NCBA Bank has been ordered to compensate a customer after his private financial information was repeatedly sent to a stranger, exposing serious concerns about how the bank handled his personal data.
Brian Githaiga opened a business account with NCBA in 2019. During the registration process, two email addresses were entered into the bank’s system, although one of them did not belong to him.
The mistake later became a major problem when NCBA continued sending Githaiga’s sensitive account statements and transaction information to the incorrect email address.
The unintended recipient eventually contacted the bank and informed it that the financial information being sent to her did not belong to her.
Githaiga also raised the issue with the bank and repeatedly asked that the incorrect email address be removed from his account.
He formally made the request in July 2023, expecting the matter to be resolved.
NCBA said it acted on the request on the same day. However, evidence presented later showed that the bank continued sending Githaiga’s private financial information to the stranger’s email address months after the complaint had been made.
The information was reportedly still being sent to the wrong recipient as late as February 2024.
This meant the problem continued despite both the customer and the unintended recipient alerting the bank to the mistake.
Githaiga eventually took the matter to the Office of the Data Protection Commissioner after his efforts to have the problem resolved through the bank failed.
The Commissioner reviewed the evidence and found NCBA responsible for violating Githaiga’s right to erasure under the Data Protection Act.
The bank was directed to remove the third-party email address from the customer’s account within fourteen days.
NCBA was also ordered to pay Githaiga Ksh250,000 in compensation for the breach of his personal data.
The decision highlights the responsibility that banks have when handling information belonging to their customers.
Financial institutions routinely hold highly private details, including account balances, transaction records, identification information and contact details.
Such information is not meant to be shared with people who have no right to access it. When a bank discovers that customer information is being sent to the wrong person, it is expected to take immediate steps to correct the mistake and prevent further disclosure.
In Githaiga’s case, the Commissioner found that NCBA’s explanation that the email address had been provided during the original registration and that the bank had acted promptly was not enough to explain what happened.
The continued transmission of the information showed that the problem had not been properly addressed despite the concerns raised.
The case also demonstrates the importance of the right to erasure under Kenya’s data protection framework. Customers have the right to ask organisations to correct or remove personal information when it is inaccurate or being handled improperly.
Banks, like other organisations that collect and process personal information, have a responsibility to ensure that customer records are accurate and securely managed.
Customers should not have to make repeated complaints before an obvious data error is corrected.
Once a problem is reported, the institution handling the information should investigate it and take appropriate action without unnecessary delays.
The ruling against NCBA also raises concerns about the systems used by financial institutions to manage customer records. Modern banking systems are designed to handle large amounts of sensitive information, but errors can still occur.
What matters is how quickly and effectively an institution responds when such an error is discovered.In this case, the wrong email address remained linked to Githaiga’s financial information for an extended period, despite warnings that it did not belong to him.
The continued disclosure of his account details ultimately led to intervention by the Data Protection Commissioner.
The Ksh250,000 compensation may be relatively small compared with the size of a major banking institution, but the decision sends a clear message to organisations that handle personal data.
Customers have rights over how their information is collected, stored and shared. Those rights cannot simply be overlooked when mistakes occur.
Githaiga’s case shows that customers have avenues available to them when they believe their personal information has been mishandled. The Data Protection Commissioner can investigate complaints and take action where an organisation is found to have failed in its obligations.
For NCBA, the ruling means the bank must not only compensate the customer but also address the data management failure that allowed the wrong email address to remain connected to his account.
The case serves as a reminder to banks and other institutions that protecting customer information is part of their responsibility. Personal financial details must be treated with care, and mistakes involving sensitive information must be corrected as soon as they are identified.
NCBA’s failure to stop the repeated disclosure of Githaiga’s information, despite being alerted to the problem, ultimately resulted in a financial penalty and an order to remove the incorrect email address.
The decision reinforces the principle that customers should have control over their private information and that institutions entrusted with such data must be held accountable when they fail to protect it.


