NDPC Launches Forensic Probe into UNILAG and Lotus Bank Over Unauthorized Account Creation
According to Punch Newspapers, the NDPC has launched a forensic investigation into the University of Lagos (UNILAG), Lotus Bank, and Hackerbella Ltd following complaints that students' personal data…
Jocelyn Davenport·updated August 14, 2026

If you've ever wondered what happens when a neobank, a fintech intermediary, and a university all touch the same pool of personal data — and none of them quite agree on who asked for permission first — the Nigeria Data Protection Commission just gave us a case study. According to Punch Newspapers, the NDPC has launched a forensic investigation into the University of Lagos (UNILAG), Lotus Bank, and Hackerbella Ltd following complaints that students' personal data was used to open bank accounts without a lawful basis. This isn't a generic privacy notice update; it's a regulator pulling the curtain back on a textbook example of choice architecture built without the user in the room.
What the commission is actually looking at
The NDPC's investigation team, directed by National Commissioner Dr Vincent Olatunji, has a fairly long shopping list. As reported, the probe will examine Data Protection Impact Assessments, the lawfulness of any credit scoring or profiling, and the use of automated decision-making systems tied to those accounts. It will also dig into privacy notices, data-sharing arrangements between the three parties, lawful bases for processing, data minimisation, purpose limitation, retention policies, and the technical and organisational safeguards meant to protect data subjects' rights.
Read that list slowly. It's not just "did they leak the data" — it's "was the data ever allowed to move at all, and if so, who told the student." That's the friction point most of us never see, because it happens before we ever download the app.
Why a neobank ends up on the regulator's desk
For a digital-first bank like Lotus, the onboarding journey is the product. If a third party funnels pre-collected student data straight into a KYC pipeline, the bank gets account growth without doing the slow, consent-heavy work — and the user inherits a relationship they didn't ask for. The NDPC has now warned educational institutions still out of compliance with its existing directives to course-correct immediately, which is regulator-speak for "we are done warning."
For us as consumers, the practical takeaway is small but worth keeping: when a "quick" bank account appears tied to your student status, your employer, or any institutional affiliation, treat the consent moment as the actual product. That's where your rights are decided, not in the privacy policy you'll never read.