Data Protection Policy

Version 1.0 · July 2025

This Data Protection Policy outlines how DASH Microfinance Bank Limited (“the Bank”) complies with the Nigerian Data Protection Regulation (NDPR), Nigerian Data Protection Act (NDPA), GDPR, and other applicable data protection laws.

1. Definitions

This Policy defines key terms such as Personal Data, Data Subject, Processing, Consent, Data Controller, Data Protection Officer (DPO), and Data Protection Laws as applicable under NDPR, NDPA, and GDPR.

2. Introduction

  • The Bank takes data protection obligations seriously.
  • This Policy governs how personal data of customers, employees, applicants, and users is processed.
  • All processing is carried out in line with Data Protection Laws.

3. Scope

This Policy applies to all personal data processed by the Bank, regardless of storage location or format. All staff, contractors, and third parties processing data on behalf of the Bank must comply.

4. Personal Data Protection Principles

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality

5. Consent

Where no other legal basis exists, the Bank obtains explicit and informed consent before processing personal data. Consent may be withdrawn at any time.

6. Data Collection

The Bank collects personal data via physical and electronic channels including websites, mobile applications, emails, forms, and communications necessary for regulatory compliance and service delivery.

7. Lawful Basis for Processing

  • Consent of the data subject
  • Contractual necessity
  • Legal obligation
  • Vital interests
  • Public interest or official authority

8. Data Subject Rights

  • Right to access and rectification
  • Right to restrict or object to processing
  • Right to withdraw consent
  • Right to lodge complaints with regulators
  • Right not to be subject to automated decision-making

9. Accountability & Governance

The Bank appoints a Data Protection Officer and implements organizational, technical, and administrative controls to ensure compliance with data protection laws. For any data protection inquiries, you may contact our Data Protection Officer (DPO) at compliance@dash-mfb.com.

10. Data Security

We employ encryption, access controls, pseudonymization, audits, and staff training to protect personal data from unauthorized access, loss, or misuse.

11. Third-Party Processors

All third-party processors must be approved, contractually bound, and compliant with applicable data protection laws.

12. Data Breach Management

The Bank maintains procedures for identifying, reporting, investigating, and remediating personal data breaches within legally required timelines.

13. International Data Transfers

Personal data may only be transferred outside Nigeria in compliance with NDPR, NDPA, and approvals from relevant authorities.

14. Policy Review

This Policy is reviewed every two years or as required by regulatory changes.