Skip to content
FSE

Privacy Policy

How FSE Microfinance Bank Limited collects, uses, shares and protects your personal data.

Policy details

FSE Microfinance Bank Limited · In line with NDPA 2023

Effective date
Version
1.0
Last reviewed

01. Introduction

FSE Microfinance Bank Limited (FSE Bank) is a licensed microfinance bank offering digital banking services, including USSD banking, mobile app banking, and agent banking (cash-in/cash-out services). We are committed to protecting the privacy and personal data of everyone who uses our services.

This Policy is issued in line with the Nigeria Data Protection Act, 2023 (NDPA), the Nigeria Data Protection Regulation, and applicable Central Bank of Nigeria (CBN) guidelines on consumer protection and data privacy for financial institutions. It applies alongside, and does not replace, our Terms and Conditions and any account-opening agreement you have signed with us.

02. Scope of This Policy

This Policy applies to personal data we collect through:

  • Our mobile banking application(s) and USSD banking channel
  • Our website and any web-based banking portal
  • Account opening, KYC/BVN verification, and onboarding processes

03. Personal Data We Collect

We collect the following categories of personal data:

Categories of personal data we collect
CategoryWhat it includes
Identity and verification informationIncluding your Bank Verification Number (BVN), National Identification Number (NIN), full name, date of birth, address, phone number, and email address.
KYC imagesIncluding your selfie/photograph captured during onboarding and periodic KYC re-verification, and any identity documents you upload.
Phone contact informationWith your consent, we may access contacts stored on your device to facilitate certain services (e.g. referrals or fund transfers to your contacts).
Transaction informationDetails of deposits, withdrawals, transfers, loan applications, repayments, and other account activity.
Device and technical informationDevice identifiers, IP address, and geolocation data, used for identity verification, fraud prevention and regulatory compliance.
Information from third partiesWe may obtain information from NIBSS, NIMC, credit bureaus, and other licensed verification providers to confirm your identity and creditworthiness.
Customer support and communication dataInformation you provide when you contact us, raise a complaint, or respond to a survey.

We only collect what is necessary for the purposes described in this Policy.

04. How We Use Your Information

We use your personal data to:

  • Open, verify and manage your account, in compliance with KYC and anti-money-laundering (AML) requirements
  • Process transactions, transfers, cash-withdrawal and cash-token requests
  • Assess creditworthiness and manage loan applications and repayments
  • Detect, investigate and prevent fraud, money laundering and other financial crime
  • Provide customer support and respond to enquiries or complaints
  • Send transaction alerts, service notifications and, where you have consented, marketing communications
  • Improve our products, app performance and USSD service reliability
  • Comply with legal, regulatory and reporting obligations, including those of the CBN and NDPC (Nigeria Data Protection Commission)

05. Legal Basis for Processing

We process your personal data on one or more of the following legal bases recognised under the NDPA:

  • Performance of a contract — to open and operate your account and provide banking services you request
  • Legal obligation — to meet KYC, AML/CFT, tax and CBN regulatory reporting requirements
  • Legitimate interest — for fraud prevention, network and information security, and service improvement, balanced against your rights
  • Consent — for marketing communications, optional location-based features and any processing that is not otherwise required by law or contract

06. How We Share Your Information

We do not sell your personal data. We may share your information with:

  • Regulators and law enforcement, including the CBN, NDPC, NIBSS, EFCC and courts of competent jurisdiction, where it is legally required
  • Credit bureau, for credit assessment and reporting as permitted by law
  • Payment processors, switching companies and agent banking partners, solely to complete your transactions
  • Service providers who support our IT infrastructure, cloud hosting, SMS/USSD gateway and customer support, under confidentiality and data-processing agreements
  • Professional advisers (auditors, lawyers) where necessary for legal or audit purposes
  • A successor entity in the event of a merger, acquisition or restructuring of FSE Bank, subject to equivalent privacy protections

07. International Data Transfers

Where personal data is transferred outside Nigeria (for example, to a cloud service provider), we ensure the transfer is carried out in accordance with the NDPA’s cross-border transfer requirements, including verifying that the receiving country or organisation provides an adequate level of data protection, or by relying on appropriate safeguards such as standard contractual clauses.

08. Data Security

We implement technical and organisational measures designed to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Multi-factor authentication and PIN/biometric protection on our app and USSD channel
  • Access controls limiting staff access to personal data on a need-to-know basis
  • Regular security testing, monitoring and fraud-detection systems
  • Staff training on data protection and confidentiality obligations
  • Policies and procedures governing access to personal data
  • Regular review of our security measures and systems
  • Incident management and response procedures

No method of transmission or storage is completely secure. You also play a role in protecting your data: never share your PIN, password, OTP or USSD codes with anyone, including persons claiming to be from FSE Bank.

09. Data Retention

We retain personal data for as long as your account remains active, and thereafter for the period required to meet legal, regulatory, tax and audit obligations (generally at least five years after account closure, in line with CBN and AML/CFT record-keeping requirements). After the applicable retention period, we securely delete or anonymize your data.

10. Your Rights

Subject to the NDPA and applicable exceptions, you have the right to:

Be informed

Be informed about how your personal data is processed.

Access

Access a copy of the personal data we hold about you.

Correction

Request correction of inaccurate or incomplete data.

Deletion and restriction

Request deletion or restriction of processing, where applicable.

Object

Object to processing based on legitimate interest or for direct marketing.

Withdraw consent

Withdraw consent at any time, where processing is based on consent.

Portability

Request data portability, where technically feasible.

Complain

Lodge a complaint with the Nigeria Data Protection Commission (NDPC).

To exercise any of these rights, contact our Data Protection Officer using the details in Section 14.

11. Cookies and Similar Technologies

Our website and app may use cookies, SDKs and similar technologies to keep you signed in, remember your preferences, and understand how our digital channels are used. You can manage cookie preferences through your browser or device settings; disabling certain cookies may limit some features of our services.

12. USSD and Agent Banking Notice

USSD sessions are carried over your mobile network operator’s infrastructure, and menu selections and PIN entries are transmitted for the purpose of completing your request. Agents facilitating cash-in/cash-out and cash-token transactions on our behalf are contractually required to protect your information and may only use it to complete the transaction you have requested.

13. Information Relating to Minors

The Bank recognizes the importance of protecting the personal data of children and minors. Where our products or services involve the processing of personal data relating to a minor, the Bank will process such information in accordance with applicable data protection laws and regulatory requirements. Where required, the Bank may obtain appropriate consent or authorization from a parent, guardian or other legally authorized person before processing the minor’s personal data. We will take reasonable steps to ensure that information relating to minors is processed only for legitimate and appropriate purposes.

14. Data Protection Officer and Contact Details

If you have questions, requests or complaints about this Policy or how we handle your personal data, please contact:

Data Protection Officer

FSE Microfinance Bank Limited

Address

Purplac Mall Km 44, Lekki-Epe Expressway,
Oribanwa, Ibeju Lekki, Lagos.

You may also contact the Nigeria Data Protection Commission (NDPC) at www.ndpc.gov.ng if you believe your data protection rights have not been respected.

15. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal or regulatory requirements. We will notify you of material changes via the app, USSD notice, SMS, email or our website, and will indicate the “last reviewed” date at the top of this document. Continued use of our services after an update constitutes acceptance of the revised Policy.