Terms & Privacy Policy
PRIVACY POLICY | UPDATED: APRIL 23, 2025.
Sterling Bank values and respects the privacy of the people we deal with. Sterling Bank is committed to protecting your privacy and complying with the Data Protection Act (2023) of Nigeria and other applicable data privacy laws and regulations.
This Privacy Policy (“Policy”) describes how we collect, hold, use and disclose your personal information, and how we maintain the quality and security of your personal information. Throughout this document, “Sterling”, “Bank”, “we”, “us”, “our” and/or “ours” refer to Sterling Bank Ltd incorporated under the laws of the Federal Republic of Nigeria with its registered office at Sterling Towers, 20 Marina, Lagos. The reference to ‘you’ or ‘your’, means you, any authorised person on your account, anyone who conducts your banking services for you or other related people (including authorised signatories, partners or any authorised third party).
The information we collect about you
We collect several different types of information for various purposes to provide and improve our services to you.
We may also collect your information at events hosted or organised by or for the bank, regardless of whether such an event is a physical or virtual one. The Personal Data we collect, fall into various categories, such as:
- Personal Data: While using our services, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally, identifiable information may include, but is not limited to Name and Contact Data: We collect your first, middle and last name, email address, bank verification number, postal address, phone number, signature, date of birth, an identification document such as a copy of driver’s license, international passport, national identity card, Bank Verification Number (BVN), and other similar contact data.
- Payment Data: If you subscribe to our ATM card products, we will issue you ATM cards with unique numbers called Personal Access Number (PAN), Personal Identity Number (PIN), and Card Verification Number. You are required to keep your card and these security numbers from being accessed by another person. For certain payment cards, a default PIN may be provided by us. In such circumstances, you are required to change the default PIN to a new PIN to enable activation and/or use of the card. When you carry out transactions or enrolment related to card services or online services, these card security numbers or any of them may be required for authentication. We collect the data necessary to process your payment if you make payments or transfers, such as your card number and the security code associated with your payment card. All payment data is processed, transmitted, and stored securely in line with PCI DSS requirements.
- Sensitive Data: We may hold information about you which includes without limitation health, criminal conviction information or biometric information used to uniquely identify you, (for example your fingerprint, facial recognition or voice recording). We will only hold this data when we need to for the purposes of the product or services we provide to you, where we are required to process the data for a public interest purpose, or where we have a legal obligation or your consent to do so.
- Credentials: when you subscribe to any of our products, particularly our e-channel products (Online/Mobile Banking, Instant Banking, Mvisa), you may be required to provide a User ID, a password, details from a token response device, password hints, and similar security information used for authentication and account access. You may also be required to use biometric identification to access your account and authenticate transactions. While this information is required to ensure that you carry out transactions securely, appropriate security measures have been implemented to protect this data, including encryption and storage in a secured environment if required.
- Usage Data: We may also collect information that your browser sends whenever you access our online services or when you access the services by or through a mobile device (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data. When you access services on or through a mobile device, this Usage Data may include:
- Geo-Location information: We may request access to or permission to track location-based information from your mobile device, either continuously or while you are using our mobile application, to provide location-based services. If you wish to change our access or permissions, you may do so in your device’s settings.
- Mobile Device Access: We may request access or permission to certain features on your mobile device, including your mobile device’s camera, calendar, Bluetooth, contacts, storage, and other features. If you wish to change our access or permissions, you may do so in your device’s settings.
- Mobile Device Data: We may automatically collect device information (such as your mobile device ID, model, and Manufacturer), operating system, version information, IP address, and diagnostic data.
- Use of Analytics to Collect, Monitor, and Analyse Data.
We may use third-party Service Providers to monitor and analyse the use of our Service. We may also collect information about your marketing preferences to provide you with information about relevant services, products, and offers that we think may be of interest to you. - Google Analytics
Google Analytics is a web analytics service offered by Google that tracks and reports website and mobile app traffics and events, currently as a platform inside the Google Marketing Platform brand. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads on its own advertising network. For more information on the privacy policies of Google, please visit the Google Privacy and Terms web page located at https://policies.google.com/privacy?hl=en. - Tracking and Cookies Data
We use cookies and similar tracking technologies to track the activity on our Services and hold certain information. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyse our Service. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. You can also refuse permissions to read your phone data by the mobile application. However, if you do not accept cookies on your browser or allow permissions on your mobile device, our online service experience to you may be degraded and you may not be able to use some portions of our Service. We may also collect information about your internet browser settings and Internet Protocol (IP) address and other relevant information to help us identify your geographic location when providing you with our services.- Examples of Cookies we use:
- Session Cookies: We use Session Cookies to operate our Service. Session cookies will expire at the end of your browser session and allow us to link your actions during that browser session.
- Preference Cookies: We use Preference Cookies to remember your preferences and actions, across multiple sites.
- Security Cookies: We use Security Cookies for security purposes.
- Third-party cookies: These cookies are placed by third-party websites that we use for website functionality and analytics. We have no control over these cookies.
- You can learn more about how we use cookies in our Cookie Policy (https://sterling.ng/cookie-policy/)
- Examples of Cookies we use:
- Information from social networks or online accounts: This includes Information from any social media profiles or any accounts that you share with us.
- Information which you have consented to us using and other personal information: Other personal data which we collect includes image recordings this could include CCTV images of you at our bank branches, offices and ATMs but only for surveillance, monitoring and auditing purposes, to help forestall crime.
How we use your personal Information
To the extent permissible under applicable law, we may use your information for the following legitimate actions:
- Determine your eligibility for our products and services.
- Verify your identity when you access your account information.
- Administer your accounts or other products and services that we or our partners/affiliates may provide to you.
- Respond to your requests and communicate with you.
- For understanding your financial needs
- Prevention of crime, fraud, money laundering or terrorism financing activities
- Managing our risks
- Reviewing credit or loan eligibility.
- For marketing the products and services of Sterling, related entities and affiliates. We may send you marketing and promotional messages by post, email, telephone, text, secure messaging, Mobile app, or through our social media channels. You can change your mind on how you wish to receive marketing messages from us, or opt out of receiving such messages at anytime. However, we will continue to use your contact details to send you important information regarding your dealings with us.
- Process transactions, design products and profile customers
- Notify you about changes to our Services.
- Allow you to participate in interactive features of our Services when you choose to do so.
- Provide customer care and support and for internal operations, including troubleshooting, data analysis, testing, security, fraud-detection, and account management.
- Process your information for audit, statistical or research purposes in order to help us understand trends in our customer behaviour and to understand our risks better and curate products and services that are suitable to our customers’ needs.
- Monitor our conversation with you when we speak on the telephone (for example, to check your instructions to us, to analyse, to assess and improve customer service; for training and quality assurance purposes; for verification, fraud analysis and prevention purposes
- Recover any debts that you may owe the Bank.
- Carry out analysis to evaluate and improve our business.
- Monitor the usage of our Services
- Detect, prevent and address technical issues.
- Prevent fraud and enhance security of your account or our service platform.
- Comply with and enforcing applicable legal and regulatory requirements, relevant industry standards, contractual obligations and our policies.
- Provide you with tailored content and marketing messages such as recommending other products or services we believe you may be interested in
- For other purposes required by law or regulation
How do we share your information?
We may share the information about you and your dealings with us, to the extent permitted by law, with the following:
- Sterling Branches and related entities
- Legal/Regulatory Authorities – It may be necessary by law, legal process, litigation, and/or requests from public and governmental authorities for Sterling to disclose your personal information. We may also disclose information about you if we determine that for purposes of national security, law enforcement, or other issues of public importance, disclosure is necessary or appropriate.
- Professional Advisers: Auditors/Legal Advisers
- Credit Agencies.
- Correspondent Banks.
- External Auditors.
- Strategic partners/service providers – for the purpose of providing our services to you. Your Personal information will not be shared with third parties for their marketing purposes.
We may also disclose your Personal Information in good faith and belief that such action is necessary in any of the following circumstances:
- We have your consent to share the information.
- To comply with a legal obligation.
- To bring you improved service across our array of products and services, when permissible under relevant laws and regulations, by disclosing your personal information with Sterling Bank’s affiliated websites and businesses.
- To protect and defend the rights or property of the Bank.
- To prevent or investigate possible wrongdoing in connection with our Service.
- To protect the personal safety of users of our Service or the public.
- To protect against legal liability.
- in the event of a reorganisation, merger, or sale we may transfer any and all personal information we collect to the relevant third party or
- We find that your actions on our web sites or banking applications violate any part of our Privacy Policy.
Joint Account Holders
When you open or use a joint account, your Personal Data will be shared with the other Account Holder. For instance, the joint account holder will be able to see transactions made by you. We may act on the authority of one joint Account Holder to share or allow a third-party access to your account information for the provision of payment services, including transaction details. In this regard, we will treat the authority of one Account Holder as authorization on behalf of the other Account Holder.
Guarantors
We may share your information with any person or entity which guarantees your credit obligations to us as part of security requirement for a credit scheme or facility advanced to you.
Transfer of Data
These days, both the world and the delivery of banking services are interconnected. For instance, there could be many counterparties involved for a card transaction to be successfully completed. These include the card personalization companies, the switching companies, processors, acquirers, merchants, and the card schemes. Certain personal data will traverse these parties in the normal course of carrying out transactions.
Save as related to the provision of banking services and meeting legal, regulatory, contractual, and other uses tangential or incidental to these, Sterling will not share your personal data with a third party.
Where it becomes necessary to do so, adequate security measures will be taken to protect the data from access by recipients other than those for which it is intended. All data we collect will reside in Sterling’s computer systems in Nigeria. Where cloud services are used, adequate governance measures that apply to such cloud services will be complied with.
Sterling will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. No transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
How we secure your Information
We have implemented appropriate organizational and technical measures to keep your Personal Information/Data confidential and secure. This includes the use of encryption, access controls and other forms of security to ensure that your data is protected. We require all parties including our staff and third-parties processing data on our behalf to comply with relevant policies and guidelines. Where you have a password which grants you access to specific areas on our site or to any of our services, you are responsible for keeping this password confidential. We request that you do not share your password or other authentication details (e.g., token generated codes) with anyone.
Although we have taken measures to secure and keep your information confidential, because the security of your data is important to us, please be aware that no method of transmission over the Internet, or method of electronic storage can guarantee 100% security at all times. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security, you are responsible for securing and maintaining the privacy of your password and Account/profile registration information and verifying that the Personal Data we maintain about you is valid, accurate and up to date. If we receive instructions using your account login information, we will consider that you have authorised the instructions and process your instruction accordingly and without incurring any liability for doing so.
How long we keep your information
We retain your Information for as long as the purpose for which the information was collected continues. The information is then securely destroyed unless its retention is required to satisfy legal, regulatory, internal compliance or accounting requirements or to protect Sterling’s interest.
Please note that regulations may require Sterling to retain your personal data for a specified period even after the end of your banking relationship with us.
Information from locations outside Nigeria
If you are located outside Nigeria and choose to provide information to us, please note that the data, including Personal Data, will be processed in Nigeria. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Accuracy and update of your Information
You are responsible for making sure the information provided to the Bank is accurate and should inform the Bank on any changes as it occurs, this will enable us to update your information with us.
Any changes will affect only future uses of your Personal Information. Subject to applicable law, which might, from time to time, oblige us to store your Personal Information for a certain period of time, we will respect your wishes to correct inaccurate information. Otherwise, we will hold your Personal Information for as long as we believe it will help us achieve our objectives as detailed in this Privacy Policy.
Your Rights
You have certain rights in relation to the personal data we collect as provided by the enacted Data Protection Act (DPA 2023) of Nigeria, these rights include:
- A right to access your personal data.
- A right to rectify/update your information in our possession.
- A right to request the erasure of personal data.
- A right to withdraw your consent to processing of personal data. This will however not affect the legality of processing carried out prior to any such withdrawal.
- Right to object to processing of personal data. This will only be applicable where there are no legal or operational reasons.
- Request that your personal data be made available to you in a common electronic format and/or request that such data be sent to a third party.
- Request that your information be erased. We might continue to retain such data if there are valid legal, regulatory or operational reasons.
- Right to opt-out of marketing communications.
- A right to make an official complaint to the Nigeria Data Protection Commission (NDPC)
If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. Please note, however, that this will not affect the lawfulness of the processing before its withdrawal.
These rights are however subject to certain limitations as provided under the Nigeria Data Protection Act 2023.
Privacy of minors
The Bank has a children’s account called the I-Can-Save Kiddies account and may provide other children’s account types from time to time. These accounts are opened and run by a child’s parent or guardian until the child reaches the age of majority. All personal information pertaining to such account is provided by the guardian. A parent or guardian should therefore read this policy thoroughly to understand how the data provided is handled.
Students of tertiary institutions with valid identification, an admission letter to a tertiary institution, and passport photographs can open the TrybeOne (Campus Hype Account). Such customers’ personal data will be processed as adult’s data as long as the individual is above the age of thirteen (13), as contained in the Nigeria Data Protection Act 2023.
Sterling Bank information meant for public use Other than as related to the operation of the aforementioned children’s account and student’s account, the Bank does not enter into banking relationships with minors (persons under the age of 16). We do not knowingly collect personally identifiable information from anyone under the age of 16, except under the conditions stated above. If you are a parent or guardian and you are aware that your children have provided us with Personal data; please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we will take steps to remove that information from our servers.
Social Media Platforms
We operate and communicate through our designated pages and accounts on some social media platforms to communicate and engage with our customers. We monitor and record comments and posts made about us on these channels so that we can improve our Services. The general public can access and read any information posted on these sites. Please note that any content you post to such social media platforms is subject to the applicable social media platform’s terms of use and privacy policies. We recommend that you review the information carefully in order to better understand your rights and obligations regarding such content.
Our Services may allow you to connect and share your actions, comments, content, and information publicly or with friends. We are not responsible for maintaining the confidentiality of any information you share publicly or with friends.
Our Services may also allow you to connect with us on, share on, and use third-party websites, applications, and services. Please be mindful of your personal privacy needs and the privacy needs of others, as you choose whom to connect with and what to share and make public. We cannot control the privacy or security of information you choose to make public or share with others. We also do not control the privacy practices of third parties. Please contact those sites and services directly if you want to learn about their privacy practices.
Career Platforms
As part of our recruitment process and as an applicant, you explicitly consent to the collection, use, transfer, and storage or in any other form of your personal data contained in application forms/letters, curriculum vitae (CV)/resumes obtained from your identity document(s) or collected through interviews/other forms assessment by Sterling Bank Ltd or its affiliates. This information is for the exclusive purpose of assessing and evaluating applicants’ suitability for employment in any current or prospective position within our organisation, verifying applicants’ identity and the accuracy of your details provided to us or for other related purposes. We shall, in line with our internal policies, controls and relevant Data Protection Regulations ensure that this data is not disclosed or assessed by unauthorised persons. By providing any information on Sterling’s career page, you confirm that you have read the terms and privacy statement and accept it. As an applicant, you consent to Sterling Bank using the data provided in accordance with terms described above.
Third Party Websites
Our website, related websites and mobile applications may have links to or from other websites that are not operated by us. We have no control over and assume no responsibility for the security, privacy practices or content of third-party websites or services. We recommend that you always read the privacy and security statements on these websites.
Service Providers
We may employ third party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform specific Service-related roles or to assist us in analysing how our Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose outside of the service-specific need for which the data is required.
Public Appearance and Events
If you register and/or attend our events, you may be photographed, recorded and/or videotaped by the Bank and/or those acting under its authority, in relation to your attendance and/or participation at such event. You acknowledge that the Bank and its affiliates may, without payment to you, copyright, publish, reproduce, exhibit, transmit, broadcast, televise, digitize, display, otherwise use materials containing your Personal Data, more specifically: (a) your name, image, likeness, and voice; (b) photographs, recordings, videotapes, audiovisual materials, writings, statements, and quotations of or by you; (c) the negatives, transparencies, prints, or digital information (collectively, the “Materials”), pertaining to you, in still, single, multiple, moving, video or animation format, or in which you may be included in whole or in part, or composite, or distorted in form, or reproductions thereof, in color or otherwise in any other manner, form or format whatsoever and for any lawful purpose, including, but not limited to, advertising or promotion of the Bank, its brand, affiliates or services.
All Materials (as defined above), collected at our events remain the sole property of the Bank. Notwithstanding, the Bank shall not share your personal data with an unauthorized third party or process your Personal Data under this sub-section for any unlawful purpose.
Changes to this Policy
This Privacy Policy is effective as of the date stated above and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on our website.
Based on the changing nature of privacy laws, user needs and our business, we may modify this Privacy Policy from time to time. Any change to our privacy policy will be communicated on our website, via email or by placing a notice on our Platform and this will be effective as soon as published. Accordingly, we encourage periodic reviews of this Privacy Policy for awareness of any changes that may have occurred. Your continued use of the Services after we post any modifications to the Privacy Policy on our website will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.
Contact Us
If you have any questions, comments or requests in relation to this Privacy Policy or objections, complaints or requirements in relation to the use of your personal data, please contact us by sending an email to [email protected] or 02018888822 / 07008220000, or write a letter addressed as follows:
The Data Protection Officer
Sterling Bank Limited
20 Marina, Lagos.