Home News Serious breach exposes NCBA systemic failure to protect clients confidential financial records

Serious breach exposes NCBA systemic failure to protect clients confidential financial records

The bank has recently been on the spotlight for data breaches

by Guest Editor
0 comment


Financial giant NCBA Bank has been forced to pay a customer for repeatedly exposing his private financial details to a complete stranger. This is not a minor mistake that got fixed quickly. It is a clear failure by one of Kenya’s major banks to protect the information it holds on behalf of its clients.

Brian Githaiga opened a business account with NCBA in 2019. During the process, two email addresses somehow ended up in the system. One of them did not belong to him.


From that point on, NCBA kept sending his sensitive account statements and transaction details to the wrong person.

The stranger who received these emails contacted the bank and told them the information was not hers.

Githaiga himself repeatedly asked the bank to remove the incorrect email address. He made the request in July 2023.

The bank claimed it had acted on the same day. Yet evidence later showed that NCBA was still sending his private financial information to the stranger’s email as late as February 2024.

That means for months after both the customer and the unintended recipient had raised the alarm, NCBA continued the breach.

The bank had every chance to correct the error. It failed to do so. Only after Githaiga took the matter to the Office of the Data Protection Commissioner did the truth come out.

The Commissioner examined the evidence and found NCBA liable for violating the customer’s right to erasure under the Data Protection Act.


The bank was ordered to delete the third-party email from the account within fourteen days and to pay Githaiga two hundred and fifty thousand shillings in compensation.

This ruling exposes a serious weakness. Banks handle some of the most private information people have.

Account balances, transaction histories, and personal contact details are not public property.

When a bank allows that information to reach the wrong hands and then ignores clear requests to stop, it breaks the trust customers place in it.


NCBA’s defense that the email was part of the original registration and that it acted promptly did not hold up. The Commissioner looked at the facts and concluded the bank had either failed or refused to fix the problem properly.

Customers should not have to fight this hard to protect their own data. The law is clear. Banks do not own the personal information they collect.

They have a legal duty to keep it accurate, secure, and confidential. When they fail, the consequences should be real.

In this case, the Data Commissioner delivered those consequences. NCBA now has to pay for the damage caused by its negligence.

The episode also raises wider questions about how carefully Kenya’s banks manage customer records. Technical systems are supposed to prevent this kind of error. When an error does occur, banks are expected to correct it without delay.

NCBA did neither. It allowed a stranger to receive private financial statements for an extended period even after being told the details were wrong. That is not acceptable for any institution that claims to prioritise customer service and data security.

Githaiga’s case shows that ordinary people can hold banks to account. The Data Protection Commissioner exists for exactly this reason. Customers who discover their information is being mishandled have the right to complain and to demand compensation when the bank fails in its duties.

NCBA has now been held responsible. The compensation of two hundred and fifty thousand shillings may not seem large compared to the bank’s overall size, but it sends a message. Ignoring a customer’s right to control their own data carries a cost.

NCBA's breach brings to fore the undispuable truth that banks must treat personal information with greater care. They must act quickly when mistakes are pointed out. And they must accept that customers, not the bank, control their private details. NCBA’s failure in this matter stands as a clear example of what happens when that responsibility is ignored.

You may also like

You cannot copy content of this page