By Odo Christian Obinna

On July 29 2026, something happened before his lordship, Honourable Justice K. Agunloye of the Abuja division of Federal High Court of Nigeria. Two lawyers, also partners in a law firm called Earnest Attorneys LP, closed their business bank account with Stanbic IBTC. An average Nigerian, can relate with how pesky and unwanted it can be when your bank and other entities, including those you have no smattering of how and where they got your data, keep dumping their promotional posts and what have them in your email, private messaging, and other private enclosures of yours.
It was to avoid this pesky intrusion that the lawyers, following the closure of their business account, explicitly requested that the bank delete their personal data. Well, they received a letter from the bank to that effect: that their contact details had been removed from its marketing database. But the lawyers kept receiving promotional emails and SMS messages from the same bank anyway. Being lawyers, they did what lawyers do. They sued.
The result of that action is David O. Ogundipe & Anor v. Stanbic IBTC Bank Limited with suit no. CV/2190/25), a judgment that entities and businesses and customers alike at the crossroads of banking, data protection, and consumer rights should read carefully. Not exactly because it breaks entirely new legal ground, but because it applies the Nigeria Data Protection Act 2023 to a fact pattern that is depressingly common in Nigerian financial services (in fact virtually in every aspect of our life), and does so with a clarity that leaves very little room for creative compliance arguments.
How It All Started
Let us set the scene properly, because the facts matter here. If you have ever written law exams, you will also know that facts matter to your marks too. Lol. David Ogundipe and his partner Salami Toluope Ibrahim operate a law firm called Earnest Attorneys LP, a limited partnership registered under Part C of the Companies and Allied Matters Act, 2020. To be fair to both sides, the legal status of the partnership was contested in the preliminary tussle: was it just a business name or incorporation in which case the rights and liabilities attached to it are separate from those of the partners? The defendant deposed in its affidavit that it was a limited liability partnership to which the claimants in counter affidavit discredited, claiming it was just a limited partnership registered under Part C of the Companies and Allied Matters Act, 2020 or business name in simple parlance. Whichever was the case, it probably didn’t matter much.
Sometime in 2024, they opened a corporate account with Stanbic IBTC. Like every other business opening a bank account in Nigeria, they went through the standard know your customer (KYC) process: filling forms, submitting identity documents, handing over personal information including names, phone numbers, email addresses, and residential addresses. They also, as is standard in bank account opening documentation, signed off on clauses relating to marketing and promotional communications.
The relationship did not last long. In February 2025, they requested that the account be closed. The bank eventually closed it and transferred the account balance to an account nominated by the claimants. So far, so unremarkable. But the claimants did not just want their account closed; they also wanted their personal data deleted. To this effect, they wrote a formal letter to their former banker, explicitly withdrawing consent to continued use of their data for anything and invoking their right to erasure. The bank’s legal team responded with a letter dated 18 June 2025 stating that the account had been closed and that the claimants’ contact details had been removed from the promotional database.
But the messages kept coming.
Promotional emails. SMS communications. All addressed to the very email addresses and phone numbers the claimants had supplied during account opening. These messages were tended as evidence before the court, lending credence to the obvious inference that whatever the compliance team had told the legal department had not actually filtered through to the automated marketing systems doing the sending.
The Bank’s First Defence: “These Aren’t Even Your Rights to Enforce in the First Place”
Before throwing all its weight in the ring of data protection brawls, the bank dished out preliminary procedural blows that are actually quite interesting from a corporate law standpoint which I have already alluded to earlier on: the issue of the legal status of the partnership. The bank argued that the claimants were suing in the wrong capacity. The account belonged to Earnest Attorneys LP and as such the LP is a distinct legal entity. Therefore, any claim arising from the banking relationship, including any data rights claim, belonged to the partnership, not to the individual partners.
This is a perfectly respectable argument when you are dealing with contractual or commercial claims. If Stanbic had wrongfully dishonoured a cheque drawn on the firm’s account, the right to sue would indeed belong to the firm, if the firm was indeed a limited liability partnership distinct from the partners. The separate legal personality principle would bite. But the court dispatched this argument with a meticulous articulation and formulation that should settle the point definitively going forward, and the reasoning is worth sitting with.
The court drew a distinction that sounds simple on the surface but are deeply reaching in practical ramifications: the source through which personal data is obtained is legally distinct from the statutory rights that attach to that data. When Stanbic collected David Ogundipe’s name, phone number, email address, and home address during the account opening process, it obtained his personal data. Not Earnest Attorneys LP’s data. His. The partnership does not have a phone number that texts you good morning; Mr. Ogundipe does. The partnership does not have an email inbox that receives the promotional content; the individual partners do.
From the reasoning of the Court, once personal data relating to an identifiable natural person is collected, the Nigerian Data Protection Act (NDPA) 2023 confers on that individual, not on any corporate vehicle through whose activities the data was obtained, the right to challenge unlawful retention, processing, or continued use of their information. Those statutory rights exist independently of the contractual relationship through which the data was originally captured. The corporate personality cases the bank cited all concerned disputes about corporate rights and liabilities. This dispute was about personal data rights. Different legal regime, different analysis, and certainly different outcome.
What this means in practical terms is that every time a bank or financial institution collects personal information from a director, partner, authorised signatory, or beneficial owner during corporate onboarding, it creates a direct statutory relationship between itself and that individual. The individual becomes a data subject with enforceable rights under the NDPA, regardless of whether they ever had a personal account with the bank. The takeaway for every bank out there is that its onboarding documentation is not just a corporate compliance exercise; it is the moment it assumes data protection obligations toward the actual human beings whose information they are collecting.
The Core Question: What Lawful Basis Are You Relying On, Dear Bank?
With the preliminary distraction successfully dispatched out of the way, the court moved to the substance. Section 25 of the NDPA is the relevant provision which requires every instance of personal data processing to rest on one of a recognised set of lawful bases: consent, contract, legal obligation, vital interests, public interest, or legitimate interests. Processing without a lawful basis is unlawful. Full stop, capital one even.
The bank’s position was essentially that the claimants had consented to their data being processed and to receive marketing or promotional communications when they signed the account opening documentation in 2024, and that this consent remained valid. How can there not be a few problems with this argument and how can each not be more fatal than the last though?
The first problem is that consent under the NDPA is not a gift that, once given, belongs to the data controller forever. Sections 34 & 35 of the Act gives every data subject the right to withdraw consent, while Section 35 specifically imposes a corresponding obligation on data controllers to act on that withdrawal. When the claimants wrote formally to withdraw consent and request deletion, the consent-based lawful basis for processing their data evaporated at that moment. Any continued processing after that point needed an entirely different justification.
The second problem is that the bank could not identify any other lawful basis to justify continued retention of the data post contractual relationship between them. The law sometimes mandates certain institutions, especially financial institutions, to retain some categories of customer information for a defined purpose after termination of commercial relationship. E.g., for purpose of anti-money laundering obligations. Such is not as of right; it must be expressly donated by law. The court in this case was not unsympathetic to the idea that financial institutions may have genuine regulatory reasons to retain certain records after account closure but such must be explicitly donated by law. The court acknowledged this expressly.
Even where such power is donated by a statute, there is an enormous difference between retaining records in a compliance archive to satisfy a regulatory obligation and actively using personal contact details to send promotional emails and SMS messages. Nobody’s AML obligations require them to keep emailing you about new loan products after you have closed your account and asked them to stop. The court dispatched this point home when it finds that the bank failed to demonstrate any lawful commercial necessity for continuing to use the claimants’ email addresses and phone numbers for promotional purposes after the banking relationship ended. It could not point to any statutory obligation that required it to maintain those particular marketing communications. The lawful basis column was simply empty.
There is a passage in the judgment that I think deserves to be quoted in compliance training materials across the financial services industry:
“If the Defendant considered itself legally obliged to retain certain records for regulatory or statutory compliance, nothing prevented it from explaining that obligation to the Claimants while simultaneously refraining from further promotional communications unrelated to such legal obligation.”
In other words, the law allows you to keep what you genuinely need to keep. It does not allow you to use what you are keeping for purposes that have nothing to do with why you are keeping it. We should remember again the purpose-specific principle thrust of data processing and use: it must be limited to only specified purpose and what is necessary. You are allowed to keep what you genuinely need; you are forbidden to direct it to other purposes or uses. These are different things, and conflating them, as many institutions do, is not a compliance strategy but a liability.
A Systemic Problem Hiding in Plain Sight
What makes this case genuinely instructive beyond its legal holdings is what it reveals about how data protection compliance actually fails in large organisations. This is where organisations dealing with data of customers or employers should pay more attention to. Reading through the bank’s position in this case, I see a bank that thought it had done everything that was statutorily required of it and a communication gap somewhere in the organisation’s information chart/channel. No deliberate (I use “deliberate” for reasons we will see shortly below) bad faith. Just a gap. The bank’s legal team told the claimants’ solicitors, in writing, that their contact details had been removed from the marketing database. The letter was delivered. The record of delivery was produced as evidence. And yet the messages kept coming.
What certainly happened is gap between what the legal and compliance departments believe they have instructed the business to do, and what the automated marketing technology stack is actually doing. Modern banks operate sophisticated CRM systems, email marketing platforms, SMS gateways, and digital engagement tools. These systems do not always talk to each other in real time. A compliance team can log a deletion request and consider the matter resolved, but the CRM system does not get the memo for diverse of reasons. Could be it is operating on a cached dataset that has not been updated. It could be that the SMS gateway may be working off a separate list that nobody thought to update. The list goes on and on.
The result of any of these gaps is exactly what happened in this case: a legal undertaking that was contradicted by automated system outputs, which is about the worst possible evidentiary position to occupy in data protection litigation.
The court correctly identified this gap though without mentioning it, and it is worth dwelling on the legal consequence. When you give a formal undertaking that data has been deleted and then continue sending communications that use that data, you have not merely failed to comply with your NDPA obligations; you have also created documentary proof that you failed to comply, while simultaneously undermining any good-faith narrative you might otherwise have advanced. The bank’s affidavit denied any unlawful retention or processing, but the claimants exhibited the actual messages they received after the deletion confirmation was sent. The court found the exhibited messages more persuasive than the general denial.
For any institution out there that gives two straws about taking its data governance seriously, the lesson to take from this piece is: the standard operating procedure for account closure needs to include, as a mandatory automated step, the propagation of deletion or suppression instructions across every system that holds or uses that customer’s contact data. This is not a legal department task; it is an engineering and data architecture task that legal and compliance teams must mandate and audit. Manual opt-out processes and sequential database updates create exactly the kind of lag that turns compliance failures into litigation.
The Consumer Protection Angle: Double Exposure for a Single Mistake?
One other commercially significant side to the judgment is what I frame as a double exposure in its treatment of the Federal Competition and Consumer Protection Act 2018. Having found that the bank violated the NDPA, the court did not stop there. It went on to hold that the same conduct, using a former customer’s personal data to send them unsolicited promotional communications after the relationship ended and consent was withdrawn, also constitutes an unfair and improper trade practice under Sections 17(g), 123, and 124 of the FCCPA.
The FCCPA was designed to protect consumers against deceptive, unconscionable, and unfair conduct by suppliers of goods and services. Banks providing banking services are also within the net reach of this framework. The court’s reasoning on this point is thus: a consumer who has unequivocally terminated his or her relationship with a service provider, withdrawn consent, and demanded deletion of his or her personal information is entitled to have that request treated with seriousness and respect. Continued promotional engagement in the face of an express objection amounts to an unwarranted intrusion into the consumer’s privacy and an unnecessary exploitation of information originally supplied for an entirely different purpose. Commercial convenience, the court observed crisply, cannot supersede statutory obligations.
The practical implication of this dual liability finding is something that deserves attention at board level and in risk committee meetings. A data protection failure of the kind that occurred here is no longer just a matter for the Nigeria Data Protection Commission. It simultaneously opens the door to consumer protection enforcement by the Federal Competition and Consumer Protection Commission. Two regulators. Two enforcement regimes. Double exposure.
Dear banks and other organisations, What This Judgment Actually Requires of You
This judgement operationalise the NDPA in a banking context in ways that are immediately actionable. I will be direct to the point:
Your account closure workflow needs to be a complete data lifecycle event, not just a financial transaction. When a customer closes an account, that event should trigger automatic suppression or deletion of his or her contact data across every marketing system: email platforms, SMS gateways, CRM segments, push notification lists, and any third-party marketing service providers that hold a copy of your customer database. The compliance confirmation you send to a departing customer’s solicitors needs to actually reflect what your systems are doing.
The distinction the court draws between regulatory archiving and active marketing channels will no doubt prove an important judicial formulation going forward.
Your consent approach also needs to be revisited. The account opening documentation that bundled operational communications and promotional marketing under a single consent clause is the kind of clause that creates the problem this litigation illustrates. When the customer withdraws consent, which consent has he or she withdrawn? All of it? Just the marketing part? A clean separation between the operational communications consent (which may survive account closure for defined regulatory purposes) and the promotional marketing consent (which absolutely should not) would have made the bank’s compliance position more clear and certainly more defensible.
Finally, data protection is not just a responsibility of legal department that ends once the policy is approved; it is operational risk that requires a regular audit. The legal team can document the right processes. Only the technology team can ensure those processes are actually what the systems are executing.
A Final Thought
Is it not a satisfying irony that the claimants in this case are lawyers? They knew exactly what rights they had, exactly what the NDPA required, exactly what formal steps to take to create a documentary record, and exactly how to exhibit that record in affidavit evidence. Most people are however not lawyers. Most customers certainly would not know any of these. Most people who receive unwanted marketing messages after closing a bank account simply mark them as spam and move on, having no idea that each one represents a continuing statutory violation of their privacy rights.
This imbalance is not lost on anyone who thinks seriously about data protection. The individuals best positioned to enforce these rights are the ones who least need the law’s protection. But individuals most affected by data misuse are often the ones least equipped to identify what happened to them, let alone pursue a legal remedy.
Good thing is that judgments like this one create precedents that outlive the specific litigants. When next your bank sends you a promotional message after you have closed your account and asked to be forgotten, you should know better that a court now shares your sentiment that such is unlawful processing, a constitutional privacy violation, and an unfair trade practice… all at once. That is, as it were, quite a lot to be getting on with.

