NCBA Bank is facing renewed scrutiny after the Office of the Data Protection Commissioner (ODPC) found the lender liable in cases involving the unauthorized handling and disclosure of customer information.
The findings have raised fresh concerns about data security in Kenya’s banking sector, where millions of customers rely on financial institutions to protect their personal and financial records.
NCBA, one of Kenya’s largest banks, grew into a major financial player after the 2019 merger between Commercial Bank of Africa and NIC Group. The lender has built a strong market presence through services such as vehicle financing, digital lending and retail banking.
Despite maintaining profitability and a significant role in the financial sector, the bank has recently faced increased scrutiny over governance, customer protection and operational controls.
The Data Protection Commissioner’s findings revealed cases where NCBA was found to have failed to adequately safeguard customer information. In one matter, the regulator determined that customer details were disclosed to third parties without proper authorization.
Another case involved the repeated transmission of customer transaction information to an incorrect email address, despite efforts to notify the bank and stop the error.
The incidents have placed the spotlight on the importance of strong data management systems, especially as banks continue expanding digital services and handling larger volumes of customer information.
For customers, confidentiality is a fundamental expectation when dealing with financial institutions. Banks are entrusted with sensitive details ranging from identity information to account records and transaction histories.
Any failure to protect such information can affect customer confidence and expose individuals to risks linked to fraud and misuse of personal data.
The data protection findings come at a time when NCBA has also faced scrutiny over other operational issues, including reported cases of fraud and customer complaints.
A notable case involved an employee accused of stealing more than Sh52 million from customer accounts, with questions later raised about internal monitoring systems and access controls.
The bank has maintained that such incidents involve isolated actions by individuals and has continued to state that it is strengthening its systems to enhance security and customer protection.
As Kenya’s financial sector becomes increasingly digital, regulators are placing greater emphasis on accountability, privacy and cybersecurity.
For NCBA, the challenge will be demonstrating that it can maintain customer trust while navigating growing competition and increased public scrutiny.
