A banking error that should have been corrected quickly continued for months at NCBA Bank, resulting in the lender being ordered to pay a customer Ksh250,000 for mishandling his private financial information.
The case involved Brian Githaiga, who opened a business account at NCBA’s Lavington branch in May 2019. During the account opening process, two email addresses were entered into the bank’s records. One of the addresses, however, did not belong to Githaiga.
The incorrect email address became a serious problem because the bank used it to send account statements and other transaction information belonging to Githaiga.
This meant that a person who had no relationship with the account was able to receive information about his business finances.
The problem became known to the bank in July 2023 when Githaiga contacted NCBA and asked it to remove the incorrect email address from his account. He wanted the bank to use only the email address that belonged to him.
The unintended recipient also contacted the bank around the same period. She informed NCBA that she did not have an account with the lender and was receiving financial information that belonged to another person.
This gave the bank two clear warnings that its records were wrong and that confidential customer information was being sent to the wrong person.
NCBA told Githaiga on July 7, 2023 that the issue had been resolved.
However, the matter did not end there.Evidence presented in the case showed that the bank continued sending Githaiga’s account information to the incorrect email address.
On February 7, 2024, more than six months after the bank said it had fixed the problem, another communication containing his account details was sent to the third-party address.
The continued disclosure led Githaiga to seek the intervention of the Office of the Data Protection Commissioner.
His complaint was considered by Commissioner Immaculate Kassait, who found that NCBA had violated his rights under the Data Protection Act.
The Commissioner specifically found that the bank had failed to respect Githaiga’s right to erasure. The right allows individuals to seek the removal of personal information that should no longer be held or processed in certain circumstances.
NCBA was ordered to remove the incorrect email address from its records within 14 days. The bank was also directed to pay Githaiga Ksh250,000 as compensation for the violation of his data protection rights.
The case highlights the responsibility that financial institutions have when handling customer information. Banks routinely hold sensitive details, including account balances, transactions, business records and contact information.
Such information is expected to be handled carefully and only shared with the appropriate people.What makes the case significant is that NCBA had been given more than one warning about the problem. Both the customer and the person receiving the information had informed the bank that something was wrong.
The bank also told the customer that the issue had been corrected, yet the incorrect email remained active for months.The matter therefore goes beyond the initial mistake made when the account was opened. Errors can happen when customer information is entered into banking systems.
The bigger concern is how such an error is handled after it has been reported.
A bank receiving a complaint that confidential financial information is being sent to the wrong person is expected to investigate and correct the problem promptly. In this case, the regulator found that the necessary action was not taken effectively.
The Ksh250,000 compensation may not be a large amount compared with the operations of a major financial institution, but the decision sends a clear message to organisations that collect and process personal information.
Data protection is not simply an internal administrative matter. Customers have legal rights, and institutions can face consequences when those rights are ignored.
The decision also shows customers that they can seek help when their personal information is mishandled. A person who believes that an organisation has violated their data protection rights can raise the matter with the Office of the Data Protection Commissioner.
For banks and other institutions, the case is a reminder that correcting inaccurate customer records should not be delayed. Once an organisation is made aware that personal information is being sent to the wrong person, the issue requires immediate attention.
In Githaiga’s case, what started as an incorrect email address became a prolonged data privacy problem because the error was not properly resolved.
The regulator’s decision has now placed a financial cost on the bank and reinforced the need for financial institutions to take customer data protection seriously.


