NDPC probes UNILAG, Lotus Bank data breach
Analysis based on 22 articles · First reported Aug 11, 2026 · Last updated Aug 13, 2026
The investigation could lead to fines and reputational damage for UNILAG, Lotus Bank, and Hackerbella, potentially affecting their operations and public trust. It may also prompt stricter data protection enforcement across Nigeria's education and banking sectors, increasing compliance costs.
The Ghana — Data Protection Commission (Ghana) (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank, and Hackerbella Ltd over alleged violations of students' personal data. The probe follows public complaints that students' personal data were used to open bank accounts without a lawful basis. NDPC National Commissioner Vincent Olatunji directed the investigation team to conduct a comprehensive assessment of the collection, use, and disclosure of the affected students' data, and to determine the roles and responsibilities of each party. The investigation will cover compliance with the Nigeria Data Protection Act, 2023, including Data Protection Impact Assessments, lawfulness of credit scoring or profiling, use of automated decision-making, adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation, purpose limitation, retention policies, and technical and organisational safeguards. The NDPC also warned educational institutions to comply with existing data protection directives. The investigation is ongoing, and the affected parties have not yet publicly responded.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard