NDPC launches investigation into alleged data breach involving Remita

The Nigeria Data Protection Commission (NDPC) has officially commenced a full-scale investigation into an alleged data breach involving prominent financial service providers, Remita Payment Services Ltd. and Sterling Bank.
In a press statement released on Sunday, the Commission confirmed that a formal notice of investigation was served to the involved parties on April 1, 2026.
According to the NDPC, several entities and individuals have already begun providing information to assist in determining the circumstances surrounding the incident.
The NDPC, led by National Commissioner and CEO Dr. Vincent Olatunji stated that the primary objective is to safeguard data subjects through the enforcement of appropriate technical and organizational measures.
The investigation will specifically scrutinize the alleged categories of personal data compromised and also the nature and scale of the alleged breach.
Dr. Olatunji further issued a directive to examine all organizations utilizing digital payment systems that fail to implement the security standards mandated by the Nigeria Data Protection Act, 2023 (NDP Act).
"Organizations that employ digital payment systems without putting in place appropriate technical and organizational measures... will also be examined as part of a wider effort to ensure the integrity of the ecosystem," the statement read.
The NDPC's move underscores its commitment to the NDP Act, 2023, which grants the Commission powers to penalize organizations found negligent in their data handling duties.
While the investigation is ongoing, the outcome could have significant implications for the operational standards of fintech firms and commercial banks across the country.
Neither Remita nor Sterling Bank has issued a public rebuttal as at the time of this report.
