Draft for internal review. This notice is a working template prepared for FSE Microfinance Bank Limited and has not yet been reviewed by Legal/Compliance or approved under the NDPA 2023. Confirm every bracketed detail and data practice against actual operations before publishing.
FSE Microfinance Bank
Data & Privacy Notice
FSE Microfinance Bank NDPA 2023 · CBN Compliant
Legal & Compliance

Data & Privacy Notice

How FSE Microfinance Bank Limited collects, uses, shares and protects your personal and financial information when you apply for, hold, or use our products.

Effective date  15 September 2026 Version  1.0 — Draft Governing law  Nigeria Data Protection Act, 2023

The short version

A plain-language summary. The clauses below are what actually governs — read them in full before relying on this page.

We collect what onboarding requires

Identity/KYC data (BVN, NIN, ID), contact details, financial and transaction records, and basic device data.

We use it to serve & protect you

Opening and running your account, processing transactions, meeting KYC/AML law, and stopping fraud.

We share only where necessary

With regulators (CBN, NDPC), credit bureaus, payment partners, and providers bound by contract — never sold for marketing.

You have real control

Access, correct, export, restrict or ask us to delete your data by writing to our Data Protection Officer.

01

Introduction

FSE Microfinance Bank Limited ("FSE", "the Bank", "we", "us") is licensed by the Central Bank of Nigeria (CBN) to provide microfinance banking services. This notice explains what personal data we collect from customers, prospective customers, agents, guarantors and website/app visitors (together, "you"), why we collect it, who we share it with, and the choices and rights available to you.

This notice applies to information collected through our branches, agent locations, USSD channel, mobile app, website, customer service lines, and any other channel we use to deliver our services. It should be read alongside your account terms and conditions and any product-specific disclosures.

02

Information we collect

The information we collect depends on your relationship with us — browsing our website, applying for a product, or holding an active account.

CategoryExamples
Identity & KYC dataFull name, date of birth, gender, passport photograph, signature, Bank Verification Number (BVN), National Identification Number (NIN), government-issued ID, utility bill or address verification.
Contact detailsPhone number, email address, residential and business address, next of kin and guarantor details.
Financial & account dataAccount and loan details, transaction history, balances, income and employment information, credit history and bureau reports.
Device & usage dataIP address, device identifiers, mobile network, app/USSD session logs, approximate location, log-in timestamps.
CommunicationsCall recordings and records from our contact centre, emails, chat and in-branch service requests, satisfaction survey responses.
Special categoriesBiometric data (photograph/fingerprint) only where required for identity verification under CBN KYC requirements.
03

How we collect it

We collect information directly from you — on account-opening and loan-application forms, in branch or through our agents, by phone, on our website and mobile app, and through USSD. We also receive information from third parties: credit bureaus (such as CRC Credit Bureau or FirstCentral), the Nigeria Inter-Bank Settlement System (NIBSS) for BVN validation, the National Identity Management Commission (NIMC) for NIN verification, guarantors and referees you nominate, and joint account holders. Where our website or app uses cookies or similar technology, this is described in section 10.

04

How we use your information

We use your personal data to:

  • Verify your identity and carry out Know-Your-Customer (KYC), anti-money-laundering (AML) and counter-terrorism-financing checks before and during your relationship with us.
  • Open, administer and service your account, loan or other product, including processing deposits, withdrawals, repayments and transfers.
  • Assess creditworthiness and affordability for loan and overdraft applications, including checks with licensed credit bureaus.
  • Detect, investigate and prevent fraud, financial crime and unauthorised access to your account.
  • Communicate with you about your account, respond to enquiries and complaints, and send statutory notices.
  • Improve our products, digital channels and customer service, including through call-quality monitoring.
  • Meet reporting obligations to the CBN, the Nigeria Deposit Insurance Corporation (NDIC), the Nigerian Financial Intelligence Unit (NFIU) and other regulators.
  • With your consent, tell you about products, offers or services that may interest you. You may opt out at any time — see section 9.
05

Legal basis for processing

Under the Nigeria Data Protection Act, 2023 (NDPA), we rely on one or more of the following bases to process your personal data:

  • Contract — processing necessary to open and operate your account or deliver a product you have requested.
  • Legal obligation — KYC/AML checks, tax reporting and regulatory returns required by the CBN, NDIC and NFIU.
  • Legitimate interest — fraud prevention, network and information security, and improving our services, balanced against your rights.
  • Consent — marketing communications and any optional data use, which you may withdraw at any time without affecting the underlying account relationship.
06

Sharing & disclosure

We do not sell your personal data. We disclose it only where necessary, including to:

  • Regulators and government bodies — the CBN, NDIC, NFIU and the Nigeria Data Protection Commission (NDPC).
  • Credit bureaus licensed by the CBN, for credit reporting and affordability checks.
  • Payment and settlement infrastructure providers, including NIBSS, card schemes and payment processors, to complete transactions.
  • Service providers who process data on our behalf under written confidentiality and data-processing agreements — for example, core banking, cloud hosting, SMS/email delivery and identity-verification vendors.
  • Guarantors, next of kin or joint account holders, to the extent relevant to a shared product.
  • Law enforcement or courts, where compelled by a valid legal order.
  • A successor entity, only in connection with a merger, acquisition or restructuring of the Bank, and subject to equivalent confidentiality protection.

Every third party we share data with is contractually bound to protect it and to use it only for the purpose we specify — never for their own marketing.

07

Data retention

We retain customer and transaction records for at least five (5) years after an account is closed or a relationship ends, in line with CBN and NDIC record-keeping requirements, and longer where required to resolve a dispute, satisfy legal, accounting or reporting obligations, or where a longer period is directed by a regulator or court. Call recordings and website analytics data are held for shorter, defined periods before secure deletion or anonymisation.

08

Keeping your data secure

We apply administrative, technical and physical safeguards appropriate to the sensitivity of your data, including encryption of data in transit and at rest, role-based access controls, transaction monitoring, firewalls, and regular security testing. Staff and agents are trained on data-handling obligations and bound by confidentiality undertakings. No system is completely immune to risk; if a breach is likely to affect your rights or freedoms, we will notify the NDPC and affected customers as required under the NDPA.

09

Your rights

Subject to applicable exceptions (for example, ongoing KYC/AML obligations), you have the right to:

Access

Request a copy of the personal data we hold about you.

Correction

Ask us to correct inaccurate or incomplete data.

Erasure

Request deletion of data we no longer have a lawful reason to keep.

Restriction

Ask us to limit how we use your data in specific circumstances.

Portability

Receive certain data in a structured, machine-readable format.

Object & withdraw consent

Opt out of marketing or withdraw consent where consent is our basis for processing.

To exercise any of these rights, contact our Data Protection Officer using the details in section 15. We will respond within the timeframe required by the NDPA, and may ask you to verify your identity first. If you are unsatisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC).

10

Cookies & tracking technologies

Our website and mobile app use cookies and similar technologies to keep you signed in, remember your preferences, understand how our digital channels are used, and measure the effectiveness of communications. You can control cookies through your browser settings; disabling essential cookies may affect your ability to use online and mobile banking.

11

Third-party links

Our website, app or USSD menu may link to third-party services, such as bill-payment partners or social media pages. We are not responsible for the privacy practices of those third parties, and we encourage you to review their own privacy notices before sharing information with them.

12

Children's privacy

Our products are intended for individuals who meet the minimum age and legal capacity to contract under Nigerian law. We do not knowingly open accounts for or market to children outside of a permitted minor/guardian savings product operated with a parent or legal guardian as the account controller.

13

Cross-border data transfers

Personal data is primarily stored and processed within Nigeria. Where a service provider processes data outside Nigeria (for example, cloud infrastructure or fraud-screening tools), we ensure an adequate level of protection is in place, through contractual safeguards recognised under the NDPA, before any such transfer occurs.

14

Changes to this notice

We may update this notice from time to time to reflect changes in our practices, products or the law. The "Effective date" at the top of this page shows when it was last revised. Material changes will be communicated through our website, app or other appropriate channels before they take effect.

15

Contact & the Data Protection Officer

Questions, requests or complaints about this notice or how we handle your data can be directed to our Data Protection Officer:

Data Protection Officer

FSE Microfinance Bank Limited

dpo@fsebank-nigeria.com

Customer service

info@fsebank-nigeria.com

[Insert customer-service phone line]

Registered address

[Insert registered head-office address, Lagos, Nigeria]