Download Privacy Needle App

Type to search

General Privacy

NDPC Probes UNILAG, Lotus Bank and Heckerbella Over Alleged Data Protection Violations

Share
Nigeria Set for Stricter NDPA Enforcement in 2026

NDPC Investigates UNILAG, Lotus Bank, Heckerbella Over Data Protection Concerns as Nigerian Schools Face Fresh Compliance Pressure

  1. NDPC Probes UNILAG, Lotus Bank and Heckerbella Over Alleged Data Protection Violations
  2. UNILAG, Lotus Bank Face Data Privacy Scrutiny as NDPC Tightens Enforcement
  3. NDPC Turns Up Heat on Nigerian Universities Over Data Protection Compliance
  4. UNILAG Under NDPC Spotlight Over Student Data Collection and Smart ID Project
  5. Student Data in Focus as NDPC Investigates UNILAG, Lotus Bank and Heckerbella
  6. NDPC Warns Nigerian Universities as Data Protection Investigations Expand
  7. UNILAG Data Controversy Puts Student Privacy Under the Microscope
  8. NDPC Investigates UNILAG Data Practices as Privacy Pressure Mounts on Universities
  9. Nigeria’s Privacy Regulator Takes Action as Universities Face Tougher Data Rules
  10. UNILAG Smart ID Project Sparks Data Privacy Questions as NDPC Steps In

Nigeria’s data protection regulator is tightening its scrutiny of the education sector, with the Nigeria Data Protection Commission (NDPC) investigating compliance concerns involving institutions and organisations that process large volumes of students’ and staff members’ personal information.

The development has placed the University of Lagos (UNILAG), Lotus Bank and Heckerbella Limited under heightened attention following allegations surrounding the university’s Smart Identity Card project and the collection and processing of students’ personal data.

The scrutiny comes as the NDPC carries out a broader sector-wide investigation of tertiary institutions across Nigeria, warning educational organisations that handle sensitive personal information that they must comply with the Nigeria Data Protection Act (NDPA) 2023.

What Triggered the UNILAG Data Protection Concerns?

The controversy centres on UNILAG’s Smart ID Card initiative, launched in partnership with Heckerbella Limited and Lotus Bank.

According to an investigation by FIJ, students and staff were asked to provide information including their names, National Identification Numbers (NINs), residential addresses, phone numbers and dates of birth as part of the Smart ID Card registration process.

The information was also connected to the opening of Lotus Bank accounts for students and staff.

FIJ reported that the consent notice used during the registration process did not adequately identify the lawful basis for processing the information or fully disclose all parties receiving or processing the data. It specifically reported that Heckerbella, which operated the registration platform, was not identified in the disclosure provided to students.

These allegations raise important questions under Nigeria’s data protection framework, particularly around transparency, lawful processing, consent and the disclosure of third parties involved in handling personal information.

Heckerbella’s Role Comes Under the Spotlight

Heckerbella Limited is a technology partner involved in the Smart ID Card project.

UNILAG itself described the initiative as a digital transformation project delivered through a partnership involving the university, Heckerbella and Lotus Bank.

However, FIJ’s investigation raised questions about whether students were adequately informed about the company’s role in collecting and processing their personal information.

That distinction matters because data protection obligations do not disappear simply because personal information is collected through a third-party technology platform.

Organisations involved in processing personal information must understand their responsibilities under the NDPA and ensure that data subjects receive appropriate information about how their data is being handled.

Lotus Bank Also Faces Questions

Lotus Bank’s involvement stems from the Smart ID Card’s connection to bank accounts opened in students’ names.

FIJ reported that the registration process involved collecting personal information that would be used to facilitate the opening of Lotus Bank accounts, while some students alleged that they were required to activate the accounts before receiving their Smart ID cards.

The allegations raise broader questions about whether individuals were given a genuinely informed choice when their personal information was being processed for multiple purposes.

For financial institutions, the issue is particularly significant because banks routinely handle highly valuable personal and financial information and operate within multiple layers of regulatory requirements.

NDPC Has Already Put Educational Institutions on Notice

The UNILAG controversy comes against the backdrop of a much larger regulatory exercise.

In February 2026, the NDPC commenced a sector-wide investigation of tertiary institutions across Nigeria to assess compliance with the Nigeria Data Protection Act. The exercise covers universities and other higher-education institutions processing substantial amounts of personal information.

The Commission also issued a compliance notice to hundreds of higher-learning institutions requiring them to provide evidence of key data protection measures.

Among the requirements were evidence of filing data protection compliance audit returns, appointment of a Data Protection Officer, implementation of appropriate technical and organisational safeguards, and registration as Data Controllers or Data Processors of Major Importance where applicable.

This means universities can no longer treat data protection as simply an IT or cybersecurity issue.

Why Universities Are Becoming a Major Privacy Concern

Educational institutions are among the largest holders of personal information in Nigeria.

A university may maintain students’ names, photographs, NINs, addresses, telephone numbers, academic records, financial information, biometric data and staff records.

That makes universities attractive targets for cybercriminals — but it also creates significant responsibilities for institutions collecting and sharing that information.

The growing regulatory scrutiny suggests that Nigerian universities will increasingly be expected to demonstrate not only that they collect data, but that they can explain why they collect it, who receives it, how long it is retained and what safeguards protect it.

The Issue Goes Beyond UNILAG

The NDPC’s actions indicate that the regulator’s attention is not limited to one institution.

The Commission’s sector-wide approach means educational institutions across Nigeria could face increasing pressure to demonstrate compliance.

Recent reporting has also raised concerns about major Nigerian educational institutions that were not appearing on the NDPC’s public compliance database despite handling significant amounts of personal information.

For universities, polytechnics and colleges, the message is becoming increasingly difficult to ignore: holding large amounts of personal data comes with equally large legal responsibilities.

What Happens Next?

The allegations involving UNILAG, Lotus Bank and Heckerbella do not by themselves establish that any of the organisations have been found liable for violating the NDPA. Regulatory investigations are intended to establish the facts, assess compliance and determine whether enforcement action is warranted.

But the case demonstrates why data protection is becoming a much more serious issue for Nigerian organisations.

As the NDPC expands its enforcement activities, educational institutions and their technology and financial partners will likely face greater scrutiny over how they collect, share and protect personal information.

For millions of Nigerian students and staff, the issue is ultimately about more than compliance paperwork.

It is about knowing where their personal data goes, who has access to it and whether the organisations entrusted with it are protecting it properly.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
Australia’s Facial Recognition Database Is Expanding, Where Does Privacy End?
Published: August 11, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.