254 News Blog Business How NCBA Bank ignored its own customer warnings and exposed private data for years
Business

How NCBA Bank ignored its own customer warnings and exposed private data for years

When a major financial institution routinely promotes its digital capabilities and commitment to customer satisfaction, the bare minimum expected of it is keeping private banking data private. Yet NCBA Bank recently demonstrated a troubling level of operational negligence, proving that basic data protection standards can easily collapse inside its systems.

The lender was officially called to account and penalized after systematically broadcasting a client’s sensitive financial records to a complete stranger over an extended period.

The breakdown dates back to 2019, when Brian Githaiga opened a business account with NCBA. During the initial onboarding process, two separate email addresses were mistakenly linked to his financial profile.

One of those addresses belonged to an unrelated third party who had zero connection to Githaiga or his business enterprise.

Predictably, NCBA began regularly routing confidential bank statements, balance updates, and transactional data straight to the wrong inbox.What makes this failure so egregious is not simply the original clerical mistake, but how the bank handled it once exposed.

The unintended recipient actually took the initiative to notify NCBA directly, informing the institution that she was continuously receiving private financial information meant for someone else.

Months later, in July 2023, Githaiga himself formally petitioned the bank to remove the erroneous email address from his account profile once and for all.

NCBA claimed that it resolved the issue on the exact day Githaiga made his request.

That assurance proved to be entirely false.

Documentary evidence later reviewed during official proceedings showed that NCBA was still actively transmitting Githaiga’s confidential financial records to the stranger’s email inbox as late as February 2024.

That means for over seven months after both the customer and the accidental recipient explicitly raised the alarm, the bank casually allowed the security breach to persist.

Faced with persistent corporate indifference, Githaiga took his grievance to the Office of the Data Protection Commissioner. Following a detailed investigation, the privacy watchdog saw right through the bank’s administrative excuses.

The Commissioner formally found NCBA liable for infringing upon the customer’s explicit right to erasure as provided under Kenya’s Data Protection Act.

As a result, NCBA was instructed to permanently delete the third-party email address within fourteen days and ordered to pay Githaiga two hundred and fifty thousand shillings in financial damages for the breach.

In its defence, NCBA tried to argue that the second email address was part of the original account setup documentation and maintained that it had acted promptly to resolve the complaint.

The Data Commissioner firmly rejected that line of reasoning. A review of the timeline proved that the bank had either profoundly failed or blatantly neglected to fix the security loophole when prompted.

This ruling exposes a glaring vulnerability in how customer records are managed within major financial organizations. Technical systems in place are supposed to prevent such basic errors, and when glitches occur, financial institutions are expected to rectify them immediately.

Account balances, transaction patterns, and contact details represent highly sensitive personal property.

They are not public data to be mishandled without consequence. When an institution repeatedly disregards explicit warnings from both sides of a breach, it damages the fundamental trust that underpins the entire banking sector.

Ordinary account holders should never be forced to launch a legal campaign simply to stop their bank from sharing private financial statements with strangers. The legal framework in Kenya is unambiguous: banks do not own the personal data they gather.

They are custodians bound by a legal mandate to maintain accurate, secure, and strictly confidential records.

While a penalty of two hundred and fifty thousand shillings is modest relative to NCBA’s overall corporate size, the ruling establishes a critical precedent. It proves that ordinary consumers can successfully hold banking giants accountable when their privacy is compromised. The Data Protection Commissioner’s intervention delivers a stark reminder to the entire sector: customer data rights are non-negotiable, technical errors must be fixed promptly, and ignoring compliance carries genuine regulatory consequences.

NCBA’s mishandling of this case stands as a clear example of what happens when that statutory duty is disregarded.

Exit mobile version