrained the bank, its agents and assigns from further processing, using or transmitting the information for marketing or any other unauthorized purpose.
While the claimants sought N250 million in damages, the court described the amount as excessive. It awarded N15 million as general damages for persistent unsolicited communications, failure to respond to requests for data erasure, and invasion of privacy.
The court also awarded N500,000 as cost of suit and 10% post-judgment interest per annum until the judgment sum is fully paid.
However, the court declined to order wholesale deletion of all customer records, noting that banks are legally required under banking and anti-money laundering laws to retain certain records.
Lead counsel to the claimants, O.E. Oluwadamisi of Earnest Attorneys LP, described the ruling as a landmark decision that reinforces enforcement of data protection rights in Nigeria.
One of the claimants, David Ogundipe, said the judgment affirmed that customers do not lose control of their personal information simply because they previously had a banking relationship.
The ruling is expected to serve as an important precedent for financial institutions and other organizations on compliance with the Nigeria Data Protection Act 2023, especially regarding handling of customers’ data after account closure.






















