Privacy Policy
1.0 Purpose of this Privacy Policy
This Privacy Policy (“Privacy Policy” or “Policy”) explains how Sterling Bank (“the Bank”, “we”, “us” or “our”) collects, uses, stores, shares, protects and otherwise processes personal data relating to customers, prospective customers, job applicants, vendors and other individuals who interact with us or use our products and services (“you” or “your”). This policy is established in compliance with the Nigeria Data Protection Act (NDPA), 2023, as well as other relevant data privacy laws and regulations.
This Policy also explains:
- the types of personal data we collect;
- how and why we use your personal data;
- who we may share your personal data with;
- how we protect your personal data; and
- the rights available to you under applicable data protection laws.
We process personal data in accordance with the Nigeria Data Protection Act, 2023 (“NDPA”), the General Application and Implementation Directive (NDP Act GAID) and other applicable data protection and privacy laws and regulations.
2.0 Definitions of Terms
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
Consent: your clear agreement allowing Sterling Bank to collect, use, or otherwise process your personal data for a specific purpose. Where processing is based on your consent, you may withdraw it at any time.
Data Controller: the organisation that decides why and how your personal data is collected, used, stored, shared, or otherwise processed. Under this Privacy Policy, Sterling Bank is the Data Controller.
Data Processor: an individual or organisation that processes personal data on behalf of Sterling Bank and in accordance with our instructions.
Data Protection Officer (DPO): the designated officer responsible for overseeing Sterling Bank's compliance with applicable data protection laws and serving as the primary contact for privacy-related enquiries, requests, and complaints.
Data Subject: any individual whose personal data is collected, used, stored, shared, or otherwise processed by Sterling Bank.
Lawful Basis: the legal reason that allows Sterling Bank to process your personal data. These include consent, performance of a contract, legal obligation, legitimate interests, vital interests, and public interest, as permitted by applicable law.
Legitimate Interest: a lawful basis that allows Sterling Bank to process personal data where it is necessary for a legitimate business purpose, provided your rights and freedoms are respected.
Nigeria Data Protection Act (NDPA): the law that governs how personal data is collected, used, stored, shared, and protected in Nigeria.
Nigeria Data Protection Commission (NDPC): the independent regulatory authority responsible for overseeing and enforcing compliance with data protection and privacy laws in Nigeria.
Personal Data: any information that identifies you or can be used to identify you, either on its own or together with other information. Examples include your name, contact details, identification number, photograph, or financial information.
Personal Data Breach: a security incident that results in personal data being lost, altered, accessed, disclosed, or destroyed without authorisation.
Processing: any activity carried out on personal data, including collecting, recording, storing, organising, using, sharing, updating, transferring, or deleting it.
Recipient: any individual, organisation, or public authority that receives your personal data from Sterling Bank where necessary and in accordance with applicable law.
Sensitive Personal Data: personal data that requires additional protection under applicable law because of its sensitive nature. This may include biometric information, health information, and other categories of personal data recognised by law as sensitive.
Third Party: any individual or organisation, other than you or Sterling Bank, that receives or processes your personal data in accordance with this Privacy Policy and applicable law.
3.0 Who We Are
Sterling Bank is a limited liability company incorporated under the laws of the Federal Republic of Nigeria, with its registered office at 20 Marina, Lagos Island, Lagos State, Nigeria.
We provide retail banking, business banking, corporate banking, digital banking, payment services, lending, investment, treasury, and other financial services.
This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal data when you:
- use our products and services;
- visit our branches, websites, or digital platforms;
- communicate with us; or
- otherwise, interact with the Bank.
4.0 How We Use Personal Data
At Sterling Bank, we collect and process personal data responsibly, fairly and lawfully, and only where we have a valid legal basis to do so.
We use personal data to:
- provide and manage our products and services;
- verify identity and carry out customer due diligence;
- process transactions and respond to inquiries;
- improve our services and customer experience;
- comply with legal and regulatory obligations; and
- protect the security and integrity of our systems, premises and operations.
We are committed to safeguarding your personal data and ensuring that it is processed in line with applicable data protection laws and industry standards.
4.1 Data Protection Principles
Sterling Bank processes personal data in accordance with the principles set out under the Nigeria Data Protection Act (NDPA). Accordingly, we are committed to ensuring that personal data is:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes;
- adequate, relevant and limited to what is necessary for the purposes for which it is processed;
- accurate and kept up to date where necessary;
- retained only for as long as necessary for the purposes for which it was collected or as required by law; and
- protected through appropriate technical and organisational measures to ensure its confidentiality, integrity, and availability.
5.0 Lawful Bases for Processing
The lawful basis for processing your personal data depends on the nature of the processing activity and your relationship with the Bank. We may process your personal data based on one of the six lawful bases:
- Consent: We may process your personal data where you have given clear, informed, and specific consent for one or more purposes to do so.
- Legitimate interest: We may process your personal data to fulfill the legitimate interests pursued by Sterling Bank.
- Legal Obligation: We may process your personal data to comply with a legal or regulatory requirement.
6.0 Individuals to Whom This Privacy Policy Is Addressed
This Privacy Policy applies to individuals whose personal data we process, including:
- Customers and prospective customers;
- Vendors, contractors and service providers;
- Individuals who contact our customer service or contact center;
- Visitors to our websites, web applications, and digital platforms; and
- Recipients of electronic or other communications that reference this privacy policy.
7.0 The Data That We Collect and How It Is Used
7.1 How We Collect and Use Your Data
We collect and process personal data to provide our products and services, manage our relationship with you, comply with legal and regulatory obligations, protect our customers and business operations, prevent fraud and financial crime, improve our services, and support our legitimate business activities.
The personal data we collect depends on your relationship with the Bank and the products, services, channels, and interactions you have with us. We may collect personal data directly from you, automatically through your use of our services, or from third parties where permitted by law. Examples of collection channels include:
- Account opening and onboarding processes.
- Our websites, mobile applications, and digital banking platforms.
- Emails, telephone calls, customer support interactions, and other communications.
- Cookies and similar technologies used across our digital channels.
- Social media and online interactions with the Bank.
- Third parties, including regulators, service providers, identity verification providers, payment processors, government agencies, business partners, and other entities within our corporate group, where permitted by law.
We only collect personal data that is reasonably necessary and proportionate for the purposes described in this Privacy Policy. We do not sell your personal data.
Where we process your personal data based on consent, you may withdraw your consent at any time using the channels identified in this Privacy Notice. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
Further information on the categories of personal data we process and the lawful basis for processing is set out below.
7.2 Categories of Personal Data We Process
Depending on your relationship with the Bank and the services you use, we may process the following categories of personal data.
a. Identification and Verification Information
Information used to identify and verify individuals and comply with customer due diligence, Know Your Customer (KYC), fraud prevention, and regulatory obligations.
Examples may include:
- Full name
- Date of birth
- Photograph
- Government-issued identifiers (including National Identification Number (NIN), Bank Verification Number (BVN), tax identification number, passport details, or driver’s license details)
- Copies of identification documents are required
b. Contact information
Information used to communicate with you and manage our relationship with you. Examples may include:
- Residential address
- Email address
- Telephone number
- Customer communication preferences
c. Employment and Professional Information
Where relevant to recruitment, employment, service delivery, vendor onboarding, or regulatory obligations, we may process:
- Employer details
- Job title
- Employment history
- Professional qualifications
- Certifications
- References
d. Financial and Transaction Information
Information necessary to provide financial services and manage customer relationships. Examples may include:
- Account information
- Payment and transaction records
- Card and payment information
- Credit or lending information
- Source of funds information
- Financial risk information
Where payment card information is processed, appropriate security controls and applicable industry standards are applied.
e. Sensitive Personal Data
Where required or permitted by applicable law, we may process limited categories of sensitive personal data with relevant safeguards. Depending on the nature of your interaction with the Bank and the relevant processing activity, this may include:
- biometric information used for identity verification or access control;
- facial images collected through identity verification processes or CCTV systems;
- other categories of sensitive personal data where required or permitted by applicable law.
f. Authentication and Security Information
To secure access to our systems and services, we may process authentication and security information, including:
- Username
- Authentication credentials
- Multi-factor authentication data
- Device verification information
- Security logs
g. Technical and Device Information
When you use our websites, applications, or digital services, we may collect information such as:
- IP address
- Browser type
- Operating system
- Device identifiers
- Access dates and times
- Session information
- Device and network information
h. Location Information
Where enabled through your device settings or otherwise permitted by law, we may process location information to:
- Support service delivery
- Enhance security controls
- Prevent fraud
- Improve user experience
You may manage location permissions through your device settings.
i. Usage, Analytics, and Digital Interaction Information
We may collect information relating to how you interact with our websites, applications, products, and services. This may include:
- Browsing activity
- Product usage patterns
- Customer preferences
- Interaction history
- Analytics information generated through cookies and similar technologies
Additional information regarding cookies and tracking technologies is provided in our Cookie Notice.
7.3 Profiling and Automated Decision-Making
We may use analytics, monitoring tools, and automated processes to support service delivery, improve customer experience, strengthen security controls, prevent fraud, meet regulatory obligations, and improve our products and services.
This may involve evaluating information such as transaction activity, service usage, device information, and interaction history. Where profiling or automated processing significantly affects you, we will implement appropriate safeguards in accordance with applicable law. Such safeguards may include:
- Providing additional information about the processing
- Enabling review by authorised personnel where appropriate
- Allowing you to exercise applicable rights in relation to such processing
Profiling may occur in the following contexts:
- Analysis of transaction history, account activity, and product usage to understand your banking needs and preferences;
- Credit risk assessment and evaluation of applications for certain products and services;
- Monitoring of account activity and transaction patterns to detect suspicious or potentially fraudulent activity; and
- Analysis of customer trends and service usage patterns to improve our products, services, and business operations.
We may carry out profiling activities for business and service delivery purposes, including to personalise and improve your digital experience, recommend products and services that may be relevant to you, provide tailored marketing communications and promotional offers, improve customer engagement and service delivery, support fraud detection, transaction monitoring, and security measures, support credit assessment, lending decisions, and risk management activities; assess operational performance and customer trends, and support internal reporting, analytics, and business planning activities.
In certain circumstances, we may use automated processes to support decisions relating to fraud prevention, transaction monitoring, service optimization, security authentication, credit assessment, risk management, or regulatory compliance. Where legally required, or where such processing may significantly affect you, we will implement appropriate safeguards, including providing you with information about the processing and, where applicable, the ability to request human review or object to such processing. Where required under applicable law, including the Nigeria Data Protection Act (NDPA), we will obtain your explicit consent before carrying out profiling or analytics activities that are not strictly necessary for providing our services, safeguarding your personal data or otherwise permitted by law.
Consequences of profiling activities may include identification of potentially fraudulent, unusual, or high-risk activity, which may result in additional monitoring, temporary restrictions, security reviews, or requests for further information to verify transactions or account activity, enhanced fraud prevention measures, including additional verification checks where unusual or potentially suspicious activity is detected, assessment of eligibility for certain financial products, services, or credit facilities, and the possibility that certain offers or services may not be made available to you where profiling indicates that they are unlikely to be relevant to your usage circumstances or preferences.
7.4 Cookies and Similar Technologies
We use cookies and similar technologies such as web beacons, tags, scripts, and pixels to enhance functionality, improve performance, analyze usage patterns, maintain security, and personalize your experience across our digital channels. Cookies are small data files stored on your device when you visit a website. We use cookies to:
- Operate and secure our digital services
- Remember user preferences
- Analyze service usage
- Improve functionality and performance
- Support customer experience and service optimization
Further information about our use of cookies is available in our Cookie Policy.
7.5 Information from Social Media and Online Platforms
We may collect information from social media platforms or online accounts where you interact with us, or from which you choose to share such information with us.
7.6 Other Information We Process
Other categories of personal data we may process and the lawful bases for processing are highlighted below:
| Data Subjects |
Personal Data Processed |
Business/Commercial Purpose for Processing |
Lawful Basis for Processing |
|---|---|---|---|
| Customers | Name, BVN, address, email, phone number, passport photograph, date of birth, employer’s details, Employment details, next of kin details, Means of Identification, Email, Payment Details/bank Details, Source of funds, Medical History/Medical report/health status, nationality, Location, Asset details, Vehicle details | To provide our tailored products and services. To provide support services. | For the performance of a contract |
| Customers | Name, BVN, address, email, phone number, passport photograph, date of birth, employer’s details, Employment details, next of kin details, Means of Identification, Email, Payment Details/bank Details, Source of funds, Medical History/Medical report/health status, nationality, Location, Asset details, Vehicle details | To fulfill our KYC obligations prior to you opening an account with us | Legal obligation |
| Customers | Name, BVN, address, email, phone number, passport photograph, date of birth, employer’s details, Employment details, next of kin details, Means of Identification, Email, Payment Details/bank Details, Source of funds, Medical History/Medical report/health status, nationality, Location, Asset details, Vehicle details | To complete asset validation | For the performance of a Contract To comply with legal and regulatory obligations. |
| Customers | Name, BVN, address, email, phone number, passport photograph, date of birth, employer’s details, Employment details, next of kin details, Means of Identification, Email, Payment Details/bank Details, Source of funds, Medical History/Medical report/health status, nationality, Location, Asset details, Vehicle details | For marketing purposes | Consent |
| Customers | Name, BVN, address, email, phone number, passport photograph, date of birth, employer’s details, Employment details, next of kin details, Means of Identification, Email, Payment Details/bank Details, Source of funds, Medical History/Medical report/health status, nationality, Location, Asset details, Vehicle details | Regulatory reporting to government and tax authorities | Legal Obligation |
| Cardholders | PAN, CVV etc. | Processing card transactions (credit/debit cards). To comply with applicable legal, regulatory, and industry requirements relating to payment card processing. | For the performance of a Contract Legal Obligation |
| Website Visitors | Name, phone number, email, country, address, product/selection, content | To respond to inquiries made via web forms and fulfill service requests | Necessary step before entering a contract. |
| Website Visitors | Session ID, cookies, IP address, browser information, Location, Device Type | To optimize website performance, analytics, marketing, and personalization | Consent |
| Voice Data Subjects | Call Audio | Quality assurance and record maintenance. | Legitimate interest |
8.0 Your Rights
You have certain rights that you may exercise regarding your personal data. These rights may include:
- Right to be Informed: You have the right to receive clear and transparent information about how we collect, use, store, disclose and otherwise process your personal data.
- Right of Access: request confirmation of whether we process your personal data and obtain access to information about such processing. You may request details such as what personal data we hold about you, the purposes of the processing, the categories of personal data concerned, the recipients of your personal data or who it will be disclosed to, how long we intend to store your personal data for, and the source of the data if we did not collect the data directly from you.
- Right to Rectification: request correction of inaccurate or incomplete personal data.
- Right to Data Portability: request a copy of certain personal data in a structured, commonly used, and machine-readable format, where applicable.
- Right to Erasure: requests to delete your personal data were permitted by law.
- Right to Restrict Processing: request that we limit how we process your personal data in certain circumstances.
- Right to Object: object to certain processing activities, including processing based on legitimate interests and direct marketing.
- Right to Withdraw Consent: withdraw consent at any time where consent is relied upon as the lawful basis for processing.
- Rights Relating to Automated Decision-Making: where applicable, request information about decisions made solely through automated processing and request review where permitted by law.
- Right to Lodge a Complaint: submit a complaint to the Bank and/or the Nigeria Data Protection Commission (NDPC).
Please note that some rights are not absolute and may be limited where processing is necessary to comply with legal or regulatory obligations, prevent fraud, maintain security, exercise legal claims, or fulfill contractual obligations.
9.0 Sharing and Disclosing Your Personal Data
Sterling Bank may share or disclose your personal data where necessary to provide our products and services, perform our contractual obligations, comply with legal and regulatory requirements, prevent or detect fraud and financial crime, protect our legitimate interests, or where you have provided your consent where required by applicable law.
We may share your personal data with authorised third parties, including regulatory authorities, service providers, payment partners, professional advisers, and other entities within the Sterling Financial Holdings Group, only to the extent necessary for the purposes described in this Privacy Policy and in accordance with applicable data protection laws.
Where third parties process personal data on our behalf, we require them to process such data only in accordance with our instructions and to implement appropriate technical and organisational measures to protect your personal data and comply with applicable data protection laws.
9.1 Law Enforcement
Under certain circumstances, we may be required to disclose your Personal Data if required by Law or in response to valid requests from public authorities (e.g., a court or a government agency).
9.2 Our Entities
We may share the information about you and your dealings with us, to the extent permitted by law, with our entities, including:
- Sterling Financial Holdings Company
- Alternative Bank Limited
- SterlingFi Wealth Management Limited
Such sharing may occur for operational, administrative, risk management, compliance, customer service, reporting, audit, fraud prevention, business continuity, and other legitimate business purposes.
9.3 Third Party Services
We may use third-party services on our website or applications or in the course of providing services to you. These services may collect and process personal information on our behalf. We ensure that these third-party services are reputable and comply with applicable data protection laws.
- Regulatory Authorities
- Credit Bureaus
- Identity Verification Service Providers
- Payment Processors and Payment Schemes
- Cloud Service Providers
- Technology Service Providers
- Collection and Recovery Agents (where applicable)
10.0 Protecting and Safeguarding Your Information
We take your privacy seriously and take every reasonable measure and precaution to protect and secure your personal data. Sterling Bank stores your data in secure databases in our data centers (on-premises and cloud) protected by firewalls and intrusion detection devices. We work hard to protect you and your information from unauthorised access, alteration, disclosure, or destruction and have implemented security controls at several layers of our IT infrastructure, including but not limited to network security, encryption, restricted access, firewalls, anti-virus/malware, and other forms of security to ensure that your data is protected.
We require all parties, including our staff and third parties processing data on our behalf, to comply with relevant policies and guidelines to ensure the confidentiality and protection of information in use, in storage, and in transit. Our security controls and processes are regularly updated to meet industry standards.
11.0 Children or Minors
The Bank’s products and services are generally intended for individuals aged 18 years and above. However, in certain circumstances, we may process personal data relating to children in connection with specific products or services, where such data is provided by a parent, guardian, authorised representative, or otherwise processed in accordance with applicable law.
Where we process personal data relating to children, we will implement appropriate safeguards and obtain parental or guardian consent or authorisation where required by applicable law.
If a parent or guardian believes that a child’s personal data has been provided to us in error or wishes to make inquiries regarding the processing of a child’s personal data, please get in touch with us by sending an email to the Data Protection Officer at dpo@sterling.ng.
12.0 Retention of Data and Disposal
Sterling Bank retains personal data only for as long as necessary to fulfill the purposes for which it was collected, including providing products and services, complying with legal and regulatory obligations, resolving disputes, establishing or defending legal claims, and meeting legitimate business requirements.
Retention periods are determined based on the nature of the personal data, the purpose of processing, applicable legal and regulatory requirements, and operational needs. Where personal data is no longer required, it will be securely deleted, destroyed, anonymized, or de-identified in accordance with the Bank’s retention practices.
Please note that where personal data has been deleted, anonymized, or is no longer retained in accordance with applicable retention requirements, this may affect the Bank’s ability to fulfill certain Data Subject Access Requests (DSARs).
14.0 Links to Other Websites
Our website may contain links to other sites that we do not operate. When you click on such links, you will be directed to that third party's site.
We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
15.0 Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and indicate the effective date at the top of the revised Privacy Policy.
Where required by applicable law, or where changes materially affect how we handle your personal data, we will provide additional notice before such changes take effect. This may be done via email, a prominent notice on our website, or other appropriate communication channels. We encourage you to review this Privacy Policy periodically to stay informed of any updates.
16.0 Account Deletion
You can delete your account from within the app or you can send an email to hello@snapcash.ng.
If you would like to delete your SnapCash account and associated personal data by email, please send an email to hello@snapcash.ng with the subject line “Account Deletion Request”.
Please note that certain information may be retained where required to satisfy legal, regulatory, internal compliance, audit, dispute resolution or fraud prevention obligations.
Contact Us
If you have any questions about this Privacy Policy, how we process your personal data, or if you wish to exercise any of your rights under applicable data protection laws, please contact our Data Protection Officer using the contact information provided in this section.
We may ask you to verify your identity before acting on your request to help protect your personal data and prevent unauthorised access.
We will respond to your request within thirty (30) days of receiving it. Where we are unable to meet this timeframe, we will notify you and provide an update on the expected response date.
If you have concerns or wish to make a complaint regarding our processing of your personal data, you may contact our Data Protection Officer using the contact details below. If you are dissatisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) in accordance with applicable law.
Our registered office is at 20 Marina, Lagos Island, Lagos State.
Our designated Data Protection Officer can be reached by email at dpo@sterling.ng.