Glostarep

The Hidden Risk in Digital Banking: How Data Protection Gaps Could Expose Your Money

The Hidden Risk in Digital Banking: How Data Protection Gaps Could Expose Your Money

A father walked into a Lagos bank one January morning in 2025 to report a stuck ATM card. By the time he left, N1.4 million was gone, stolen through a distant PoS terminal by a fraudster who had posed as a sympathetic fellow customer and lifted his PIN. His wife suffered a stroke when she heard the news. She never recovered.

That is the human cost hiding behind Nigeria’s celebrated leap from ATM cards to fintech apps. And it is not an isolated case.

When “convenience” becomes a trap

A 27-year-old cloud engineer in Lagos, Tunde Adekunle, applied for a car loan and got rejected over a “non-performing loan” he never took. The real story: a lending app he had once used had harvested his contacts and SMS history, disbursed an unauthorised N25,000 loan on top of one he had already repaid, attached a 90 per cent interest rate, then messaged his colleagues calling him a fraudster when he refused to pay.

Two very different Nigerians. One outcome: personal data turned against them by systems meant to serve them.

This is the real argument buried in the Guardian’s report, and it deserves to be said plainly, Nigeria’s Data Protection Act 2023 exists on paper far more convincingly than it exists in practice. The law is sound. The enforcement is not keeping up with how fast fraud is evolving.

The Numbers Behind Nigeria’s Data Protection Challenge

The scale is not anecdotal. Cybersecurity firm Surfshark found that 10 percent of Nigerians have been hit by a data breach, with more than 566,300 breached accounts recorded in 2025 alone. A Sumsub global identity fraud report ranked Nigeria the worst in Africa for identity fraud, at a 5.91 percent fraud rate.

The Nigeria Inter-Bank Settlement System reported N400 million in fraud proceeds moved through accounts opened with stolen identities in 2024 alone. In March 2024, weak API security at the National Identity Management Commission allowed millions of Nigerians’ NINs, BVNs, biometric photos and demographic data to be sold online for as little as N70 each, the price of a phone recharge card.

Even the regulator meant to police all this has stumbled. The Nigeria Data Protection Commission fined Meta $32.8 million in 2025 for collecting data from over 60 million Nigerian users without consent, then quietly dropped the fine in 2026 after a confidential settlement, a decision that undercuts confidence in the whole enforcement system.

Infrastructure built on uneven ground

Data Processing Officer Bola Adepegba, who spoke with The Guardian, put it starkly: Nigeria’s Digital Public Infrastructure is only partially formed. Payment platforms, identity databases and regulators still don’t fully talk to each other, unlike India’s Aadhaar-anchored system. That fragmentation is exactly where fraud and unauthorised data-sharing slip through.

NIBSS says it is trying to close the gap through consent-based access frameworks and security-by-design architecture, including encryption and continuous monitoring. Those are the right instincts. But instincts on a slide deck don’t stop a fraudster on a phone call.

When the Law Can Hold Violators Accountable

To be fair, the Nigeria Data Protection Act 2023 has produced real consequences. Multichoice Nigeria was fined N766.2 million for intrusive data practices and illegal cross-border transfers. Fidelity Bank paid N555.8 million for processing customer data without consent. The regulated sector generated N12 billion in 2024, up from N4 billion in 2021, and created 23,000 jobs.

These are not small numbers. They prove the framework can bite. What they don’t prove yet is that it bites consistently, fast enough, or hard enough to protect the next Ifeanyi Chukwu or Tunde Adekunle before the damage is done, as seen in cases involving the Corporate Affairs Commission, Remita, Sterling Bank, and, in May 2026, the leak of Nollywood actor Emeka Ike’s voter data from an INEC portal.

Under the Act, Nigerians technically have the right to be informed, to object, to demand deletion, and to report breaches within 72 hours. Few know these rights exist. Fewer still trust that reporting a breach changes anything, given how the Meta fine was quietly reversed.

Nigeria did not build its ATMs, its BVNs, or its fintech apps to fail people. But a system is only as trustworthy as its weakest safeguard, and right now that weak point is enforcement, not innovation.

So here is the question worth sitting with: if a $32.8 million fine against one of the world’s biggest tech companies can be walked back in secret, what protection does an ordinary Nigerian actually have when their own data is the one for sale?

Leave a Comment

Your email address will not be published. Required fields are marked *