Loan Apps And Privacy: What Happens To Nigerians’ Personal Data After They Borrow?

By Opeyemi Adelakun

The growing use of digital lending platforms in Nigeria has changed the way millions of consumers access short-term credit, with loan applications increasingly completed through mobile phones rather than conventional banking channels.

For borrowers, the process usually involves submitting personal information required for identification, credit assessment and disbursement.

But once the loan is approved and subsequently repaid, the information supplied during the application does not necessarily disappear from the lender’s systems.

The continued retention and processing of such information are governed by data-protection and consumer-protection rules, including the Nigeria Data Protection Act 2023 and regulations governing digital lenders.

The Federal Competition and Consumer Protection Commission (FCCPC), which regulates digital lending alongside other relevant agencies, has identified data privacy violations, harassment and abusive recovery practices among the issues that have required regulatory intervention in the sector.

What information do loan apps collect?

Digital lending applications typically require information that enables the lender to establish the identity of a borrower and assess the person’s ability to repay.

Depending on the lender, this may include a borrower’s name, telephone number, date of birth, identification details, bank or payment information, employment or income details and information provided during the application process.

Some applications may also request access to information stored on a mobile device.

The extent of information that a digital lender can lawfully collect or access is, however, subject to data-protection requirements.

The FCCPC has previously taken action over digital lending applications accessing sensitive information such as contacts, photographs, videos, precise location data and call logs.

In 2023, the Commission welcomed Google’s policy restricting digital lending applications capable of accessing such information from its Play Store.

The FCCPC said such access could be intrusive and could affect the privacy rights of third parties whose information was stored on borrowers’ devices but who had no relationship with the lender.

The Commission has also warned about illegal digital lenders that use alternative application-installation methods, including APK files, to circumvent regulatory controls.

In a 2023 update, the FCCPC said its investigations had found cases where unregistered lenders accessed and downloaded consumers’ private information through such channels.

What happens after the loan is repaid?

Repayment of a loan does not automatically mean that all information associated with the transaction must immediately be deleted.

Financial institutions and other regulated businesses may have legitimate reasons to retain certain records, including compliance, accounting, auditing, dispute resolution and other legal or regulatory purposes.

However, continued retention and processing must have a lawful basis.

The Nigeria Data Protection Act 2023 establishes principles governing the collection and processing of personal data and provides rights to individuals whose information is being processed.

The framework requires personal data to be processed lawfully and for specified purposes, while the amount of information collected should be adequate, relevant and necessary for those purposes.

Where personal data is no longer necessary for the purpose for which it was collected or processed, the law provides circumstances in which a data subject may request its erasure.

This means that repayment alone does not provide a simple answer to the question of whether a borrower’s information should remain on a lender’s database.

The relevant consideration is whether the lender still has a lawful reason to retain or process the particular information.

Can lenders share borrowers’ information?

Data supplied to a loan provider can sometimes be processed by other parties where there is a lawful basis and the arrangement complies with applicable data-protection requirements.

This can include service providers involved in operating digital lending platforms or supporting functions such as technology, payments, verification and other services.

The existence of a third-party service provider does not, however, remove the lender’s obligations concerning the protection and lawful processing of personal information.

The borrower should be informed through the lender’s privacy notice about relevant processing activities and, where applicable, disclosures or transfers of personal information.

The Nigeria Data Protection Act also provides safeguards around the processing and transfer of personal data.

The issue of phone contacts

Access to borrowers’ contact lists has been one of the most prominent privacy concerns associated with digital lending in Nigeria.

The issue became particularly significant because some consumers complained that people listed in their phones were contacted during debt-recovery processes.

The FCCPC has distinguished between a lender’s legitimate interest in recovering money owed and methods that infringe the rights of borrowers or unrelated third parties.

In its 2023 statement on Google’s policy, the Commission said digital lending applications capable of accessing contacts and other sensitive information raised privacy concerns involving people who had no relationship with the lending transaction.

Google subsequently restricted applications with such capabilities from its Play Store.

The policy did not eliminate all possible forms of data misuse, but it placed additional restrictions on how digital lending applications could access sensitive information through Android devices.

Nigeria’s regulatory framework

The regulatory environment for digital lenders has continued to develop.

The FCCPC issued the Digital, Electronic, Online or Non-Traditional Consumer Lending Regulations 2025, known as the DEON Regulations, to establish requirements for digital lending businesses.

The Commission said the regulations address issues including transparency, consumer protection, data privacy, responsible lending and debt-recovery practices.

The regulations apply to unsecured consumer lending conducted electronically, including lending through mobile applications and other digital platforms.

Under the framework, digital lenders are required to register with the FCCPC and meet specified consumer-protection and compliance requirements.

The Commission subsequently set January 5, 2026, as the deadline for full compliance with the regulations.

In January 2026, the FCCPC announced the commencement of phased enforcement measures against digital money-lending operators that had failed to regularise their status.

The Commission’s public register currently contains hundreds of approved digital lending companies and applications, allowing consumers to check the status of operators before obtaining loans.

What rights do borrowers have?

The Nigeria Data Protection Act provides data subjects with several rights concerning their personal information.

These include rights relating to access, correction, objection to certain processing, restriction of processing, data portability and erasure in applicable circumstances.

A borrower who wants to know what information a lender holds can therefore make a request to the organisation concerned.

Such a request can also seek information about how the data is being processed and the purpose for which it is being retained.

The existence of a right to erasure does not mean that every request must result in immediate deletion.

Where an organisation has a lawful reason to retain particular information, that obligation or right may take precedence over a request for deletion.

The specific circumstances therefore matter.

What regulators say consumers should do

The FCCPC advises consumers to verify digital lenders against its public register before using their services.

The Commission also advises consumers to read loan agreements carefully, understand interest rates, fees and repayment obligations, and pay attention to how their personal information will be used.

Its current guidance states that consumers should ensure that they consent to data usage and report harassment, privacy breaches or unfair treatment through the Commission’s complaint channels.

The FCCPC has also warned consumers against unregistered digital lenders and encouraged them to use approved platforms.

Enforcement over data and recovery practices

The regulatory intervention in the sector followed years of complaints involving digital lending practices.

According to the FCCPC, complaints between 2021 and 2023 included public shaming, defamation, intimidation and privacy breaches by some online lenders.

When the FCCPC introduced the DEON Regulations in 2025, its Executive Vice Chairman and Chief Executive Officer, Tunji Bello, said the rules were intended to address such practices.

“For too long, Nigerians have endured harassment, data breaches, and unethical practices by unregulated digital lenders,” Bello said.

He added that the regulations provided “legal tools to hold violators accountable and promote responsible digital finance.”

The FCCPC said the regulations could attract sanctions for non-compliant operators, including administrative penalties and other enforcement measures.

What borrowers should do after repayment

For borrowers who have completed repayment, the first step in determining what happens to their information is to examine the lender’s privacy policy and data-processing terms.

A former borrower can also contact the lender to request information about the personal data held on them, the purpose for which it is being processed and, where applicable, the period for which it will be retained.

Where information is inaccurate, the borrower can request correction.

Where the legal conditions for erasure are met, the borrower may also request deletion.

If a borrower believes a lender has unlawfully processed or disclosed personal information, the matter can be reported to the appropriate data-protection or consumer-protection authority.

The FCCPC has specifically advised consumers to report privacy violations and unlawful digital lending practices to the Commission.

The data trail behind digital credit

The expansion of digital lending means that borrowing now involves more than the transfer of money from a lender to a customer’s account.

The transaction generates a digital record containing information used to identify the borrower, assess the application, administer the loan and, where necessary, manage repayment.

Some of that information may continue to be retained after repayment where a lawful basis exists.

At the same time, Nigeria’s data-protection framework places limits on how personal information can be collected, processed, disclosed and retained.

For regulators, the challenge is to ensure that digital lending remains accessible while operators comply with consumer-protection and data-protection obligations.

For borrowers, the practical implication is that taking a digital loan involves both a financial transaction and the processing of personal information.

The loan may end when the outstanding balance is cleared, but the treatment of the borrower’s data thereafter remains subject to the legal and regulatory framework governing personal information in Nigeria.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *