What Stanbic IBTC judgement means for clients, PR consultants, others

Franklyn Ginger-Eke
9 Min Read

The headline is ₦15 million. The real story is bigger

 

On 29 July 2026, a Federal Capital Territory High Court ordered Stanbic IBTC Bank to pay ₦15 million in general damages to two former customers, David Ogundipe and Salami Tolulope Ibrahim. The offence is for continuing to retain and process their personal data, and sending them marketing messages, long after they had closed their accounts and withdrawn consent.

On the face of it, this is a customer-service failure that escalated into litigation. Read against the current regulatory climate, it is definitely something more consequential. It signals that Nigeria’s data protection regime moved decisively from regulator-led enforcement to judicially enforced individual rights.

It is at this point that comms professionals who treat data protection as a legal back-office matter are about to find out how expensive that assumption is.

So, what actually happened?

The facts are almost mundane, which is precisely why they matter. The claimants closed a corporate account. The bank kept emailing and texting them, on both corporate and personal contacts, with promotional content.

They complained. The bank acknowledged the complaint and promised to stop. But it didn’t. They sued. Justice Kayode Agunloye’s ruling turned on a principle every organisation with a CRM system should internalise, which is that consent and lawful basis are not permanent once granted. They expire when the purpose they were given for ends.

The banking relationship ended. The lawful basis for marketing communications ended with it. Continued processing after that point was not a grey area. It was, in the court’s words, a breach of the NDPA 2023, an infringement of the constitutional right to privacy under Section 37, and an unfair trade practice under the FCCPA 2018.

Notably, the court did not order blanket deletion of the claimants’ records. It recognised that banks have independent statutory retention obligations under AML and banking regulation. The order was narrower and more precise, “delete what you have no legal basis to keep, and stop using what remains for marketing”.

That distinction, statutory retention versus marketing retention, is the single most useful compliance takeaway in the entire judgment.

Why this is different from a regulatory fine?

This case did not originate with the Nigeria Data Protection Commission. It came from two individuals, represented by private counsel, using the courts directly. That is a materially different threat model for organisations to plan around.

It also arrives in the middle of what is unmistakably a bullish enforcement season. Recently, the Nigeria Data Protection Commission (NDPC) fined MultiChoice Nigeria (reportedly around ₦766.2 million), alongside enforcement actions against Fidelity Bank (around ₦555 million), Meta Platforms Inc. ($32.8m – settled out of court) and several other businesses in different sectors for Nigeria Data Protection Act (NDPA) violations.

Add a judicial precedent enforcing the same underlying principles through private litigation, and the picture for any organisation holding Nigerian customer data or (data subject’s details) is now four-fold:

1. Two live enforcement tracks – NDPC regulatory action and individual civil suits running in parallel.

2. A judiciary now willing to quantify privacy harm in Naira, and not just issue declaratory relief.

3. A widening precedent base other claimants’ lawyers will cite, meaning the exposure compounds with every new ruling.

4. A specific, well-defined violation – post-relationship marketing use of retained data, which is common across banking, telecoms, insurance, subscription services, PR events, and any consumer-facing brand with a CRM.

For clients and their communication advisors, the question is no longer “are we compliant on paper?” It is “would our actual data retention and marketing practice survive the same scrutiny Stanbic IBTC’s faced, and failed?”

Why is this a PR and communications problem, not just legal’s alone?

This is where clients’ communication professionals need to pay close attention, because three things converge here that sit squarely in the comms function:

• Marketing databases are now legal liabilities, not just growth assets. Every “re-engagement” campaign, every dormant-customer or media/stakeholder mailing list, every retargeting segment built from former customers carries the same exposure Stanbic IBTC just discovered in court. Comms and marketing teams that do not coordinate list hygiene with data protection counsel are building the next case file.

• The reputational damage arrives before the legal outcome does. By the time a judgment lands, the story is already public, “Bank Fined for Ignoring Customer’s Data Request” is a headline that writes itself, and it lands hardest on institutions (brands) whose entire value proposition rests on trust. PR/Comms consultants need to treat unresolved data-erasure complaints as reputational risk indicators long before they become litigation.

• “We stopped the emails” is not a defence, and neither is a good-faith apology after the fact. Remember that the bank acknowledged the complaint and promised to stop. The court still ruled against it, specifically citing the “failure to respond adequately to requests for data erasure.” For crisis communications, this is the critical lesson where an operational failure to act on a stated commitment is now a distinct, court-recognised aggravating factor. Note that it is quite separate from the underlying violation itself.

The implications for clients and comms advisors

• Audit marketing databases against active relationships, not historical ones. If the underlying customer relationship (account, subscription, contract, engagement) has ended, the lawful basis for marketing communications needs independent justification, not inherited consent.

• Separate statutory retention data from marketing-use data in both policy and systems architecture. The court’s own reasoning shows regulators and judges are willing to draw this line precisely, so organisations should draw it first, on their own terms.

• Treat data-erasure and opt-out requests as SLA-bound, auditable processes, with comms and customer service teams looped in, not just legal or IT.

• Build a joint legal-comms response protocol for data protection complaints before they escalate. The gap between “we said we’d fix it” and “we actually fixed it” is where reputational and legal risk both compound.

• Brief client leadership now, while this is still a live news story and not yet a settled pattern. The organisations that get ahead of this precedent will be positioned as proactive, while the ones that wait for their own version of this lawsuit will be reactive by definition.

The bigger picture

Nigeria’s data protection ecosystem is no longer an emerging framework that organisations can treat as aspirational.

Between an increasingly assertive NDPC and a judiciary now willing to enforce individual data rights with real damages, the compliance conversation has shifted from “do we have a policy?” to “does our actual practice hold up in either circumstance?”

For clients, PR consultants, and communication professionals navigating this landscape, the Stanbic IBTC judgment is a useful, low-cost warning as it is a ₦15 million lesson learned by someone else.

The organisations that treat it as a template for their own audit, rather than someone else’s headline, are the ones that will avoid writing the next one.

Ginger-Eke, PhD, a Fellow of the Nigerian Institute of Public Relations and Institute of Information Management, is the Founder & Chief Strategist at The Rainbow Strategy – a Public Affairs, Strategic Communication & Data Protection Compliance Firm. As an NDPC-licensed Data Protection Compliance Organisation (DPCO), TRS supports organisations in auditing data retention and marketing practices, building lawful-basis frameworks, and preparing communications teams to respond to emerging data protection compliance risks before they become litigation or regulatory sanctions.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *