Important notice
Important notice. This Privacy Policy explains how Bethel Microfinance Bank Limited (“Bethel MFB”, “the Bank”, “we”, “us” or “our”) collects and processes personal data. It is a transparency notice and does not make consent the legal basis for every processing activity.
1. Introduction and Purpose
Bethel MFB conducts its business in a responsible manner and is committed to protecting the privacy, confidentiality, integrity and security of personal data entrusted to it.
This Privacy Policy explains what personal data we collect, how we collect it, why we use it, the lawful bases on which we process it, who we may share it with, how long we retain it, the safeguards we apply, and the rights available to data subjects.
This Policy is designed to support compliance with the Nigeria Data Protection Act 2023 (“NDP Act”), the Nigeria Data Protection Act – General Application and Implementation Directive (“NDP Act-GAID”), applicable directives and guidance of the Nigeria Data Protection Commission (“NDPC”), applicable Central Bank of Nigeria (“CBN”) requirements, and other laws and regulatory obligations relevant to a Nigerian microfinance bank.
2. Scope
This Policy applies to personal data processed by Bethel MFB in connection with its banking operations and related activities, including information relating to:
Where a specific product, service, campaign or digital feature has an additional privacy notice, that more specific notice should be read together with this Policy.
- Customers and prospective customers;
- Account holders, borrowers, guarantors, referees and beneficiaries;
- Website visitors and users of digital channels;
- Employees of corporate or business customers where their data is provided to us;
- Vendors, contractors, agents, professional advisers and business partners;
- Job applicants and other persons who communicate or interact with the bank; and
- Visitors to bank premises where visitor-management or CCTV systems are used.
3. Key Definitions
For this Policy:
applicable law, including biometric data used for unique identification and other sensitive categories recognised by the NDP Act.
restricting, deleting or otherwise handling personal data.
processing personal data. For the processing described in this Policy, Bethel MFB generally acts as data controller.
- “Personal data” means information relating to an identified or identifiable individual.
- “Sensitive personal data” includes categories of personal data that receive enhanced protection under
- “Processing” includes collecting, recording, organising, storing, using, sharing, transmitting, analysing,
- “Data subject” means the individual to whom personal data relates.
- “Data controller” means the person or organisation that determines the purposes and means of
4. Personal Data We May Collect
The categories of personal data we collect depend on your relationship with the Bank, the product or service involved, and applicable legal or regulatory requirements. They may include:
documents and identification numbers.
emergency contact details where relevant.
history, income information, source-of-funds information, beneficiary details and transaction instructions.
related identity-verification information where applicable.
collateral information, risk assessments and fraud-prevention indicators.
security logs, session information and other data generated when using our website or digital services.
communications with the Bank.
and lawfully collected.
deployed.
security process lawfully requires or uses such technology.
We seek to collect only personal data that is adequate, relevant and reasonably necessary for the stated purpose.
- Identity and KYC data: name, date of birth, nationality, photograph, signature, occupation, identification
- Contact data: residential or business address, email address, telephone number, next-of-kin or
- Financial and transaction data: account details, deposits, withdrawals, transfers, loan details, repayment
- Regulatory identity data: Bank Verification Number (BVN), National Identification Number (NIN) and
- Credit and risk data: affordability information, credit history, credit bureau data, guarantor information,
- Digital and technical data: IP address, device identifiers, browser information, login information,
- Communication data: customer-service records, complaints, correspondence, enquiries and other
- Location data: approximate or precise location information where it is necessary for a particular service
- Marketing and preference data: communication preferences, product interests and marketing choices.
- Physical-security data: CCTV images, visitor records or access records where such systems are
- Biometric data: fingerprints, facial images or similar biometric information only where a Bank service or
5. How We Collect Personal Data
We may collect personal data:
us or use a bank service;
product or service and lawfully provided;
involved in a transaction;
Where we obtain personal data from another source, we remain responsible for ensuring that our own processing has an appropriate lawful basis and is carried out in accordance with applicable data-protection requirements.
- Directly from you when you open an account, apply for a loan, complete a form, visit a branch, contact
- From authorised financial-sector and identity-verification platforms where permitted by law;
- From credit bureaus, fraud-prevention and risk-management sources;
- From employers, co-operatives, guarantors, referees, agents or business partners where relevant to a
- From payment processors, switches, settlement service providers and other financial institutions
- From government agencies, regulators, courts or lawful public sources where applicable; and
- Automatically through website logs, cookies and similar technologies when you use our online services.
6. Lawful Bases for Processing
Bethel MFB processes personal data only where there is an appropriate lawful basis. Depending on the activity, we may rely on one or more of the following:
Contract or Steps Before a Contract We process personal data where it is necessary to open and operate an account, assess an application, provide a loan or other banking service, process transactions, manage repayments, answer service requests or perform another agreement with you.
Legal and Regulatory Obligation We process personal data where necessary to comply with applicable banking, KYC, BVN/NIN, anti-money- laundering, counter-terrorist-financing, anti-fraud, tax, audit, court, regulatory-reporting or other legal obligations.
Legitimate Interests We may process personal data for legitimate business or security interests, such as preventing fraud, protecting customers and Bank assets, improving services, managing operational risk, maintaining network and information security, recovering debts, handling complaints and protecting legal rights, where those interests do not override the rights and freedoms of the data subject. Where required, the Bank should document an appropriate Legitimate Interest Assessment.
Consent Where applicable law requires consent, we will request it in clear and specific terms. Consent will not be assumed merely because you continue to use a service. Where processing is based on consent, you may withdraw that consent, and withdrawal will not affect the lawfulness of processing carried out before withdrawal.
Other Lawful Bases Where permitted by law, we may also process personal data to protect vital interests, carry out a task in the public interest, or rely on another lawful basis recognised by the NDP Act.
7. How We Use Personal Data
We may process personal data for the following purposes:
other unlawful activity;
obligations;
messages;
- To identify and verify customers and prospective customers;
- To open, maintain and administer accounts;
- To provide savings, deposits, loans, payments and other financial services;
- To assess creditworthiness, affordability and repayment capacity;
- To process, authorise, settle, reconcile and monitor transactions;
- To prevent, detect, investigate and respond to fraud, cybercrime, identity theft, money laundering and
- To comply with KYC, AML/CFT, sanctions-screening, regulatory-reporting, audit, tax and other legal
- To maintain accurate customer and operational records;
- To communicate transaction alerts, service information, security notices and other operational
- To manage complaints, disputes, claims and legal matters;
- To protect bank premises, systems, networks, applications and information assets;
- To maintain business continuity, disaster recovery and incident response;
- To improve products, services, processes, customer experience and digital performance;
- To perform lawful analytics and risk-management activities;
- To manage vendors, agents, advisers and business partners; and
- To send marketing communications where permitted by law and in accordance with your preferences.
8. Digital Banking, Mobile Services and Device Information
Where Bethel MFB makes a mobile application, mobile-optimised website, internet-banking service or other digital channel available, the service may process device, security and usage information needed to authenticate users, secure sessions, prevent fraud, provide requested functionality and improve performance.
Where a digital feature seeks access to precise geolocation, contacts, photographs, camera functions, biometrics or other device permissions, the Bank should provide an appropriate notice and obtain the permission or consent required by applicable law and the relevant device platform.
Customers should use only official Bethel MFB channels and should never disclose passwords, PINs, card PINs or one-time passwords (OTPs) to anyone.
9. Cookies and Similar Technologies
Our website may use cookies and similar technologies for security, essential website functionality, user preferences, analytics and other approved purposes.
Strictly necessary cookies may operate where they are required to provide or secure the website. Non- essential cookies should be activated only after the user has been given the required choice or consent.
Users should be able to reject non-essential cookies and manage their preferences.
Further details about cookie categories, providers, purposes and retention periods should be provided in Bethel MFB’s separate Cookie Notice and live cookie preference centre.
10. Biometrics, CCTV and High-Risk Processing
Where the Bank deploys facial recognition, fingerprint systems, CCTV, systematic monitoring, profiling or another technology that may create a high risk to the rights and freedoms of individuals, the Bank should assess the necessity, proportionality and privacy risks before deployment.
Where required by the NDP Act and NDP Act-GAID, the Bank will conduct and document a Data Privacy Impact Assessment (DPIA) and implement safeguards before or in connection with the relevant processing.
11. Automated Decision-Making and Profiling
The Bank may use technology-assisted tools to support credit assessment, affordability checks, fraud detection, transaction monitoring, customer verification and other risk-management activities.
Where a decision is based solely on automated processing and produces legal or similarly significant effects, Bethel MFB will apply the safeguards required by applicable law. Where applicable, a data subject may request human intervention, express their point of view and contest the decision.
12. Disclosure and Sharing of Personal Data
We may disclose personal data only where there is an appropriate lawful basis and the disclosure is reasonably necessary for the stated purpose. Recipients may include:
regulators;
financial-sector infrastructure;
institutions involved in a transaction;
powers;
and
corporate transaction.
Service providers that process personal data on our behalf are expected to act only on authorised instructions, maintain appropriate confidentiality and security safeguards, and comply with applicable data- protection obligations.
- The Central Bank of Nigeria (CBN), Nigeria Deposit Insurance Corporation (NDIC) and other competent
- The Nigeria Inter-Bank Settlement System (NIBSS), identity-verification platforms and other authorised
- The national identity management commission (NIMC), where applicable;
- Licensed credit bureaus and fraud-prevention service providers;
- Payment processors, switches, settlement providers, correspondent institutions and other financial
- Courts, law-enforcement agencies, tax authorities and other public authorities acting within their lawful
- Auditors, legal advisers, insurers and other professional advisers;
- Technology, cybersecurity, cloud, communications, data-storage and support service providers;
- Debt-recovery, collateral-management or field-support providers where lawfully engaged;
- Agents, co-operatives, partners or other parties involved in delivering an authorised product or service;
- Another entity in connection with a lawful merger, restructuring, acquisition, transfer or similar
13. International Transfers of Personal Data
Where personal data is transferred outside Nigeria, Bethel MFB will apply a lawful cross-border transfer mechanism and appropriate safeguards in accordance with the NDP Act, the NDP Act-GAID and applicable NDPC requirements.
Depending on the circumstances, this may involve an adequacy assessment, approved or recognised contractual safeguards, another lawful transfer basis, or consent where consent is legally appropriate. The Bank will document the basis relied upon for material international transfers.
14. Information Security
Bethel MFB applies administrative, technical and physical safeguards appropriate to the nature and risk of the personal data it processes. These may include access controls, strong authentication, encryption, secure configuration, network protection, endpoint security, logging and monitoring, backup and recovery controls, vulnerability management, incident-response procedures, staff confidentiality obligations, vendor controls and security-awareness training.
Access to personal data is limited to authorised persons who require it for legitimate business, legal or regulatory purposes.
No technology environment can be guaranteed to be completely secure. The Bank therefore reviews security controls and responds to emerging risks, incidents and vulnerabilities.
15. Personal Data Breaches
Where Bethel MFB becomes aware of a personal data breach, the Bank will assess the nature and risk of the incident, take reasonable steps to contain and remediate it, preserve relevant evidence and comply with applicable notification obligations.
Where required by the NDP Act, the Bank will notify the NDPC and, where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, communicate the breach to affected data subjects in plain and clear language.
16. Retention of Personal Data
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and for periods required by banking, KYC/AML, audit, tax, regulatory, fraud-prevention, dispute, litigation and record-retention obligations.
Closing an account or withdrawing consent does not automatically require deletion of information that the Bank must retain to comply with law, regulation, contractual obligations, fraud-prevention requirements or the establishment, exercise or defence of legal claims.
When personal data is no longer required, it will be securely deleted, destroyed or anonymised in accordance with the Bank’s approved retention and disposal procedures.
17. Privacy by Design and Data Privacy Impact Assessment
Bethel MFB seeks to apply privacy by design and by default when introducing new products, technology, digital channels, software, surveillance systems or material changes in processing.
A DPIA will be conducted where processing is likely to create a high risk to the rights and freedoms of data subjects and in other circumstances required by applicable NDPC rules. The assessment should consider the purpose of processing, necessity, proportionality, risks, security controls and measures for protecting data-subject rights.
18. Your Data-Protection Rights
Subject to applicable law and lawful exceptions, you may have the right to:
to that data;
applicable; and
A request may be subject to identity verification and lawful limitations. Where providing a copy of personal data would impose unreasonable costs, the Bank may require the data subject to bear some or all of those costs only to the extent permitted by applicable law.
- Obtain confirmation of whether bethel mfb is processing personal data about you and request access
- Request correction of inaccurate, incomplete, outdated or misleading personal data;
- Request erasure where the data is no longer necessary and there is no other lawful basis for retention;
- Request restriction of processing in appropriate circumstances;
- Object to processing in appropriate circumstances;
- Object at any time to processing for direct marketing;
- Withdraw consent where processing is based on consent;
- Exercise data-portability rights where applicable;
- Obtain safeguards relating to certain automated decisions and request human intervention where
- Lodge a complaint with the nigeria data protection commission.
19. Marketing Communications
Bethel MFB may send information about products and services where permitted by law. Where consent is required for a marketing activity, we will obtain it.
You may object to or opt out of direct marketing at any time using the method provided in the communication or by contacting the Bank. Transaction alerts, security notices, legal notices and essential service communications are not marketing and may still be sent where necessary.
20. Children and Persons Who Cannot Lawfully Consent
Where the Bank offers an account or service intended for a minor or another person who does not have legal capacity to provide the required consent, Bethel MFB will process the information in accordance with applicable law and obtain the involvement, authorisation or consent of a parent, guardian or other legally authorised person where required.
The Bank will not rely on a blanket rule that every person below 18 may independently consent to every form of data processing. The applicable legal requirement and the nature of the service will be considered.
21. Third-Party Websites and Services
Our website or digital services may contain links to third-party websites or services. Those third parties may have their own privacy practices and notices.
Where Bethel MFB selects a third party to process personal data on our behalf, we will apply appropriate due diligence and contractual safeguards. Where you independently choose to visit a third-party website, that third party’s privacy notice will generally govern its own processing.
22. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in law, regulation, technology, our products or our processing activities. The current version will be published on our official website with the effective or last- updated date.
Where a change materially affects how we process personal data, we will provide additional notice where required. Continued use of a Bank service will not, by itself, be treated as consent to a new processing purpose where the law requires specific consent.
23. Contact, Privacy Requests and Complaints
For questions, privacy requests or complaints concerning personal data, please contact:
The Data Protection Officer / Privacy Contact Bethel Microfinance Bank Limited Suite B1, Elim Plaza No. 1 Ebeano Tunnel Crossing Road Off Ogui Road, Enugu Enugu State, Nigeria P.O. BOX 9558 Enugu Email: info@bethelmfb.com Telephone: +2348145815504 +2349137486970 Website: https://www.bethelmfb.com You may also lodge a complaint with the Nigeria Data Protection Commission if you believe your rights under applicable data-protection law have been infringed.
Before website publication, Bethel MFB should confirm that the email address and telephone number above are active and monitored for privacy requests.
