NCBA Bank kept sending a customer’s private account statements and transaction details to a complete stranger long after it had been told the email address was wrong.
The Office of the Data Protection Commissioner later ordered the bank to pay that customer two hundred and fifty thousand shillings because it failed to fix a clear and repeated error.
Brian Githaiga opened a business account at NCBA’s Lavington branch in May 2019. Two email addresses were recorded at the time. One of them did not belong to him.
From that point the bank began forwarding his sensitive business information to the wrong address.
In July 2023 Githaiga asked the bank to delete the incorrect email and use only the right one.
The stranger who was receiving the messages also wrote to NCBA and stated clearly that she had no account with the bank and was getting someone else’s financial records.
NCBA told the customer the problem had been solved on 7 July 2023. Yet evidence later proved the bank was still sending Githaiga’s account details to the third-party email on 7 February 2024.
That is more than half a year after both the account holder and the unintended recipient had reported the mistake.
The bank simply did not act.Githaiga filed a complaint with the Data Protection Commissioner. After examining the facts, Commissioner Immaculate Kassait ruled that NCBA had violated the customer’s right to erasure under the Data Protection Act. The bank was ordered to remove the wrong email address within fourteen days and to pay two hundred and fifty thousand shillings in compensation.
This was not a minor administrative slip. NCBA had been notified twice, by two different people, that private financial information was going to the wrong place.
It continued the practice anyway. Banks hold some of the most personal and valuable data citizens possess. When that data is sent to strangers, the risk of misuse is obvious. The law requires banks to keep customer information accurate, secure and confidential. NCBA failed that basic duty.
The compensation amount is small next to the size of the bank, yet the ruling matters. It shows that customers are not powerless when a bank mishandles their data.
Anyone in the same position can complain to the Data Protection Commissioner or take the matter to court. The NCBA case proves the system can work when a customer pushes hard enough.
What stands out is the length of time the error was allowed to continue.
A major bank received clear notice and still left the wrong email in its system for months. That kind of delay is not acceptable. Customers trust banks with their financial lives. When a bank ignores repeated warnings and keeps exposing private information, it damages that trust.
NCBA’s handling of this matter was careless and slow. The Data Protection Commissioner called it what it was: a breach of the customer’s legal rights.
The two hundred and fifty thousand shilling award is the direct result. Banks that treat data protection as an afterthought should take note. The rules are clear, and regulators are prepared to enforce them.











Add Comment