Stanbic IBTC’s privacy judgment is a warning to every brand holding customer data
On 29 July 2026, a Federal Capital Territory High Court ordered Stanbic IBTC Bank to pay N15 million in general damages to two former customers, David Ogundipe and Salami Tolulope Ibrahim. The post Stanbic IBTC’s privacy judgment is a warning to every brand holding customer data appeared first on Nairametrics .
On 29 July 2026, the Federal Capital Territory High Court ruled that Stanbic IBTC Bank must pay N15 million to two former customers, David Ogundipe and Salami Tolulope Ibrahim, for retaining and processing their personal data and sending marketing messages after they had closed their accounts and withdrawn consent. This case is a clear warning to brands holding customer data, signaling that Nigeria's data protection regime has moved from regulator-led enforcement to judicially enforced individual rights.
The facts are simple, but their implications are profound. The court ruled that consent and lawful basis for marketing communications are not permanent once granted; they expire when the purpose for which they were given ends. The bank's continued processing of personal data for marketing purposes after the customer relationship had ended was found to be a breach of the NDPA 2023, an infringement of the constitutional right to privacy, and an unfair trade practice.
The court did not require a complete deletion of the claimants' records, but instructed the bank to delete what it had no legal basis to keep and stop using what remained for marketing. This distinction between statutory retention versus marketing retention is crucial for compliance. The case was initiated by two individuals through private counsel, indicating that individuals can also sue for data protection violations.
The enforcement season in Nigeria is currently intense, with recent fines against MultiChoice Nigeria, Fidelity Bank, Meta Platforms Inc., and others for NDPA violations. For organizations holding Nigerian customer data, this case underscores the need to audit marketing databases against active relationships, separate statutory retention data from marketing-use data, treat data-erasure and opt-out requests as SLA-bound processes, and establish a joint legal-comms response protocol for data protection complaints.
The Stanbic IBTC judgment serves as a low-cost warning for clients, PR consultants, and communication professionals, highlighting that compliance has shifted from "do we have a policy?" to "does our actual practice hold up?" Organizations that treat this case as a template for their own audit are more likely to avoid similar lawsuits in the future.
Written by urgent.news from Nairametrics's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.