.
A Federal Capital Territory High Court judgment against Stanbic IBTC Bank has highlighted the growing legal and reputational risks businesses face when they continue using customers’ personal information after a relationship has ended or consent has been withdrawn.
The court, in a judgment delivered on July 29, 2026, ordered Stanbic IBTC to pay ₦15 million in general damages to two former customers, David Ogundipe and Salami Tolulope Ibrahim, over the continued retention and processing of their personal information and the sending of promotional messages after they had closed their account.
How the Dispute Started
The case arose after the two customers ended their banking relationship with Stanbic IBTC but continued receiving promotional emails and text messages through both corporate and personal contact details.
They reportedly complained to the bank and requested that the communications stop. Although the bank acknowledged the complaint and indicated that the messages would be discontinued, the promotional communications allegedly continued.
The customers subsequently took the matter to court, leading to the judgment by Justice Kayode Agunloye.
Court Draws Line Between Retention and Marketing
A key aspect of the ruling is that the court did not require Stanbic IBTC to erase every record relating to the former customers.
Instead, the judgment recognised that financial institutions have separate legal and regulatory obligations requiring them to retain certain records, including information connected to banking and anti-money-laundering requirements.
The distinction is therefore between retaining information where the law requires it and continuing to use that information for marketing without a valid legal basis.
The court ordered the bank to delete personal information it was not legally required to retain and restrained further processing of the customers’ information for marketing or other purposes without lawful justification.
Privacy Rights Move Beyond Regulatory Enforcement
The case is particularly significant because it was brought directly by individuals rather than originating as an enforcement action by the Nigeria Data Protection Commission (NDPC).
That creates another potential route through which organisations can face consequences for data-protection failures.
The development comes amid increased enforcement activity around Nigeria’s data-protection regime, with the NDPC having taken action against organisations in sectors including financial services and technology.
The Stanbic IBTC ruling therefore demonstrates that compliance risks can arise through both regulatory enforcement and private legal action.
Implications for Marketing and Communications Teams
The ruling has implications beyond banks.
Companies across telecommunications, insurance, retail, technology, subscription services and other consumer-facing industries routinely maintain customer databases containing contact details and behavioural information.
When a customer relationship ends, organisations may therefore need to distinguish between information they are legally required to retain and information they continue using for promotional purposes.
The judgment also raises questions for companies operating customer relationship management systems, mailing lists and re-engagement campaigns. A former customer’s presence in a database does not automatically mean the organisation has an unlimited right to continue marketing to that person.
A Warning for Nigeria’s Digital Economy
The case arrives as Nigerian businesses collect and process increasingly large volumes of personal information through digital platforms.
Banks, fintechs, e-commerce companies, telecom operators and other businesses depend heavily on customer data to provide services and conduct marketing.
At the same time, Nigeria’s data-protection framework gives individuals rights concerning how their information is collected, processed, retained and used. Stanbic IBTC’s own privacy policy recognises rights including requests for access, correction and deletion, as well as the ability to object to processing for direct marketing, subject to applicable legal exceptions.
The Bigger Picture
The Stanbic IBTC judgment reinforces a broader shift in Nigeria’s data-protection landscape: having a privacy policy is no longer enough if an organisation’s actual data practices do not match it.
For businesses, the case highlights the importance of knowing what customer information is being retained, why it is being retained and whether there remains a lawful basis for using it.
For customers, it reinforces the principle that ending a commercial relationship does not necessarily mean surrendering control over personal information indefinitely.
As Nigeria’s digital economy expands and businesses accumulate more customer data, the ₦15 million judgment could serve as an important warning that privacy obligations extend beyond the point at which a customer closes an account or stops using a service.













