1. Introduction & Scope

This Privacy Policy explains how Nri Microfinance Bank Nigeria Limited ("we", "us", "our") collects, uses, stores, and protects personal data when you use our services. This policy is issued in compliance with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR). It applies to all personal data processed by Nri Microfinance Bank Nigeria Limited, whether collected online or offline.

Effective Date: 2007-12-12. We are committed to protecting your privacy and ensuring that your personal data is handled responsibly and in accordance with applicable data protection legislation.

2. Data We Collect

Nri Microfinance Bank Nigeria Limited collects the following categories of personal data in the course of providing our services. Data may be collected directly from you (e.g. through forms, account registration, or correspondence) or automatically (e.g. through cookies, server logs, and similar technologies).

Identity & Contact Information:

  • Full Name: first name, last name, middle name, title.
  • Contact Details: email address, phone number, postal address.
  • Government-Issued Identifiers: NIN, passport number, driver's licence number, voter's card number.
  • Account Credentials: username, hashed password, security questions.

Financial Information:

  • Payment Information: bank account number, billing address.
  • Financial Records: transaction history, account balance, income details.
  • Bank Verification Number (BVN).

Technical & Behavioral Data: Location data — GPS coordinates, city, country, time zone.

Sensitive / Special-Category Data:

  • Biometric Data: fingerprints, facial recognition data, voiceprints.
  • Ethnic Origin & Religious Beliefs: ethnic origin, religious affiliation, political opinions.

Children's Data: Child identity information — child's name, date of birth, school name, parent/guardian contact.

We only collect personal data that is adequate, relevant, and limited to what is necessary for the purposes described in this policy, in accordance with the NDPA 2023.

3. Legal Basis for Processing

Nri Microfinance Bank Nigeria Limited processes personal data under one or more of the following lawful bases as prescribed by the NDPA 2023:

  • Consent — where you have given clear, informed, and voluntary consent for specific processing activities (NDPA Section 25).
  • Contract — where processing is necessary for the performance of a contract to which you are a party, or to take pre-contractual steps at your request (NDPA Section 25).
  • Legal Obligation — where processing is required for compliance with a legal obligation under Nigerian law.
  • Legitimate Interest — where processing is necessary for our legitimate interests (such as fraud prevention and network security), provided those interests are not overridden by your rights and freedoms (NDPA Section 25).

We will always inform you of the specific legal basis applicable to each processing activity at the time of data collection.

4. How We Use Your Data

  • Service Delivery — to provide, maintain, and improve the services you have requested from us.
  • Legal Compliance — to meet our obligations under Nigerian law, including the NDPA 2023.
  • Fraud Prevention — to detect, prevent, and respond to fraud, security threats, and abuse.
  • Analytics — to analyse usage patterns and improve user experience.

We will not process your personal data for purposes incompatible with those stated above without providing you with prior notice and, where required by the NDPA, obtaining your consent.

5. Data Sharing & Disclosure

Nri Microfinance Bank Nigeria Limited does not sell personal data under any circumstances. We do not currently share your personal data with third-party processors. Should this change, we will update this policy and, where required, obtain your consent before any sharing takes place. We may also disclose personal data where required by law, regulation, or valid legal process, including requests from Nigerian regulatory and law enforcement authorities.

6. Your Rights as a Data Subject

Under the NDPA 2023, you are entitled to the following rights regarding your personal data:

  • Right of Access — confirm whether we process your personal data and obtain a copy of it (Section 34(1)(a)–(b)).
  • Right to Rectification — request correction of inaccurate or incomplete personal data (Section 34(1)(c)).
  • Right to Erasure — request deletion of your personal data where there is no compelling legal reason for continued processing (Section 34(1)(d), 34(2)).
  • Right to Restrict Processing — request that we limit processing in certain circumstances (Section 34(1)(e)).
  • Right to Withdraw Consent — where processing is based on consent, withdraw it at any time (Section 35).
  • Right to Object — object to processing based on legitimate interest or carried out for direct marketing (Section 36).
  • Right Not to Be Subject to Automated Decisions — including profiling that produces legal or similarly significant effects (Section 37).
  • Right to Data Portability — receive your personal data in a structured, commonly used, machine-readable format (Section 38).

To exercise any of these rights, please contact us at nmfb@nrimfbltd.com. We will respond within 30 days (extendable in complex cases per NDPC GAID 2025). If you are unsatisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) under NDPA Section 46(1).

7. Data Security Measures

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
  • Access controls and least-privilege principles for all systems handling personal data.
  • Regular security assessments, penetration testing, and vulnerability scanning.
  • Staff training on data protection obligations and information security best practices.
  • Incident response procedures aligned with NDPA breach notification requirements (72-hour notification to NDPC).

While we employ industry-standard safeguards, no method of electronic transmission or storage is entirely secure. If you become aware of any security incident affecting your data, please contact us immediately.

8. Contact Information

  • Organization: Nri Microfinance Bank Nigeria Limited
  • Email: nmfb@nrimfbltd.com
  • Address: Peter Umeadi Way, Eke Market Square, Nri, Anaocha LGA, Anambra State
  • Data Protection Officer: Ezema Henry
  • DPO Email: ezema.p@nrimfbltd.com

You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data protection rights have been infringed.

Nigeria Data Protection Commission — Website: ndpc.gov.ng   Email: info@ndpc.gov.ng

9. Data Retention Schedule

Nri Microfinance Bank Nigeria Limited retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable Nigerian law, based on: the nature and sensitivity of the data; the purposes for which it is processed; legal, regulatory and contractual obligations; and legitimate business needs such as audits, dispute resolution and regulatory examinations.

  • Account data: retained for the duration of your relationship with us, plus three (3) years.
  • Communication records: retained for two (2) years from the date of correspondence.
  • Analytics and usage data: retained in identifiable form for twelve (12) months, then aggregated or anonymised.

When personal data is no longer required, it is securely deleted or irreversibly anonymised in accordance with our internal data retention and disposal policy.


Want your account and personal data deleted? Use our Account Deletion Request page.