The Office of the Data Protection Commissioner received a complaint from Rose Muigai against NCBA Group, alleging that the bank disclosed her personal data to third parties, who were former employees, without a lawful basis. The Office investigated the complaint and found that the violation occurred between May 2023 and June 2024, after the third parties had ceased working for the bank. The critical question of how the former employees accessed the complainant's personal data without valid credentials or access logs remained unaddressed by the bank. The Office determined that the bank failed to fulfill its obligations under Sections 25(a), 41, and 43 of the Data Protection Act, 2019, which require data controllers to process personal data in accordance with the right to privacy, implement appropriate technical and organizational measures, and report personal data breaches to the Commissioner. Consequently, the Office ordered the bank to compensate the complainant KES 250,000 for the unlawful and unauthorized disclosure of her personal data and issued an enforcement notice against the bank. The determination highlights the importance of robust data protection measures and the consequences of failing to safeguard personal data, even from former employees.
🔒 Guarding Data Isn’t Just Child’s Play - its REAL! 🔒 This ruling is a clear message: when it comes to data, no one should cut corners! Just like in safeguarding, protecting personal info means honoring consent and keeping things transparent. No more "borrowed" permissions - data privacy deserves the same respect as safeguarding people. A big win for accountability and a big step toward a safer digital world!
Oh, the determination has made its way here. This is cool. Iwe funzo Kwa wengine.👍
Equity Bank Limited You are headed to spamming me! _ I'm headed to lodge my Complaint (when due) too, to @Office of the Data Protection Commissioner
Fantastic update!
Interesting times - Clear reminder of the critical need for robust data safeguards!
Caroline Oyula Caroline Nungari, CHRP(K) Vuhya N. Amulyoto, CHRP, MIHRM (K)
Very helpful
Very informative
Founder & C.E.O at Peachy Village Company Limited
1moWow that's why I'm in love with KENYA , you know know I'm from the coastal ( Mombasa, Lamu), back to the post that's how regulator should act on matters regarding complaints, it's justify accountability, reliability, transparency, justice, professionalism, No double standards etc...but in Tanzania you can report a forgery and unauthorized action of the commercial bank opened the company's account to UNAUTHORIZED PERSONS WITHOUT THE CONSENT OF RIGHTFUL OWNERS And still no investigation, no resolution no any kind of assistance ..Bank of Tanzania Emmanuel Tutuba EMMANUEL TUTUBA should learn from our neighbor specifically KENYA..We should not take advantage of small brands against biggest brands pamoja na umaarufu wa viongozi wa taasisi au makampuni...I'm the Victim of the system and I'm not ready to be silenced until I get justice to my company funds