Nigeria’s data-protection regulator is investigating how students’ personal information may have been used to open bank accounts without an adequate legal basis.
The Nigeria Data Protection Commission (NDPC) has launched a forensic investigation involving the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd.
The probe follows complaints alleging that students’ personal data were collected, processed and disclosed for financial purposes without sufficient legal justification or transparency.
But there is a bigger question behind the investigation: what happened to the data after it was collected, and who authorised each step?

What the NDPC is investigating
The regulator says its investigation will establish the roles played by UNILAG, Lotus Bank and Hackerbella in handling the affected students’ information.
Investigators will assess whether the organisations complied with the Nigeria Data Protection Act 2023 and whether their actions created risks to students’ rights and freedoms.
The inquiry is expected to examine:
- The original purpose for collecting the students’ information
- The legal grounds used to process it
- How the information was transferred between the organisations
- Whether students were adequately informed
- Whether data were collected or retained beyond what was necessary
- How long the information was kept
- What technical and organisational safeguards were in place
- Whether students’ information was used for profiling or credit assessment
- Whether automated systems influenced decisions affecting the students
The Commission is also expected to review relevant Data Protection Impact Assessments and privacy notices.
Credit scoring and automated decisions come under scrutiny
One of the most significant aspects of the investigation is its focus on profiling, credit scoring and automated decision-making.
If students’ information was used to assess their financial profiles or make decisions through automated systems, the NDPC will examine whether that processing was lawful, transparent and appropriately disclosed.
That matters because automated processing can influence whether an individual receives access to financial products or other services.
The regulator will therefore need to establish not only whether data were shared, but also what happened to the information once it reached another organisation.
That includes determining:
What was the data originally collected for?
Was the subsequent use compatible with that purpose?
Were students told about the additional processing?
Did the organisations have a valid legal basis for each stage?
Those questions could prove more consequential than the alleged opening of bank accounts itself.
How did the data move between the organisations?
The investigation will examine the chain connecting the university, bank and technology company.
That is particularly important when personal information moves across institutional boundaries.
A university may collect data for academic, administrative or student-service purposes. When that information is subsequently provided to a bank, fintech or technology provider, the legal and governance obligations surrounding the new processing become critical.
The NDPC’s investigation will therefore look beyond a single transaction and examine the entire data-processing chain.
NDPC puts universities on notice
The Commission has also used the case to issue a broader warning to educational institutions.
Universities and other schools routinely hold substantial amounts of personal information about students, employees and other members of their communities. The NDPC says organisations entrusted with that information have a responsibility to process it lawfully, fairly, transparently and securely.
Institutions that have not complied with the Commission’s existing data-protection directives have been urged to take corrective action.
For universities, the message is clear: sharing student information with an outside organisation is not simply an administrative exercise.
It requires appropriate governance, transparency and safeguards.
Why banks and technology companies should pay attention
The investigation could extend its impact well beyond UNILAG, Lotus Bank and Hackerbella.
Banks, fintechs and technology providers that receive information from educational institutions may face closer questions about:
- Why they need the data
- What legal basis permits the processing
- Whether students were properly informed
- Whether the information is being used for a new purpose
- How profiling and automated decisions are conducted
- How long personal information is retained
- What safeguards protect the information
The NDPC’s emphasis on data minimisation, purpose limitation, privacy notices and impact assessments suggests that the regulator is examining the wider governance framework rather than focusing solely on the alleged account-opening activity.
The investigation is not a finding of wrongdoing
There is an important distinction.
The NDPC’s investigation does not, by itself, establish that UNILAG, Lotus Bank or Hackerbella violated Nigerian data-protection law.
The forensic inquiry is intended to establish the facts, determine the responsibilities of the organisations involved and assess whether their processing activities complied with applicable requirements.
The eventual findings will therefore matter.
If the investigation identifies deficiencies, it could prompt institutions across Nigeria’s education, banking and technology sectors to reconsider how they obtain, exchange and reuse personal information.
What this means for students
For students, the case highlights a basic but increasingly important question:
Where does your personal data go after you give it to an institution?
Information collected for education or administration can potentially become involved in other services when organisations share data with third parties.
That makes transparency essential.
Students should be able to understand, in meaningful terms, what information is being collected, why it is needed, who may receive it and how it may subsequently be used.
The NDPC’s investigation puts those questions at the centre of a case involving three very different types of organisation.
A test for Nigeria’s digital-data ecosystem
As universities adopt more digital services and financial institutions increasingly partner with technology companies, personal information is moving through more complex networks.
That creates opportunities for better services—but also raises the stakes when data governance fails.
The NDPC’s forensic investigation could therefore become a significant test of how Nigeria applies its data-protection framework when education, banking and technology intersect.
For now, the facts remain under investigation. The key issue is not simply whether student information was used to open bank accounts. It is whether every organisation involved could lawfully justify how it obtained, shared, processed and potentially repurposed that information.