By Olatunbosun Obafemi
Leading data privacy lawyers and regulatory experts in Nigeria have raised serious concerns over revelations that over 12,000 Nigerian youths are allegedly selling sensitive personal information – such as Bank Verification Numbers (BVN) and National Identification Numbers (NIN) – to fintech companies.
The development, now under investigation by the Economic and Financial Crimes Commission (EFCC), has sparked calls for urgent legal action, better regulation, and accountability.
In an exclusive interview with Nairametrics, Barrister Oladipupo Ige, Director of Policy at the Data Privacy Lawyers Association (DPLAN), said the scandal highlights systemic failures among data controllers like the National Identity Management Commission (NIMC) and the Nigeria Inter-Bank Settlement System (NIBSS). He referenced Section 39 of the Nigeria Data Protection Act (NDPA), which mandates data controllers to protect data from unauthorized access, misuse, or exposure.
Ige accused NIMC and NIBSS of repeated data leaks without proper disclosures, stating that their failure to notify the public of breaches or provide mitigation advice violates legal requirements under the NDPA. “The agencies’ silence amid public reports of widespread data misuse strongly suggests non-compliance,” he said.
Aloysius Gapa Paul, a data lawyer at AAGU Legal & Notaries, backed this view, citing Section 37 of the 1999 Constitution, which guarantees the right to privacy, forming the legal basis for the NDPA. He emphasized that fintech platforms purchasing stolen data are equally liable, especially under Sections 39 and 40 of the NDPA, which impose duties of confidentiality and mandatory breach reporting.
Paul said if the data was obtained through insider leaks or security lapses, NIMC and NIBSS could be held accountable. However, if individuals voluntarily sold their data, the liability may shift – but not entirely. “Regardless, both agencies must reinforce public education and digital safeguards,” he added.
Barrister Uche John Paul also emphasized that NIMC and NIBSS, as custodians of citizens’ data, have a moral and regulatory duty to prevent such massive breaches. He urged fintech companies to implement stricter KYC verification and avoid data of questionable origin.
The scandal has heightened public outrage, with many demanding criminal prosecution of those involved. The EFCC’s initial findings revealed that the youths buy personal data for as little as ₦1,500 and sell it to fintechs for ₦5,000, fueling scams and identity fraud.
While NIMC has denied any wrongdoing, data experts insist that coordinated enforcement by the NDPC, EFCC, and regulators is vital to restoring trust in Nigeria’s data protection framework.


