Stanbic IBTC Bank is now at the centre of a raging data privacy firestorm after a Federal Capital Territory High Court delivered a stinging judgment that has triggered outrage, raised red flags across the financial sector, and opened the door to what insiders warn could be a flood of damaging revelations.
In a bombshell ruling on July 29, 2026, Justice Kayode Agunloye found the bank guilty of unlawfully retaining and exploiting customers’ personal data — even after their accounts had been shut down and consent explicitly withdrawn.
But beyond the courtroom verdict, troubling claims are beginning to surface.
Inside sources familiar with banking operations allege that what happened in this case may not be an isolated incident, but part of a wider, deeply embedded culture where customer data is aggressively retained and monetised long after relationships end.
The case (CV/2190/25), brought by David Ogundipe and Salami Tolulope Ibrahim, laid bare what the court described as a clear violation of Nigeria’s data protection framework. After closing their corporate account with the bank, the claimants repeatedly demanded that their personal data be erased and no longer used.
Yet, in what the court viewed as a blatant defiance of the law, Stanbic IBTC allegedly continued to flood them with promotional emails and SMS messages — even after acknowledging the complaints and promising to stop.
Justice Agunloye’s verdict was scathing.
He ruled that the bank had no lawful basis whatsoever to continue processing the claimants’ data once consent had been withdrawn, declaring the actions a direct breach of the Nigeria Data Protection Act (NDPA) 2023 and a violation of the constitutional right to privacy.
The court went further, branding the conduct an unfair trade practice, effectively accusing the bank of exploiting personal data for commercial gain in violation of consumer protection laws.
Stanbic IBTC was hit with a N15 million penalty, ordered to immediately purge all unlawfully retained customer data, and slammed with a perpetual injunction barring it and its network of agents and partners from further processing or using the claimants’ information.
But critics say the financial penalty may only scratch the surface.
“What we are seeing could be the tip of the iceberg,” one industry insider said, warning that many financial institutions may be quietly engaging in similar practices under the radar. “Customer data has become a currency and some players are reluctant to let it go.”
Although the claimants demanded N250 million, the court awarded N15 million in damages, along with N500,000 in legal costs and a 10 per cent annual interest citing persistent unsolicited communications, failure to comply with data erasure requests, and a clear invasion of privacy.
Still, the court stopped short of ordering a total data wipe, acknowledging that banks are legally required to retain certain records under anti-money laundering regulations a loophole some critics argue could be exploited.
Legal analysts say the judgment is a potential game-changer one that could unleash regulatory probes, class-action lawsuits, and a wave of customer backlash if similar practices are uncovered across the industry.
Counsel to the claimants, O.E. Oluwadamisi, described the ruling as a landmark moment, signalling that the era of unchecked data control by corporations may be drawing to a close.
For the victims, however, the message is even more direct.
“Closing an account should mean closing the door on your data,” Ogundipe said. “Anything beyond that is a violation.”
Now, with this explosive ruling, Stanbic IBTC faces not just a legal setback, but a looming credibility crisis one that could force uncomfortable questions about how customer data is handled behind closed doors.
And if insider warnings are anything to go by, this scandal may just be the beginning.

