JOSEPHINE EKATI ANINDO VERSUS NCBA BANK PLC
1. Introduction
The grievance in this matter stems from Josephine Ekati Anindo’s complaint against NCBA Bank PLC on the receipt of multiple unsolicited emails containing sensitive financial information belonging to another customer, despite her objections. This action is in contravention of the Data Protection Act, 2019.
Table of Contents
2. Nature of Complaint
The Complainant’s email address differs from the Respondent’s customer’s by a single letter, yet the Respondent continued to send sensitive financial information, including PIN/Password/OTP alerts, mobile transaction notifications, account statements, and promotional communications. Despite repeated objections and a meeting on 23rd October 2024, she continued to receive financial transaction details belonging to another individual, and the Respondent failed to act on her objections.
3. Analysis of Evidence
Complainant’s Position
- Since March 2024, she has been receiving multiple emails despite not being the rightful owner of the bank account
- She made several attempts in July 2024 to request the bank to stop using the incorrect email address, but the issue remained unresolved
- During a meeting on 23rd October 2024, the Respondent committed to resolving the matter, but she received another transaction email on 26th October 2024
- She has never received written communication from the Respondent to her correct email address
- Provided copies of account activity emails and an email thread with the Respondent’s Channel Support Agent
Respondent’s Defense
- Claimed the email address was correctly associated with the account holder as confirmed during account opening on 22nd March 2024
- Relied on contractual necessity, legal obligation, and legitimate interests as the lawful basis for processing
- Conducted an investigation and confirmed the Complainant’s email address was similar to the customer’s but different by one letter
- Disabled the email address from the customer’s profile on 15th October 2024 and requested the customer to visit the branch
- Claimed the issue was resolved amicably following a meeting on 23rd October 2024
4. Issues for Determination
- Whether the Respondent fulfilled its obligations under the Act
- Whether the Complainant is entitled to remedies under the Act
5. Final Determination
The Data Commissioner found:
- The Respondent sent sensitive financial data to the Complainant due to a single-letter email error.
- The Respondent failed to act on the Complainant’s objections despite multiple requests.
- The Respondent continued processing the Complainant’s personal data without a lawful basis.
- The Respondent is liable for violation of the Complainant’s rights under the Act.
Orders:
- An Enforcement Notice is issued against the Respondent.
- Right of appeal to the High Court within 30 days.
6. Significance and Impact
Data Accuracy and Rectification
- Reinforces the obligation to ensure personal data is accurate and corrected without delay
- Even a single-letter error in an email address constitutes a data accuracy violation
Right to Object and Erasure
- Confirms the right to object to processing and the right to erasure
- Data controllers must act promptly on objections and erasure requests
Broader Impact: This case exposes a critical vulnerability in banking data management: how a single character error in an email address can expose customers to serious privacy breaches. It establishes that financial institutions must implement proactive verification mechanisms to prevent such errors, rather than relying on reactive fixes after complaints arise.