The short version
We collect what onboarding requires
Identity/KYC data (BVN, NIN, ID), contact details, financial and transaction records, and basic device data.
We use it to serve & protect you
Opening and running your account, processing transactions, meeting KYC/AML law, and stopping fraud.
We share only where necessary
With regulators (CBN, NDPC), credit bureaus, payment partners, and providers bound by contract — never sold for marketing.
You have real control
Access, correct, export, restrict or ask us to delete your data by writing to our Data Protection Officer.
Introduction
FSE Microfinance Bank Limited ("FSE", "the Bank", "we", "us") is licensed by the Central Bank of Nigeria (CBN) to provide microfinance banking services. This notice explains what personal data we collect from customers, prospective customers, agents, guarantors and website/app visitors (together, "you"), why we collect it, who we share it with, and the choices and rights available to you.
This notice applies to information collected through our branches, agent locations, USSD channel, mobile app, website, customer service lines, and any other channel we use to deliver our services. It should be read alongside your account terms and conditions and any product-specific disclosures.
Information we collect
The information we collect depends on your relationship with us — browsing our website, applying for a product, or holding an active account.
| Category | Examples |
|---|---|
| Identity & KYC data | Full name, date of birth, gender, passport photograph, signature, Bank Verification Number (BVN), National Identification Number (NIN), government-issued ID, utility bill or address verification. |
| Contact details | Phone number, email address, residential and business address, next of kin and guarantor details. |
| Financial & account data | Account and loan details, transaction history, balances, income and employment information, credit history and bureau reports. |
| Device & usage data | IP address, device identifiers, mobile network, app/USSD session logs, approximate location, log-in timestamps. |
| Communications | Call recordings and records from our contact centre, emails, chat and in-branch service requests, satisfaction survey responses. |
| Special categories | Biometric data (photograph/fingerprint) only where required for identity verification under CBN KYC requirements. |
How we collect it
We collect information directly from you — on account-opening and loan-application forms, in branch or through our agents, by phone, on our website and mobile app, and through USSD. We also receive information from third parties: credit bureaus (such as CRC Credit Bureau or FirstCentral), the Nigeria Inter-Bank Settlement System (NIBSS) for BVN validation, the National Identity Management Commission (NIMC) for NIN verification, guarantors and referees you nominate, and joint account holders. Where our website or app uses cookies or similar technology, this is described in section 10.
How we use your information
We use your personal data to:
- Verify your identity and carry out Know-Your-Customer (KYC), anti-money-laundering (AML) and counter-terrorism-financing checks before and during your relationship with us.
- Open, administer and service your account, loan or other product, including processing deposits, withdrawals, repayments and transfers.
- Assess creditworthiness and affordability for loan and overdraft applications, including checks with licensed credit bureaus.
- Detect, investigate and prevent fraud, financial crime and unauthorised access to your account.
- Communicate with you about your account, respond to enquiries and complaints, and send statutory notices.
- Improve our products, digital channels and customer service, including through call-quality monitoring.
- Meet reporting obligations to the CBN, the Nigeria Deposit Insurance Corporation (NDIC), the Nigerian Financial Intelligence Unit (NFIU) and other regulators.
- With your consent, tell you about products, offers or services that may interest you. You may opt out at any time — see section 9.
Legal basis for processing
Under the Nigeria Data Protection Act, 2023 (NDPA), we rely on one or more of the following bases to process your personal data:
- Contract — processing necessary to open and operate your account or deliver a product you have requested.
- Legal obligation — KYC/AML checks, tax reporting and regulatory returns required by the CBN, NDIC and NFIU.
- Legitimate interest — fraud prevention, network and information security, and improving our services, balanced against your rights.
- Consent — marketing communications and any optional data use, which you may withdraw at any time without affecting the underlying account relationship.
Sharing & disclosure
We do not sell your personal data. We disclose it only where necessary, including to:
- Regulators and government bodies — the CBN, NDIC, NFIU and the Nigeria Data Protection Commission (NDPC).
- Credit bureaus licensed by the CBN, for credit reporting and affordability checks.
- Payment and settlement infrastructure providers, including NIBSS, card schemes and payment processors, to complete transactions.
- Service providers who process data on our behalf under written confidentiality and data-processing agreements — for example, core banking, cloud hosting, SMS/email delivery and identity-verification vendors.
- Guarantors, next of kin or joint account holders, to the extent relevant to a shared product.
- Law enforcement or courts, where compelled by a valid legal order.
- A successor entity, only in connection with a merger, acquisition or restructuring of the Bank, and subject to equivalent confidentiality protection.
Every third party we share data with is contractually bound to protect it and to use it only for the purpose we specify — never for their own marketing.
Data retention
We retain customer and transaction records for at least five (5) years after an account is closed or a relationship ends, in line with CBN and NDIC record-keeping requirements, and longer where required to resolve a dispute, satisfy legal, accounting or reporting obligations, or where a longer period is directed by a regulator or court. Call recordings and website analytics data are held for shorter, defined periods before secure deletion or anonymisation.
Keeping your data secure
We apply administrative, technical and physical safeguards appropriate to the sensitivity of your data, including encryption of data in transit and at rest, role-based access controls, transaction monitoring, firewalls, and regular security testing. Staff and agents are trained on data-handling obligations and bound by confidentiality undertakings. No system is completely immune to risk; if a breach is likely to affect your rights or freedoms, we will notify the NDPC and affected customers as required under the NDPA.
Your rights
Subject to applicable exceptions (for example, ongoing KYC/AML obligations), you have the right to:
Access
Request a copy of the personal data we hold about you.
Correction
Ask us to correct inaccurate or incomplete data.
Erasure
Request deletion of data we no longer have a lawful reason to keep.
Restriction
Ask us to limit how we use your data in specific circumstances.
Portability
Receive certain data in a structured, machine-readable format.
Object & withdraw consent
Opt out of marketing or withdraw consent where consent is our basis for processing.
To exercise any of these rights, contact our Data Protection Officer using the details in section 15. We will respond within the timeframe required by the NDPA, and may ask you to verify your identity first. If you are unsatisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC).
Cookies & tracking technologies
Our website and mobile app use cookies and similar technologies to keep you signed in, remember your preferences, understand how our digital channels are used, and measure the effectiveness of communications. You can control cookies through your browser settings; disabling essential cookies may affect your ability to use online and mobile banking.
Third-party links
Our website, app or USSD menu may link to third-party services, such as bill-payment partners or social media pages. We are not responsible for the privacy practices of those third parties, and we encourage you to review their own privacy notices before sharing information with them.
Children's privacy
Our products are intended for individuals who meet the minimum age and legal capacity to contract under Nigerian law. We do not knowingly open accounts for or market to children outside of a permitted minor/guardian savings product operated with a parent or legal guardian as the account controller.
Cross-border data transfers
Personal data is primarily stored and processed within Nigeria. Where a service provider processes data outside Nigeria (for example, cloud infrastructure or fraud-screening tools), we ensure an adequate level of protection is in place, through contractual safeguards recognised under the NDPA, before any such transfer occurs.
Changes to this notice
We may update this notice from time to time to reflect changes in our practices, products or the law. The "Effective date" at the top of this page shows when it was last revised. Material changes will be communicated through our website, app or other appropriate channels before they take effect.
Contact & the Data Protection Officer
Questions, requests or complaints about this notice or how we handle your data can be directed to our Data Protection Officer:
Registered address
[Insert registered head-office address, Lagos, Nigeria]