Privacy & data
Loan apps, permissions and your privacy
- Why permissions matter
- Which permissions are common and why
- The contacts-scraping problem
- Your rights under the NDPC
- How to protect your data
Why permissions matter
When you install a loan app, it asks your phone for permissions — access to your contacts, your photos, your location, your camera, and more. On the surface these pop-ups look routine. In reality, the permissions an app asks for tell you a great deal about how the lender behaves. A loan app that needs your photos to scan an ID is one thing; an app that demands your entire contacts list and your file storage is another matter entirely.
Which permissions are common, and why
- Camera / storage: an app may legitimately want this so you can photograph an identity document for verification.
- Location: sometimes used for fraud checks. Reasonable but not essential for a small loan.
- Contacts: not needed to verify identity. This is the permission that loan-shark apps most commonly abuse.
- Call logs / SMS: again, not a normal part of a legitimate loan check.
The pattern to worry about is any permission that lets the app learn about everyone you know, or that lets it read personal messages and files far beyond what a loan decision needs.
The contacts-scraping problem
Predatory loan apps are known for harvesting the entire contact list and using it as a tool of pressure. If you fall behind, they call, text and shame your family, friends and even your employer to force you to pay. This is not legitimate collection practice — it is intimidation and it violates your privacy.
Why would a real lender need to know your whole network just to check you can repay a small amount? The honest answer is that it would not. A licensed lender verifies your identity through official channels. It does not need your contacts.
Your rights under the NDPC
In Nigeria your personal information is protected. The Nigeria Data Protection Act is supervised by the Nigeria Data Protection Commission (NDPC). Under these rules, entities that handle personal data are supposed to:
- Tell you what data they collect and why.
- Only collect what they actually need.
- Keep your data secure.
- Give you a way to complain if they misuse it.
This means you have grounds to complain when a loan app harvests and misuses your contacts. You can raise a complaint with the data controller (the lender) and, if needed, with the NDPC. For complaints about lending behaviour itself, the CBN is the relevant authority — see your rights as a borrower.
How to protect your data
- Go through official stores — the Google Play Store or Apple App Store — and check reviews.
- Read the permission prompts and deny anything that is not clearly needed.
- Read the app’s privacy policy — even a quick scan tells you whether it collects contacts.
- Prefer licensed lenders from our directory that follow proper identity verification.
- Know when to say no. Denying contacts access is a normal thing for a legitimate lender to handle.
What to do if your data is already misused
If a loan app has already scraped your contacts and used them to harass you, the damage is partly done — but you still have practical routes. First, revoke the app’s permissions in your phone settings and uninstall it once you have noted what you need. Second, take screenshots of the messages, the permission screens, and the app’s own privacy policy as evidence. Third, complain: raise the misuse with the provider and, if needed, escalate to the NDPC for the data breach and to the CBN for the predatory lending behaviour itself. You do not have to accept the situation quietly, and a documented paper trail is what makes any follow-up effective.
The deeper point is that protecting your data and protecting yourself from loan sharks are the same fight. A lender that respects your privacy is usually a lender that respects your rights; a lender that grabs at your contacts is telling you who it is. Give the permission-vetting step a few seconds of attention, and you will already be ahead of most borrowers.