Our Commitment to Privacy
At MainTrust MFB Plc, we recognize the importance of protecting the privacy and confidentiality of personal information entrusted to us by our customers, employees, vendors, partners, visitors, and other stakeholders.
We are committed to ensuring that personal data is collected, processed, stored, and protected responsibly, transparently, and in compliance with applicable data protection laws and regulatory requirements.
This Privacy Policy explains the types of personal data we collect, why we collect it, how we use it, who we may share it with, how long we retain it, and the rights available to individuals regarding their personal information.
1.Introduction and Scope
This Privacy Policy has been developed in accordance with the provisions of the Nigeria Data Protection Act (NDPA) 2023, applicable regulations issued by the Nigeria Data Protection Commission (NDPC), and other relevant international data protection frameworks, including the European Union General Data Protection Regulation (EU GDPR), where applicable.
The policy outlines how MainTrust MFB collects, processes, uses, stores, and protects personal data belonging to customers, employees, vendors, visitors, applicants, business partners, and other individuals who interact with the Bank.
MainTrust MFB is committed to applying the principles of lawful, fair, transparent, and secure processing of personal data. This policy is reviewed periodically and updated where necessary to ensure continued alignment with regulatory requirements, industry standards, and privacy best practices.
This document also explains the rights of data subjects and the measures available to them to exercise control over their personal information.
2.Roles and Responsibilities
The Data Protection Officer (DPO) of MainTrust MFB is responsible for overseeing compliance with this Privacy Policy and ensuring that it remains accurate, current, and aligned with applicable data protection requirements.
The DPO is responsible for ensuring that:
- Data subjects are appropriately informed before their personal data is collected and processed.
- Privacy notices are made available through relevant channels, including the Bank's website and digital platforms.
- Data processing activities comply with applicable privacy laws and internal policies.
- Data protection risks are identified, assessed, and appropriately managed.
All MainTrust MFB employees, contractors, and third parties who handle personal data are required to comply with this Privacy Policy and ensure that personal information is processed securely and responsibly.
3.Policy Statement
MainTrust MFB Plc is committed to safeguarding the privacy, confidentiality, and security of personal data entrusted to us.
As a data controller, MainTrust MFB determines the purposes and methods through which personal data is processed and ensures that all processing activities comply with applicable data protection laws.
In accordance with the Nigeria Data Protection Act (NDPA), MainTrust MFB provides transparency regarding:
- The personal data collected.
- The purpose for processing personal data.
- The legal basis for processing.
- Third parties with whom information may be shared.
- Data retention periods.
- Rights available to data subjects.
3.1.About MainTrust MFB Plc
MainTrust MFB Plc is a technology-driven financial institution committed to providing innovative financial solutions and superior banking services to individuals, businesses, and other stakeholders.
The Bank leverages digital technology, operational excellence, and industry best practices to deliver secure, reliable, and customer-focused financial services.
As part of its operations, MainTrust MFB processes personal data belonging to customers, employees, vendors, regulatory bodies, business partners, and other stakeholders to provide financial services, comply with legal obligations, manage operations, and improve customer experience.
Due to the nature of financial services provided by the Bank, personal data may be collected and processed from individuals within Nigeria and, where applicable, individuals residing in other jurisdictions.
3.2.Categories of Personal Data We Collect
Depending on the nature of the service or interaction, MainTrust MFB may collect and process the following categories of personal data:
| Data Category | Description |
|---|---|
| Identity Data | Full name, title, date of birth, gender, nationality, marital status, biometric information, National Identification Number (NIN), passport details, driver's licence details, employment information, and other identity verification information. |
| Contact Data | Residential address, email address, telephone numbers, communication records from emails, calls, SMS, letters, and physical interactions. |
| Financial Data | Bank account details, Bank Verification Number (BVN), income information, financial records, account statements, credit information, debit/credit card details, and transaction-related financial information. |
| Transaction Data | Details of products and services accessed, payment transactions, account activities, card usage information, and transaction locations where applicable. |
| Technical Data | IP address, device information, browser details, operating system, login information, location information, cookies, device identifiers, and online activity information. |
| Profile Data | Usernames, passwords, account preferences, customer profiles, and service preferences. |
| Recruitment Data | Information provided during employment applications, including names, contact details, qualifications, employment history, and supporting documents. |
| Usage Data | Information regarding interaction with MainTrust MFB websites, applications, products, and digital services. |
| Marketing and Communication Data | Communication preferences, marketing consent records, and interactions with the Bank. |
| Other Data | CCTV recordings, call recordings, ATM monitoring information, and other security-related records. |
3.3.Processing of Biometric and Facial Data
Where MainTrust MFB collects biometric information or facial recognition data, such information shall be processed responsibly and securely in accordance with applicable data protection requirements.
Collection
Biometric and facial data may be collected through secure channels, including mobile applications, ATMs, digital platforms, and other approved verification systems, where required and appropriately authorized.
Purpose of Use
Biometric information may be used for:
- Identity verification.
- Fraud prevention.
- Authentication.
- Enhancing security of banking services.
- Providing approved personalized services.
Disclosure
Biometric information will only be shared where necessary with trusted third parties, regulatory authorities, payment partners, or service providers operating under appropriate confidentiality and data protection obligations.
Retention
Biometric data shall only be retained for as long as necessary to fulfill regulatory, operational, contractual, or legal obligations. Where retention is no longer required, the data will be securely deleted, destroyed, or anonymized.
Consent
Where required by law, explicit consent will be obtained before collecting and processing biometric information.
